Qilin
· Published 20/12/2025 08:53 · Modified 10/06/2026 13:00
· Source: Ransomware.Live
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 08:53
- Modified
- 10/06/2026 13:00
- Updated at
- 10/06/2026 13:00
- Revoked
- No
- Author / Source
- Ransomware.Live
- Resource level
- —
- Primary motivation
- —
- Related entities
- 8 reports, 35 attack patterns (mitre), 4 malware, 16 sectors, 25 countries, 58 indicators, 3 vulnerabilities (cve), 104 organization
Description
Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
Marking (TLP)
TLP:CLEAR
Labels
ransomware
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (8)
-
2 CVEs 11 MITREs 1 Malware 7 Observables 1 APTPublished 09/06/2026 15:50 · Modified 10/06/2026 11:00
-
1 APTPublished 19/12/2025 17:54 · Modified 20/12/2025 07:53
-
1 APTPublished 19/12/2025 14:46 · Modified 20/12/2025 07:53
-
19 MITREs 3 Malwares 17 Observables 1 APTPublished 27/10/2025 08:11 · Modified 27/10/2025 10:34
-
3 MITREs 2 Malwares 5 Observables 1 APTPublished 08/10/2025 16:25 · Modified 08/10/2025 16:40
-
11 MITREs 2 Malwares 1 APTPublished 19/08/2025 18:06 · Modified 19/08/2025 21:53
-
6 MITREs 1 Malware 7 Observables 1 APTPublished 31/07/2025 13:13 · Modified 31/07/2025 15:22
-
14 MITREs 1 Malware 1 APTPublished 01/04/2025 15:24 · Modified 01/04/2025 17:58
Attack patterns (MITRE) (35)
-
T1068 usesExploitation for Privilege Escalation
-
T1105 usesIngress Tool Transfer
-
T1560 usesArchive Collected Data
-
T1573 usesEncrypted Channel
-
T1055 usesProcess Injection
-
T1033 usesSystem Owner/User Discovery
-
T1082 usesSystem Information Discovery
-
T1489 usesService Stop
-
T1543 usesCreate or Modify System Process
-
T1070.001 usesClear Windows Event Logs
-
T1222 usesFile and Directory Permissions Modification
-
T1071.001 usesWeb Protocols
-
T1190 usesExploit Public-Facing Application
-
T1566 usesPhishing
-
T1046 usesNetwork Service Discovery
-
T1567 usesExfiltration Over Web Service
-
T1083 usesFile and Directory Discovery
-
T1018 usesRemote System Discovery
-
T1133 usesExternal Remote Services
-
T1087.002 usesDomain Account
-
T1053 usesScheduled Task/Job
-
T1090 usesProxy
-
T1048 usesExfiltration Over Alternative Protocol
-
T1589.002 usesEmail Addresses
-
T1110 usesBrute Force
-
T1486 usesData Encrypted for Impact
-
T1021.001 usesRemote Desktop Protocol
-
T1078 usesValid Accounts
-
T1070 usesIndicator Removal
-
T1059.001 usesPowerShell
-
T1057 usesProcess Discovery
-
T1484.001 usesGroup Policy Modification
-
T1537 usesTransfer Data to Cloud Account
-
T1490 usesInhibit System Recovery
-
T1176 usesSoftware Extensions
Malware (4)
-
KaWaLocker 2.0 usesFamilyPublished 19/08/2025 18:06 · Modified 19/08/2025 18:06
-
SystemBC usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
-
KaWaLocker usesFamilyPublished 19/08/2025 18:06 · Modified 19/08/2025 18:06
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:39 · Modified 27/05/2026 21:40
Sectors (16)
- Consumer Services targets
- Education targets
- Technology targets
- Retail targets
- Transportation targets
- Healthcare targets
- Finance targets
- Manufacturing targets
- Business Services targets
- Energy targets
- Telecommunications targets
- Construction targets
- Agriculture Food Production targets
- Transportation/Logistics targets
- Wholesale trade targets
- Hospitality Tourism targets
Countries (25)
- Italy targets
- Germany targets
- Colombia targets
- Netherlands targets
- Japan targets
- Belgium targets
- Mexico targets
- Finland targets
- Jordan targets
- Austria targets
- United Kingdom of Great Britain and Northern Ireland targets
- Tunisia targets
- Malaysia targets
- Sweden targets
- Taiwan targets
- United States of America targets
- India targets
- Thailand targets
- Puerto Rico targets
- Argentina targets
- Singapore targets
- Republic of Korea targets
- Peru targets
- Australia targets
- Poland targets
Indicators (58)
-
d1347f4dccebf2fcd672dcef9c66c91b9d3f12b9881e3e390626927718fda616related -
209.182.225.136related -
e705f69afd97f343f3c1f2bc6027d30935a0bfd29ff025c563f6f8c1f9a7478erelated -
cloud.screenconect.eurelated -
0b9b0715a1ffb427a02e61ae8fd11c00b5d086eb76102d4b12634e57285c1abarelated -
fadfef5caf6aede2a3a02a856b965ed40ee189612fa6fde81a30d5ed5ee6ae7drelated -
cloud.screenconnect.clrelated -
6ce228240458563d73c1c3cbbd04ef15cb7c5badacc78ce331848f5431b406ccrelated -
[email protected]related -
cloud.screenconnect.com.sorelated -
011df46e94218cbb2f0b8da13ab3cec397246fdc63436e58b1bf597550a647f6related -
cloud.screenconnect.com.lyrelated -
cloud.screenconnect.isrelated -
8fe746dd277e644fa0337db3394f0eadfafe57df029e13df9feef25c536adf4drelated -
792182b7c5a56e5ccefd32073dc374e66c6a4e7981075e3804f49a276878e0fbrelated -
cloud.screenconnect.com.borelated -
e129dd5cc80f39b24db489df999c847335d169910bd966814d2f81b0b1bbc365related -
account.microsoftonline.com.ecrelated -
cloud.screenconnect.com.serelated -
ef3e42e5fa24acaee2428ff0118feb2be925bfe6b1ea4eccce8b70a7ac5ab2ccrelated -
2fcloud.screenconnect.com.msrelated -
162.33.177.101related -
33a0121068748f6e6149bc6104228a81aecdfed387d7eb7547d95481e60150b7related -
38.54.107.167related -
cloud.screenconect.com.mxrelated -
b60ef95da28cba0d44cad8d03121b0bec3bc3865044d010cffb8450629d91c9frelated -
9da70c521b929725774c3980763a4aed9baf9de4e6f83fc8f668c3a365a55f82related -
f3a6d4ccdd0f663269c3909e74d6847608b8632fb2814b0436a4532b8281e617related -
cloud.screenconnect.com.phrelated -
holapor67.toprelated -
dbe9ed8e8e8cdff3670e7205cb9f11b5a0fa9d1983a6c6bab67527d8775c4ffdrelated -
cloud.screenconnect.com.vcrelated -
144.208.127.155related -
fdf6b0560385a6445bd399eba03c8662be9e61928d6cbc268d550163a5a09285related -
08224e4c619c7bbae1852d3a2d8dc1b7eb90d65bba9b73500ef7118af98e7e05related -
b52917b0658cd2a9197e6bb62bade243ee1ad164f2bb566f3a1e09dfa580397frelated -
kbsqoivihgdmwczmxkbovk7ss2dcynitwhhfu5yw725dboqo5kthfaad.onionrelated -
cloud.screenconnect.com.ngrelated -
45.61.136.173related -
ji57fr53anp7wb44tbbnp72qcgbhqywy4jmbncawdcrejj5amuvh3zqd.onionrelated -
38.60.157.139related -
d3af11d6bb6382717bf7b6a3aceada24f42f49a9489811a66505e03dd76fd1afrelated -
wikileaksv2.comrelated -
912018ab3c6b16b39ee84f17745ff0c80a33cee241013ec35d0281e40c0658d9related -
45c8716c69f56e26c98369e626e0b47d7ea5e15d3fb3d97f0d5b6e8997299d1arelated -
dd29138bf369863c33402a3fc995458ab5fc015a13a9378022131ab31d940c9frelated -
cloud.screenconnect.com.cmrelated -
cloud.iscreenconnect.comrelated -
cloud.screenconnect.com.amrelated -
38.54.88.201related -
aeddd8240c09777a84bb24b5be98e9f5465dc7638bec41fb67bbc209c3960ae1related -
ozsxj4hwxub7gio347ac7tyqqozvfioty37skqilzo2oqfs4cw2mgtyd.onionrelated -
a068f595472c4f94baf1c2a8fba6831a327514e24ec4b38e1eee2cf1646b1591related -
cloud.screenconnect.co.zarelated -
38ddde36929a2ddf13b1844973550072c41004187eaa2456f86e20aa93036b18related -
regsvchst.comrelated -
[email protected]related -
cloud.screenconnect.com.msrelated
Vulnerabilities (CVE) (3)
CVE-2023-27532
KEV
7.5
High
Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within …
- Attack vector
- Network
- Published
- 22/08/2023
- Modified
- 27/05/2026
CVE-2026-50751
KEV
9.3
Critical
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker …
- Attack vector
- NETWORK
- Complexity
- LOW
- EPSS
- 0.0001 (P1.2%)
- Published
- 08/06/2026
- Modified
- 10/06/2026
7.4
High
A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle …
- Attack vector
- Network
- Complexity
- High
- Published
- 08/06/2026
- Modified
- 10/06/2026
Organization (104)
- CoreHQ targets
- Cedar Valley Services targets
- BTX Global Logistics targets
- Publicidad Sarmiento targets
- SEIMITSU THAI COMPANY LIMITED targets
- STESAD targets
- Root Security targets
- Felix Gonzalez Law Firm targets
- сj Global targets
- Arimex Importadora targets
- Maison Law targets
- Silvon Software targets
- LogicVein targets
- Shore Gardens Rehabilitation & Nursing Center targets
- Jacobs & Sons targets
- Atalian targets
- Hongfa America targets
- National Biscuit Industries targets
- Happy Telecom targets
- MCC Economics targets
- Dom Development targets
- Hopital La Rabta targets
- PODOVIA targets
- Lasercomb targets
- Special Shapes Refractory targets
- TDS Construction targets
- Victoria Benelux targets
- RetireRight Financial Planning targets
- Besco Electrical targets
- GOOD+ Foundation targets
- Sugawara Laboratories targets
- GIV SRL targets
- A-Fast Tile & Coping targets
- Health Bridge Chiropractic targets
- Berkmann Wine Cellars targets
- Lugiano Medical targets
- Josh Steel targets
- Jing Cheng Enterprise Co., Ltd. targets
- mdm®NT targets
- Bangchak Corporation targets
- Sievert Electric Service and Sales targets
- Von Weise Associates targets
- Telstar-Hommel targets
- loginport targets
- Anteriad targets
- hollu Systemhygiene targets
- Syed Professional Services targets
- Georgia Dermatology & Skin Cancer Center targets
- Grandes Vinos targets
- Goodwin College targets
- Eastern Townships School Board targets
- IAPMO targets
- Jaf Gifts targets
- Sintac Recycling targets
- Rio supermarket targets
- Tommotek targets
- Typhoo Tea targets
- Farmacia San Pablo targets
- Hometech Window targets
- Fürth targets
- Cal Spas, Inc. targets
- USArt targets
- Questica targets
- Shah Law Office targets
- Sipl targets
- Omega Optical targets
- Dolan Construction targets
- Grupo Amanus targets
- Curtiembre Austral S.R.L. targets
- Integrated Technology Group targets
- Millard Manufacturing targets
- Sönmezler Metal targets
- La Papelera targets
- Ellison Educational Equipment targets
- Secorp Industries targets
- Jadtec Security Services targets
- SW/WC Service Cooperative targets
- Fortress Systems targets
- MG Chartered Professional Accountant targets
- Madera County Superintendent of Schools targets
- Sai Oral SurgeryOral targets
- Duffy's Sports Grill targets
- NECO Equipment targets
- daispa.it targets
- Z-Tronix targets
- Affinity Designs targets
- Luminex Software targets
- Acme Electric targets
- Scenic Solutions targets
- Arca Service targets
- Club Atlético River Plate targets
- Ruhnau Clarke targets
- Tlechaim targets
- Callipo Group targets
- Spring Grove Area School District targets
- Biogel targets
- Commercial Paving targets
- SV-Büro Ing. Schulz GmbH targets
- Enviaseo ESP targets
- KOPA Kozmetik A targets
- RWB Consulting Engineers targets
- Lynn Electrical targets
- Universiti Sains Islam Malaysia targets
- FMRS Health Systems targets