Back to Ransomware Database
Ransomware Group
qilin
Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
Known victims2285
Threat Level
CRITICAL
Tactics, Techniques & Procedures (TTPs)
CredentialTheft
- Mimikatz
DefenseEvasion
- EDRSandBlast
- PCHunter
- PowerTool
- Toshiba power management driver (BYOVD)
- Updater for Carbon Black’s Cloud Sensor AV (upd.exe)
- +2 more
DiscoveryEnum
- Nmap
- Nping
Exfiltration
- EasyUpload.io
- MEGA
LOLBAS
- PowerShell
- PsExec
- WinRM
- fsutil
Networking
- Proxychains
Offsec
- Cobalt Strike
- Evilginx
- Kali Linux
- NetExec
- SystemBC
- +1 more
RMM-Tools
- NetSupport
- ScreenConnect
Indicators of Compromise (IOCs)
IP Addresses
5- 176.113.115.97
- 176.113.115.209
- 85.209.11.49
- 31.41.244.100
- 188.119.66.189
Get Complete IOC Feed
Access our full IOC database via API for integration with your SIEM/SOAR.
Get StartedNo credit card required · Free API key
Check If You’re Affected
Search our database to see if your organization appears in qilin’s victim list.
Try it nowFree⌘K
Try
risk score · threat categories · sources · age · confidence — in one request