S1242: Qilin
Qilin is a ransomware family operated as a ransomware-as-a-service (RaaS) that has been active since at least 2022. It includes variants written in Go and Rust capable of targeting Windows, Linux, and VMware ESXi environments. Qilin shares functionality overlaps with Black Basta, REvil, and BlackCat ransomware. Qilin affiliates have targeted multiple entities worldwide with the majority of victims in the US, France, Canada, and the UK, primarily in the manufacturing, technology, financial services, and healthcare sectors.[1][2][3][4][5]
Security context for executives and security teams
S1242: Qilin describes [Qilin](https://attack.mitre.org/software/S1242) is a ransomware family operated as a ransomware-as-a-service (RaaS) that has been active since at least 2022. It includes variants written in Go and Rust capable of targeting Windows, Linux, and VMware ESXi environments. [Qilin](https://attack.mitre.org/software/S1242) shares functionality overlaps with [Black Basta](https://attack.mitre.org/software/S1070), [REvil](https://attack.mitre.org/software/S0496), and [BlackCat](https://attack.mitre.org/software/S1068) rans...
Executive priority
S1242: Qilin is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate S1242: Qilin by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (ESXi, Windows, Linux), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
- Network, endpoint, and security-tool telemetry
Detection direction
- Validate whether S1242: Qilin appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Qilin
Qilin is a ransomware family operated as a ransomware-as-a-service (RaaS) that has been active since at least 2022. It includes variants written in Go and Rust capable of targeting Windows, Linux, and VMware ESXi environments. Qilin shares functionality overlaps with Black Basta, REvil, and BlackCat ransomware. Qilin affiliates have targeted multiple entities worldwide with the majority of victims in the US, France, Canada, and the UK, primarily in the manufacturing, technology, financial services, and healthcare sectors.[1][2][3][4][5]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1027.013 | Encrypted/Encoded FileSub-technique | Qilin can employ several code obfuscation methods, including renaming functions, altering control flows, and encrypting strings.CitationHC3 Qilin Threat Profile JUN 2024 |
| Enterprise | T1082 | System Information Discovery | |
| Enterprise | T1134 | Access Token Manipulation | |
| Enterprise | T1480.002 | Mutual ExclusionSub-technique | Qilin can create a mutex to ensure only one instance is running.CitationHalcyon Qilin.B OCT 2024 |
| Enterprise | T1547.004 | Winlogon Helper DLLSub-technique | |
| Enterprise | T1529 | System Shutdown/Reboot | Qilin can initiate a reboot of the backup server to hinder recovery.CitationPicus Qilin MAR 2025 |
| Enterprise | T1071.002 | File Transfer ProtocolsSub-technique | |
| Enterprise | T1087.001 | Local AccountSub-technique | |
| Enterprise | T1489 | Service Stop | |
| Enterprise | T1566.002 | Spearphishing LinkSub-technique | |
| Enterprise | T1047 | Windows Management Instrumentation | Qilin can use WMIC to change the Volume Shadow Copy Service (VSS) startup type to manual.CitationCisco Talos Qilin Ransomware OCT 2025 |
| Enterprise | T1106 | Native API | |
| Enterprise | T1036.004 | Masquerade Task or ServiceSub-technique | Qilin has created a scheduled task named TVInstallRestore to mimic TeamViewer. CitationCisco Talos Qilin Ransomware OCT 2025 |
| Enterprise | T1673 | Virtual Machine Discovery | Qilin can detect virtual machine environments including ESXi hosts, datacenters, and clusters within vCenter environments.CitationHalcyon Qilin.B OCT 2024CitationCisco Talos Qilin Ransomware OCT 2025 |
| Enterprise | T1548.002 | Bypass User Account ControlSub-technique | Qilin can bypass standard user access controls by using stolen tokens to launch processes at an elevated security context.CitationPicus Qilin MAR 2025 |
| Enterprise | T1480 | Execution Guardrails | |
| Enterprise | T1021.002 | SMB/Windows Admin SharesSub-technique | |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | Qilin has named its payload file TeamViewer_Host_Setup to disguise itself as a legitimate TeamViewer file.CitationCisco Talos Qilin Ransomware OCT 2025 |
| Enterprise | T1057 | Process Discovery | |
| Enterprise | T1053.005 | Scheduled TaskSub-technique | |
| Enterprise | T1112 | Modify Registry | Qilin can make Registry modifications to share networked drives between elevated and non-elevated processes and to increase the number of outstanding network requests per client.CitationHalcyon Qilin.B OCT 2024CitationPicus Qilin MAR 2025 Qilin can also modify `HKEY_CURRENT_USER\Control Panel\Desktop\Wallpaper` to enable posting of ransom messages.CitationCisco Talos Qilin Ransomware OCT 2025 |
| Enterprise | T1135 | Network Share Discovery | |
| Enterprise | T1685.005 | Clear Windows Event LogsSub-technique | |
| Enterprise | T1007 | System Service Discovery | |
| Enterprise | T1570 | Lateral Tool Transfer | |
| Enterprise | T1055.001 | Dynamic-link Library InjectionSub-technique | |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | Qilin has run `cmd /C [PsExec] -accepteula \\IP Address -c -f -h -d -i C:\Users\xxx\.exe --password [PASSWORD] --spread --spread-process` to execute its encryptor to target multiple network shares.CitationCisco Talos Qilin Ransomware OCT 2025 |
| Enterprise | T1012 | Query Registry | |
| Enterprise | T1069.002 | Domain GroupsSub-technique | Qilin can run PowerShell cmdlets to discover domain groups.CitationCisco Talos Qilin Ransomware OCT 2025 |
| Enterprise | T1016 | System Network Configuration Discovery | |
| Enterprise | T1680 | Local Storage Discovery | Qilin has used `GetLogicalDrives()` and `EnumResourceW()` to locate mounted drives and shares.CitationHalcyon Qilin.B OCT 2024 |
| Enterprise | T1222 | File and Directory Permissions Modification | Qilin can use symbolic links to redirect file paths for remote and local objects and can use `chmod +x` to make its payload binary executable.CitationPicus Qilin MAR 2025CitationCisco Talos Qilin Ransomware OCT 2025 |
| Enterprise | T1486 | Data Encrypted for Impact | Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys.[1][2]CitationPicus Qilin MAR 2025[3]CitationHalcyon Qilin.B OCT 2024CitationHC3 Qilin Threat Profile JUN 2024[5]CitationCisco Talos Qilin Ransomware OCT 2025 |
| Enterprise | T1204.001 | Malicious LinkSub-technique | |
| Enterprise | T1190 | Exploit Public-Facing Application | |
| Enterprise | T1547.001 | Registry Run Keys / Startup FolderSub-technique | |
| Enterprise | T1484.001 | Group Policy ModificationSub-technique | |
| Enterprise | T1021.004 | SSHSub-technique | Qilin can enable SSH access on ESXi hosts.CitationCisco Talos Qilin Ransomware OCT 2025 |
| Enterprise | T1003.001 | LSASS MemorySub-technique | |
| Enterprise | T1678 | Delay Execution | |
| Enterprise | T1204.002 | Malicious FileSub-technique | |
| Enterprise | T1083 | File and Directory Discovery | |
| Enterprise | T1688 | Safe Mode Boot | |
| Enterprise | T1685 | Disable or Modify Tools | |
| Enterprise | T1018 | Remote System Discovery | |
| Enterprise | T1566.001 | Spearphishing AttachmentSub-technique | |
| Enterprise | T1087.002 | Domain AccountSub-technique | Qilin can use PowerShell cmdlets to enumerate domain users.CitationCisco Talos Qilin Ransomware OCT 2025 |
| Enterprise | T1490 | Inhibit System Recovery | |
| Enterprise | T1070.004 | File DeletionSub-technique | |
| Enterprise | T1491.001 | Internal DefacementSub-technique | |
| Enterprise | T1059.001 | PowerShellSub-technique | |
| Enterprise | T1219.002 | Remote Desktop SoftwareSub-technique |
Groups, software, and campaigns
G1050: Water Galura
Water Galura are the operators of the Qilin Ransomware-as-a-Service (RaaS) who handle payload generation, ransom negotiations, and the publication of stolen data for Qilin affilates recruited on Russian cybercrime forums. Water Galura have been active since at least 2022 and use a double extortion model where they demand payment for providing decryption keys and for refraining from publishing the stolen data to their leak site.[1][2]
G1036: Moonstone Sleet
Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.[1]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 2.0 | Current bundle | 09bb6c248146… | ||
| 19.1 | 2.0 | Older bundle | 09bb6c248146… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Trend Micro Agenda Ransomware AUG 2022
Magdy, S. et al. (2022, August 25). New Golang Ransomware Agenda Customizes Attacks. Retrieved September 26, 2025.
Open source URL - [2]SentinelOne Qilin NOV 2022
SentinelOne. (2022, November 30). Agenda (Qilin). Retrieved September 26, 2025.
Open source URL - [3]BushidoToken Qilin RaaS JUN 2024
Thomas, W. (2024, June 12). Tracking Adversaries: The Qilin RaaS. Retrieved September 26, 2025.
Open source URL - [4]Sophos Qilin MSP APR 2025
Bradshaw, A. et al. (2025, April 1). Qilin affiliates spear-phish MSP ScreenConnect admin, targeting customers downstream. Retrieved September 26, 2025.
Open source URL - [5]Trend Micro Agenda Ransomware OCT 2025
Trend Micro. (2025, October 23). Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques. Retrieved March 26, 2026.
Open source URL - [6]Agenda
(Citation: Sophos Qilin MSP APR 2025)(Citation: Trend Micro Agenda Ransomware AUG 2022)(Citation: SentinelOne Qilin NOV 2022)(Citation: Trend Micro Agenda Ransomware OCT 2025)
- [7]mitre-attackS1242Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
