Real-world descriptions of how a group, tool or campaign used a technique.
52 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
MalwareQilin | Qilin can employ an embedded Mimikatz module to dump LSASS memory. |
| T1007 System Service Discovery |
MalwareQilin | Qilin can identify specific services for termination or to be left running at execution. |
| T1012 Query Registry |
MalwareQilin | Qilin can check `HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control SystemStartOptions` to determine if a machine is running in safe mode. |
| T1016 System Network Configuration Discovery |
MalwareQilin | Qilin can accept a command line argument identifying specific IPs. |
| T1018 Remote System Discovery |
MalwareQilin | Qilin can enumerate domain-connected hosts during its discovery phase. |
| T1021.002 SMB/Windows Admin Shares |
MalwareQilin | Qilin can embed a copy of PsExec within its payload and place it in the %Temp% directory under a randomly generated filename. |
| T1021.004 SSH |
MalwareQilin | Qilin can enable SSH access on ESXi hosts. |
| T1027.013 Encrypted/Encoded File |
MalwareQilin | Qilin can employ several code obfuscation methods, including renaming functions, altering control flows, and encrypting strings. |
| T1036.004 Masquerade Task or Service |
MalwareQilin | Qilin has created a scheduled task named TVInstallRestore to mimic TeamViewer. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareQilin | Qilin has named its payload file TeamViewer_Host_Setup to disguise itself as a legitimate TeamViewer file. |
| T1047 Windows Management Instrumentation |
MalwareQilin | Qilin can use WMIC to change the Volume Shadow Copy Service (VSS) startup type to manual. |
| T1053.005 Scheduled Task |
MalwareQilin | Qilin has pushed scheduled tasks via Group Policy Objects (GPOs) for execution. Qilin has also created a scheduled task named TVInstallRestore, configured to run at logon using the `/SC ONLOGON` argument. |
| T1055.001 Dynamic-link Library Injection |
MalwareQilin | Qilin can inject pwndll.dll, a patched DLL from the legitimate DLL WICloader.dll, into svchost.exe for continuous execution. |
| T1057 Process Discovery |
MalwareQilin | Qilin can define specific processes to be terminated or left alone at execution. |
| T1059.001 PowerShell |
MalwareQilin | Qilin has been deployed on VMware vCenter and ESXi servers via custom PowerShell script. Qilin has also used PowerShell for discovery in vCenter and Active Directory environments. |
| T1059.003 Windows Command Shell |
MalwareQilin | Qilin has run `cmd /C [PsExec] -accepteula \\IP Address -c -f -h -d -i |
| T1069.002 Domain Groups |
MalwareQilin | Qilin can run PowerShell cmdlets to discover domain groups. |
| T1070.004 File Deletion |
MalwareQilin | Qilin can delete itself from infected hosts after execution. |
| T1071.002 File Transfer Protocols |
MalwareQilin | Qilin can use WinSCP for the secure file transfer of the Linux ransomware binary to a targeted system. |
| T1082 System Information Discovery |
MalwareQilin | Qilin can detect whether a system is running FreeBSD, VMkernel (ESXi), Nutanix AHV, or a standard Linux distribution to enable platform-specific encryption behaviors. |
| T1083 File and Directory Discovery |
MalwareQilin | Qilin can exclude specific directories and files from encryption. |
| T1087.001 Local Account |
MalwareQilin | Qilin can list all local users found on a targeted system. |
| T1087.002 Domain Account |
MalwareQilin | Qilin can use PowerShell cmdlets to enumerate domain users. |
| T1106 Native API |
MalwareQilin | Qilin can attempt to log on to the local computer via `LogonUserW` and use `GetLogicalDrives()` and `EnumResourceW()` for discovery. |
| T1112 Modify Registry |
MalwareQilin | Qilin can make Registry modifications to share networked drives between elevated and non-elevated processes and to increase the number of outstanding network requests per client. Qilin can also modify `HKEY_CURRENT_USER\Control Panel\Desktop\Wallpaper` to enable posting of ransom messages. |
| T1134 Access Token Manipulation |
MalwareQilin | Qilin can use an embedded Mimikatz module for token manipulation. |
| T1135 Network Share Discovery |
MalwareQilin | Qilin has the ability to list network drives. |
| T1190 Exploit Public-Facing Application |
MalwareQilin | Qilin has been delivered through exploitation of exposed applications and interfaces including Citrix and RDP. |
| T1204.001 Malicious Link |
MalwareQilin | Qilin has been executed by luring victims into clicking links in spearphishing emails. |
| T1204.002 Malicious File |
MalwareQilin | Qilin has been delivered to victims through spearphishing emails with malicious attachments. |
| T1219.002 Remote Desktop Software |
MalwareQilin | Qilin can use the Splashtop remote management service (SRManager.exe) to execute the Linux ransomware binary directly on Windows systems. |
| T1222 File and Directory Permissions Modification |
MalwareQilin | Qilin can use symbolic links to redirect file paths for remote and local objects and can use `chmod +x` to make its payload binary executable. |
| T1480 Execution Guardrails |
MalwareQilin | Qilin can require a specific password to be passed by command-line argument during execution which must match a pre-defined value in the configuration in order for it to continue execution. |
| T1480.002 Mutual Exclusion |
MalwareQilin | Qilin can create a mutex to ensure only one instance is running. |
| T1484.001 Group Policy Modification |
MalwareQilin | Qilin has pushed a scheduled task via a Group Policy Object for payload execution. |
| T1486 Data Encrypted for Impact |
MalwareQilin | Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys. |
| T1489 Service Stop |
MalwareQilin | Qilin can terminate specific services on compromised hosts. |
| T1490 Inhibit System Recovery |
MalwareQilin | Qilin can execute `vssadmin.exe delete shadows /all /quiet` to remove volume shadow copies and can disable High Availability (HA) and Distributed Resource Scheduler (DRS) in vCenter clusters. |
| T1491.001 Internal Defacement |
MalwareQilin | Qilin can set the wallpaper on compromised hosts to display a ransom message in each encrypted folder. |
| T1529 System Shutdown/Reboot |
MalwareQilin | Qilin can initiate a reboot of the backup server to hinder recovery. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareQilin | Qilin has created a RunOnce autostart entry at `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce*aster = %Public%\enc.exe` pointing to a dropped copy of itself in the Public folder. |
| T1547.004 Winlogon Helper DLL |
MalwareQilin | Qilin can configure a Winlogon registry entry. |
| T1548.002 Bypass User Account Control |
MalwareQilin | Qilin can bypass standard user access controls by using stolen tokens to launch processes at an elevated security context. |
| T1566.001 Spearphishing Attachment |
MalwareQilin | Qilin has been delivered to victims through malicious email attachments. |
| T1566.002 Spearphishing Link |
MalwareQilin | Qilin has been delivered via malicious links in spearphishing emails. |
| T1570 Lateral Tool Transfer |
MalwareQilin | Qilin has used PsExec to distribute a second encryptor, named encryptor_1.exe, across the targeted environment. |
| T1673 Virtual Machine Discovery |
MalwareQilin | Qilin can detect virtual machine environments including ESXi hosts, datacenters, and clusters within vCenter environments. |
| T1678 Delay Execution |
MalwareQilin | Qilin has the ability to delay execution. |
| T1680 Local Storage Discovery |
MalwareQilin | Qilin has used `GetLogicalDrives()` and `EnumResourceW()` to locate mounted drives and shares. |
| T1685 Disable or Modify Tools |
MalwareQilin | Qilin can terminate antivirus-related processes and services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.