Credential Theft
- Mimikatz
Qilin, also known as Agenda and Qilin Locker, is a ransomware-as-a-service operation that emerged in 2022 and became one of the most active ransomware threats through 2025 and 2026.
Profile source: Mallory opens in a new tabQilin
Qilin, also known as Agenda and Qilin Locker, is a ransomware-as-a-service operation that emerged in 2022 and became one of the most active ransomware threats through 2025 and 2026. It operates a double-extortion model in which affiliates steal data before encrypting systems and then threaten publication to increase pressure on victims. Reporting has repeatedly linked the operation to Russian-speaking or CIS-based cybercriminal activity, and the group is described as prohibiting attacks against CIS member states while primarily targeting higher-GDP Western countries.
Qilin has affected a wide range of sectors, with repeated reporting of victimization in manufacturing, business services, technology, healthcare, financial services, education, local government, critical infrastructure, energy, and public administration. Multiple assessments identified it as one of the highest-volume ransomware groups in 2025 and the most active group in several 2026 quarterly tallies.
Initial access associated with Qilin and its affiliates has included exploitation of internet-facing VPN and firewall infrastructure, especially authentication-bypass flaws in Palo Alto Networks GlobalProtect and Check Point Remote Access VPN and Mobile Access deployments. Other reporting also associates Qilin intrusions with use of stolen VPN or RDP administrator credentials. After access, affiliates have conducted credential theft, reconnaissance, lateral movement, persistence establishment, data exfiltration, and defense evasion before ransomware deployment. Observed tradecraft includes use of remote administration tools, credential dumping from LSASS and Active Directory, scheduled tasks and registry-based persistence, enterprise log clearing, security-tool impairment, and exfiltration to cloud storage services. Additional reporting links Qilin activity to BYOVD-style evasion, obfuscated PowerShell, AMSI bypass, and termination of security products.
Observed post-compromise behavior varies across incidents, consistent with an affiliate-driven ecosystem. Some intrusions progressed rapidly from perimeter compromise to encryption, while others involved extended dwell time with credential harvesting, reconnaissance, lateral movement, and data theft. Qilin affiliates have also been observed using legitimate administrative tooling and common post-exploitation frameworks to move through victim environments and target backup infrastructure, increasing operational impact and recovery difficulty.
d6e7547ad7dfd1fbc62e8282aebcc391f588802958c35fe18eb87bc36651a3d12bb209ccfc5103eccab523c875050cfaa7e7d00d531cb7ca27d0f3bee448573f964c13b68dc6b6b918b66a9a10469d2a3b10127e65fa3e215d21e0a2e7fd32bed1c331c17ddd4abe0d53755461c1ec9a417ad60624345ef85e648038e18902abb04e8ee43aba85fa5c585b9335c953c259d756280b06cf113ca43abc0050edd5176.113.115.97176.113.115.20985.209.11.4931.41.244.100188.119.66.189ftp://176.113.115.97/ftp://176.113.115.209/Reported operators
Exploitation confirmée dès le 17 mai 2026 ; affiliés Qilin confirmés en juillet 2026 ... Affilié Qilin confirmé dans des activités post-compromission
Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS, which Unit 42 tracks as Spikey Scorpius.
Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.
Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.
According to VX-Underground, DragonForce proposed establishing communication channels with the LockBit and the Qilin group.
Our Threat Hunter Team has separately observed ModeloRAT used in attacks that deployed Qilin ransomware, linking this tool to ransomware deployment.
Our Threat Hunter Team has separately observed ModeloRAT used in attacks that deployed Qilin ransomware, linking this tool to ransomware deployment.
Qilin is a Ransomware-as-a-Service program that has been in operation since 2022, previously operating under the name “Agenda.”
The financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while leveraging resources from various ransomware-as-a-service (RaaS) schemes like LockBit (aka Tenacious Mantis), Qilin (aka Pestilent Mantis), and Medusa (aka Venomous Mantis).
The Gentlemen - не стартап с нуля. Ядро группы работало как ArmCorp - affiliate-команда внутри Qilin RaaS.
By June 2022, DEV-0237 was still primarily deploying Hive and sometimes Nokoyawa but was seen experimenting with other ransomware payloads, including Agenda and Mindware.
Qilin maintained its position as the most prominent ransomware operation for the third consecutive quarter, posting 338 victims.
Researchers last year tied MuddyWater to the Qilin ransomware ecosystem after the strain was used to attack an Israeli organization.
Qilin is a Russian-speaking ransomware-as-a-service (RaaS) operation first observed in July 2022 under the "Agenda" name and rebranded as Qilin in September 2022.
Qilin is a Russian-speaking ransomware-as-a-service (RaaS) operation first observed in July 2022 under the "Agenda" name and rebranded as Qilin in September 2022.
“Qilin (AKA Agenda) ransomware was first observed in July 2022 and operates it the double extortion method, where victims’ data is stolen and leaked via a data leak site if the ransom demand is not paid.”
Last year, Bitdefender revealed that another North Korean threat actor tracked as Moonstone Sleet, which previously dropped a custom ransomware family called FakePenny, had likely targeted several South Korean financial firms with Qilin ransomware.
"... led to the deployment of Qilin ransomware"
Exploited software
MITRE ATT&CK
Reporting
The Qilin ransomware group claimed multiple new victims across the United States, Canada, Austria, and Germany, hitting organizations in manufacturing, professional services, financial services, media, retail, property management, and utilities. Named victims included Community Management Associates, Pointe Property Group, Ceragres, Dienst Pack Systems, Schreiner Trockenbau GmbH, Commercial Furniture Interiors, The Saturday Evening Post, Wire Products, Freedom Claims Management, and Service Electric. Several reports described the incidents as both ransomware attacks and associated data breaches, indicating continued emphasis on extortion through stolen data as well as operational disruption. Separate reporting tied Qilin affiliates to active exploitation of Internet-facing VPN and firewall infrastructure, including Palo Alto GlobalProtect CVE-2026-0257 and Check Point VPN CVE-2026-50751, as part of broader mid-2026 ransomware access campaigns. That activity was reported alongside common post-compromise tradecraft such as Impacket, NTLM relay, Mimikatz, PsExec, RDP, WMI, browser credential theft, and use of WSL for EDR evasion. A weekly ransomware trend report counted Qilin among the most active groups, with 31 claimed victims during the period, reinforcing its position as a leading extortion threat affecting organizations across sectors and regions.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.