Qilin
Agenda
Qilin ransomware, initially observed in July 2022 under the name “Agenda,” operates on a Ransomware-as-a-Service (RaaS) model. This model allows core developers to provide their malicious software and infrastructure to affiliates in exchange for a percentage of the profits generated from attacks. The name “Qilin” references a Chinese mythological creature symbolizing power and prosperity, a… Fuente: MISP
Actividad en Jábega · 12 semanas
1 noticias · vista por primera vez el 7 oct 2026 · la última, el 7 oct 2026
Noticias
- Qilin Ransomware Suspect Arrested in Japan, Extradited to GermanySecurityWeek · 7 oct 2026
Técnicas MITRE ATT&CK
Acceso inicial
T1190Exploit Public-Facing Application 40 reglas SigmaT1566.001Spearphishing Attachment 21 reglas SigmaT1566.002Spearphishing Link 3 reglas Sigma
Ejecución
T1047Windows Management Instrumentation 40 reglas SigmaT1053.005Scheduled Task 40 reglas SigmaT1059.001PowerShell 40 reglas SigmaT1059.003Windows Command Shell 40 reglas SigmaT1106Native API 12 reglas SigmaT1204.001Malicious Link 4 reglas SigmaT1204.002Malicious File 32 reglas Sigma
Persistencia
T1112Modify Registry 40 reglas SigmaT1547.001Registry Run Keys / Startup Folder 38 reglas SigmaT1547.004Winlogon Helper DLL 4 reglas Sigma
Escalada de privilegios
T1055.001Dynamic-link Library Injection 7 reglas SigmaT1134Access Token Manipulation 16 reglas SigmaT1484.001Group Policy Modification 6 reglas SigmaT1548.002Bypass User Account Control 40 reglas Sigma
Acceso a credenciales
Descubrimiento
T1007System Service Discovery 7 reglas SigmaT1012Query Registry 11 reglas SigmaT1016System Network Configuration Discovery 4 reglas SigmaT1018Remote System Discovery 9 reglas SigmaT1057Process Discovery 3 reglas SigmaT1069.002Domain Groups 13 reglas SigmaT1082System Information Discovery 18 reglas SigmaT1083File and Directory Discovery 17 reglas SigmaT1087.001Local Account 8 reglas SigmaT1087.002Domain Account 19 reglas SigmaT1135Network Share Discovery 6 reglas SigmaT1673Virtual Machine DiscoveryT1680Local Storage Discovery
Movimiento lateral
T1021.002SMB/Windows Admin Shares 35 reglas SigmaT1021.004SSH 5 reglas SigmaT1570Lateral Tool Transfer 4 reglas Sigma
Mando y control
Impacto
T1486Data Encrypted for Impact 14 reglas SigmaT1489Service Stop 13 reglas SigmaT1490Inhibit System Recovery 26 reglas SigmaT1491.001Internal Defacement 3 reglas SigmaT1529System Shutdown/Reboot 6 reglas Sigma
Stealth
T1027.013Encrypted/Encoded FileT1036.004Masquerade Task or Service 3 reglas SigmaT1036.005Match Legitimate Resource Name or Location 20 reglas SigmaT1070.004File Deletion 9 reglas SigmaT1480Execution GuardrailsT1480.002Mutual ExclusionT1678Delay Execution
Defense impairment
Relaciones por coaparición en noticias, no atribución. Fuentes: MISP galaxy, MITRE ATT&CK y SigmaHQ. attack.mitre.org ↗ malpedia.caad.fkie.fraunhofer.de ↗