Free, Unbiased, and Open threat intelligence

Uncovering Qilin Ransomware Attack Methods Through Multiple Cases

threat Profile

Description

Qilin (formerly Agenda) is a highly active Ransomware-as-a-Service (RaaS) group that has been operational since July 2022. In the second half of 2025, Qilin published victim information at a pace of more than 40 cases per month, reaching a peak of 100 cases in June 2025. The group employs double-extortion tactics, combining file encryption with data exfiltration and public disclosure threats. Manufacturing is the most affected sector (23%), followed by professional and scientific services (18%), and wholesale trade (10%). The group uses sophisticated attack methods including VPN compromise via leaked credentials, credential harvesting with Mimikatz and custom tools, dual ransomware deployment (encryptor_1.exe via PsExec for lateral spread and encryptor_2.exe for network share encryption), legitimate tools for data exfiltration (Cyberduck to Backblaze cloud storage), and persistence mechanisms through scheduled tasks and registry modifications. Character encodings in attacker scripts suggest Eastern European or Russian-speaking origins. The group targets critical infrastructure including healthcare, construction, retail, education, and finance sectors.

MITRE ATT&CK Techniques

T1078 T1133 T1110 T1110.003 T1003 T1482 T1018 T1087.002 T1033 T1057 T1222 T1222.001 T1046 T1082 T1059.001 T1086 T1048 T1537 T1484.001 T1021.001 T1021.002 T1105 T1562.001 T1070.001 T1490 T1489 T1486 T1112 T1053 T1547.001

Related Entities

Indicators of Compromise (10)

38ddde36929a2ddf13b1844973550072c41004187eaa2456f86e20aa93036b18
SHA256 hash of Qilin ransomware executable or related tool
d1347f4dccebf2fcd672dcef9c66c91b9d3f12b9881e3e390626927718fda616
SHA256 hash of Qilin ransomware executable or related tool
912018ab3c6b16b39ee84f17745ff0c80a33cee241013ec35d0281e40c0658d9
SHA256 hash of Qilin ransomware executable or related tool
dbe9ed8e8e8cdff3670e7205cb9f11b5a0fa9d1983a6c6bab67527d8775c4ffd
SHA256 hash of Qilin ransomware executable or related tool
e705f69afd97f343f3c1f2bc6027d30935a0bfd29ff025c563f6f8c1f9a7478e
SHA256 hash of Qilin ransomware executable or related tool
regsvchst.com
Command and control domain associated with Qilin ransomware operations
6ce228240458563d73c1c3cbbd04ef15cb7c5badacc78ce331848f5431b406cc
SHA256 hash of Qilin ransomware executable or related tool
86.106.85.36
IP address associated with Qilin ransomware infrastructure
dd29138bf369863c33402a3fc995458ab5fc015a13a9378022131ab31d940c9f
SHA256 hash of Qilin ransomware executable or related tool
holapor67.top
Command and control domain associated with Qilin ransomware operations

Metadata

Published

7 months ago

Views

4