Takeda, T. et al. (2025, October 26). Uncovering Qilin attack methods exposed through multiple cases. Retrieved March 26, 2026.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
MalwareCobalt Strike | Cobalt Strike can leverage the HTTP protocol for C2 communication, while hiding the actual data in either an HTTP header, URI parameter, the transaction body, or appending it to the URI. Cobalt Strike has also added Host: ocsp.verisign.com to HTTP headers to mimic Online Certificate Status Protocol (OCSP) traffic. |
| T1007 System Service Discovery |
MalwareQilin | Qilin can identify specific services for termination or to be left running at execution. |
| T1018 Remote System Discovery |
MalwareQilin | Qilin can enumerate domain-connected hosts during its discovery phase. |
| T1021.002 SMB/Windows Admin Shares |
MalwareQilin | Qilin can embed a copy of PsExec within its payload and place it in the %Temp% directory under a randomly generated filename. |
| T1021.004 SSH |
MalwareQilin | Qilin can enable SSH access on ESXi hosts. |
| T1036.004 Masquerade Task or Service |
MalwareQilin | Qilin has created a scheduled task named TVInstallRestore to mimic TeamViewer. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareQilin | Qilin has named its payload file TeamViewer_Host_Setup to disguise itself as a legitimate TeamViewer file. |
| T1047 Windows Management Instrumentation |
MalwareQilin | Qilin can use WMIC to change the Volume Shadow Copy Service (VSS) startup type to manual. |
| T1053.005 Scheduled Task |
MalwareQilin | Qilin has pushed scheduled tasks via Group Policy Objects (GPOs) for execution. Qilin has also created a scheduled task named TVInstallRestore, configured to run at logon using the `/SC ONLOGON` argument. |
| T1057 Process Discovery |
MalwareQilin | Qilin can define specific processes to be terminated or left alone at execution. |
| T1059.001 PowerShell |
MalwareQilin | Qilin has been deployed on VMware vCenter and ESXi servers via custom PowerShell script. Qilin has also used PowerShell for discovery in vCenter and Active Directory environments. |
| T1059.003 Windows Command Shell |
MalwareQilin | Qilin has run `cmd /C [PsExec] -accepteula \\IP Address -c -f -h -d -i |
| T1069.002 Domain Groups |
MalwareQilin | Qilin can run PowerShell cmdlets to discover domain groups. |
| T1087.002 Domain Account |
MalwareQilin | Qilin can use PowerShell cmdlets to enumerate domain users. |
| T1106 Native API |
MalwareCobalt Strike | Cobalt Strike's Beacon payload is capable of running shell commands without |
| T1112 Modify Registry |
MalwareQilin | Qilin can make Registry modifications to share networked drives between elevated and non-elevated processes and to increase the number of outstanding network requests per client. Qilin can also modify `HKEY_CURRENT_USER\Control Panel\Desktop\Wallpaper` to enable posting of ransom messages. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCobalt Strike | Cobalt Strike can deobfuscate shellcode using a rolling XOR and decrypt metadata from Beacon sessions. The Cobalt Strike loader component can also decrypt the .bss section of the Beacon binary prior to execution. |
| T1222 File and Directory Permissions Modification |
MalwareQilin | Qilin can use symbolic links to redirect file paths for remote and local objects and can use `chmod +x` to make its payload binary executable. |
| T1486 Data Encrypted for Impact |
MalwareQilin | Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys. |
| T1489 Service Stop |
MalwareQilin | Qilin can terminate specific services on compromised hosts. |
| T1490 Inhibit System Recovery |
MalwareQilin | Qilin can execute `vssadmin.exe delete shadows /all /quiet` to remove volume shadow copies and can disable High Availability (HA) and Distributed Resource Scheduler (DRS) in vCenter clusters. |
| T1491.001 Internal Defacement |
MalwareQilin | Qilin can set the wallpaper on compromised hosts to display a ransom message in each encrypted folder. |
| T1497.002 User Activity Based Checks |
MalwareCobalt Strike | The Cobalt Strike loader can use the `MessageBoxA` API to prompt for user interaction as an anti-sandbox measure. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareQilin | Qilin has created a RunOnce autostart entry at `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce*aster = %Public%\enc.exe` pointing to a dropped copy of itself in the Public folder. |
| T1570 Lateral Tool Transfer |
MalwareQilin | Qilin has used PsExec to distribute a second encryptor, named encryptor_1.exe, across the targeted environment. |
| T1673 Virtual Machine Discovery |
MalwareQilin | Qilin can detect virtual machine environments including ESXi hosts, datacenters, and clusters within vCenter environments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.