Trend Micro. (2025, October 23). Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques. Retrieved March 26, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareQilin | Qilin can define specific processes to be terminated or left alone at execution. |
| T1071.002 File Transfer Protocols |
MalwareQilin | Qilin can use WinSCP for the secure file transfer of the Linux ransomware binary to a targeted system. |
| T1082 System Information Discovery |
MalwareQilin | Qilin can detect whether a system is running FreeBSD, VMkernel (ESXi), Nutanix AHV, or a standard Linux distribution to enable platform-specific encryption behaviors. |
| T1083 File and Directory Discovery |
MalwareQilin | Qilin can exclude specific directories and files from encryption. |
| T1219.002 Remote Desktop Software |
MalwareQilin | Qilin can use the Splashtop remote management service (SRManager.exe) to execute the Linux ransomware binary directly on Windows systems. |
| T1480 Execution Guardrails |
MalwareQilin | Qilin can require a specific password to be passed by command-line argument during execution which must match a pre-defined value in the configuration in order for it to continue execution. |
| T1486 Data Encrypted for Impact |
MalwareQilin | Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys. |
| T1491.001 Internal Defacement |
MalwareQilin | Qilin can set the wallpaper on compromised hosts to display a ransom message in each encrypted folder. |
| T1678 Delay Execution |
MalwareQilin | Qilin has the ability to delay execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.