Skip to main content
Back to Ransomware Database
Ransomware Group

qilin

Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.

Known victims2285

Threat Level

CRITICAL

Tactics, Techniques & Procedures (TTPs)

CredentialTheft

  • Mimikatz

DefenseEvasion

  • EDRSandBlast
  • PCHunter
  • PowerTool
  • Toshiba power management driver (BYOVD)
  • Updater for Carbon Black’s Cloud Sensor AV (upd.exe)
  • +2 more

DiscoveryEnum

  • Nmap
  • Nping

Exfiltration

  • EasyUpload.io
  • MEGA

LOLBAS

  • PowerShell
  • PsExec
  • WinRM
  • fsutil

Networking

  • Proxychains

Offsec

  • Cobalt Strike
  • Evilginx
  • Kali Linux
  • NetExec
  • SystemBC
  • +1 more

RMM-Tools

  • NetSupport
  • ScreenConnect

Indicators of Compromise (IOCs)

IP Addresses

5
  • 176.113.115.97
  • 176.113.115.209
  • 85.209.11.49
  • 31.41.244.100
  • 188.119.66.189

Get Complete IOC Feed

Access our full IOC database via API for integration with your SIEM/SOAR.

Get Started

No credit card required · Free API key

0

Check If You’re Affected

Search our database to see if your organization appears in qilin’s victim list.

Try it nowFree⌘K
Try

risk score · threat categories · sources · age · confidence — in one request