Also known as Agenda, Qilin has been active since August 2022 and has become one of the most prolific ransomware-as-a-service (RaaS) operations, hitting hundreds of organizations worldwide and causing millions of dollars in damages.
Qilin
Qilin, also known as Agenda, is a ransomware family and ransomware-as-a-service operation active since August 2022.
Qilin
Family profile
Qilin, also known as Agenda, is a ransomware family and ransomware-as-a-service operation active since August 2022. Its affiliate model supports financially motivated intrusions combining file encryption with data theft and threats to publish stolen information. The operation maintains a Tor-based data-leak site to pressure victims. Qilin attacks have affected organizations worldwide across healthcare, manufacturing, education, energy, transportation, professional services, and other sectors. Its 2024 attack against pathology services provider Synnovis disrupted services at multiple London hospitals.
Qilin has been deployed in Windows enterprise environments and against VMware ESXi infrastructure. An observed Rust ransomware payload encrypted ESXi virtual-machine disks, rendering affected virtual machines inoperable. Operators also target backup infrastructure, identity services, and virtualization management systems to obstruct recovery.
Affiliate intrusion methods include exploitation of internet-facing VPN gateways, mail servers, and helpdesk systems. A documented infection chain began with malicious advertisements promoting counterfeit administrative-software installers, delivered the SmokedHam backdoor, and subsequently culminated in Qilin deployment. Post-compromise activity in Qilin-associated intrusions includes network and privileged-group discovery, credential harvesting, remote-access tooling, lateral movement, and data exfiltration using cloud-transfer utilities such as Rclone and s5cmd. Operators disable security controls and use bring-your-own-vulnerable-driver techniques to bypass antivirus and endpoint detection products.
Affiliates associated with Qilin include Storm-2570 and DevMan; Scattered Spider has also used or partnered with the operation. Intrusion techniques and supporting tools vary by affiliate and should be distinguished from capabilities implemented directly in the ransomware payload.
Capabilities
- Byovd
- Credential Theft
- Defense Evasion
- Exfiltration
- Extortion
- Initial Access
- Lateral Movement
- Persistence
- Reconnaissance
- Scanning
Samples
Recent samples
2 sandbox samples in the Derp library, newest 2 shown
Reported operators
Threat actors
26 named in public reportingDevMan is an affiliate of several RaaS programs, mainly Qilin, APOS and also Dragon Force.
Analysts from Microsoft identified a consistent pattern after access was gained, even when attacks ended with Qilin, DragonForce, Anubis or BERT ransomware.
In one particular incident, the SmokedHam infection led to the deployment of Qilin ransomware.
In one particular incident, the SmokedHam infection led to the deployment of Qilin ransomware.
In one particular incident, the SmokedHam infection led to the deployment of Qilin ransomware.
In one particular incident, the SmokedHam infection led to the deployment of Qilin ransomware.
In one particular incident, the SmokedHam infection led to the deployment of Qilin ransomware.
Scattered Spider also established ransomware-as-a-service operations, including ALPHV/BlackCat, DragonForce, and Qilin, to monetize access through encryption and extortion.
Qilin is an open-affiliate RaaS operation that exfiltrates data, encrypts systems using configurable Rust payloads, and conducts dual-track extortion. It was originally known as Agenda before a September 2022 Rust rewrite and rebrand.
Qilin is an open-affiliate RaaS operation that exfiltrates data, encrypts systems using configurable Rust payloads, and conducts dual-track extortion. It was originally known as Agenda before a September 2022 Rust rewrite and rebrand.
Qilin is an open-affiliate RaaS operation that exfiltrates data, encrypts systems using configurable Rust payloads, and conducts dual-track extortion. It was originally known as Agenda before a September 2022 Rust rewrite and rebrand.
UAT-11988 — Qilin ransomware operator; exploits CVE-2026-20316 for initial access, then conducts reconnaissance, credential theft, AV killing, and ransomware deployment.
In recent months, the Lazarus Group and its related intrusion set Moonstone Sleet have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.
Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS, which Unit 42 tracks as Spikey Scorpius.
According to VX-Underground, DragonForce proposed establishing communication channels with the LockBit and the Qilin group.
Our Threat Hunter Team has separately observed ModeloRAT used in attacks that deployed Qilin ransomware, linking this tool to ransomware deployment.
Our Threat Hunter Team has separately observed ModeloRAT used in attacks that deployed Qilin ransomware, linking this tool to ransomware deployment.
The financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while leveraging resources from various ransomware-as-a-service (RaaS) schemes like LockBit (aka Tenacious Mantis), Qilin (aka Pestilent Mantis), and Medusa (aka Venomous Mantis).
The Gentlemen - не стартап с нуля. Ядро группы работало как ArmCorp - affiliate-команда внутри Qilin RaaS.
By June 2022, DEV-0237 was still primarily deploying Hive and sometimes Nokoyawa but was seen experimenting with other ransomware payloads, including Agenda and Mindware.
Qilin maintained its position as the most prominent ransomware operation for the third consecutive quarter, posting 338 victims.
Researchers last year tied MuddyWater to the Qilin ransomware ecosystem after the strain was used to attack an Israeli organization.
Qilin is a Russian-speaking ransomware-as-a-service (RaaS) operation first observed in July 2022 under the "Agenda" name and rebranded as Qilin in September 2022.
“Qilin (AKA Agenda) ransomware was first observed in July 2022 and operates it the double extortion method, where victims’ data is stolen and leaked via a data leak site if the ransom demand is not paid.”
"... led to the deployment of Qilin ransomware"
Exploited software
Vulnerabilities linked to Qilin
11 CVEsMITRE ATT&CK
Qilin in ATT&CK
94 distinct techniquesTechniques
94 techniquesReporting
Research mentioning Qilin
Aktiivisesti hyväksikäytetty kriittinen haavoittuvuus Check Pointin hallintapalvelimissa | Traficom
Check Point has disclosed CVE-2026-93616, a critical CVSS 9.8 path-traversal and unsafe file-upload vulnerability affecting its Security Management infrastructure. An unauthenticated remote attacker can upload and execute arbitrary scripts and load arbitrary Java classes, enabling remote code execution. Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. The company confirmed that the flaw was exploited in a small number of targeted attacks before fixes were available, though it has not identified the threat actor, victims, or objectives. Organizations should immediately deploy the R82.20 Security Hotfix or applicable fixed Jumbo Hotfix Accumulator, review Check Point-provided indicators and relevant logs/core dumps, and restrict management access—including TCP/19009—to trusted systems; where patching is delayed, SmartConsole Trusted Clients and firewall rules should limit access to approved IP addresses.
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Check Point Management Server 0-Day Vulnerability Actively Exploited in Attacks
Check Point warns of Management Server zero-day exploited in attacks
Security Advisory - Action Required - Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616 - Check Point Blog
Ransomware Group qilin Hits: Trends And Concepts
Researchers reported that the Agenda ransomware operation, also tracked as Qilin, is conducting highly customized enterprise attacks across Asia and Africa and has now been linked to a victim in South Africa. A recent victim listing identified Trends And Concepts in South Africa, associated with the domain www.trendsandconceptsinteriors.com, as impacted by the Qilin group. Trend researchers said Agenda operators build victim-specific Go-based payloads that can include leaked account credentials, unique company identifiers, customized RSA keys, and ransom demands ranging from $50,000 to $800,000, with observed targeting of healthcare and education organizations in Indonesia, Saudi Arabia, South Africa, and Thailand. The intrusion methods described across the reports show a flexible and increasingly sophisticated playbook. In one case, attackers accessed a public-facing Citrix server using a valid account, moved laterally with RDP and leaked Active Directory credentials, scanned networks with Nmap and Nping, and deployed ransomware through Group Policy in under two days. A separate Trend investigation found Agenda actors using fake Google CAPTCHA pages to deliver credential stealers, then abusing legitimate remote-management tools including ATERA, AnyDesk, ScreenConnect, and Splashtop, while deploying COROXY SOCKS proxies, targeting Veeam backup infrastructure, and using BYOVD techniques with vulnerable drivers such as eskle.sys; the final ransomware payload was reportedly a Linux variant executed on Windows, likely through Windows Subsystem for Linux.