White Paper
THREAT PROFILE: Qilin Ransomware
Qilin is a ransomware-as-a-service (RaaS) group first identified in 2022 that operates using a double-extortion strategy to increase pressure on victims. The group encrypts files to disrupt operations while also stealing sensitive data and threatening to publish it on a dedicated data leak site if ransom demands are not met. This threat profile examines Qilin’s operations through frameworks such as the Diamond Model, MITRE ATT&CK mappings, and kill chain analysis to provide insight into its tactics, techniques, and procedures. The report covers the industries and geographic regions targeted by the group, known exploited vulnerabilities, associated threat actors, and tools used during attacks. It also analyzes observed behaviors across both Windows and Linux environments, helping organizati
