Qilin
Agenda
Qilin ransomware, initially observed in July 2022 under the name “Agenda,” operates on a Ransomware-as-a-Service (RaaS) model. This model allows core developers to provide their malicious software and infrastructure to affiliates in exchange for a percentage of the profits generated from attacks. The name “Qilin” references a Chinese mythological creature symbolizing power and prosperity, a… Source: MISP
Activity on Jábega · 12 weeks
1 stories · first seen on 7 Oct 2026 · last seen on 7 Oct 2026
News
- Qilin Ransomware Suspect Arrested in Japan, Extradited to GermanySecurityWeek · 7 Oct 2026
MITRE ATT&CK techniques
Initial Access
T1190Exploit Public-Facing Application 40 Sigma rulesT1566.001Spearphishing Attachment 21 Sigma rulesT1566.002Spearphishing Link 3 Sigma rules
Execution
T1047Windows Management Instrumentation 40 Sigma rulesT1053.005Scheduled Task 40 Sigma rulesT1059.001PowerShell 40 Sigma rulesT1059.003Windows Command Shell 40 Sigma rulesT1106Native API 12 Sigma rulesT1204.001Malicious Link 4 Sigma rulesT1204.002Malicious File 32 Sigma rules
Persistence
T1112Modify Registry 40 Sigma rulesT1547.001Registry Run Keys / Startup Folder 38 Sigma rulesT1547.004Winlogon Helper DLL 4 Sigma rules
Privilege Escalation
T1055.001Dynamic-link Library Injection 7 Sigma rulesT1134Access Token Manipulation 16 Sigma rulesT1484.001Group Policy Modification 6 Sigma rulesT1548.002Bypass User Account Control 40 Sigma rules
Credential Access
Discovery
T1007System Service Discovery 7 Sigma rulesT1012Query Registry 11 Sigma rulesT1016System Network Configuration Discovery 4 Sigma rulesT1018Remote System Discovery 9 Sigma rulesT1057Process Discovery 3 Sigma rulesT1069.002Domain Groups 13 Sigma rulesT1082System Information Discovery 18 Sigma rulesT1083File and Directory Discovery 17 Sigma rulesT1087.001Local Account 8 Sigma rulesT1087.002Domain Account 19 Sigma rulesT1135Network Share Discovery 6 Sigma rulesT1673Virtual Machine DiscoveryT1680Local Storage Discovery
Lateral Movement
T1021.002SMB/Windows Admin Shares 35 Sigma rulesT1021.004SSH 5 Sigma rulesT1570Lateral Tool Transfer 4 Sigma rules
Command and Control
Impact
T1486Data Encrypted for Impact 14 Sigma rulesT1489Service Stop 13 Sigma rulesT1490Inhibit System Recovery 26 Sigma rulesT1491.001Internal Defacement 3 Sigma rulesT1529System Shutdown/Reboot 6 Sigma rules
Stealth
T1027.013Encrypted/Encoded FileT1036.004Masquerade Task or Service 3 Sigma rulesT1036.005Match Legitimate Resource Name or Location 20 Sigma rulesT1070.004File Deletion 9 Sigma rulesT1480Execution GuardrailsT1480.002Mutual ExclusionT1678Delay Execution
Defense impairment
Relationships come from co-occurrence in the news, not attribution. Sources: MISP galaxy, MITRE ATT&CK and SigmaHQ. attack.mitre.org ↗ malpedia.caad.fkie.fraunhofer.de ↗