Thomas, W. (2024, June 12). Tracking Adversaries: The Qilin RaaS. Retrieved September 26, 2025.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1053.005 Scheduled Task |
MalwareQilin | Qilin has pushed scheduled tasks via Group Policy Objects (GPOs) for execution. Qilin has also created a scheduled task named TVInstallRestore, configured to run at logon using the `/SC ONLOGON` argument. |
| T1059.001 PowerShell |
MalwareQilin | Qilin has been deployed on VMware vCenter and ESXi servers via custom PowerShell script. Qilin has also used PowerShell for discovery in vCenter and Active Directory environments. |
| T1484.001 Group Policy Modification |
MalwareQilin | Qilin has pushed a scheduled task via a Group Policy Object for payload execution. |
| T1486 Data Encrypted for Impact |
GroupWater Galura | Water Galura has encrypted files on victim networks through the generation of Qilin ransomware payloads. |
| T1486 Data Encrypted for Impact |
MalwareQilin | Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys. |
| T1585.001 Social Media Accounts |
GroupWater Galura | Water Galura operates a news channel on Telegram to make announcements for the Qilin RaaS. |
| T1657 Financial Theft |
GroupWater Galura | Water Galura has extorted victims for ransomware decryption keys and to prevent publication of data exfiltrated to their Tor data leak site. |
| T1688 Safe Mode Boot |
MalwareQilin | Qilin can reboot targeted systems in safe mode to avoid detection. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.