BushidoUK ToolMatrix GroupProfiles: Qilin

Fecha
18 Jun 2026
Actor
bushidouk
Tipo
Report
Pais
United States
Sector
Defense
Confianza
high
80
Prioridad analitica
Alta

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

6IOCs
0TTPs
bushidoukActor
United StatesPais
Executive Summary
Recurso del BushidoUK Ransomware Tool Matrix - GroupProfiles.

Key Points

  • Source: GroupProfiles/Qilin.md
  • BushidoUK Tool Matrix

GroupProfiles: Qilin.md

Recurso del BushidoUK Ransomware Tool Matrix - GroupProfiles.

Qilin's Tools

| Discovery | RMM Tools | Defense Evasion | Credential Theft | OffSec | Networking | LOLBAS | Exfiltration |

|---|---|---|---|---|---|---|---|

| Nmap | ScreenConnect | EDRSandBlast | Mimikatz | Cobalt Strike | Proxychains | fsutil | EasyUpload |

| Nping | | PCHunter | | Evilginx | | PsExec | |

| | | PowerTool | | NetExec | | WinRM | |

| | | Toshiba power management driver (BYOVD) | | | | | |

| | | Updater for Carbon Black’s Cloud Sensor AV (upd.exe) | | | | | |

| | | YDArk | | | | | |

| | | Zemana Anti-Rootkit driver | | | | | |

> [!NOTE]

> This is the list of tools that have been observed during various intrusions that lead to Qilin ransomware deployment.

#### Sources

| Date Published | Report |

|---|---|

| 25 April 2025 | https://redpiranha.net/news/qilin-ransomware-all-you-need-know |

| 1 April 2025 | https://news.sophos.com/en-us/2025/04/01/sophos-mdr-tracks-ongoing-campaign-by-qilin-affiliates-targeting-screenconnect/ |

| 10 March 2025 | https://www.picussecurity.com/resource/blog/qilin-ransomware |

| 19 June 2024 | https://www.secureworks.com/research/threat-profiles/gold-feather |

| 26 March 2024 | https://www.trendmicro.com/en_us/research/24/c/agenda-ransomware-propagates-to-vcenters-and-esxi-via-custom-pow.html |

| 25 August 2022 | https://www.trendmicro.com/en_us/research/22/h/new-golang-ransomware-agenda-customizes-attacks.html |

Referencias

Diamond Model

Adversary
bushidouk
Ver perfil →
Victim
BushidoUK ToolMatrix GroupProfiles: Qilin
United States
Capability
Report
Infrastructure
redpiranha.net
news.sophos.com
www.picussecurity.com
www.secureworks.com

Relations

Mapa de nodos relacionados por IOCs compartidos, actor, enlaces IntelTracker/OSINT, campanas y victimas observadas. Haz click en un nodo para abrir el post, filtro o fuente.

21 enlaces
Nodo actual
BushidoUK ToolMatrix GroupProfiles: Qilin
bushidouk · United States

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
File upd.exe Artefacto observado VT OffSec SOCRadar
Domain redpiranha.net Extraido del contenido VT OffSec SOCRadar
Domain news.sophos.com Extraido del contenido VT OffSec SOCRadar
Domain www.picussecurity.com Extraido del contenido VT OffSec SOCRadar
Domain www.secureworks.com Extraido del contenido VT OffSec SOCRadar
Domain www.trendmicro.com Extraido del contenido VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor bushidouk en el blog → Ver bushidouk en IntelTracker → Fuente OSINT: github.com→ Fuente OSINT: github.com → Buscar bushidouk en APTTrail → Repositorio APTTrail → Mas incidentes en United States → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes