qilin
Ransomware group profile
Description
Qilin is an emerging ransomware group recognized for its advanced attack methodologies and ransomware-as-a-service (RaaS) model. The group has gained notoriety for targeting various sectors globally, employing double extortion tactics and exploiting software vulnerabilities to demand substantial ransoms in cryptocurrency. Known for their adaptability, Qilin continues to evolve in response to developing cybersecurity measures.
Key insights
- •Utilizes advanced encryption methods and double extortion techniques.
- •Targets high-value organizations worldwide across multiple sectors.
- •Gains initial access primarily through spear phishing and exploiting software vulnerabilities.
- •Employs ransomware variants written in Golang and Rust for enhanced evasion capabilities.
- •Rapidly adapts tactics to bypass security measures and leverage zero-day vulnerabilities.
- •Exploits public-facing applications and administrative tools for lateral movement.
- •Demands high ransoms, sometimes reaching tens of millions of dollars, causing significant operational disruptions.
Threat Level & Status Breakdown
For qilin · Based on incidents in selected period
Recent activity
Monthly attack count for qilin in the selected period
Intelligence
IOCs, YARA/Sigma rules, and related families for qilin
- e1763c22d4a4bad7987552d0327c83c850358f207c7b22d3af67a6af887a9870
- 50520639cf77df0c15cc95076fac901e3d04b708
- f0ac3999d4020cd051052a0627a2056d
- a4566f8bd274ccdd7b0b5f958e1a8097573ad695
- 1e52d9f04f99be66d5bc13db767c6acb5f0515906633f76e5c713681af9454df
- 4fde7b67da86fdd1587f78254acf9cd6766a7d77
- 72231dc69a71f3ac971fa335dc79a04569dd7a09
- 561d5036a1ecb3f12f2a0e9a439106b794993273f5775fe801717cd13ceb7631
- d003f34b61bcd624e154297e262004d5a4b02960f7a360ad7671173fd68c3cf5
- f28d811bd2072bd6f18cd09e5e4ebb77c9bec2729bb198d873c9b588784a903c
- ebddc99a00bd7a5dcaf7b73349309d970e5c69b8
- 88bd49b1bd9c2bde78bc4e394c993035e0fde3ea
- e705f69afd97f343f3c1f2bc6027d30935a0bfd29ff025c563f6f8c1f9a7478e
- 12500f6c87ce62712a0ed6652c57468d15c14223
- 9ddae47ff968343a8c32a5344060257fdc08e2a7bdb9a227c8b3a584ee3c9f1e
- a26f0a2da63a838161a7d335aaa5e4b314a232acc15dcabdb6f6dbec63cda642
- 468121e7d6952799f92940677268937c4c5f92ed
- b2398a81b5467f75f476a107027b3259
- a7f2a21c0cd5681eab30265432367cf4b649d2b340963a977e70a16738e955ac
- 24ffabbf13f4e9926d56faecfb11539b906e1a7730aa44cd2829b3a18bcd1175
- a0dc80a37eb7e2716c02a94adc8df9baedec192a77bde31669faed228d9ff526
- a3a06422e0a35c7722fce88343f32a6d
- f0a6b89ec7eee83274cd484cea526b970a3ef28038799b0a5774bb33c5793b55
- f9fb816a81b732b0631d9c1bed2958edc47ca52160c0bb03db352872bbd6cbd9
- 27a91c2e53e9e7bd6a1ccb8b0bed1f954f3011973248e710598a5e7d6c6ed668
- 7a89b347beb55f63dbcbcfc0beedbe43
- 6ae7c9a7ea0b8c40a64225734f6bd01d
- 5859e72f41ec951f10a188cc7d250b88
- 9b04a93e05ccff94667f04bffa7af600
- a11ee9cdc59e5caa59aefd27b30d104f3ad68e62
- 03c90fd77221e1b5b9d98e32ada70990
- 96bb4ec6c820e485782bd206975a66a11f40dd7424abd9bace54760cbda0ae93
- 227f14f4c3aa35b9fb279f52c73b2e1e
- 603f38559310eb36089845343eddd8b5baa853aa
- bf80c96089d37b8571b5de7cab14dd9f
- 6f018848fe17c63af6b62486a64a17d6a37192fa10dec02060efb3c570c10585
- a9deac7dfa66c4fa0d94e448da73c50eb50501de
- 15cd13e0cad20394ec1405748e4bd50e3f27313c6274aee098c4eb0ede970b4c
- 06a0a243811e9c4738a9d413597659ca8d07b00f640b74adc9cb351c179b3268
- f736be55193c77af346dbe905e25f6a1dee3ec1aedca8989ad2088e4f6576b12
- 6fd538e4a8e3493dda6f9fcdc96e814bdd14f3e2ef8aa46f0143bff34b882c1b
- 9b95baa91c2e92756da970d7846b6c14
- b7703a59c39a0d2f7ef6422945aaeaaf061431af0533557246397551b8eed505
- 411b2ed12df1ace6559d3ea666c672617ce23e2ace06806bb53c55bcccb83303
- 8729815f87f4186fd46d52418c1b7ae2a54aebcf
- 254b7cca40f9e624b21841f60bff0919
- 347e61572fcd5871163fa034cd3fa52841f2788a3911235c5c338322b81704cf
- 66c27ef465437a28bc13ced74253a712af3cf3ac
- 7f26515b9422a852b98dbbb3519fd2b92ff088c22faef4d03d125f783f63c530
- de30d2b6d48804485994539356875fb4
- f97fdd1525fd9658352b793dc2e1a9b5ddac9ea24e95f8fc7d1780ef39d0960e
- 9bac4d59b06239ac6e5cf124e3d8bb13a7145547
- bd79aec521aa9f0cec374d57692b540b7b5a6ea8
- af4066ca0ae65ac63de6af60f46a9b23bb6dbfee
- e624e606597f8ae8a5522cd9547afd7c
- 82a4d2f69211d7931079be1a7fb36a058ab34f5e7a02adb020cb28165865edb5
- a5bfb7a7bfaf645edc78e30796d38508603ae1ea7aa76484138433badcdab329
- a53a9ca8a074c7108f8412c3f8c1fc5d
- b0de65b3bf5919910086f7fd1d2130570a2caee15580c95364c4341f89086f46
- 67e8e85e6e316cd3008a7d8ce0d72064416c7a00
- f150d19c57a910d714ef773a470bbb8ad88185f4b4713852fce706a1e7482b59
- 5a4164420db1e1bb6803981aada44b4e728914f7356d90ca91dd13cfdb097900
- 4373fefdec70547cb513be8e908997033197dc86
- 2674ad25fabe97a9eb10dcdbd32e4c9d
- 68225c5613afe2174ed46e074147676b0f9a3915
- 907c48316ea3d9592204cc16c817530b7bdaeed7f04d32535dac66de3713202c
- 0274b39e79fa142adb154d090fa2d09e
- 147ad250400bb8c5ec2f7542afc82491fd23d665b070db03c17022ec969024a6
- 4885adc9de7e91b74a3ac01187775459acf3e4e026ee2fa776b3419cf8dbaf00
- 51d39aa39478beeac94f2d12f682ecce
- 8410f85c1710bfefccf0517cbbc91c0019073ced28d66539eeb596a9de8be1a9
- 56dfe55b016c08f09dd5a2ab58504b377a3cd66ffba236a5a0539f6e2e39aa71
- 77962a384d251f0aa8e3008a88f206d6cb1f7401c759c4614e3bfe865e3e985c
- 86233a285363c2a6863bf642deab7e20f062b8eb
- e35d10d019fdb04bdb9212235e580b141fc72a7432388c0f9509f2893d605898
- 5cdabf41672241798bcca94a7fdb25974ba5ab2289ebadc982149b3014677ae3
- 56e1d092c07322d9dad7d85d773953573cc3294b9e428b3bbbaf935ca4d2f7e7
- a97a28276e4f88134561d938f60db495
- d96762faa2323ba1e43e794ccf3ac2ba6674fa235d50bb4260766a2ea3156e0c
- 67cdee825311acf1048ddb273e53228e8a64106e2bf2f56043825fce78976b61
- 0ba2306ec15f7124fafc7615e81f34c7986ba9a5
- 21ab6e4cfe7a17c6fca334c920cd73dbbfac79ce881403b540c8001ae1aae010
- d6e7547ad7dfd1fbc62e8282aebcc391
- fe1033335a045c696c900d435119d210361966e2fb5cd1ba3382608cfa2c8e68
- 7d1118562d9ce29535a185244b14f2b7814ffc94580888ab9af06673bf5fa03e
- f3897381b9a4723b5f1f621632b1d83d889721535f544a6c0f5b83f6ea3e50b3
- 9f7080e56d9b33fe8465da4759146655
- 54de95cc33834a2f877ba4842860af27
- 21e3dba05111c86468bd060a51e6884c0954940d7b2d8f0ca3f72687e2d5fbac
- 770c1dc157226638f8ad1ac9669f4883
- 5537c708edb9a2c21f88e34e8a0f1744
- f65f27e8541da17f46ea61fb5896287d7f16684824eb8df6bb966479efceffc5
- f588802958c35fe18eb87bc36651a3d1
- 5aa3124e5c4921e5edfc60133b5d71da21b07da3
- d842bc9b4a6491c7955d9b645aea1a56b2531f59
- 2ae6f61321f32c9cdf8ac6a6f99cf7b191ae96fb9b22f64fb97d3ce47e49feef
- 9e82ee5bde6b5d29281a3c280e6d1f2e
- e3bba315a700fa7d10f86aa47db3346c799c0b0786717e8b73512d5439125b1d
- d34ca886266b7ce5f75f4caaa6e48f61e194bb55605c2bc4032ba8af5580b2e7
- bc33d5bee693ff6900c603b82262fff7a6cfabdf89e984fdccd12b52f21d0dc5
- 1f3e35e1e9df7f1428de5ca3cc4a9c21864a0144603d627f75f3d0778bba0d60
- 18033a3e5dddb1c155f5c68d5ccbb49e0072cef92f21104536b6d20040540660
- 9f61ff4deb8afced8b1ecdc8787a134c63bde632b18293fbfc94a91749e3e454
- 01ba260bd5c7cdeb6470fabcaccee32ac978d60dc1077e96ca0fbddea200c4cc
- 707f55096157aaf84174c2238f56f7addcd76f8d
- 54ff98956c3a0a3bc03a5f43d2c801ebcc1255bed644c78bad55d7f7beebd294
- 0f73b467ff03f9224c024f4eb3aecedb
- 1f5ae3b51b2dbf9419f4b7d51725a49023abc81c
- 0833762349e7ca085f1e1fc7ae6052404dd24833b103b0f0ba1db31c0c16bfb2
- 59906b022adfc6f63903adbdbb64c82881e0b1664d6b7f7ee42319019fcb3d7e
- 8208c9c1d7e1ceafe552500557dd5af6fffe64bfc20bc7bcc348a1ffce8ab658
- 73b1fffd35d3a72775e0ac4c836e70efefa0930551a2f813843bdfb32df4579a
- 7543750b905175ce1ad18774852d945003cb9bde
- 60bc22a15a52fe605c337fd9b53bb6c1593c5c8deff18fcc2817ac51d0d300a2
- 01735bb47a933ae9ec470e6be737d8f646a8ec66
- 0f9cd505df07e4ebfff3fe61b689e527
- dbcad7f3121dd0ccbcac1315337b25789fa86ca976472bea0531762d87b801a3
- 0bec4a243d5ca6180c60f26d49f49db5
- e5d28d70c2083e90d78ad5fc557cae68fc770c8787f366fc7dedc881c5abce64
- de5e2c06fc430da77cb7ee8db936c3664d5ef6bd
- 966743447745a30c93ffc1cf1e59ec58
- b16e217cdca19e00c1b68bdfb28ead53b20adeabd6edcd91542f9fbf48942877
- b67958afc982cafbe1c3f114b444d7f4c91a88a3e7a86f89ab8795ac2110d1e6
- 8c57b97b04d7eabbae651c3400a5e6b897aea1ae8964507389340c44b99c523a
- 2c89a18944d3a895bd6432415546635e
- eaa9dc1c9dc8620549fee54d81399488292349d2c8767b58b7d0396564fb43e7
- 077ab28d66abdafad9f5411e18d26e87fe43da1410ee8fe846bd721ab0cb52de
- df5ab9015833023a03f92a797e20196672c1d6525501a9f9a94a45b0904c7403
- 11af4566539ad3224e968194c7a9ad7b596460d8f6e423fc62d1ea5fc0724326
- 62ae1907a67e73205bd2c88450d44127fe5aecb1e8ec06c67d537a0e566a3343
- 59f699db1c6b84d00cdcc47b782c99577df3816748b77d61a2e771e5ec928a7b
- ad69adcad0080974061b6b41dcfebe41d76489ef58c5c0f6330c268fcddb85b3
- 6ee94f6bdc4c4ed0fff621fec36c70ff093659ed
- e97bdf7fafb1cb2a2bf0a4e14f51e18a34f3ff2f6f7b99731e93070d50801bef
- 7556ae58c215b8245a43f764f0676c7a8f0fdd1a
- 2d91a78e739891c9854c254f5b2a6b84c0e167dfa253466cbccd2cdd1c20145d
- 597de376b1f80c06d501415dd973dcec
- cc14df781475ef0f3f2c441d03a622ea67cd86967526f8758ead6f45174db78e
- 888fa36b196c9b7722026e366fc574015fb7b552
- 94f05495eb1b2ebe592481e01d3900615040aa02bd1807b705a50e45d7c53444
- e3b6ea8c46fa831cec6f235a5cf48b38a4ae8d69
- f47e3555461472f23ab4766e4d5b6f6fd260e335a6abc31b860e569a720a5446
- e078778b62796bab2d7ab2b04d6b01bf
- 33fe6dc935c1b0df70761d05e26a00f8e5223087
- 83c6c1bb37c9071e569aa4b247e54ab763bbf5da
- 50edef3388c7764610d86356b90ba9ebda87c4b6ce45d29987d0c45c8e8d1bb9
- c9707a3bc0f177e1d1a5587c61699975b1153406962d187c9a732f97d8f867c5
- ee24110ddb4121b31561f86692650b63215a93fb2357b2bd3301fabc419290a3
- 44324ab4fcfcac9933670e8969e7ce334ed0d8139df6b6101c003d94480a9305
- 19bbc2daa05a0e932d72ecfa4e08282aa4a27becaabad03b8fc18bb85d37743a
- 5288353d7946566a1247f78239a98b2c859071c1547ce3f6db88ebae43db5f40
- 3928c5874249cc71b2d88e5c0c00989ac394238747bb7638897fc210531b4aab
- 0b30ea60e73c20a70e7462014f91e22dfe08ee03
- 47ec51b5f0ede1e70bd66f3f0152f9eb536d534565dbb7fcc3a05f542dbe4428
- 9d69703ea944a68812fbcc09a5a31e94ed533e7d87c6b411fb14c905e620a64c
- 1979530e00102fd69aa217aeda725571e91d99a04610187d367760f2c04c86ec
- c46b5a18ab3fb5fd1c5c8288a41c75bf0170c10b5e829af89370a12c86dd10f8
- ba914fe77b177b45799403b16dd14765c510a074
- 1406e538fc441e89ce3d1747017f97a5
- fb9cb023e9e209b51dc8128036564a70e7015d03247ef4a49525c2fc902e4808
- 033b4d28791b318fee5017e79c87c974ee621bae3b137d78ff11e2623ecf78a5
- fe52e893986a4fbec77634d2a87332205d512375b9d3d7a482188cd973746c0b
- 8f31f69f88a75d5faab4f94cfc2ec8a649fe1a24
- 1334f20e9559777fba749918a72bf174f0ab2437059161027d2f29949e9845e5
- 7e6d9dac619c04ae1b3c8c0906123e752ed66d63
- 8e8f463c37ea7133194731bfe4490e6713dd0133f30fe08a6d069d10fa7db2c6
- 39300863bcaad71e5d4efc9a1cae118440aa778f
- 58bb9dab4e9b3aa2fd1e7a7b17d2eeb1
- 794a0b6f21d80a426ac33a706a962b66a6cc0492
- bc65ed919988c8e4b8f5a1cd371745456601700a
- 5d6b9e80e12bfc595d4d26f6afb099b3cb471dd4
- 6f6246246365a7aa3c82fa3ee258ba806f4c8927bad9d4a9b44e955afb85caad
- a9da26cba0230c60880b1bec3f391ab43095de01
- b01056d3d5479039e3c0490e800adb6bfaafb2412e901fce35313aacd8c3c544
- 338d4f4ec714359d589918cee1adad12ef231907
- 74096848382ffb86a5ff0c7811b9867ad97f83d3f406b2c5aa9f357e1619fe21
- 849ef3cf2c251f6088d735c7b67c3434e915a1d924efecf4d608dbe9bb01928a
- 4f8dc8a051f72b46179175cda7a4625fee7ce41abc13aac322d248c1918085bc
- a1aad716ef61cc29379a4fd096f891f86b3aa8c4aea038a09b59e61cc1d36302
- 0ed04a6f924b2757e64940fb909ae1e8b46eb7dcf377985074434a44c38ff64f
- 13fe3c1072ce308192994f2d7b329f7c8cbb192d49bdb538872383192d133ebb
- 110a5b08b1f83748019545067a69216b
- 534bd6b99ed0e40ccbefad1656f03cc56dd9cc3f6d990cd7cb87af4cceebe144
- 3e2272b916da4be3c120d17490423230ab62c174
- 6bc8e3505d9f51368ddf323acb6abc49
- 485f804ddf201224915ed9df0112109b
- f3d09afc535097b0c5523579054b381e73ca58a2568e028fac0046ce73139d54
- c0979ec20b87084317d1bfa50405f7149c3b5c5f
- 3a24cd31c8287f7ee7336936a95f82b5d71a3746d210b4240869f3e3f5b34208
- cb77734eda7de79cd8ccedfb70f2a26c4c2847ad
- 572b37a5c1a2a6e53bbaa92433fbc529c6c7f8b2dec43e778e9c59e3ebce0b1c
- d8d074f8b0969536b87d5d1cffb88a7ee12c2ec1d4ee4fd44e5a8792180ad575
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for qilin
T1486
T1486
T1490
T1490
T1021
T1021
T1562
T1562
T1080
T1080
T1078
T1078
T1547
T1547
T1059
T1059
T1021.001
T1021.001
T1036
T1036
T1040
T1040
T1210
T1210
Victims(200)
| Company | Domain | Country | Industry | Status | Discovered | |
|---|---|---|---|---|---|---|
| ISOPLUS | isoplus.gr | GR Greece | Professional Services | Claimed | about 12 hours ago | |
| Cash Canada | cashcanada.com | CA Canada | Financial Services | Claimed | 1 day ago | |
| Schumacher Homes | schumacherhomes.com | US United States | Other | Claimed | 3 days ago | |
| Central Bank of Libya | cbl.gov.ly | LY Libya | Financial Services | Claimed | 3 days ago | |
| Sivatel Bangkok | sivatelbangkok.com | TH Thailand | Technology | Claimed | 4 days ago | |
| Tri-tec | tri-tec.com | US United States | Professional Services | Claimed | 4 days ago | |
| Florida Engineering Services | florida-engineering-services.com | US United States | Other | Claimed | 4 days ago | |
| Taiwan Sintong Machinery Co., Ltd | twsinto.com.tw | TW Taiwan | Manufacturing | Claimed | 4 days ago | |
| Pacific Lamp & Supply | pacificlamp.com | US United States | Manufacturing | Claimed | 5 days ago | |
| Roth Industries | roth-industries.com | DE Germany | Manufacturing | Claimed | 6 days ago | |
| Sparkle Pools | sparklepoolsinc.com | US United States | Retail & E-Commerce | Claimed | 6 days ago | |
| PJ Daly Contracting | pjdalycontracting.com | IE Ireland | Other | Claimed | 6 days ago | |
| Commune d'Eyguires | eyguieres.org | FR France | Government & Defense | Claimed | 6 days ago | |
| Homes By J Anthony | homesbyjanthony.com | US United States | Other | Claimed | 7 days ago | |
| ATCOM Outsourcing | atcom.cl | CL Chile | Professional Services | Claimed | 7 days ago | |
| Skupina Don Don - GRUPO BIMBO | dondon.si | SI Slovenia | Other | Claimed | 7 days ago | |
| Makel Companies Group | makel.com.tr | TR Turkey | Other | Claimed | 7 days ago | |
| THL PROJECT MANAGEMENT SDN. BHD. | — | MY Malaysia | Professional Services | Claimed | 7 days ago | |
| Golfview Developmental Center | golfview.org | US United States | Healthcare | Claimed | 9 days ago | |
| Misericórdia de Santo Tirso | iscmst.pt | PT Portugal | Healthcare | Claimed | 9 days ago |
Page 1 of 10
Affected countries(110)
Countries where this group has been reported to target or leak victims.