Magdy, S. et al. (2022, August 25). New Golang Ransomware Agenda Customizes Attacks. Retrieved September 26, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareQilin | Qilin can identify specific services for termination or to be left running at execution. |
| T1012 Query Registry |
MalwareQilin | Qilin can check `HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control SystemStartOptions` to determine if a machine is running in safe mode. |
| T1016 System Network Configuration Discovery |
MalwareQilin | Qilin can accept a command line argument identifying specific IPs. |
| T1053.005 Scheduled Task |
MalwareQilin | Qilin has pushed scheduled tasks via Group Policy Objects (GPOs) for execution. Qilin has also created a scheduled task named TVInstallRestore, configured to run at logon using the `/SC ONLOGON` argument. |
| T1055.001 Dynamic-link Library Injection |
MalwareQilin | Qilin can inject pwndll.dll, a patched DLL from the legitimate DLL WICloader.dll, into svchost.exe for continuous execution. |
| T1057 Process Discovery |
MalwareQilin | Qilin can define specific processes to be terminated or left alone at execution. |
| T1083 File and Directory Discovery |
MalwareQilin | Qilin can exclude specific directories and files from encryption. |
| T1087.001 Local Account |
MalwareQilin | Qilin can list all local users found on a targeted system. |
| T1106 Native API |
MalwareQilin | Qilin can attempt to log on to the local computer via `LogonUserW` and use `GetLogicalDrives()` and `EnumResourceW()` for discovery. |
| T1135 Network Share Discovery |
MalwareQilin | Qilin has the ability to list network drives. |
| T1484.001 Group Policy Modification |
MalwareQilin | Qilin has pushed a scheduled task via a Group Policy Object for payload execution. |
| T1486 Data Encrypted for Impact |
MalwareQilin | Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys. |
| T1489 Service Stop |
MalwareQilin | Qilin can terminate specific services on compromised hosts. |
| T1490 Inhibit System Recovery |
MalwareQilin | Qilin can execute `vssadmin.exe delete shadows /all /quiet` to remove volume shadow copies and can disable High Availability (HA) and Distributed Resource Scheduler (DRS) in vCenter clusters. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareQilin | Qilin has created a RunOnce autostart entry at `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce*aster = %Public%\enc.exe` pointing to a dropped copy of itself in the Public folder. |
| T1547.004 Winlogon Helper DLL |
MalwareQilin | Qilin can configure a Winlogon registry entry. |
| T1685 Disable or Modify Tools |
MalwareQilin | Qilin can terminate antivirus-related processes and services. |
| T1688 Safe Mode Boot |
MalwareQilin | Qilin can reboot targeted systems in safe mode to avoid detection. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.