Hacioglu, S. (2025, March 10). Qilin Ransomware: Exposing the TTPs Behind One of the Most Active Ransomware Campaigns of 2024. Retrieved September 26, 2025.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
MalwareQilin | Qilin can employ an embedded Mimikatz module to dump LSASS memory. |
| T1018 Remote System Discovery |
MalwareQilin | Qilin can enumerate domain-connected hosts during its discovery phase. |
| T1021.002 SMB/Windows Admin Shares |
MalwareQilin | Qilin can embed a copy of PsExec within its payload and place it in the %Temp% directory under a randomly generated filename. |
| T1059.001 PowerShell |
MalwareQilin | Qilin has been deployed on VMware vCenter and ESXi servers via custom PowerShell script. Qilin has also used PowerShell for discovery in vCenter and Active Directory environments. |
| T1112 Modify Registry |
MalwareQilin | Qilin can make Registry modifications to share networked drives between elevated and non-elevated processes and to increase the number of outstanding network requests per client. Qilin can also modify `HKEY_CURRENT_USER\Control Panel\Desktop\Wallpaper` to enable posting of ransom messages. |
| T1134 Access Token Manipulation |
MalwareQilin | Qilin can use an embedded Mimikatz module for token manipulation. |
| T1222 File and Directory Permissions Modification |
MalwareQilin | Qilin can use symbolic links to redirect file paths for remote and local objects and can use `chmod +x` to make its payload binary executable. |
| T1480 Execution Guardrails |
MalwareQilin | Qilin can require a specific password to be passed by command-line argument during execution which must match a pre-defined value in the configuration in order for it to continue execution. |
| T1486 Data Encrypted for Impact |
MalwareQilin | Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys. |
| T1529 System Shutdown/Reboot |
MalwareQilin | Qilin can initiate a reboot of the backup server to hinder recovery. |
| T1548.002 Bypass User Account Control |
MalwareQilin | Qilin can bypass standard user access controls by using stolen tokens to launch processes at an elevated security context. |
| T1685 Disable or Modify Tools |
MalwareQilin | Qilin can terminate antivirus-related processes and services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.