Qilin ransomware now harvests cached RDP connection logs from Windows servers to map internal networks and prioritize targets for encryption.