S1242: Qilin
Qilin is a ransomware family operated as a ransomware-as-a-service (RaaS) that has been active since at least 2022. It includes variants written in Go and Rust capable of targeting Windows, Linux, and VMware ESXi environments. Qilin shares functionality overlaps with Black Basta, REvil, and BlackCat ransomware. Qilin affiliates have targeted multiple entities worldwide with the majority of victims in the US, France, Canada, and the UK, primarily in the manufacturing, technology, financial services, and healthcare sectors.CitationTrend Micro Agenda Ransomware AUG 2022CitationSentinelOne Qilin NOV 2022CitationBushidoToken Qilin RaaS JUN 2024CitationSophos Qilin MSP APR 2025CitationTrend Micro Agenda Ransomware OCT 2025
Security context for executives and security teams
Qilin matters because it is a ransomware-as-a-service family documented by ATT&CK as targeting Windows, Linux, and VMware ESXi environments, including variants written in Go and Rust. For leaders, the practical issue is not only endpoint encryption risk: the related ATT&CK behaviors point to credential access, discovery, lateral movement, remote execution, stealth, and file-transfer activity that can affect identity systems, server estates, virtualization hosts, and recovery operations.
Executive priority
Prioritize Qilin as an operational resilience and incident-readiness scenario, especially where ESXi, Windows servers, Linux systems, managed service access, or privileged administration paths support critical business services. The Water Galura relationship describes Qilin RaaS operations including payload generation, ransom negotiation, and publication of stolen data, so executive planning should cover both outage response and data-exposure decision-making. Security leaders should ask whether backup recoverability, privileged access controls, remote administration monitoring, and evidence retention are strong enough to support a ransomware investigation and recovery.
Technical view
ATT&CK provides no dedicated detection text for this software, so defenders should validate coverage through the related techniques. On Windows, confirm visibility for LSASS access, registry queries, WMI, PowerShell, command shell, scheduled tasks, DLL injection, SMB/admin share use, service/task masquerading, file deletion, process discovery, local/domain account discovery, and remote system discovery. On Linux and ESXi, confirm visibility for SSH use, system/process/network discovery, file and directory enumeration, file-transfer protocol activity, masqueraded resource names or locations, and deletion activity. Treat Qilin coverage as a behavior chain rather than a single malware-signature problem.
Likely telemetry
- Endpoint process creation and command-line telemetry on Windows, Linux, and ESXi where available
- Windows Security, PowerShell, WMI, Task Scheduler, service-control, registry, and LSASS access events
- EDR telemetry for process injection, suspicious file creation, masquerading, and file deletion
- SMB/admin share access logs and Windows authentication events
- SSH authentication and session logs for Linux and ESXi hosts
Detection direction
- Map detections to the related ATT&CK techniques rather than relying on the malware name alone, because the official object does not provide detection guidance.
- Prioritize chained analytics: credential access or account discovery followed by remote execution, SMB or SSH lateral movement, discovery, file deletion, and ransomware-like file activity.
- Tune administrative-tool detections carefully because WMI, PowerShell, command shell, SSH, SMB, scheduled tasks, and service management have legitimate operational use.
- Validate ESXi visibility specifically; many organizations have weaker telemetry on hypervisors than on standard endpoints.
- Review blind spots in privileged account monitoring, remote management tooling, Linux logging, and file-transfer protocol monitoring.
Mitigation priorities
- Harden privileged access first: reduce standing admin rights, monitor privileged sessions, and protect credentials that could enable LSASS access or lateral movement.
- Restrict and monitor remote administration paths including SMB/admin shares, SSH, WMI, PowerShell, and scheduled task creation.
- Improve segmentation around critical servers, ESXi hosts, backup infrastructure, and identity systems.
- Ensure recoverable, protected backups and test restoration procedures for Windows, Linux, and virtualization workloads.
- Standardize logging and retention for endpoints, servers, ESXi, identity infrastructure, and network controls before an incident.
Additional notes and limits
The strongest decision value is to use Qilin as a ransomware readiness test across Windows, Linux, and ESXi. ATT&CK associates the software with many techniques spanning discovery, execution, lateral movement, credential access, stealth, command-and-control, persistence, and privilege escalation, even though the malware object itself lists no tactics. The group relationships include Moonstone Sleet using Qilin and Water Galura operating Qilin RaaS; these relationships should inform threat-intelligence context, not automatic attribution in a local incident.
Official detection guidance is not provided in the supplied ATT&CK fields. This take does not claim active exploitation, local customer exposure, or guaranteed detection coverage. Control priority and detection quality must be validated against the organization’s actual platforms, logging depth, administrative practices, and incident history.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Qilin
Qilin is a ransomware family operated as a ransomware-as-a-service (RaaS) that has been active since at least 2022. It includes variants written in Go and Rust capable of targeting Windows, Linux, and VMware ESXi environments. Qilin shares functionality overlaps with Black Basta, REvil, and BlackCat ransomware. Qilin affiliates have targeted multiple entities worldwide with the majority of victims in the US, France, Canada, and the UK, primarily in the manufacturing, technology, financial services, and healthcare sectors.CitationTrend Micro Agenda Ransomware AUG 2022CitationSentinelOne Qilin NOV 2022CitationBushidoToken Qilin RaaS JUN 2024CitationSophos Qilin MSP APR 2025CitationTrend Micro Agenda Ransomware OCT 2025
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
