Skip to content

Qilin

Qilin, also known as Agenda, is a ransomware family and ransomware-as-a-service operation active since August 2022.

Qilin

Family profile

Qilin, also known as Agenda, is a ransomware family and ransomware-as-a-service operation active since August 2022. Its affiliate model supports financially motivated intrusions combining file encryption with data theft and threats to publish stolen information. The operation maintains a Tor-based data-leak site to pressure victims. Qilin attacks have affected organizations worldwide across healthcare, manufacturing, education, energy, transportation, professional services, and other sectors. Its 2024 attack against pathology services provider Synnovis disrupted services at multiple London hospitals.

Qilin has been deployed in Windows enterprise environments and against VMware ESXi infrastructure. An observed Rust ransomware payload encrypted ESXi virtual-machine disks, rendering affected virtual machines inoperable. Operators also target backup infrastructure, identity services, and virtualization management systems to obstruct recovery.

Affiliate intrusion methods include exploitation of internet-facing VPN gateways, mail servers, and helpdesk systems. A documented infection chain began with malicious advertisements promoting counterfeit administrative-software installers, delivered the SmokedHam backdoor, and subsequently culminated in Qilin deployment. Post-compromise activity in Qilin-associated intrusions includes network and privileged-group discovery, credential harvesting, remote-access tooling, lateral movement, and data exfiltration using cloud-transfer utilities such as Rclone and s5cmd. Operators disable security controls and use bring-your-own-vulnerable-driver techniques to bypass antivirus and endpoint detection products.

Affiliates associated with Qilin include Storm-2570 and DevMan; Scattered Spider has also used or partnered with the operation. Intrusion techniques and supporting tools vary by affiliate and should be distinguished from capabilities implemented directly in the ransomware payload.

Capabilities

  • Byovd
  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Initial Access
  • Lateral Movement
  • Persistence
  • Reconnaissance
  • Scanning

Samples

Recent samples

2 sandbox samples in the Derp library, newest 2 shown

Reported operators

Threat actors

26 named in public reporting
Qilin

Also known as Agenda, Qilin has been active since August 2022 and has become one of the most prolific ransomware-as-a-service (RaaS) operations, hitting hundreds of organizations worldwide and causing millions of dollars in damages.

Devman

DevMan is an affiliate of several RaaS programs, mainly Qilin, APOS and also Dragon Force.

Storm-2570

Analysts from Microsoft identified a consistent pattern after access was gained, even when attacks ended with Qilin, DragonForce, Anubis or BERT ransomware.

Scattered Spider

In one particular incident, the SmokedHam infection led to the deployment of Qilin ransomware.

UNC2465

In one particular incident, the SmokedHam infection led to the deployment of Qilin ransomware.

STAC4365

In one particular incident, the SmokedHam infection led to the deployment of Qilin ransomware.

Ruthless Mantis

In one particular incident, the SmokedHam infection led to the deployment of Qilin ransomware.

REVENANT SPIDER

In one particular incident, the SmokedHam infection led to the deployment of Qilin ransomware.

Scattered Lapsus$ Hunters

Scattered Spider also established ransomware-as-a-service operations, including ALPHV/BlackCat, DragonForce, and Qilin, to monetize access through encryption and extortion.

Moonstone Sleet

Qilin is an open-affiliate RaaS operation that exfiltrates data, encrypts systems using configurable Rust payloads, and conducts dual-track extortion. It was originally known as Agenda before a September 2022 Rust rewrite and rebrand.

Arkana Security

Qilin is an open-affiliate RaaS operation that exfiltrates data, encrypts systems using configurable Rust payloads, and conducts dual-track extortion. It was originally known as Agenda before a September 2022 Rust rewrite and rebrand.

fin12

Qilin is an open-affiliate RaaS operation that exfiltrates data, encrypts systems using configurable Rust payloads, and conducts dual-track extortion. It was originally known as Agenda before a September 2022 Rust rewrite and rebrand.

UAT-11988

UAT-11988 — Qilin ransomware operator; exploits CVE-2026-20316 for initial access, then conducts reconnaissance, credential theft, AV killing, and ransomware deployment.

Lazarus

In recent months, the Lazarus Group and its related intrusion set Moonstone Sleet have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.

Spikey Scorpius

Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS, which Unit 42 tracks as Spikey Scorpius.

DragonForce

According to VX-Underground, DragonForce proposed establishing communication channels with the LockBit and the Qilin group.

KongTuke

Our Threat Hunter Team has separately observed ModeloRAT used in attacks that deployed Qilin ransomware, linking this tool to ransomware deployment.

Woodgnat

Our Threat Hunter Team has separately observed ModeloRAT used in attacks that deployed Qilin ransomware, linking this tool to ransomware deployment.

Phantom Mantis

The financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while leveraging resources from various ransomware-as-a-service (RaaS) schemes like LockBit (aka Tenacious Mantis), Qilin (aka Pestilent Mantis), and Medusa (aka Venomous Mantis).

ArmCorp

The Gentlemen - не стартап с нуля. Ядро группы работало как ArmCorp - affiliate-команда внутри Qilin RaaS.

WIZARD SPIDER

By June 2022, DEV-0237 was still primarily deploying Hive and sometimes Nokoyawa but was seen experimenting with other ransomware payloads, including Agenda and Mindware.

Hastalamuerte

Qilin maintained its position as the most prominent ransomware operation for the third consecutive quarter, posting 338 victims.

MuddyWater

Researchers last year tied MuddyWater to the Qilin ransomware ecosystem after the strain was used to attack an Israeli organization.

Arkana

Qilin is a Russian-speaking ransomware-as-a-service (RaaS) operation first observed in July 2022 under the "Agenda" name and rebranded as Qilin in September 2022.

WikiLeaksV2

“Qilin (AKA Agenda) ransomware was first observed in July 2022 and operates it the double extortion method, where victims’ data is stolen and leaked via a data leak site if the ransom demand is not paid.”

Exploited software

Vulnerabilities linked to Qilin

11 CVEs

MITRE ATT&CK

Qilin in ATT&CK

94 distinct techniques

Techniques

94 techniques
T1059.001 PowerShell T1489 Service Stop T1548.002 Bypass User Account Control T1204.002 Malicious File T1055.001 Dynamic-link Library Injection T1490 Inhibit System Recovery T1547.004 Winlogon Helper DLL T1547.001 Registry Run Keys / Startup Folder T1480 Execution Guardrails T1190 Exploit Public-Facing Application T1112 Modify Registry T1673 Virtual Machine Discovery T1685.005 Clear Windows Event Logs T1685 Disable or Modify Tools T1688 Safe Mode Boot T1480.002 Mutual Exclusion T1529 System Shutdown/Reboot T1018 Remote System Discovery T1083 File and Directory Discovery T1135 Network Share Discovery T1012 Query Registry T1134 Access Token Manipulation T1021.002 SMB/Windows Admin Shares T1027.013 Encrypted/Encoded File T1057 Process Discovery T1222 File and Directory Permissions Modification T1053.005 Scheduled Task T1566.001 Spearphishing Attachment T1484.001 Group Policy Modification T1016 System Network Configuration Discovery T1204.001 Malicious Link T1007 System Service Discovery T1491.001 Internal Defacement T1566.002 Spearphishing Link T1680 Local Storage Discovery T1070.004 File Deletion T1087.001 Local Account T1106 Native API T1003.001 LSASS Memory T1486 Data Encrypted for Impact T1036.005 Match Legitimate Resource Name or Location T1047 Windows Management Instrumentation T1036.004 Masquerade Task or Service T1678 Delay Execution T1059.003 Windows Command Shell T1082 System Information Discovery T1219.002 Remote Desktop Software T1069.002 Domain Groups T1570 Lateral Tool Transfer T1021.004 SSH T1087.002 Domain Account T1071.002 File Transfer Protocols T1567 Exfiltration Over Web Service T1657 Financial Theft T1090 Proxy T1078 Valid Accounts T1550.002 Pass the Hash T1046 Network Service Discovery T1572 Protocol Tunneling T1552 Unsecured Credentials T1078.001 Default Accounts T1021.006 Windows Remote Management T1021 Remote Services T1003 OS Credential Dumping T1087 Account Discovery T1556.001 Domain Controller Authentication T1055 Process Injection T1021.001 Remote Desktop Protocol T1071 Application Layer Protocol T1548 Abuse Elevation Control Mechanism T1059 Command and Scripting Interpreter T1027 Obfuscated Files or Information T1041 Exfiltration Over C2 Channel T1068 Exploitation for Privilege Escalation T1195 Supply Chain Compromise T1074 Data Staged T1537 Transfer Data to Cloud Account T1036 Masquerading T1003.003 NTDS T1567.002 Exfiltration to Cloud Storage T1053 Scheduled Task/Job T1566 Phishing T1133 External Remote Services T1219 Remote Access Tools T1558.001 Golden Ticket T1569.002 Service Execution T1497 Virtualization/Sandbox Evasion T1555 Credentials from Password Stores T1498 Network Denial of Service T1588.002 Tool T1685.001 Disable or Modify Windows Event Log T1210 Exploitation of Remote Services T1027.002 Software Packing T1098 Account Manipulation

Reporting

Research mentioning Qilin

Sep 22
Kyberturvallisuuskeskus Alerts

Aktiivisesti hyväksikäytetty kriittinen haavoittuvuus Check Pointin hallintapalvelimissa | Traficom

Check Point has disclosed CVE-2026-93616, a critical CVSS 9.8 path-traversal and unsafe file-upload vulnerability affecting its Security Management infrastructure. An unauthenticated remote attacker can upload and execute arbitrary scripts and load arbitrary Java classes, enabling remote code execution. Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. The company confirmed that the flaw was exploited in a small number of targeted attacks before fixes were available, though it has not identified the threat actor, victims, or objectives. Organizations should immediately deploy the R82.20 Security Hotfix or applicable fixed Jumbo Hotfix Accumulator, review Check Point-provided indicators and relevant logs/core dumps, and restrict management access—including TCP/19009—to trusted systems; where patching is delayed, SmartConsole Trusted Clients and firewall rules should limit access to approved IP addresses.

Sep 22
The Hacker News

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

Sep 22
Cyber Security News

Check Point Management Server 0-Day Vulnerability Actively Exploited in Attacks

Sep 22
Bleeping Computer

Check Point warns of Management Server zero-day exploited in attacks

Sep 22
Checkpoint

Security Advisory - Action Required - Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616 - Check Point Blog

Aug 20
Hookphish

Ransomware Group qilin Hits: Trends And Concepts

Researchers reported that the Agenda ransomware operation, also tracked as Qilin, is conducting highly customized enterprise attacks across Asia and Africa and has now been linked to a victim in South Africa. A recent victim listing identified Trends And Concepts in South Africa, associated with the domain www.trendsandconceptsinteriors.com, as impacted by the Qilin group. Trend researchers said Agenda operators build victim-specific Go-based payloads that can include leaked account credentials, unique company identifiers, customized RSA keys, and ransom demands ranging from $50,000 to $800,000, with observed targeting of healthcare and education organizations in Indonesia, Saudi Arabia, South Africa, and Thailand. The intrusion methods described across the reports show a flexible and increasingly sophisticated playbook. In one case, attackers accessed a public-facing Citrix server using a valid account, moved laterally with RDP and leaked Active Directory credentials, scanned networks with Nmap and Nping, and deployed ransomware through Group Policy in under two days. A separate Trend investigation found Agenda actors using fake Google CAPTCHA pages to deliver credential stealers, then abusing legitimate remote-management tools including ATERA, AnyDesk, ScreenConnect, and Splashtop, while deploying COROXY SOCKS proxies, targeting Veeam backup infrastructure, and using BYOVD techniques with vulnerable drivers such as eskle.sys; the final ransomware payload was reportedly a Linux variant executed on Windows, likely through Windows Subsystem for Linux.

Aug 19
Trendai Security

Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques | TrendAI (US)

Aug 14
Trendai Security

New Golang Ransomware Agenda Customizes Attacks | TrendAI (US)