Qilin

S1242

Malware.View on attack.mitre.org

About this malware

Qilin is a ransomware family operated as a ransomware-as-a-service (RaaS) that has been active since at least 2022. It includes variants written in Go and Rust capable of targeting Windows, Linux, and VMware ESXi environments. Qilin shares functionality overlaps with Black Basta, REvil, and BlackCat ransomware. Qilin affiliates have targeted multiple entities worldwide with the majority of victims in the US, France, Canada, and the UK, primarily in the manufacturing, technology, financial services, and healthcare sectors.

Techniques used52

Procedure examples52

TechniqueProcedure example
T1003.001
LSASS Memory

Qilin can employ an embedded Mimikatz module to dump LSASS memory.

T1007
System Service Discovery

Qilin can identify specific services for termination or to be left running at execution.

T1012
Query Registry

Qilin can check `HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control SystemStartOptions` to determine if a machine is running in safe mode.

T1016
System Network Configuration Discovery

Qilin can accept a command line argument identifying specific IPs.

T1018
Remote System Discovery

Qilin can enumerate domain-connected hosts during its discovery phase.

T1021.002
SMB/Windows Admin Shares

Qilin can embed a copy of PsExec within its payload and place it in the %Temp% directory under a randomly generated filename.

T1021.004
SSH

Qilin can enable SSH access on ESXi hosts.

T1027.013
Encrypted/Encoded File

Qilin can employ several code obfuscation methods, including renaming functions, altering control flows, and encrypting strings.

T1036.004
Masquerade Task or Service

Qilin has created a scheduled task named TVInstallRestore to mimic TeamViewer.

T1036.005
Match Legitimate Resource Name or Location

Qilin has named its payload file TeamViewer_Host_Setup to disguise itself as a legitimate TeamViewer file.

T1047
Windows Management Instrumentation

Qilin can use WMIC to change the Volume Shadow Copy Service (VSS) startup type to manual.

T1053.005
Scheduled Task

Qilin has pushed scheduled tasks via Group Policy Objects (GPOs) for execution. Qilin has also created a scheduled task named TVInstallRestore, configured to run at logon using the `/SC ONLOGON` argument.

T1055.001
Dynamic-link Library Injection

Qilin can inject pwndll.dll, a patched DLL from the legitimate DLL WICloader.dll, into svchost.exe for continuous execution.

T1057
Process Discovery

Qilin can define specific processes to be terminated or left alone at execution.

T1059.001
PowerShell

Qilin has been deployed on VMware vCenter and ESXi servers via custom PowerShell script. Qilin has also used PowerShell for discovery in vCenter and Active Directory environments.

View all 52 procedure examples

Groups that use it2

Campaigns0

None recorded.

References5

  1. BushidoToken Qilin RaaS JUN 2024 Open source
    Thomas, W. (2024, June 12). Tracking Adversaries: The Qilin RaaS. Retrieved September 26, 2025.
  2. SentinelOne Qilin NOV 2022 Open source
    SentinelOne. (2022, November 30). Agenda (Qilin). Retrieved September 26, 2025.
  3. Sophos Qilin MSP APR 2025 Open source
    Bradshaw, A. et al. (2025, April 1). Qilin affiliates spear-phish MSP ScreenConnect admin, targeting customers downstream. Retrieved September 26, 2025.
  4. Trend Micro Agenda Ransomware AUG 2022 Open source
    Magdy, S. et al. (2022, August 25). New Golang Ransomware Agenda Customizes Attacks. Retrieved September 26, 2025.
  5. Trend Micro Agenda Ransomware OCT 2025 Open source
    Trend Micro. (2025, October 23). Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques. Retrieved March 26, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.