Bradshaw, A. et al. (2025, April 1). Qilin affiliates spear-phish MSP ScreenConnect admin, targeting customers downstream. Retrieved September 26, 2025.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
MalwareQilin | Qilin can enumerate domain-connected hosts during its discovery phase. |
| T1070.004 File Deletion |
MalwareQilin | Qilin can delete itself from infected hosts after execution. |
| T1204.001 Malicious Link |
MalwareQilin | Qilin has been executed by luring victims into clicking links in spearphishing emails. |
| T1490 Inhibit System Recovery |
MalwareQilin | Qilin can execute `vssadmin.exe delete shadows /all /quiet` to remove volume shadow copies and can disable High Availability (HA) and Distributed Resource Scheduler (DRS) in vCenter clusters. |
| T1491.001 Internal Defacement |
MalwareQilin | Qilin can set the wallpaper on compromised hosts to display a ransom message in each encrypted folder. |
| T1566.002 Spearphishing Link |
MalwareQilin | Qilin has been delivered via malicious links in spearphishing emails. |
| T1685.005 Clear Windows Event Logs |
MalwareQilin | Qilin has the ability to clear Windows Event Logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.