Qilin — Malware Profile
Qilin is a ransomware family operated as a ransomware-as-a-service (RaaS) that has been active since at least 2022. It includes variants written in Go and Rust capable of targeting Windows, Linux, and VMware ESXi environments. Qilin shares functionality overlaps with Black Basta, REvil, and BlackCat ransomware. Qilin affiliates have targeted multiple entities worldwide with the majority of victims in the US, France, Canada, and the UK, primarily in the manufacturing, technology, financial services, and healthcare sectors.
MITRE ATT&CK techniques (52)
- T1003.001 LSASS Memory
- T1007 System Service Discovery
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1018 Remote System Discovery
- T1021.002 SMB/Windows Admin Shares
- T1021.004 SSH
- T1027.013 Encrypted/Encoded File
- T1036.004 Masquerade Task or Service
- T1036.005 Match Legitimate Resource Name or Location
- T1047 Windows Management Instrumentation
- T1053.005 Scheduled Task
- T1055.001 Dynamic-link Library Injection
- T1057 Process Discovery
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1069.002 Domain Groups
- T1070.004 File Deletion
- T1071.002 File Transfer Protocols
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087.001 Local Account
- T1087.002 Domain Account
- T1106 Native API
- T1112 Modify Registry
- T1134 Access Token Manipulation
- T1135 Network Share Discovery
- T1190 Exploit Public-Facing Application
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1219.002 Remote Desktop Software
- T1222 File and Directory Permissions Modification
- T1480 Execution Guardrails
- T1480.002 Mutual Exclusion
- T1484.001 Group Policy Modification
- T1486 Data Encrypted for Impact
- T1489 Service Stop
- T1490 Inhibit System Recovery
- T1491.001 Internal Defacement
- T1529 System Shutdown/Reboot
- T1547.001 Registry Run Keys / Startup Folder
- T1547.004 Winlogon Helper DLL
- T1548.002 Bypass User Account Control
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1570 Lateral Tool Transfer
- T1673 Virtual Machine Discovery
- T1678 Delay Execution
- T1680 Local Storage Discovery
- T1685 Disable or Modify Tools
- T1685.005 Clear Windows Event Logs
- T1688 Safe Mode Boot
IntelFusions coverage
- LockBit 5.0 Cross-Platform Analysis: ChaCha20 Encryption, ESXi VM Shutdown Automation, and Near-Zero VirusTotal Detection 2026-02-16
- Handala Claims Breach of Clalit, Israel's Largest Healthcare Network 2026-02-26
- Check Point VPN zero-day lets attackers bypass login, now actively exploited 2026-06-12
- LockBit floods its leak site with 26 victims in two days 2026-06-12
- New ransomware crew The Gentlemen claims 20 victims in one week 2026-06-12
- Ransomware crew Gentlemen arms affiliates with custom EDR killers 2026-06-19
- Newer ransomware crews claim diagnostics maker Hologic and an Australian fire service 2026-06-28
- Ransomware gang claims to hit German submarine builder Thyssenkrupp 2026-06-28
- Qilin ransomware adds dentist referral and tolling firms to leak site 2026-06-29
- ShinyHunters claims to hit test gear maker Fluke and distributor Ingram Content 2026-07-02
- The Gentlemen ransomware lures affiliates with rare 90 percent payouts 2026-07-11
- Qilin ransomware claims 31 victims in a week across 15 countries 2026-07-11
- Ransomware crew D1R claims Synopsys breach reaching ARM and Bosch 2026-07-14
- DragonForce ransomware posts more than 20 victims in three days 2026-07-17
- INC Ransom floods its leak site with Asia-Pacific victims 2026-07-18
- Qilin ransomware sweeps up US churches, schools and small businesses 2026-07-19
- Smaller ransomware brands crowd the leak sites as Blackout debuts 2026-07-20
- Nova ransomware outpaces rivals with a global wave of leak claims 2026-07-22
- Qilin ransomware lists Argentina's army on its leak site 2026-07-25
- Qilin lists Stryker four months after the medtech giant ruled out ransomware 2026-07-26
- Colombia warns on Gentlemen ransomware as 30 victims land in a day 2026-07-26
- Extortion crew claims data theft at Coca-Cola's Fairlife dairy arm 2026-07-29
- Low-profile crew CMD keeps adding schools to its leak site 2026-08-01
- Ransomware crew Kyber claims US defense giant L3Harris 2026-08-01
- Qilin claims one of America's oldest magazines 2026-08-02