Technical profile
Qilin
MITRE describes Qilin as RaaS ransomware, with Go and Rust variants.
Confirmed (Confirmed) · Reference profile status, not attribution for an individual case.
- Name / status
- Qilin · Confirmed
- Aliases
- Agenda
- First seen
- At least since 2022 according to MITRE.
- Target platforms
- Windows • Linux • ESXi
- TTP
- Reference MITRE S1242, including T1486.
- Current Activity
- No verified current activity dataset is available in this profile.
- Target sectors
- Sector categories have not been standardized in V1.
- MITRE ATT&CK
- Compare techniques against the reference sources; see the TTP Map.
- IOC
- Use only sourced, contextualized indicators; see IOC Watch.
- Extension
- No separately edited extension inventory here.
- Ransom note
- Do not attribute from ransom note content alone.
- Encryption behavior
- Varies by variant; consult the source for the correct sample.
- Partial / Full / Chunked
- No separate measurements on a representative sample.
- Public decryptor status
- Insufficient data
- Recovery Intelligence
- No validated recovery observations support generalization to all variants.
- Leak site
- Leak-site claims are not independent evidence. Direct links are not published.
- Known incidents
- No separately verified incident list has been added to this profile.
- Detection notes
- Compare multiple evidence sources; distinguish a single indicator from a conclusion about the entire incident.
- Recovery notes
- Assess samples and data structures. A family name alone does not establish recovery prospects.
- Last updated
- 09/10/2026 (UTC+7)
Sources
MITRE ATT&CK — Qilin, S1242Sourced behavioral profile. Does not attribute an individual case to Qilin.
Each source's scope and date are recorded separately when available. A citation does not independently verify every assessment.
Update history
09/10/2026 · Added recovery scope, decryptor status and tool links; marked fields with insufficient data.
04/10/2026 · Created the reference profile and clearly marked missing data.