EXECUTIVE SUMMARY
Qilin is a ransomware-as-a-service (RaaS) offering that has been targeting healthcare organizations and various other industries worldwide. Originating from Russia, the group was observed recruiting affiliates. Qilin ransomware has variants written in Golang and Rust and gains initial access through spear phishing, leveraging Remote Monitoring and Management (RMM) tools, and other common methods. The group practices double extortion, demanding ransom payments to prevent data from being leaked.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Qilin is a ransomware-as-a-service (RaaS) offering that has been targeting healthcare organizations and various other industries worldwide. Originating from Russia, the group was observed recruiting affiliates. Qilin ransomware has variants written in Golang and Rust and gains initial access through spear phishing, leveraging Remote Monitoring and Management (RMM) tools, and other common methods. The group practices double extortion, demanding ransom payments to prevent data from being leaked.[emaillocker id="1283"]
Qilin ransomware, initially developed in Golang, now has variants written in Rust. It primarily targets Windows systems, but the Linux version was focusing on VMware ESXi servers. Ransomware gains initial access through spear phishing, exposed applications, and interfaces such as Citrix and RDP. It uses Remote Monitoring and Management (RMM) tools and Cobalt Strike for deployment and propagates via PsExec and SecureShell. The malware employs multiple encryption algorithms, including ChaCha20, AES-256, and RSA4096, and incorporates various obfuscation techniques. It also customizes filename extensions of encrypted files and terminates specific processes and services for optimal functionality.
Qilin ransomware continues to pose a significant threat to various industries worldwide, particularly the healthcare sector. With over 60 attacks claimed, the group's activities have steadily increased. Victims have been reported in countries including Australia, Canada, the United Kingdom, and the United States. Despite payment demands, there is no guarantee of data recovery, emphasizing the need for robust cybersecurity measures and awareness to mitigate the risks posed by this evolving ransomware operation.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| Execution | T1569 | System Services |
| T1053 | Scheduled Task/Job | |
| Persistence | T1037 | Boot or Logon Initialization Scripts |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation |
| T1548 | Abuse Elevation Control Mechanism | |
| Defense Evasion | T1078 | Valid Accounts |
| T1055 | Process Injection | |
| T1014 | Rootkit | |
| T1211 | Exploitation for Defense Evasion | |
| T1480 | Execution Guardrails | |
| T1497 | Virtualization/Sandbox Evasion | |
| T1027 | Obfuscated Files or Information | |
| Credential Access | T1003 | OS Credential Dumping |
| Discovery | T1082 | System Information Discovery |
| T1010 | Application Window Discovery | |
| T1046 | Network Service Discovery | |
| T1018 | Remote System Discovery | |
| Lateral Movement | T1021 | Remote Services |
| T1570 | Lateral Tool Transfer | |
| Collection | T1005 | Data from Local System |
| Command and Control | T1001 | Data Obfuscation |
| Exfiltration | T1011 | Exfiltration Over Other Network Medium |
| Impact | T1486 | Data Encrypted for Impact |
| T1485 | Data Destruction | |
| T1490 | Inhibit System Recovery | |
| T1561 | Disk Wipe |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]