Health Sector Cybersecurity Coordination Center. (2024, June 18). Qilin, aka Agenda Ransomware. Retrieved September 26, 2025.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareQilin | Qilin can identify specific services for termination or to be left running at execution. |
| T1027.013 Encrypted/Encoded File |
MalwareQilin | Qilin can employ several code obfuscation methods, including renaming functions, altering control flows, and encrypting strings. |
| T1057 Process Discovery |
MalwareQilin | Qilin can define specific processes to be terminated or left alone at execution. |
| T1486 Data Encrypted for Impact |
MalwareQilin | Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys. |
| T1489 Service Stop |
MalwareQilin | Qilin can terminate specific services on compromised hosts. |
| T1657 Financial Theft |
GroupWater Galura | Water Galura has extorted victims for ransomware decryption keys and to prevent publication of data exfiltrated to their Tor data leak site. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.