Qilin Ransomware: Technical analysis, from initial access to beaconing
ID: 26dbd007-02c2-5336-90f9-43b943db0df0
STIX ID: report--26dbd007-02c2-5336-90f9-43b943db0df0
Feed Name: ThreatLocker Blog
**Executive summary:** The report documents Qilin (aka Agenda), a prolific Ransomware-as-a-Service affiliate operation active in 2025 that has impacted over 900 organizations across industries; it details initial access methods (phishing, BEC, IABs, exposed services), reconnaissance and lateral movement, C2 beacon behavior to cloudflariz.com by native and .NET beacons (hosts.exe, dato.exe), persistence and command execution techniques, associated infrastructure and data leak site activity, and provides IOCs (domains, IPs, SHA-256 hashes) and hunting telemetry to detect and respond to the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
