Qilin

MITRE ATT&CK: S1242 View on attack.mitre.org

Aliases: Agenda, Qilin

First seen
2022-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
esxi, windows, linux
Related IoCs
51 (50 malicious)
Last IoC activity
2026-09-01 17:44:05
Profile updated
2026-07-07 13:18:39

Targeted industries: manufacturing technology-and-telecommunications financial-services healthcare-and-pharmaceutical

Targeted regions: country_code:us country_code:fr country_code:ca country_code:gb

Context

Qilin is a ransomware family operated as a ransomware-as-a-service (RaaS) that has been active since at least 2022. It includes variants written in Go and Rust capable of targeting Windows, Linux, and VMware ESXi environments. Qilin shares functionality overlaps with Black Basta, REvil, and BlackCat ransomware. Qilin affiliates have targeted multiple entities worldwide with the majority of victims in the US, France, Canada, and the UK, primarily in the manufacturing, technology, financial services, and healthcare sectors.

Recent IoC activity

50 malicious indicators in Maltiverse are attributed to Qilin (S1242). The 20 most recently updated:

Detection coverage

  • 1 YARA rules
  • 999 Sigma rules

Malware & tools used

  • Access Token Manipulation (attack-pattern)
  • Mutual Exclusion (attack-pattern)
  • Winlogon Helper DLL (attack-pattern)
  • System Shutdown/Reboot (attack-pattern)
  • File Transfer Protocols (attack-pattern)
  • Local Account (attack-pattern)
  • Service Stop (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Native API (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Virtual Machine Discovery (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Process Discovery (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Modify Registry (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Clear Windows Event Logs (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Windows Command Shell (attack-pattern)

Used by threat actors

Detection rules

  • SEKOIA_Ransomware_Win_Agenda (yara-rule)

Reports & references

  • blog.bushidotoken.net — Tracking Adversaries Qilin Raas (report)
  • news.sophos.com — Sophos Mdr Tracks Ongoing Campaign By Qilin Affiliates Targeting Screenconnect (report)
  • Microsoft — Re54L7V (report)
  • sentinelone.com — Crimeware Trends Ransomware Developers Turn To Intermittent Encryption To Evade Detection (report)
  • ransomlook.io — Qilin (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Qilin (report)
  • research.checkpoint.com — Iranian Mois Actors The Cyber Crime Connection (report)
  • x.com — 1897738961348374621 (report)
  • medium.com — Qilin Ransomware As A Service Threat Analysis And Strategic Outlook Daf8Bd6808B5 (report)
  • tehtris.com — Rage Against The Powershell Qilin In The Name (report)
  • twitter.com — 1724521714845937822 (report)
  • bleepingcomputer.com — Linux Version Of Qilin Ransomware Focuses On Vmware Esxi (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Agendacrypt (report)
  • Trend Micro — Iocs Blog New%20Golang%20Ransomware%20Agenda%20Customizes%20Attacks.Txt (report)
  • Trend Micro — New Golang Ransomware Agenda Customizes Attacks (report)
  • Trend Micro — Agenda Ransomware Uses Rust To Target More Vital Industries (report)
  • MITRE ATT&CK — S1242 (report)
  • sentinelone.com — Agenda Qilin (report)
  • Trend Micro — Agenda Ransomware Deploys Linux Variant On Windows Systems (report)

External references