ATT&CKReferencesPicus Qilin MAR 2025

Picus Qilin MAR 2025

Hacioglu, S. (2025, March 10). Qilin Ransomware: Exposing the TTPs Behind One of the Most Active Ransomware Campaigns of 2024. Retrieved September 26, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwareQilin

Qilin can employ an embedded Mimikatz module to dump LSASS memory.

T1018
Remote System Discovery
MalwareQilin

Qilin can enumerate domain-connected hosts during its discovery phase.

T1021.002
SMB/Windows Admin Shares
MalwareQilin

Qilin can embed a copy of PsExec within its payload and place it in the %Temp% directory under a randomly generated filename.

T1059.001
PowerShell
MalwareQilin

Qilin has been deployed on VMware vCenter and ESXi servers via custom PowerShell script. Qilin has also used PowerShell for discovery in vCenter and Active Directory environments.

T1112
Modify Registry
MalwareQilin

Qilin can make Registry modifications to share networked drives between elevated and non-elevated processes and to increase the number of outstanding network requests per client. Qilin can also modify `HKEY_CURRENT_USER\Control Panel\Desktop\Wallpaper` to enable posting of ransom messages.

T1134
Access Token Manipulation
MalwareQilin

Qilin can use an embedded Mimikatz module for token manipulation.

T1222
File and Directory Permissions Modification
MalwareQilin

Qilin can use symbolic links to redirect file paths for remote and local objects and can use `chmod +x` to make its payload binary executable.

T1480
Execution Guardrails
MalwareQilin

Qilin can require a specific password to be passed by command-line argument during execution which must match a pre-defined value in the configuration in order for it to continue execution.

T1486
Data Encrypted for Impact
MalwareQilin

Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys.

T1529
System Shutdown/Reboot
MalwareQilin

Qilin can initiate a reboot of the backup server to hinder recovery.

T1548.002
Bypass User Account Control
MalwareQilin

Qilin can bypass standard user access controls by using stolen tokens to launch processes at an elevated security context.

T1685
Disable or Modify Tools
MalwareQilin

Qilin can terminate antivirus-related processes and services.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.