Malware.View on attack.mitre.org
Qilin is a ransomware family operated as a ransomware-as-a-service (RaaS) that has been active since at least 2022. It includes variants written in Go and Rust capable of targeting Windows, Linux, and VMware ESXi environments. Qilin shares functionality overlaps with Black Basta, REvil, and BlackCat ransomware. Qilin affiliates have targeted multiple entities worldwide with the majority of victims in the US, France, Canada, and the UK, primarily in the manufacturing, technology, financial services, and healthcare sectors.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Qilin can employ an embedded Mimikatz module to dump LSASS memory. |
| T1007 System Service Discovery |
Qilin can identify specific services for termination or to be left running at execution. |
| T1012 Query Registry |
Qilin can check `HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control SystemStartOptions` to determine if a machine is running in safe mode. |
| T1016 System Network Configuration Discovery |
Qilin can accept a command line argument identifying specific IPs. |
| T1018 Remote System Discovery |
Qilin can enumerate domain-connected hosts during its discovery phase. |
| T1021.002 SMB/Windows Admin Shares |
Qilin can embed a copy of PsExec within its payload and place it in the %Temp% directory under a randomly generated filename. |
| T1021.004 SSH |
Qilin can enable SSH access on ESXi hosts. |
| T1027.013 Encrypted/Encoded File |
Qilin can employ several code obfuscation methods, including renaming functions, altering control flows, and encrypting strings. |
| T1036.004 Masquerade Task or Service |
Qilin has created a scheduled task named TVInstallRestore to mimic TeamViewer. |
| T1036.005 Match Legitimate Resource Name or Location |
Qilin has named its payload file TeamViewer_Host_Setup to disguise itself as a legitimate TeamViewer file. |
| T1047 Windows Management Instrumentation |
Qilin can use WMIC to change the Volume Shadow Copy Service (VSS) startup type to manual. |
| T1053.005 Scheduled Task |
Qilin has pushed scheduled tasks via Group Policy Objects (GPOs) for execution. Qilin has also created a scheduled task named TVInstallRestore, configured to run at logon using the `/SC ONLOGON` argument. |
| T1055.001 Dynamic-link Library Injection |
Qilin can inject pwndll.dll, a patched DLL from the legitimate DLL WICloader.dll, into svchost.exe for continuous execution. |
| T1057 Process Discovery |
Qilin can define specific processes to be terminated or left alone at execution. |
| T1059.001 PowerShell |
Qilin has been deployed on VMware vCenter and ESXi servers via custom PowerShell script. Qilin has also used PowerShell for discovery in vCenter and Active Directory environments. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.