LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S1242: Qilin

Qilin is a ransomware family operated as a ransomware-as-a-service (RaaS) that has been active since at least 2022. It includes variants written in Go and Rust capable of targeting Windows, Linux, and VMware ESXi environments. Qilin shares functionality overlaps with Black Basta, REvil, and BlackCat ransomware. Qilin affiliates have targeted multiple entities worldwide with the majority of victims in the US, France, Canada, and the UK, primarily in the manufacturing, technology, financial services, and healthcare sectors.CitationTrend Micro Agenda Ransomware AUG 2022CitationSentinelOne Qilin NOV 2022CitationBushidoToken Qilin RaaS JUN 2024CitationSophos Qilin MSP APR 2025CitationTrend Micro Agenda Ransomware OCT 2025

EnterpriseS1242MalwareObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Qilin matters because it is a ransomware-as-a-service family documented by ATT&CK as targeting Windows, Linux, and VMware ESXi environments, including variants written in Go and Rust. For leaders, the practical issue is not only endpoint encryption risk: the related ATT&CK behaviors point to credential access, discovery, lateral movement, remote execution, stealth, and file-transfer activity that can affect identity systems, server estates, virtualization hosts, and recovery operations.

Executive priority

Prioritize Qilin as an operational resilience and incident-readiness scenario, especially where ESXi, Windows servers, Linux systems, managed service access, or privileged administration paths support critical business services. The Water Galura relationship describes Qilin RaaS operations including payload generation, ransom negotiation, and publication of stolen data, so executive planning should cover both outage response and data-exposure decision-making. Security leaders should ask whether backup recoverability, privileged access controls, remote administration monitoring, and evidence retention are strong enough to support a ransomware investigation and recovery.

Technical view

ATT&CK provides no dedicated detection text for this software, so defenders should validate coverage through the related techniques. On Windows, confirm visibility for LSASS access, registry queries, WMI, PowerShell, command shell, scheduled tasks, DLL injection, SMB/admin share use, service/task masquerading, file deletion, process discovery, local/domain account discovery, and remote system discovery. On Linux and ESXi, confirm visibility for SSH use, system/process/network discovery, file and directory enumeration, file-transfer protocol activity, masqueraded resource names or locations, and deletion activity. Treat Qilin coverage as a behavior chain rather than a single malware-signature problem.

Likely telemetry

  • Endpoint process creation and command-line telemetry on Windows, Linux, and ESXi where available
  • Windows Security, PowerShell, WMI, Task Scheduler, service-control, registry, and LSASS access events
  • EDR telemetry for process injection, suspicious file creation, masquerading, and file deletion
  • SMB/admin share access logs and Windows authentication events
  • SSH authentication and session logs for Linux and ESXi hosts

Detection direction

  • Map detections to the related ATT&CK techniques rather than relying on the malware name alone, because the official object does not provide detection guidance.
  • Prioritize chained analytics: credential access or account discovery followed by remote execution, SMB or SSH lateral movement, discovery, file deletion, and ransomware-like file activity.
  • Tune administrative-tool detections carefully because WMI, PowerShell, command shell, SSH, SMB, scheduled tasks, and service management have legitimate operational use.
  • Validate ESXi visibility specifically; many organizations have weaker telemetry on hypervisors than on standard endpoints.
  • Review blind spots in privileged account monitoring, remote management tooling, Linux logging, and file-transfer protocol monitoring.

Mitigation priorities

  • Harden privileged access first: reduce standing admin rights, monitor privileged sessions, and protect credentials that could enable LSASS access or lateral movement.
  • Restrict and monitor remote administration paths including SMB/admin shares, SSH, WMI, PowerShell, and scheduled task creation.
  • Improve segmentation around critical servers, ESXi hosts, backup infrastructure, and identity systems.
  • Ensure recoverable, protected backups and test restoration procedures for Windows, Linux, and virtualization workloads.
  • Standardize logging and retention for endpoints, servers, ESXi, identity infrastructure, and network controls before an incident.
Additional notes and limits

The strongest decision value is to use Qilin as a ransomware readiness test across Windows, Linux, and ESXi. ATT&CK associates the software with many techniques spanning discovery, execution, lateral movement, credential access, stealth, command-and-control, persistence, and privilege escalation, even though the malware object itself lists no tactics. The group relationships include Moonstone Sleet using Qilin and Water Galura operating Qilin RaaS; these relationships should inform threat-intelligence context, not automatic attribution in a local incident.

Official detection guidance is not provided in the supplied ATT&CK fields. This take does not claim active exploitation, local customer exposure, or guaranteed detection coverage. Control priority and detection quality must be validated against the organization’s actual platforms, logging depth, administrative practices, and incident history.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Qilin

Qilin is a ransomware family operated as a ransomware-as-a-service (RaaS) that has been active since at least 2022. It includes variants written in Go and Rust capable of targeting Windows, Linux, and VMware ESXi environments. Qilin shares functionality overlaps with Black Basta, REvil, and BlackCat ransomware. Qilin affiliates have targeted multiple entities worldwide with the majority of victims in the US, France, Canada, and the UK, primarily in the manufacturing, technology, financial services, and healthcare sectors.CitationTrend Micro Agenda Ransomware AUG 2022CitationSentinelOne Qilin NOV 2022CitationBushidoToken Qilin RaaS JUN 2024CitationSophos Qilin MSP APR 2025CitationTrend Micro Agenda Ransomware OCT 2025

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
09bb6c248146b4fd...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.