🇷🇺Qilin
🇷🇺 Qilin is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: Criminal. We map 14 detection use cases to this actor across 50 MITRE ATT&CK techniques, with 6 threat-intel articles citing them. Active in our corpus from 2025-12-16 to 2026-07-25.
crit 6
14Use cases
6Articles
50Techniques
3IOCs
Known aliases
QilinAgenda ransomware
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1014 · RootkitT1018 · Remote System DiscoveryT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1027 · Obfuscated Files or InformationT1027.002 · Software PackingT1027.005 · Indicator Removal from ToolsT1027.009 · Embedded PayloadsT1037.001 · Logon Script (Windows)T1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1053.005 · Scheduled TaskT1055 · Process InjectionT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1068 · Exploitation for Privilege EscalationT1070.001 · T1070.001T1070.004 · File DeletionT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1090 · ProxyT1098.001 · Additional Cloud CredentialsT1140 · Deobfuscate/Decode Files or InformationT1176 · Software ExtensionsT1190 · Exploit Public-Facing ApplicationT1195.002 · Compromise Software Supply ChainT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1219 · Remote Access ToolsT1489 · Service StopT1490 · Inhibit System RecoveryT1528 · Steal Application Access TokenT1539 · Steal Web Session CookieT1543.003 · Windows ServiceT1555.003 · Credentials from Web BrowsersT1562.001 · T1562.001T1562.004 · T1562.004T1562.006 · T1562.006T1562.009 · T1562.009T1566 · PhishingT1566.001 · Spearphishing AttachmentT1569.002 · Service Execution
Detection use cases (14)
Qilin (Agenda) Safe Mode encryptor staging via bcdedit safeboot + forced reboot Qilin recovery-inhibition + defense-tampering burst before encryption DevMan/Funky Mantis locker execution by known SHA256/MD5 hash DevMan ransomware encryption artifacts: .devman extension and deterministic ransom note DevMan pre-encryption recovery inhibition and event-log clearing Suspicious browser extension installation Infostealer — non-browser process accessing browser cookie/login DBs Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process Remote service execution — PsExec / SMB lateral movement OAuth consent / suspicious app grant Ransomware-style mass file rename / extension change LSASS process access / dump (credential theft)Threat-intel articles (6)
crit DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts · 2026-07-25
crit What the ransom note won’t say · 2026-04-20
crit EDR killers explained: Beyond the drivers · 2026-03-19
crit ESET Threat Report H2 2025 · 2025-12-16
Tracked indicators
IP addresses (3)
193.233.202.17 45.86.230.112 77.110.122.137CVEs (7)
CVE-2023-27532 CVE-2024-37085 CVE-2024-55591 CVE-2025-32433 CVE-2025-33073 CVE-2025-55182 CVE-2025-7771