ATT&CKReferencesHalcyon Qilin.B OCT 2024

Halcyon Qilin.B OCT 2024

Halcyon RISE Team. (2024, October 24). New Qilin.B Ransomware Variant Boasts Enhanced Encryption and Defense Evasion. Retrieved September 26, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareQilin

Qilin can define specific processes to be terminated or left alone at execution.

T1070.004
File Deletion
MalwareQilin

Qilin can delete itself from infected hosts after execution.

T1106
Native API
MalwareQilin

Qilin can attempt to log on to the local computer via `LogonUserW` and use `GetLogicalDrives()` and `EnumResourceW()` for discovery.

T1112
Modify Registry
MalwareQilin

Qilin can make Registry modifications to share networked drives between elevated and non-elevated processes and to increase the number of outstanding network requests per client. Qilin can also modify `HKEY_CURRENT_USER\Control Panel\Desktop\Wallpaper` to enable posting of ransom messages.

T1135
Network Share Discovery
MalwareQilin

Qilin has the ability to list network drives.

T1480.002
Mutual Exclusion
MalwareQilin

Qilin can create a mutex to ensure only one instance is running.

T1486
Data Encrypted for Impact
MalwareQilin

Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys.

T1489
Service Stop
MalwareQilin

Qilin can terminate specific services on compromised hosts.

T1490
Inhibit System Recovery
MalwareQilin

Qilin can execute `vssadmin.exe delete shadows /all /quiet` to remove volume shadow copies and can disable High Availability (HA) and Distributed Resource Scheduler (DRS) in vCenter clusters.

T1547.001
Registry Run Keys / Startup Folder
MalwareQilin

Qilin has created a RunOnce autostart entry at `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce*aster = %Public%\enc.exe` pointing to a dropped copy of itself in the Public folder.

T1673
Virtual Machine Discovery
MalwareQilin

Qilin can detect virtual machine environments including ESXi hosts, datacenters, and clusters within vCenter environments.

T1680
Local Storage Discovery
MalwareQilin

Qilin has used `GetLogicalDrives()` and `EnumResourceW()` to locate mounted drives and shares.

T1685
Disable or Modify Tools
MalwareQilin

Qilin can terminate antivirus-related processes and services.

T1685.005
Clear Windows Event Logs
MalwareQilin

Qilin has the ability to clear Windows Event Logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.