---
title: Qilin Ransomware, the new RaaS?
description: Learn how the Qilin ransomwareboperates using Conti-like TTPs. Explore key findings, ransom trends, and actionable mitigation strategies from experts.
image: https://www.irongatesecurity.com/hubfs/thumbnail_IRONGATE_CareerPosts_Miner_1200x600_v2-1.jpg
---

[Skip to the main content.](https://www.irongatesecurity.com/ironintel/https/www.irongatesecurity.com/news/qilin-ransomware-the-new-raashs_previewcjzuiehv-192776938915#main-content)

[![Plexos\_IronGate\_Logo\_Final-2](https://www.irongatesecurity.com/hs-fs/hubfs/Plexos_IronGate_Logo_Final-2.png?width=1246&height=190&name=Plexos_IronGate_Logo_Final-2.png "Plexos_IronGate_Logo_Final-2")](https://www.irongatesecurity.com)

[![Plexos\_IronGate\_Logo\_Final-2](https://www.irongatesecurity.com/hs-fs/hubfs/Plexos_IronGate_Logo_Final-2.png?width=1246&height=190&name=Plexos_IronGate_Logo_Final-2.png "Plexos_IronGate_Logo_Final-2")](https://www.irongatesecurity.com)

- [Who We Are](https://www.irongatesecurity.com/who-we-are) 
    - [Our Leaders](https://www.irongatesecurity.com/who-we-are#our-leaders)
- [Services](https://www.irongatesecurity.com/services) 
    - [Active Defense](https://www.irongatesecurity.com/active-defense) 
          - [Governance, Risk & Compliance](https://www.irongatesecurity.com/governance-risk-compliance)
          - [Security Operation (SecOps) Services](https://www.irongatesecurity.com/security-operation-services)
    - [Digital Forensics and Incident Response (DFIR)](https://www.irongatesecurity.com/digital-forensics-incident-response)
    - [Insurance Advisory Services](https://www.irongatesecurity.com/insurance-advisory-services)
- [Why IronGate](https://www.irongatesecurity.com/why-irongate)
- [How We Work](https://www.irongatesecurity.com/how-we-work)
- Resources 
    - [IronINTEL Blog](https://www.irongatesecurity.com/ironintel)
    - [Careers](https://www.irongatesecurity.com/careers)

[![CONTACT US](https://no-cache.hubspot.com/cta/default/43428275/interactive-129984586382.png)](https://www.irongatesecurity.com/hs/cta/wi/redirect?encryptedPayload=AVxigLLxAAVa%2ByTO3z5uDLXuJdz%2FioZ8nOTGWbgtpYYk6vvr7anhjXmp2kuC2WQdp6NHZtgQj%2B7BHYiNgi9T1tF7WdAKVRk1lyUYnwckNhe4YcxdV5DcyKY3gYvblzm8Y50okydY%2FqkxLcG92HByHGd2%2F%2BAyTx%2FwyMNM5uj0D8q9%2FTzJuVbbykcCRkLOqa3kmIqqlbUDFd6obQ%3D%3D&webInteractiveContentId=129984586382&portalId=43428275)

Toggle Menu

Toggle Menu

[![CONTACT US](https://no-cache.hubspot.com/cta/default/43428275/interactive-129984586382.png)](https://www.irongatesecurity.com/hs/cta/wi/redirect?encryptedPayload=AVxigLLxAAVa%2ByTO3z5uDLXuJdz%2FioZ8nOTGWbgtpYYk6vvr7anhjXmp2kuC2WQdp6NHZtgQj%2B7BHYiNgi9T1tF7WdAKVRk1lyUYnwckNhe4YcxdV5DcyKY3gYvblzm8Y50okydY%2FqkxLcG92HByHGd2%2F%2BAyTx%2FwyMNM5uj0D8q9%2FTzJuVbbykcCRkLOqa3kmIqqlbUDFd6obQ%3D%3D&webInteractiveContentId=129984586382&portalId=43428275)

- [Who We Are *Toggle Menu*](https://www.irongatesecurity.com/who-we-are) 
    - [Our Leaders](https://www.irongatesecurity.com/who-we-are#our-leaders)
- [Services *Toggle Menu*](https://www.irongatesecurity.com/services) 
    - [Active Defense *Toggle Menu*](https://www.irongatesecurity.com/active-defense) 
          - [Governance, Risk & Compliance](https://www.irongatesecurity.com/governance-risk-compliance)
          - [Security Operation (SecOps) Services](https://www.irongatesecurity.com/security-operation-services)
    - [Digital Forensics and Incident Response (DFIR)](https://www.irongatesecurity.com/digital-forensics-incident-response)
    - [Insurance Advisory Services](https://www.irongatesecurity.com/insurance-advisory-services)
- [Why IronGate](https://www.irongatesecurity.com/why-irongate)
- [How We Work](https://www.irongatesecurity.com/how-we-work)
- Resources
  
  *Toggle Menu* 
  
    - [IronINTEL Blog](https://www.irongatesecurity.com/ironintel)
    - [Careers](https://www.irongatesecurity.com/careers)

 1 min read

# Qilin Ransomware, the new RaaS?

[![Picture of IronGate](https://www.irongatesecurity.com/hubfs/IronGate%20Favicon.png) IronGate](https://www.irongatesecurity.com/ironintel/author/irongate)  Jul 16, 2025, 12:40:45 PM

![Qilin Ransomware, the new RaaS?](https://www.irongatesecurity.com/hubfs/thumbnail_IRONGATE_CareerPosts_Miner_1200x600_v2-1.jpg)

**For immediate assistance with a network intrusion, ransomwareattack, or BEC, please contact: [IrongateResponse@irongatesecurity.com](mailto:IrongateResponse@irongatesecurity.com)**  

Qilin ransomware has had the spotlight on them for the last several months starting with IronGate’s early May IronSights suggesting reuse of previously seen Conti TTPs to other DFIR and security research publications highlighting TTPs, attack lifecycles, and their motives. Some publications even entertain Qilin as the next big RaaS group given their surge in recent activity.  
   
Continuing with Qilin from our previous article, the IronTeam has additional observations from this group continuing to use older tactics and techniques on unsecured systems:

- **The adversary gains access to networks either through an initial access broker, credential reuse, or through insecure VPNs without MFA.**
- **Once connected to the network, they use tactics and techniques to scan the network, inventory available services and systems, then initiate procedures to attack those systems.**
- **In recent investigations, the adversary identified an internal web application and dumped credentials using SQL injection. The dumped credentials contained a domain administrator account.**
- **The adversary leveraged the domain administrator account to move laterally, scan the network for data to exfiltrate, disrupt backups, employ anti-forensics and finally deploy Qilin ransomware.**

Notable Observations:

- Qilin’s initial ransom demands average $225,000 with an average final payment of $162,500.
- Negotiations drawn out over an average of 12 days resulted with approximately a 30% reduction in demand.
- Qilin TTPs look for and exploit the least path of security resistance.

Mitigation Recommendations: 

- Patch and secure both internal and external systems.
- Customized applications that contain open-source dependencies should be assessed on a regular cadence including monitoring through threat feeds and analysis.
- Implement secure software development operations and procedures to develop systems and software with a “security first” approach. NIST and OWASP have published guidance for secure SDLC risk frameworks, top web application security risks, and security training for development and engineering teams.
- Implement role-based access controls for all accounts including domain administrators, administrators, and user accounts.
- Implement 3-2-1 backup strategy and implement network segmentation for “online backups” using access controls and unique administration credentials from the production network.
- Implement a 24 x 7 Security Operations Center (“SOC”) to monitor and respond to alerts from security tools including SIEM, EDR software, and network devices.

[Contact us](https://www.irongatesecurity.com/contact) today to learn more about our [Digital Forensics and Incident Response (DFIR)](https://www.irongatesecurity.com/digital-forensics-incident-response) services.

[![CONTACT US](https://no-cache.hubspot.com/cta/default/43428275/interactive-129984586382.png)](https://www.irongatesecurity.com/hs/cta/wi/redirect?encryptedPayload=AVxigLLxAAVa%2ByTO3z5uDLXuJdz%2FioZ8nOTGWbgtpYYk6vvr7anhjXmp2kuC2WQdp6NHZtgQj%2B7BHYiNgi9T1tF7WdAKVRk1lyUYnwckNhe4YcxdV5DcyKY3gYvblzm8Y50okydY%2FqkxLcG92HByHGd2%2F%2BAyTx%2FwyMNM5uj0D8q9%2FTzJuVbbykcCRkLOqa3kmIqqlbUDFd6obQ%3D%3D&webInteractiveContentId=129984586382&portalId=43428275)

| ![Ramey](https://www.irongatesecurity.com/hs-fs/hubfs/Ramey.png?width=276&height=276&name=Ramey.png) | [Steve Ramey](https://www.irongatesecurity.com/steve-ramey) has spent the past two decades helping clients protect, investigate, and respond to events involving their digital interests. He has led hundreds of data breach investigations, assessed incident response and security programs, and successfully advised organizations through extortion negotiations. |
| --- | --- |

 

[![Emerging Threat: ExClop Ransomware Group](https://www.irongatesecurity.com/hubfs/thumbnail_IRONGATE_CareerPosts_Miner_1200x600_v2-1.jpg)](https://www.irongatesecurity.com/ironintel/emerging-threat-exclop-ransomware-group)

#### [Emerging Threat: ExClop Ransomware Group](https://www.irongatesecurity.com/ironintel/emerging-threat-exclop-ransomware-group)

[![Picture of IronGate](https://www.irongatesecurity.com/hs-fs/hubfs/IronGate%20Favicon.png?width=30&name=IronGate%20Favicon.png) IronGate](https://www.irongatesecurity.com/ironintel/author/irongate) : Sep 15, 2025, 2:38:42 PM

Learn how the Qilin ransomwareboperates using Conti-like TTPs. Explore key findings, ransom trends, and actionable mitigation strategies from experts.

[Read More](https://www.irongatesecurity.com/ironintel/emerging-threat-exclop-ransomware-group)

[![Inside Akira’s Surge – What You Need to Know](https://www.irongatesecurity.com/hubfs/thumbnail_IRONGATE_CareerPosts_Miner_1200x600_v2-1.jpg)](https://www.irongatesecurity.com/ironintel/inside-akiras-surge-what-you-need-to-know)

#### [Inside Akira’s Surge – What You Need to Know](https://www.irongatesecurity.com/ironintel/inside-akiras-surge-what-you-need-to-know)

[![Picture of IronGate](https://www.irongatesecurity.com/hs-fs/hubfs/IronGate%20Favicon.png?width=30&name=IronGate%20Favicon.png) IronGate](https://www.irongatesecurity.com/ironintel/author/irongate) : Sep 16, 2025, 12:50:00 PM

Learn how the Qilin ransomwareboperates using Conti-like TTPs. Explore key findings, ransom trends, and actionable mitigation strategies from experts.

[Read More](https://www.irongatesecurity.com/ironintel/inside-akiras-surge-what-you-need-to-know)

[![Devman Ransomware: Emerging Threat Analysis](https://www.irongatesecurity.com/hubfs/thumbnail_IRONGATE_CareerPosts_Miner_1200x600_v2-1.jpg)](https://www.irongatesecurity.com/ironintel/devman-ransomware-emerging-threat-analysis)

#### [Devman Ransomware: Emerging Threat Analysis](https://www.irongatesecurity.com/ironintel/devman-ransomware-emerging-threat-analysis)

[![Picture of IronGate](https://www.irongatesecurity.com/hs-fs/hubfs/IronGate%20Favicon.png?width=30&name=IronGate%20Favicon.png) IronGate](https://www.irongatesecurity.com/ironintel/author/irongate) : Dec 16, 2025, 1:10:05 PM

Devman is an emerging ransomware variant linked to the DragonForce Ransomware-as-a-Service (RaaS) operation and built on code originating from the...

[Read More](https://www.irongatesecurity.com/ironintel/devman-ransomware-emerging-threat-analysis)

 

![Plexos\_IronGate\_Logo\_Final-2](https://www.irongatesecurity.com/hs-fs/hubfs/Plexos_IronGate_Logo_Final-2.png?width=301&height=46&name=Plexos_IronGate_Logo_Final-2.png)

![Irongate\_Award\_Logos](https://www.irongatesecurity.com/hs-fs/hubfs/Irongate_Award_Logos.png?width=557&height=210&name=Irongate_Award_Logos.png)

 

- [Privacy Policy](https://www.irongatesecurity.com/privacy-policy)
- [Terms of Use](https://www.irongatesecurity.com/terms-of-use)
- [Your Privacy Choices ![](https://www.irongatesecurity.com/hubfs/privacyoptions.png)](https://www.irongatesecurity.com/your-privacy-choices)

© 2026 IronGate Cybersecurity LLC

[*LinkedIn*](https://www.linkedin.com/company/irongate-cybersecurity-llc/?lipi=urn%3Ali%3Apage%3Ad_flagship3_search_srp_companies_load_more%3BcMuuS27qSPaVn%2BG%2BihNnZw%3D%3D)

*Return to Top*

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "IronGate",
    "url" : "https://www.irongatesecurity.com/ironintel/author/irongate"
  },
  "dateModified" : "2025-07-16T16:40:45.435Z",
  "datePublished" : "2025-07-16T16:40:45.000Z",
  "headline" : "Qilin Ransomware, the new RaaS?",
  "image" : [ "https://www.irongatesecurity.com/hubfs/thumbnail_IRONGATE_CareerPosts_Miner_1200x600_v2-1.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.irongatesecurity.com/ironintel/https/www.irongatesecurity.com/news/qilin-ransomware-the-new-raashs_previewcjzuiehv-192776938915",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.irongatesecurity.com/hubfs/Plexos_IronGate_Logo_Final-1.png"
    },
    "name" : "IronGate Cybersecurity LLC"
  }
}
```