ATT&CKReferencesTrend Micro Agenda Ransomware AUG 2022

Trend Micro Agenda Ransomware AUG 2022

Magdy, S. et al. (2022, August 25). New Golang Ransomware Agenda Customizes Attacks. Retrieved September 26, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareQilin

Qilin can identify specific services for termination or to be left running at execution.

T1012
Query Registry
MalwareQilin

Qilin can check `HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control SystemStartOptions` to determine if a machine is running in safe mode.

T1016
System Network Configuration Discovery
MalwareQilin

Qilin can accept a command line argument identifying specific IPs.

T1053.005
Scheduled Task
MalwareQilin

Qilin has pushed scheduled tasks via Group Policy Objects (GPOs) for execution. Qilin has also created a scheduled task named TVInstallRestore, configured to run at logon using the `/SC ONLOGON` argument.

T1055.001
Dynamic-link Library Injection
MalwareQilin

Qilin can inject pwndll.dll, a patched DLL from the legitimate DLL WICloader.dll, into svchost.exe for continuous execution.

T1057
Process Discovery
MalwareQilin

Qilin can define specific processes to be terminated or left alone at execution.

T1083
File and Directory Discovery
MalwareQilin

Qilin can exclude specific directories and files from encryption.

T1087.001
Local Account
MalwareQilin

Qilin can list all local users found on a targeted system.

T1106
Native API
MalwareQilin

Qilin can attempt to log on to the local computer via `LogonUserW` and use `GetLogicalDrives()` and `EnumResourceW()` for discovery.

T1135
Network Share Discovery
MalwareQilin

Qilin has the ability to list network drives.

T1484.001
Group Policy Modification
MalwareQilin

Qilin has pushed a scheduled task via a Group Policy Object for payload execution.

T1486
Data Encrypted for Impact
MalwareQilin

Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys.

T1489
Service Stop
MalwareQilin

Qilin can terminate specific services on compromised hosts.

T1490
Inhibit System Recovery
MalwareQilin

Qilin can execute `vssadmin.exe delete shadows /all /quiet` to remove volume shadow copies and can disable High Availability (HA) and Distributed Resource Scheduler (DRS) in vCenter clusters.

T1547.001
Registry Run Keys / Startup Folder
MalwareQilin

Qilin has created a RunOnce autostart entry at `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce*aster = %Public%\enc.exe` pointing to a dropped copy of itself in the Public folder.

T1547.004
Winlogon Helper DLL
MalwareQilin

Qilin can configure a Winlogon registry entry.

T1685
Disable or Modify Tools
MalwareQilin

Qilin can terminate antivirus-related processes and services.

T1688
Safe Mode Boot
MalwareQilin

Qilin can reboot targeted systems in safe mode to avoid detection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.