🇷🇺Qilin
🇷🇺 Qilin is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: Criminal. We map 14 detection use cases to this actor across 49 MITRE ATT&CK techniques, with 8 threat-intel articles citing them. Active in our corpus from 2025-12-16 to 2026-06-11.
crit 7high 1
14Use cases
8Articles
49Techniques
10IOCs
Known aliases
QilinAgenda ransomware
Top techniques
All other tracked techniques
T1005 · Data from Local SystemT1014 · RootkitT1021.002 · SMB/Windows Admin SharesT1027 · Obfuscated Files or InformationT1027.002 · Software PackingT1027.005 · Indicator Removal from ToolsT1027.009 · Embedded PayloadsT1036.005 · Match Legitimate Resource Name or LocationT1037.001 · Logon Script (Windows)T1055 · Process InjectionT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.004 · Unix ShellT1059.005 · Visual BasicT1068 · Exploitation for Privilege EscalationT1070.004 · File DeletionT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1098.001 · Additional Cloud CredentialsT1105 · Ingress Tool TransferT1133 · External Remote ServicesT1140 · Deobfuscate/Decode Files or InformationT1190 · Exploit Public-Facing ApplicationT1195.002 · Compromise Software Supply ChainT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1219 · Remote Access ToolsT1489 · Service StopT1490 · Inhibit System RecoveryT1496 · Resource HijackingT1528 · Steal Application Access TokenT1539 · Steal Web Session CookieT1543.003 · Windows ServiceT1555.003 · Credentials from Web BrowsersT1562.001 · T1562.001T1562.004 · T1562.004T1562.006 · T1562.006T1562.009 · T1562.009T1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1567.002 · Exfiltration to Cloud StorageT1569.002 · Service Execution
Detection use cases (14)
Qilin (Agenda) safe-mode reboot chain — bcdedit safeboot + forced restart prior to encryption Qilin (Agenda) inhibit-recovery burst — shadow copy + backup catalog + boot recovery destruction Talos weekly prevalent malware hash execution (Coinminer/Injector/Dropper.Miner) Talos prevalent malware hash dropped to disk (DeviceFileEvents pivot) Talos prevalent malware filename pattern — VID001.exe and d4aa3e70..._N_Exe.exe Ransomware-style mass file rename / extension change LSASS process access / dump (credential theft) Remote service execution — PsExec / SMB lateral movement RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard File hash IOCs — endpoint file/process match Article-specific behavioural hunt — A tale of two eras Beaconing — periodic outbound to small set of destinations Network connections to article IPs / domains Asset exposure — vulnerability matches article CVE(s)Threat-intel articles (8)
high A tale of two eras · 2026-06-11
crit What the ransom note won’t say · 2026-04-20
crit EDR killers explained: Beyond the drivers · 2026-03-19
crit ESET Threat Report H2 2025 · 2025-12-16
Tracked indicators
IP addresses (10)
144.208.127.155 162.33.177.101 176.120.22.127 209.182.225.136 38.54.107.167 38.54.88.201 38.60.157.139 45.76.26.42 45.77.149.152 66.42.99.200CVEs (9)
CVE-2024-55591 CVE-2025-32433 CVE-2025-33073 CVE-2026-11645 CVE-2026-20131 CVE-2026-20230 CVE-2026-23479 CVE-2026-50751 CVE-2026-50752