qilin
Ransomware group profile
Description
Qilin is an emerging ransomware group recognized for its advanced attack methodologies and ransomware-as-a-service (RaaS) model. The group has gained notoriety for targeting various sectors globally, employing double extortion tactics and exploiting software vulnerabilities to demand substantial ransoms in cryptocurrency. Known for their adaptability, Qilin continues to evolve in response to developing cybersecurity measures.
Key insights
- •Utilizes advanced encryption methods and double extortion techniques.
- •Targets high-value organizations worldwide across multiple sectors.
- •Gains initial access primarily through spear phishing and exploiting software vulnerabilities.
- •Employs ransomware variants written in Golang and Rust for enhanced evasion capabilities.
- •Rapidly adapts tactics to bypass security measures and leverage zero-day vulnerabilities.
- •Exploits public-facing applications and administrative tools for lateral movement.
- •Demands high ransoms, sometimes reaching tens of millions of dollars, causing significant operational disruptions.
Threat Level & Status Breakdown
For qilin · Based on incidents in selected period
Recent activity
Monthly attack count for qilin in the selected period
Intelligence
IOCs, YARA/Sigma rules, and related families for qilin
- e1763c22d4a4bad7987552d0327c83c850358f207c7b22d3af67a6af887a9870
- 50520639cf77df0c15cc95076fac901e3d04b708
- f0ac3999d4020cd051052a0627a2056d
- 1e52d9f04f99be66d5bc13db767c6acb5f0515906633f76e5c713681af9454df
- 4fde7b67da86fdd1587f78254acf9cd6766a7d77
- 72231dc69a71f3ac971fa335dc79a04569dd7a09
- 561d5036a1ecb3f12f2a0e9a439106b794993273f5775fe801717cd13ceb7631
- d003f34b61bcd624e154297e262004d5a4b02960f7a360ad7671173fd68c3cf5
- f28d811bd2072bd6f18cd09e5e4ebb77c9bec2729bb198d873c9b588784a903c
- ebddc99a00bd7a5dcaf7b73349309d970e5c69b8
- 88bd49b1bd9c2bde78bc4e394c993035e0fde3ea
- e705f69afd97f343f3c1f2bc6027d30935a0bfd29ff025c563f6f8c1f9a7478e
- a26f0a2da63a838161a7d335aaa5e4b314a232acc15dcabdb6f6dbec63cda642
- 468121e7d6952799f92940677268937c4c5f92ed
- b2398a81b5467f75f476a107027b3259
- a7f2a21c0cd5681eab30265432367cf4b649d2b340963a977e70a16738e955ac
- 24ffabbf13f4e9926d56faecfb11539b906e1a7730aa44cd2829b3a18bcd1175
- a0dc80a37eb7e2716c02a94adc8df9baedec192a77bde31669faed228d9ff526
- a3a06422e0a35c7722fce88343f32a6d
- f0a6b89ec7eee83274cd484cea526b970a3ef28038799b0a5774bb33c5793b55
- f9fb816a81b732b0631d9c1bed2958edc47ca52160c0bb03db352872bbd6cbd9
- 27a91c2e53e9e7bd6a1ccb8b0bed1f954f3011973248e710598a5e7d6c6ed668
- 7a89b347beb55f63dbcbcfc0beedbe43
- 6ae7c9a7ea0b8c40a64225734f6bd01d
- 5859e72f41ec951f10a188cc7d250b88
- 9b04a93e05ccff94667f04bffa7af600
- 03c90fd77221e1b5b9d98e32ada70990
- 96bb4ec6c820e485782bd206975a66a11f40dd7424abd9bace54760cbda0ae93
- 227f14f4c3aa35b9fb279f52c73b2e1e
- 603f38559310eb36089845343eddd8b5baa853aa
- e8af48581142212ad00b3ca8d9cec815aa883ed72f2f0cbae59a56ed80562832
- 6f018848fe17c63af6b62486a64a17d6a37192fa10dec02060efb3c570c10585
- 15cd13e0cad20394ec1405748e4bd50e3f27313c6274aee098c4eb0ede970b4c
- 06a0a243811e9c4738a9d413597659ca8d07b00f640b74adc9cb351c179b3268
- f736be55193c77af346dbe905e25f6a1dee3ec1aedca8989ad2088e4f6576b12
- 6fd538e4a8e3493dda6f9fcdc96e814bdd14f3e2ef8aa46f0143bff34b882c1b
- 9b95baa91c2e92756da970d7846b6c14
- b7703a59c39a0d2f7ef6422945aaeaaf061431af0533557246397551b8eed505
- 411b2ed12df1ace6559d3ea666c672617ce23e2ace06806bb53c55bcccb83303
- 8729815f87f4186fd46d52418c1b7ae2a54aebcf
- 254b7cca40f9e624b21841f60bff0919
- 347e61572fcd5871163fa034cd3fa52841f2788a3911235c5c338322b81704cf
- 66c27ef465437a28bc13ced74253a712af3cf3ac
- 7f26515b9422a852b98dbbb3519fd2b92ff088c22faef4d03d125f783f63c530
- de30d2b6d48804485994539356875fb4
- f97fdd1525fd9658352b793dc2e1a9b5ddac9ea24e95f8fc7d1780ef39d0960e
- 9bac4d59b06239ac6e5cf124e3d8bb13a7145547
- bd79aec521aa9f0cec374d57692b540b7b5a6ea8
- af4066ca0ae65ac63de6af60f46a9b23bb6dbfee
- e624e606597f8ae8a5522cd9547afd7c
- 82a4d2f69211d7931079be1a7fb36a058ab34f5e7a02adb020cb28165865edb5
- a5bfb7a7bfaf645edc78e30796d38508603ae1ea7aa76484138433badcdab329
- a53a9ca8a074c7108f8412c3f8c1fc5d
- b0de65b3bf5919910086f7fd1d2130570a2caee15580c95364c4341f89086f46
- 67e8e85e6e316cd3008a7d8ce0d72064416c7a00
- f150d19c57a910d714ef773a470bbb8ad88185f4b4713852fce706a1e7482b59
- 5a4164420db1e1bb6803981aada44b4e728914f7356d90ca91dd13cfdb097900
- 4373fefdec70547cb513be8e908997033197dc86
- 2674ad25fabe97a9eb10dcdbd32e4c9d
- 68225c5613afe2174ed46e074147676b0f9a3915
- 907c48316ea3d9592204cc16c817530b7bdaeed7f04d32535dac66de3713202c
- 147ad250400bb8c5ec2f7542afc82491fd23d665b070db03c17022ec969024a6
- 4885adc9de7e91b74a3ac01187775459acf3e4e026ee2fa776b3419cf8dbaf00
- 51d39aa39478beeac94f2d12f682ecce
- 8410f85c1710bfefccf0517cbbc91c0019073ced28d66539eeb596a9de8be1a9
- 56dfe55b016c08f09dd5a2ab58504b377a3cd66ffba236a5a0539f6e2e39aa71
- 77962a384d251f0aa8e3008a88f206d6cb1f7401c759c4614e3bfe865e3e985c
- 86233a285363c2a6863bf642deab7e20f062b8eb
- e35d10d019fdb04bdb9212235e580b141fc72a7432388c0f9509f2893d605898
- 5cdabf41672241798bcca94a7fdb25974ba5ab2289ebadc982149b3014677ae3
- 56e1d092c07322d9dad7d85d773953573cc3294b9e428b3bbbaf935ca4d2f7e7
- a97a28276e4f88134561d938f60db495
- d96762faa2323ba1e43e794ccf3ac2ba6674fa235d50bb4260766a2ea3156e0c
- 67cdee825311acf1048ddb273e53228e8a64106e2bf2f56043825fce78976b61
- 0ba2306ec15f7124fafc7615e81f34c7986ba9a5
- 21ab6e4cfe7a17c6fca334c920cd73dbbfac79ce881403b540c8001ae1aae010
- d6e7547ad7dfd1fbc62e8282aebcc391
- fe1033335a045c696c900d435119d210361966e2fb5cd1ba3382608cfa2c8e68
- 7d1118562d9ce29535a185244b14f2b7814ffc94580888ab9af06673bf5fa03e
- f3897381b9a4723b5f1f621632b1d83d889721535f544a6c0f5b83f6ea3e50b3
- 54de95cc33834a2f877ba4842860af27
- 21e3dba05111c86468bd060a51e6884c0954940d7b2d8f0ca3f72687e2d5fbac
- 770c1dc157226638f8ad1ac9669f4883
- 5537c708edb9a2c21f88e34e8a0f1744
- f65f27e8541da17f46ea61fb5896287d7f16684824eb8df6bb966479efceffc5
- f588802958c35fe18eb87bc36651a3d1
- d842bc9b4a6491c7955d9b645aea1a56b2531f59
- 2ae6f61321f32c9cdf8ac6a6f99cf7b191ae96fb9b22f64fb97d3ce47e49feef
- 9e82ee5bde6b5d29281a3c280e6d1f2e
- e3bba315a700fa7d10f86aa47db3346c799c0b0786717e8b73512d5439125b1d
- d34ca886266b7ce5f75f4caaa6e48f61e194bb55605c2bc4032ba8af5580b2e7
- bc33d5bee693ff6900c603b82262fff7a6cfabdf89e984fdccd12b52f21d0dc5
- 1f3e35e1e9df7f1428de5ca3cc4a9c21864a0144603d627f75f3d0778bba0d60
- 18033a3e5dddb1c155f5c68d5ccbb49e0072cef92f21104536b6d20040540660
- 9f61ff4deb8afced8b1ecdc8787a134c63bde632b18293fbfc94a91749e3e454
- 01ba260bd5c7cdeb6470fabcaccee32ac978d60dc1077e96ca0fbddea200c4cc
- 707f55096157aaf84174c2238f56f7addcd76f8d
- 54ff98956c3a0a3bc03a5f43d2c801ebcc1255bed644c78bad55d7f7beebd294
- 0f73b467ff03f9224c024f4eb3aecedb
- 1f5ae3b51b2dbf9419f4b7d51725a49023abc81c
- 0833762349e7ca085f1e1fc7ae6052404dd24833b103b0f0ba1db31c0c16bfb2
- 59906b022adfc6f63903adbdbb64c82881e0b1664d6b7f7ee42319019fcb3d7e
- 8208c9c1d7e1ceafe552500557dd5af6fffe64bfc20bc7bcc348a1ffce8ab658
- 73b1fffd35d3a72775e0ac4c836e70efefa0930551a2f813843bdfb32df4579a
- 7543750b905175ce1ad18774852d945003cb9bde
- 60bc22a15a52fe605c337fd9b53bb6c1593c5c8deff18fcc2817ac51d0d300a2
- 01735bb47a933ae9ec470e6be737d8f646a8ec66
- 0f9cd505df07e4ebfff3fe61b689e527
- dbcad7f3121dd0ccbcac1315337b25789fa86ca976472bea0531762d87b801a3
- 0bec4a243d5ca6180c60f26d49f49db5
- e5d28d70c2083e90d78ad5fc557cae68fc770c8787f366fc7dedc881c5abce64
- de5e2c06fc430da77cb7ee8db936c3664d5ef6bd
- b16e217cdca19e00c1b68bdfb28ead53b20adeabd6edcd91542f9fbf48942877
- b67958afc982cafbe1c3f114b444d7f4c91a88a3e7a86f89ab8795ac2110d1e6
- 8c57b97b04d7eabbae651c3400a5e6b897aea1ae8964507389340c44b99c523a
- 2c89a18944d3a895bd6432415546635e
- eaa9dc1c9dc8620549fee54d81399488292349d2c8767b58b7d0396564fb43e7
- 077ab28d66abdafad9f5411e18d26e87fe43da1410ee8fe846bd721ab0cb52de
- df5ab9015833023a03f92a797e20196672c1d6525501a9f9a94a45b0904c7403
- 11af4566539ad3224e968194c7a9ad7b596460d8f6e423fc62d1ea5fc0724326
- 62ae1907a67e73205bd2c88450d44127fe5aecb1e8ec06c67d537a0e566a3343
- 59f699db1c6b84d00cdcc47b782c99577df3816748b77d61a2e771e5ec928a7b
- ad69adcad0080974061b6b41dcfebe41d76489ef58c5c0f6330c268fcddb85b3
- 6ee94f6bdc4c4ed0fff621fec36c70ff093659ed
- e97bdf7fafb1cb2a2bf0a4e14f51e18a34f3ff2f6f7b99731e93070d50801bef
- 58d529bfaf7209b27c9b920e412fc140
- 597de376b1f80c06d501415dd973dcec
- cc14df781475ef0f3f2c441d03a622ea67cd86967526f8758ead6f45174db78e
- 888fa36b196c9b7722026e366fc574015fb7b552
- 94f05495eb1b2ebe592481e01d3900615040aa02bd1807b705a50e45d7c53444
- e3b6ea8c46fa831cec6f235a5cf48b38a4ae8d69
- f47e3555461472f23ab4766e4d5b6f6fd260e335a6abc31b860e569a720a5446
- e078778b62796bab2d7ab2b04d6b01bf
- 33fe6dc935c1b0df70761d05e26a00f8e5223087
- 83c6c1bb37c9071e569aa4b247e54ab763bbf5da
- 50edef3388c7764610d86356b90ba9ebda87c4b6ce45d29987d0c45c8e8d1bb9
- c9707a3bc0f177e1d1a5587c61699975b1153406962d187c9a732f97d8f867c5
- ee24110ddb4121b31561f86692650b63215a93fb2357b2bd3301fabc419290a3
- 44324ab4fcfcac9933670e8969e7ce334ed0d8139df6b6101c003d94480a9305
- 19bbc2daa05a0e932d72ecfa4e08282aa4a27becaabad03b8fc18bb85d37743a
- 5288353d7946566a1247f78239a98b2c859071c1547ce3f6db88ebae43db5f40
- 3928c5874249cc71b2d88e5c0c00989ac394238747bb7638897fc210531b4aab
- 0b30ea60e73c20a70e7462014f91e22dfe08ee03
- 47ec51b5f0ede1e70bd66f3f0152f9eb536d534565dbb7fcc3a05f542dbe4428
- 9d69703ea944a68812fbcc09a5a31e94ed533e7d87c6b411fb14c905e620a64c
- 1979530e00102fd69aa217aeda725571e91d99a04610187d367760f2c04c86ec
- c46b5a18ab3fb5fd1c5c8288a41c75bf0170c10b5e829af89370a12c86dd10f8
- 1406e538fc441e89ce3d1747017f97a5
- fb9cb023e9e209b51dc8128036564a70e7015d03247ef4a49525c2fc902e4808
- 033b4d28791b318fee5017e79c87c974ee621bae3b137d78ff11e2623ecf78a5
- fe52e893986a4fbec77634d2a87332205d512375b9d3d7a482188cd973746c0b
- 8f31f69f88a75d5faab4f94cfc2ec8a649fe1a24
- 1334f20e9559777fba749918a72bf174f0ab2437059161027d2f29949e9845e5
- 7e6d9dac619c04ae1b3c8c0906123e752ed66d63
- 39300863bcaad71e5d4efc9a1cae118440aa778f
- 58bb9dab4e9b3aa2fd1e7a7b17d2eeb1
- 794a0b6f21d80a426ac33a706a962b66a6cc0492
- bc65ed919988c8e4b8f5a1cd371745456601700a
- 5d6b9e80e12bfc595d4d26f6afb099b3cb471dd4
- 6f6246246365a7aa3c82fa3ee258ba806f4c8927bad9d4a9b44e955afb85caad
- a9da26cba0230c60880b1bec3f391ab43095de01
- b01056d3d5479039e3c0490e800adb6bfaafb2412e901fce35313aacd8c3c544
- 338d4f4ec714359d589918cee1adad12ef231907
- 74096848382ffb86a5ff0c7811b9867ad97f83d3f406b2c5aa9f357e1619fe21
- 4f8dc8a051f72b46179175cda7a4625fee7ce41abc13aac322d248c1918085bc
- a1aad716ef61cc29379a4fd096f891f86b3aa8c4aea038a09b59e61cc1d36302
- 0ed04a6f924b2757e64940fb909ae1e8b46eb7dcf377985074434a44c38ff64f
- 13fe3c1072ce308192994f2d7b329f7c8cbb192d49bdb538872383192d133ebb
- 3e2272b916da4be3c120d17490423230ab62c174
- 6bc8e3505d9f51368ddf323acb6abc49
- 485f804ddf201224915ed9df0112109b
- f3d09afc535097b0c5523579054b381e73ca58a2568e028fac0046ce73139d54
- c0979ec20b87084317d1bfa50405f7149c3b5c5f
- 3a24cd31c8287f7ee7336936a95f82b5d71a3746d210b4240869f3e3f5b34208
- cb77734eda7de79cd8ccedfb70f2a26c4c2847ad
- 572b37a5c1a2a6e53bbaa92433fbc529c6c7f8b2dec43e778e9c59e3ebce0b1c
- d8d074f8b0969536b87d5d1cffb88a7ee12c2ec1d4ee4fd44e5a8792180ad575
- 61d29bf4b6c7fc706839bcb13583410c46c838707424380aae7496e35889b687
- 906f88817e3bf1bd4e800cf798650f3a309c81ee9b78c2a37d9118ce2567ae3d
- 15249d8fcd6c59755622790123259c8a06a0a10d8ce4de66e394609cef2abb2b
- 1129a6c4350a0f452c9a441ec7b847bdbad252f4aacdcc85145473cbcd3fcc52
- e84270afa3030b48dc9e0c53a35c65aa
- 6ffae128e0dbf14c00e35d9ca17c9d6c81743d1fc5f8dd4272a03c66ecc1ad1f
- 7be35e662568c8bf8ba478f5e3cd547caf161dc0a433c87615fcdae6cc24594e
- 9ea321b6a0f069caab7092cfe1cbbde0
- 2b7d8a519f44d3105e9fde2770c75efb933994c658855dca7d48c8b4897f81e6
- 87d25d0e5880b3b5cd30106853cbfc6ef1ad38966b30d9bd5b99df46098e546c
- 30b49ae2f685d4403d3013410f80c2e2
- e01776ec67b9f1ae780c3e24ecc4bf06
- f1fd9443a2174dd31cf5558561ba3a9214ff521297681e119d5182d59cf310db
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for qilin
T1486
T1486
T1490
T1490
T1021
T1021
T1562
T1562
T1080
T1080
T1078
T1078
T1547
T1547
T1059
T1059
T1021.001
T1021.001
T1036
T1036
T1040
T1040
T1210
T1210
Victims(200)
| Company | Domain | Country | Industry | Status | Discovered | |
|---|---|---|---|---|---|---|
| Pacific Lamp & Supply | pacificlamp.com | US United States | Manufacturing | Claimed | about 18 hours ago | |
| Roth Industries | roth-industries.com | DE Germany | Manufacturing | Claimed | 1 day ago | |
| Sparkle Pools | sparklepoolsinc.com | US United States | Retail & E-Commerce | Claimed | 1 day ago | |
| PJ Daly Contracting | pjdalycontracting.com | IE Ireland | Other | Claimed | 1 day ago | |
| Commune d'Eyguires | eyguieres.org | FR France | Government & Defense | Claimed | 2 days ago | |
| Homes By J Anthony | homesbyjanthony.com | US United States | Other | Claimed | 3 days ago | |
| ATCOM Outsourcing | atcom.cl | CL Chile | Professional Services | Claimed | 3 days ago | |
| Skupina Don Don - GRUPO BIMBO | dondon.si | SI Slovenia | Other | Claimed | 3 days ago | |
| Makel Companies Group | makel.com.tr | TR Turkey | Other | Claimed | 3 days ago | |
| THL PROJECT MANAGEMENT SDN. BHD. | — | MY Malaysia | Professional Services | Claimed | 3 days ago | |
| Golfview Developmental Center | golfview.org | US United States | Healthcare | Claimed | 5 days ago | |
| Misericórdia de Santo Tirso | iscmst.pt | PT Portugal | Healthcare | Claimed | 5 days ago | |
| Q Link Wireless | qlinkwireless.com | US United States | Technology | Claimed | 5 days ago | |
| Cng Ty Cp T Vn Xd Tng Hp | nagecco.com | VN Vietnam | Professional Services | Claimed | 6 days ago | |
| MAVA Healthcare | mavamedical.com | US United States | Healthcare | Claimed | 6 days ago | |
| Grupo Indi | grupoindi.mx | MX Mexico | Professional Services | Claimed | 6 days ago | |
| Can Healthcare Group | izmircanhastanesi.com | TR Turkey | Healthcare | Claimed | 6 days ago | |
| DISTINET MURCIA SL | distinetmurcia.es | ES Spain | Professional Services | Claimed | 9 days ago | |
| Maui Divers Jewelry | mauidivers.com | US United States | Retail & E-Commerce | Claimed | 10 days ago | |
| Bitek System | bitek.co.kr | KR South Korea | Technology | Claimed | 10 days ago |
Page 1 of 10
Affected countries(109)
Countries where this group has been reported to target or leak victims.