Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ Qilin

🇷🇺Qilin

🇷🇺 Qilin is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: Criminal. We map 14 detection use cases to this actor across 50 MITRE ATT&CK techniques, with 6 threat-intel articles citing them. Active in our corpus from 2025-12-16 to 2026-07-25.

crit 6
View full actor card → All threat actors
14Use cases
6Articles
50Techniques
3IOCs

Known aliases

QilinAgenda ransomware

Top techniques

All other tracked techniques

Detection use cases (14)

Qilin (Agenda) Safe Mode encryptor staging via bcdedit safeboot + forced reboot AI · profile SΣDD Qilin recovery-inhibition + defense-tampering burst before encryption AI · profile SDD DevMan/Funky Mantis locker execution by known SHA256/MD5 hash Bespoke DevMan ransomware encryption artifacts: .devman extension and deterministic ransom note Bespoke DevMan pre-encryption recovery inhibition and event-log clearing Bespoke Suspicious browser extension installation Internal Infostealer — non-browser process accessing browser cookie/login DBs Internal Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Remote service execution — PsExec / SMB lateral movement Internal OAuth consent / suspicious app grant Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal

Threat-intel articles (6)

Tracked indicators

IP addresses (3)

193.233.202.17 45.86.230.112 77.110.122.137

CVEs (7)

CVE-2023-27532 CVE-2024-37085 CVE-2024-55591 CVE-2025-32433 CVE-2025-33073 CVE-2025-55182 CVE-2025-7771