logo

Qilin Ransomware: Technical analysis, from initial access to beaconing

ID: 26dbd007-02c2-5336-90f9-43b943db0df0

STIX ID: report--26dbd007-02c2-5336-90f9-43b943db0df0

Feed Name: ThreatLocker Blog

Threat Score
85/100

Date Published: 2025-11-18

Date Updated: 2026-05-01

...
...

**Executive summary:** The report documents Qilin (aka Agenda), a prolific Ransomware-as-a-Service affiliate operation active in 2025 that has impacted over 900 organizations across industries; it details initial access methods (phishing, BEC, IABs, exposed services), reconnaissance and lateral movement, C2 beacon behavior to cloudflariz.com by native and .NET beacons (hosts.exe, dato.exe), persistence and command execution techniques, associated infrastructure and data leak site activity, and provides IOCs (domains, IPs, SHA-256 hashes) and hunting telemetry to detect and respond to the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.