Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data. Known victims: 1782 2 negotiation log(s) available, 3 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Countries / Regions

Taiwan

AI Analysis

No AI analysis yet.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 9 MD5 Hash 11

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

624

Campaigns

63

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Data Exfiltration

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Oct 8, 2022
Last Seen
Aug 12, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.