ATT&CKReferencesCisco Talos Qilin Ransomware OCT 2025

Cisco Talos Qilin Ransomware OCT 2025

Takeda, T. et al. (2025, October 26). Uncovering Qilin attack methods exposed through multiple cases. Retrieved March 26, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples26

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
MalwareCobalt Strike

Cobalt Strike can leverage the HTTP protocol for C2 communication, while hiding the actual data in either an HTTP header, URI parameter, the transaction body, or appending it to the URI. Cobalt Strike has also added Host: ocsp.verisign.com to HTTP headers to mimic Online Certificate Status Protocol (OCSP) traffic.

T1007
System Service Discovery
MalwareQilin

Qilin can identify specific services for termination or to be left running at execution.

T1018
Remote System Discovery
MalwareQilin

Qilin can enumerate domain-connected hosts during its discovery phase.

T1021.002
SMB/Windows Admin Shares
MalwareQilin

Qilin can embed a copy of PsExec within its payload and place it in the %Temp% directory under a randomly generated filename.

T1021.004
SSH
MalwareQilin

Qilin can enable SSH access on ESXi hosts.

T1036.004
Masquerade Task or Service
MalwareQilin

Qilin has created a scheduled task named TVInstallRestore to mimic TeamViewer.

T1036.005
Match Legitimate Resource Name or Location
MalwareQilin

Qilin has named its payload file TeamViewer_Host_Setup to disguise itself as a legitimate TeamViewer file.

T1047
Windows Management Instrumentation
MalwareQilin

Qilin can use WMIC to change the Volume Shadow Copy Service (VSS) startup type to manual.

T1053.005
Scheduled Task
MalwareQilin

Qilin has pushed scheduled tasks via Group Policy Objects (GPOs) for execution. Qilin has also created a scheduled task named TVInstallRestore, configured to run at logon using the `/SC ONLOGON` argument.

T1057
Process Discovery
MalwareQilin

Qilin can define specific processes to be terminated or left alone at execution.

T1059.001
PowerShell
MalwareQilin

Qilin has been deployed on VMware vCenter and ESXi servers via custom PowerShell script. Qilin has also used PowerShell for discovery in vCenter and Active Directory environments.

T1059.003
Windows Command Shell
MalwareQilin

Qilin has run `cmd /C [PsExec] -accepteula \\IP Address -c -f -h -d -i
C:\Users\xxx\<encryptor_1>.exe --password [PASSWORD] --spread --spread-process` to execute its encryptor to target multiple network shares.

T1069.002
Domain Groups
MalwareQilin

Qilin can run PowerShell cmdlets to discover domain groups.

T1087.002
Domain Account
MalwareQilin

Qilin can use PowerShell cmdlets to enumerate domain users.

T1106
Native API
MalwareCobalt Strike

Cobalt Strike's Beacon payload is capable of running shell commands without cmd.exe and PowerShell commands without powershell.exe Cobalt Strike can also use `CreateThreadpoolWait`, `SetThreadpoolWait`, and `MessageBoxA` for sandbox evasion and execution of embedded payloads in memory.

T1112
Modify Registry
MalwareQilin

Qilin can make Registry modifications to share networked drives between elevated and non-elevated processes and to increase the number of outstanding network requests per client. Qilin can also modify `HKEY_CURRENT_USER\Control Panel\Desktop\Wallpaper` to enable posting of ransom messages.

T1140
Deobfuscate/Decode Files or Information
MalwareCobalt Strike

Cobalt Strike can deobfuscate shellcode using a rolling XOR and decrypt metadata from Beacon sessions. The Cobalt Strike loader component can also decrypt the .bss section of the Beacon binary prior to execution.

T1222
File and Directory Permissions Modification
MalwareQilin

Qilin can use symbolic links to redirect file paths for remote and local objects and can use `chmod +x` to make its payload binary executable.

T1486
Data Encrypted for Impact
MalwareQilin

Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys.

T1489
Service Stop
MalwareQilin

Qilin can terminate specific services on compromised hosts.

T1490
Inhibit System Recovery
MalwareQilin

Qilin can execute `vssadmin.exe delete shadows /all /quiet` to remove volume shadow copies and can disable High Availability (HA) and Distributed Resource Scheduler (DRS) in vCenter clusters.

T1491.001
Internal Defacement
MalwareQilin

Qilin can set the wallpaper on compromised hosts to display a ransom message in each encrypted folder.

T1497.002
User Activity Based Checks
MalwareCobalt Strike

The Cobalt Strike loader can use the `MessageBoxA` API to prompt for user interaction as an anti-sandbox measure.

T1547.001
Registry Run Keys / Startup Folder
MalwareQilin

Qilin has created a RunOnce autostart entry at `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce*aster = %Public%\enc.exe` pointing to a dropped copy of itself in the Public folder.

T1570
Lateral Tool Transfer
MalwareQilin

Qilin has used PsExec to distribute a second encryptor, named encryptor_1.exe, across the targeted environment.

T1673
Virtual Machine Discovery
MalwareQilin

Qilin can detect virtual machine environments including ESXi hosts, datacenters, and clusters within vCenter environments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.