HackerFeeds
All ransomware groups

qilin

1,945 tracked victims
·first seen 2022-10-08·last activity 2026-06-23

Group profile

Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078Valid Accounts

    Compromised credentials used to authenticate via VPN and RDP. Qilin notably steals credentials from Chrome browsers on compromised endpoints before encryption.

  • T1190Exploit Public-Facing Application

    Exploitation of vulnerabilities in VPN appliances and remote management tools to gain initial access.

  • T1566Phishing

  • T1566.003Phishing: Spearphishing via Service

    Qilin affiliates spear-phished MSP administrators via ScreenConnect to gain access to downstream customers. Phishing campaigns using credential-harvesting pages targeting VPN and SSO portals.

TA0002

Execution

  • T1059.001Command and Scripting Interpreter: PowerShell

    PowerShell scripts used for payload execution, lateral movement, and post-exploitation tasks.

  • T1059.004Command and Scripting Interpreter: Unix Shell

    Shell scripts used to execute the Linux/ESXi variant of the Qilin ransomware payload.

  • T1569System Services

  • T1569.002System Services: Service Execution

TA0003

Persistence

  • T1037Boot or Logon Initialization Scripts

  • T1053Scheduled Task/Job

  • T1053.005Scheduled Task/Job: Scheduled Task

    Scheduled tasks created to maintain persistence and execute post-exploitation scripts.

  • T1098.004Account Manipulation: SSH Authorized Keys

  • T1136Create Account

  • T1547Boot or Logon Autostart Execution

TA0004

Privilege Escalation

  • T1068Exploitation for Privilege Escalation

TA0005

Defense Evasion

  • T1027Obfuscated Files or Information

    Qilin.B variant (October 2024) introduced enhanced obfuscation and anti-analysis techniques compared to earlier versions.

  • T1036.001Masquerading: Invalid Code Signature

  • T1134.004Access Token Manipulation: Parent PID Spoofing

  • T1211Exploitation for Defense Evasion

  • T1480Execution Guardrails

  • T1497.001Virtualization/Sandbox Evasion: System Checks

  • T1553.002Subvert Trust Controls: Code Signing

  • T1562.001Disable or Modify Tools

    Security tools and EDR solutions disabled via batch scripts and Group Policy modifications.

  • T1562.004Impair Defenses: Disable or Modify System Firewall

  • T1564Hidden Artifacts

  • T1564.003Hidden Artifacts: Hidden Window

TA0006

Credential Access

  • T1003.001OS Credential Dumping: LSASS Memory

    LSASS memory dumped to harvest credentials for lateral movement and privilege escalation.

  • T1040Network Sniffing

  • T1110.002Brute Force: Password Cracking

  • T1555.003Credentials from Web Browsers

    Qilin notably deployed a custom script to steal credentials stored in Google Chrome browsers on all domain-joined machines via Group Policy — a distinctive TTP first observed in the Synnovis NHS attack (June 2024).

TA0007

Discovery

  • T1012Query Registry

  • T1046Network Service Discovery

    Network scanning used to enumerate hosts and services within the victim environment.

  • T1082System Information Discovery

    System information collected to tailor the attack and identify high-value targets.

  • T1614System Location Discovery

TA0008

Lateral Movement

  • T1021Remote Services

  • T1021.001Remote Services: Remote Desktop Protocol

    RDP used for lateral movement across victim networks.

  • T1021.002Remote Services: SMB/Windows Admin Shares

    SMB used to propagate payloads and move laterally within the network.

  • T1021.004Remote Services: SSH

  • T1570Lateral Tool Transfer

TA0009

Collection

  • T1560.001Archive Collected Data: Archive via Utility

    Data compressed and archived prior to exfiltration.

  • T1602.002Network Device Configuration Dump

TA0010

Exfiltration

  • T1011Exfiltration Over Other Network Medium

  • T1011.001Exfiltration Over Other Network Medium: Exfiltration Over Bluetooth

  • T1048.003Exfiltration Over Alternative Protocol: Unencrypted Non-C2 Protocol

  • T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage

    Data exfiltrated to cloud storage and actor-controlled servers for double extortion via the Qilin leak site.

TA0011

Command and Control

  • T1001Data Obfuscation

  • T1001.001Data Obfuscation: Junk Data

  • T1071.001Application Layer Protocol: Web Protocols

    C2 communication over HTTPS; Tor used for victim portals.

  • T1572Protocol Tunneling

TA0040

Impact

  • T1486Data Encrypted for Impact

    Qilin (formerly Agenda) uses ChaCha20 for file encryption with RSA-4096 for key protection. Originally written in Go, later rewritten in Rust (Qilin.B). Targets Windows, Linux, and VMware ESXi. Notable attack: Synnovis NHS pathology services (June 2024) causing 10,000+ NHS appointment cancellations. Active RaaS with high affiliate revenue share.

  • T1490Inhibit System Recovery

    Shadow copies deleted; ESXi snapshots removed to prevent VM recovery.

  • T1561Disk Wipe

  • T1561.001Disk Wipe: Disk Content Wipe

TA0042

Resource Development

TA0043

Reconnaissance

  • T1590.004Gather Victim Network Information: Network Topology

Recent victims

showing 50 of 1,946
DateWebsite / victimSectorCountry
2026-06-24Financial ServicesCA
2026-06-23
leeinternational.com
Lee Internationalwww.leeinternational.com
Not FoundKR
2026-06-22
schumacherhomes.com
Schumacher Homeswww.schumacherhomes.com
ConstructionUS
2026-06-22
cbl.gov.ly
Central Bank of Libyawww.cbl.gov.ly
Financial ServicesLY
2026-06-21
twsinto.com.tw
Taiwan Sintong Machinery Co., Ltdwww.twsinto.com.tw
ManufacturingTW
2026-06-21TelecommunicationTH
2026-06-21Not FoundUS
2026-06-21
florida-engineering-services.com
Florida Engineering Serviceswww.florida-engineering-services.com
ConstructionUS
2026-06-20
pacificlamp.com
Pacific Lamp & Supplywww.pacificlamp.com
ManufacturingUS
2026-06-19ManufacturingDE
2026-06-19Consumer ServicesUS
2026-06-19
pjdalycontracting.com
PJ Daly Contractingwww.pjdalycontracting.com
ConstructionIE
2026-06-19
eyguieres.org
Commune d'Eyguireswww.eyguieres.org
Public SectorFR
2026-06-18
T
THL PROJECT MANAGEMENT SDN. BHD.THL PROJECT MANAGEMENT SDN. BHD.
Business ServicesMY
2026-06-18
homesbyjanthony.com
Homes By J Anthonywww.homesbyjanthony.com
ConstructionUS
2026-06-18
atcom.cl
ATCOM Outsourcingwww.atcom.cl
Business ServicesCL
2026-06-18
dondon.si
Skupina Don Don - GRUPO BIMBOwww.dondon.si
Agriculture and Food ProductionSI
2026-06-18
makel.com.tr
Makel Companies Groupwww.makel.com.tr
ConstructionTR
2026-06-16
golfview.org
Golfview Developmental Centerwww.golfview.org
HealthcareUS
2026-06-16
iscmst.pt
Misericórdia de Santo Tirsowww.iscmst.pt
HealthcarePT
2026-06-16
qlinkwireless.com
Q Link Wirelesswww.qlinkwireless.com
TelecommunicationUS
2026-06-15
nagecco.com
Cng Ty Cp T Vn Xd Tng Hpwww.nagecco.com
Not FoundVN
2026-06-15Business ServicesMX
2026-06-15
izmircanhastanesi.com
Can Healthcare Groupwww.izmircanhastanesi.com
HealthcareTR
2026-06-12
distinetmurcia.es
DISTINET MURCIA SLwww.distinetmurcia.es
Business ServicesES
2026-06-11
mauidivers.com
Maui Divers Jewelrywww.mauidivers.com
Consumer ServicesUS
2026-06-11
bitek.co.kr
Bitek Systemwww.bitek.co.kr
TechnologyKR
2026-06-10
altavistasp.com
AltaVista Strategic Partnerswww.altavistasp.com
Business ServicesMX
2026-06-10
plaxenadler.com
Plaxen & Adlerwww.plaxenadler.com
Not FoundDE
2026-06-10Business ServicesUS
2026-06-10Not FoundUS
2026-06-10Consumer ServicesUS
2026-06-10
mdtrialfirm.com
Bekman Marder Hopper Malarkey & Perlinwww.mdtrialfirm.com
Business ServicesMD
2026-06-10
dulany.com
Dulany Leahy Curtis & Brophywww.dulany.com
Business ServicesUS
2026-06-10HealthcareDE
2026-06-10
teserraoutdoors.com
Teserra Outdoorswww.teserraoutdoors.com
Consumer ServicesUS
2026-06-10
wcslaw.com
Wright Constable & Skeenwww.wcslaw.com
Business ServicesUS
2026-06-10Financial ServicesUS
2026-06-10ManufacturingUS
2026-06-10Not FoundUS
2026-06-10Consumer ServicesUS
2026-06-10
taglerock.com
TagleRock Technologieswww.taglerock.com
Technology
2026-06-10EnergyUS
2026-06-08
thebanyans.com.au
The Banyans Health and Wellnesswww.thebanyans.com.au
HealthcareAU
2026-06-08EducationAU
2026-06-08TelecommunicationUS
2026-06-08ManufacturingTH
2026-06-08Hospitality and TourismFR
2026-06-08
sanynj.org
Shipping Association of NY and NJwww.sanynj.org
Transportation/LogisticsUS
2026-06-05
kissimmeesmile.com
Central Florida Cosmetic & Family Dentistrywww.kissimmeesmile.com
HealthcareUS