SentinelOne. (2022, November 30). Agenda (Qilin). Retrieved September 26, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareQilin | Qilin can identify specific services for termination or to be left running at execution. |
| T1057 Process Discovery |
MalwareQilin | Qilin can define specific processes to be terminated or left alone at execution. |
| T1190 Exploit Public-Facing Application |
MalwareQilin | Qilin has been delivered through exploitation of exposed applications and interfaces including Citrix and RDP. |
| T1204.001 Malicious Link |
MalwareQilin | Qilin has been executed by luring victims into clicking links in spearphishing emails. |
| T1204.002 Malicious File |
MalwareQilin | Qilin has been delivered to victims through spearphishing emails with malicious attachments. |
| T1486 Data Encrypted for Impact |
MalwareQilin | Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys. |
| T1566.001 Spearphishing Attachment |
MalwareQilin | Qilin has been delivered to victims through malicious email attachments. |
| T1566.002 Spearphishing Link |
MalwareQilin | Qilin has been delivered via malicious links in spearphishing emails. |
| T1685 Disable or Modify Tools |
MalwareQilin | Qilin can terminate antivirus-related processes and services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.