ATT&CKReferencesTrend Micro Agenda Ransomware OCT 2025

Trend Micro Agenda Ransomware OCT 2025

Trend Micro. (2025, October 23). Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques. Retrieved March 26, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareQilin

Qilin can define specific processes to be terminated or left alone at execution.

T1071.002
File Transfer Protocols
MalwareQilin

Qilin can use WinSCP for the secure file transfer of the Linux ransomware binary to a targeted system.

T1082
System Information Discovery
MalwareQilin

Qilin can detect whether a system is running FreeBSD, VMkernel (ESXi), Nutanix AHV, or a standard Linux distribution to enable platform-specific encryption behaviors.

T1083
File and Directory Discovery
MalwareQilin

Qilin can exclude specific directories and files from encryption.

T1219.002
Remote Desktop Software
MalwareQilin

Qilin can use the Splashtop remote management service (SRManager.exe) to execute the Linux ransomware binary directly on Windows systems.

T1480
Execution Guardrails
MalwareQilin

Qilin can require a specific password to be passed by command-line argument during execution which must match a pre-defined value in the configuration in order for it to continue execution.

T1486
Data Encrypted for Impact
MalwareQilin

Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys.

T1491.001
Internal Defacement
MalwareQilin

Qilin can set the wallpaper on compromised hosts to display a ransom message in each encrypted folder.

T1678
Delay Execution
MalwareQilin

Qilin has the ability to delay execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.