ATT&CKReferencesHC3 Qilin Threat Profile JUN 2024

HC3 Qilin Threat Profile JUN 2024

Health Sector Cybersecurity Coordination Center. (2024, June 18). Qilin, aka Agenda Ransomware. Retrieved September 26, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareQilin

Qilin can identify specific services for termination or to be left running at execution.

T1027.013
Encrypted/Encoded File
MalwareQilin

Qilin can employ several code obfuscation methods, including renaming functions, altering control flows, and encrypting strings.

T1057
Process Discovery
MalwareQilin

Qilin can define specific processes to be terminated or left alone at execution.

T1486
Data Encrypted for Impact
MalwareQilin

Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys.

T1489
Service Stop
MalwareQilin

Qilin can terminate specific services on compromised hosts.

T1657
Financial Theft
GroupWater Galura

Water Galura has extorted victims for ransomware decryption keys and to prevent publication of data exfiltrated to their Tor data leak site.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.