Skip to content

Qilin

Qilin, also known as Agenda and Qilin Locker, is a ransomware-as-a-service operation that emerged in 2022 and became one of the most active ransomware threats through 2025 and 2026.

Profile source: Mallory opens in a new tab

Qilin

Family profile

Qilin, also known as Agenda and Qilin Locker, is a ransomware-as-a-service operation that emerged in 2022 and became one of the most active ransomware threats through 2025 and 2026. It operates a double-extortion model in which affiliates steal data before encrypting systems and then threaten publication to increase pressure on victims. Reporting has repeatedly linked the operation to Russian-speaking or CIS-based cybercriminal activity, and the group is described as prohibiting attacks against CIS member states while primarily targeting higher-GDP Western countries.

Qilin has affected a wide range of sectors, with repeated reporting of victimization in manufacturing, business services, technology, healthcare, financial services, education, local government, critical infrastructure, energy, and public administration. Multiple assessments identified it as one of the highest-volume ransomware groups in 2025 and the most active group in several 2026 quarterly tallies.

Initial access associated with Qilin and its affiliates has included exploitation of internet-facing VPN and firewall infrastructure, especially authentication-bypass flaws in Palo Alto Networks GlobalProtect and Check Point Remote Access VPN and Mobile Access deployments. Other reporting also associates Qilin intrusions with use of stolen VPN or RDP administrator credentials. After access, affiliates have conducted credential theft, reconnaissance, lateral movement, persistence establishment, data exfiltration, and defense evasion before ransomware deployment. Observed tradecraft includes use of remote administration tools, credential dumping from LSASS and Active Directory, scheduled tasks and registry-based persistence, enterprise log clearing, security-tool impairment, and exfiltration to cloud storage services. Additional reporting links Qilin activity to BYOVD-style evasion, obfuscated PowerShell, AMSI bypass, and termination of security products.

Observed post-compromise behavior varies across incidents, consistent with an affiliate-driven ecosystem. Some intrusions progressed rapidly from perimeter compromise to encryption, while others involved extended dwell time with credential harvesting, reconnaissance, lateral movement, and data theft. Qilin affiliates have also been observed using legitimate administrative tooling and common post-exploitation frameworks to move through victim environments and target backup infrastructure, increasing operational impact and recovery difficulty.

Capabilities

  • Byovd
  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Initial Access
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Reconnaissance

Operational record

70
Indicators
1
YARA rules
3
Ransom notes
2
Negotiations
4
Leak sites
1 available

Credential Theft

  • Mimikatz

Defense Evasion

  • EDRSandBlast
  • PCHunter
  • PowerTool
  • Toshiba power management driver (BYOVD)
  • Updater for Carbon Black’s Cloud Sensor AV (upd.exe)
  • YDArk
  • Zemana Anti-Rootkit driver

Discovery Enum

  • Nmap
  • Nping

Exfiltration

  • EasyUpload.io
  • MEGA

LOLBAS

  • PowerShell
  • PsExec
  • WinRM
  • fsutil

Networking

  • Proxychains

Offsec

  • Cobalt Strike
  • Evilginx
  • Kali Linux
  • NetExec
  • SystemBC
  • Tofsee

RMM Tools

  • NetSupport
  • ScreenConnect

Published indicators

Md5

54 total
  • d6e7547ad7dfd1fbc62e8282aebcc391
  • f588802958c35fe18eb87bc36651a3d1
  • 2bb209ccfc5103eccab523c875050cfa
  • a7e7d00d531cb7ca27d0f3bee448573f
  • 964c13b68dc6b6b918b66a9a10469d2a
  • 3b10127e65fa3e215d21e0a2e7fd32be
  • d1c331c17ddd4abe0d53755461c1ec9a
  • 417ad60624345ef85e648038e18902ab
  • b04e8ee43aba85fa5c585b9335c953c2
  • 59d756280b06cf113ca43abc0050edd5

Ip

5 total
  • 176.113.115.97
  • 176.113.115.209
  • 85.209.11.49
  • 31.41.244.100
  • 188.119.66.189

Ftp

2 total
  • ftp://176.113.115.97/
  • ftp://176.113.115.209/

Recent claims

Reported operators

Threat actors

18 named in public reporting
Qilin

Exploitation confirmée dès le 17 mai 2026 ; affiliés Qilin confirmés en juillet 2026 ... Affilié Qilin confirmé dans des activités post-compromission

Spikey Scorpius

Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS, which Unit 42 tracks as Spikey Scorpius.

Scattered Spider

Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.

Moonstone Sleet

Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.

DragonForce

According to VX-Underground, DragonForce proposed establishing communication channels with the LockBit and the Qilin group.

KongTuke

Our Threat Hunter Team has separately observed ModeloRAT used in attacks that deployed Qilin ransomware, linking this tool to ransomware deployment.

Woodgnat

Our Threat Hunter Team has separately observed ModeloRAT used in attacks that deployed Qilin ransomware, linking this tool to ransomware deployment.

STAC4365

Qilin is a Ransomware-as-a-Service program that has been in operation since 2022, previously operating under the name “Agenda.”

Phantom Mantis

The financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while leveraging resources from various ransomware-as-a-service (RaaS) schemes like LockBit (aka Tenacious Mantis), Qilin (aka Pestilent Mantis), and Medusa (aka Venomous Mantis).

ArmCorp

The Gentlemen - не стартап с нуля. Ядро группы работало как ArmCorp - affiliate-команда внутри Qilin RaaS.

WIZARD SPIDER

By June 2022, DEV-0237 was still primarily deploying Hive and sometimes Nokoyawa but was seen experimenting with other ransomware payloads, including Agenda and Mindware.

Hastalamuerte

Qilin maintained its position as the most prominent ransomware operation for the third consecutive quarter, posting 338 victims.

MuddyWater

Researchers last year tied MuddyWater to the Qilin ransomware ecosystem after the strain was used to attack an Israeli organization.

Devman

Qilin is a Russian-speaking ransomware-as-a-service (RaaS) operation first observed in July 2022 under the "Agenda" name and rebranded as Qilin in September 2022.

Arkana

Qilin is a Russian-speaking ransomware-as-a-service (RaaS) operation first observed in July 2022 under the "Agenda" name and rebranded as Qilin in September 2022.

WikiLeaksV2

“Qilin (AKA Agenda) ransomware was first observed in July 2022 and operates it the double extortion method, where victims’ data is stolen and leaked via a data leak site if the ransom demand is not paid.”

Lazarus

Last year, Bitdefender revealed that another North Korean threat actor tracked as Moonstone Sleet, which previously dropped a custom ransomware family called FakePenny, had likely targeted several South Korean financial firms with Qilin ransomware.

Exploited software

Vulnerabilities linked to Qilin

9 CVEs

MITRE ATT&CK

Qilin in ATT&CK

120 distinct techniques

Techniques

120 techniques
T1486 Data Encrypted for Impact T1041 Exfiltration Over C2 Channel T1657 Financial Theft T1567 Exfiltration Over Web Service T1562 Impair Defenses T1068 Exploitation for Privilege Escalation T1190 Exploit Public-Facing Application T1490 Inhibit System Recovery T1195 Supply Chain Compromise T1074 Data Staged T1537 Transfer Data to Cloud Account T1078 Valid Accounts T1003 OS Credential Dumping T1021.002 SMB/Windows Admin Shares T1046 Network Service Discovery T1021 Remote Services T1036 Masquerading T1003.003 NTDS T1003.001 LSASS Memory T1567.002 Exfiltration to Cloud Storage T1021.001 Remote Desktop Protocol T1547.001 Registry Run Keys / Startup Folder T1053 Scheduled Task/Job T1566 Phishing T1070.001 Clear Windows Event Logs T1082 System Information Discovery T1133 External Remote Services T1570 Lateral Tool Transfer T1112 Modify Registry T1562.001 Disable or Modify Tools T1219 Remote Access Tools T1558.001 Golden Ticket T1569.002 Service Execution T1059.001 PowerShell T1134 Access Token Manipulation T1027 Obfuscated Files or Information T1497 Virtualization/Sandbox Evasion T1016 System Network Configuration Discovery T1562.009 Safe Mode Boot T1566.001 Spearphishing Attachment T1555 Credentials from Password Stores T1498 Network Denial of Service T1087 Account Discovery T1566.002 Spearphishing Link T1529 System Shutdown/Reboot T1588.002 Tool T1562.002 Disable Windows Event Logging T1210 Exploitation of Remote Services T1480.002 Mutual Exclusion T1491.001 Internal Defacement T1027.002 Software Packing T1098 Account Manipulation T1070.004 File Deletion T1055.002 Portable Executable Injection T1497.001 System Checks T1021.004 SSH T1489 Service Stop T1105 Ingress Tool Transfer T1090.003 Multi-hop Proxy T1071 Application Layer Protocol T1587.001 Malware T1553.002 Code Signing T1059.003 Windows Command Shell T1057 Process Discovery T1484.001 Group Policy Modification T1053.005 Scheduled Task T1070 Indicator Removal T1204.002 Malicious File T1204 User Execution T1018 Remote System Discovery T1580 Cloud Infrastructure Discovery T1531 Account Access Removal T1048 Exfiltration Over Alternative Protocol T1218 System Binary Proxy Execution T1020 Automated Exfiltration T1548.002 Bypass User Account Control T1213 Data from Information Repositories T1480 Execution Guardrails T1135 Network Share Discovery T1012 Query Registry T1083 File and Directory Discovery T1007 System Service Discovery T1055.001 Dynamic-link Library Injection T1087.001 Local Account T1204.001 Malicious Link T1106 Native API T1573.002 Asymmetric Cryptography T1222 File and Directory Permissions Modification T1027.013 Encrypted/Encoded File T1547.004 Winlogon Helper DLL T1614.001 System Language Discovery T1566.003 Phishing: Spearphishing via Service T1059.004 Command and Scripting Interpreter: Unix Shell T1569 System Services T1037 Boot or Logon Initialization Scripts T1098.004 Account Manipulation: SSH Authorized Keys T1136 Create Account T1547 Boot or Logon Autostart Execution T1036.001 Masquerading: Invalid Code Signature T1134.004 Access Token Manipulation: Parent PID Spoofing T1211 Exploitation for Defense Evasion T1562.004 Impair Defenses: Disable or Modify System Firewall T1564 Hidden Artifacts T1564.003 Hidden Artifacts: Hidden Window T1040 Network Sniffing T1110.002 Brute Force: Password Cracking T1555.003 Credentials from Web Browsers T1614 System Location Discovery T1560.001 Archive Collected Data: Archive via Utility T1602.002 Network Device Configuration Dump T1011 Exfiltration Over Other Network Medium T1011.001 Exfiltration Over Other Network Medium: Exfiltration Over Bluetooth T1048.003 Exfiltration Over Alternative Protocol: Unencrypted Non-C2 Protocol T1001 Data Obfuscation T1001.001 Data Obfuscation: Junk Data T1071.001 Application Layer Protocol: Web Protocols T1572 Protocol Tunneling T1561 Disk Wipe T1561.001 Disk Wipe: Disk Content Wipe T1590.004 Gather Victim Network Information: Network Topology

Reporting

Research mentioning Qilin

Aug 3
Malware News

Cyber Conflict Briefing Q2 2026 - Malware Analysis - Malware Analysis, News and Indicators

The Qilin ransomware group claimed multiple new victims across the United States, Canada, Austria, and Germany, hitting organizations in manufacturing, professional services, financial services, media, retail, property management, and utilities. Named victims included Community Management Associates, Pointe Property Group, Ceragres, Dienst Pack Systems, Schreiner Trockenbau GmbH, Commercial Furniture Interiors, The Saturday Evening Post, Wire Products, Freedom Claims Management, and Service Electric. Several reports described the incidents as both ransomware attacks and associated data breaches, indicating continued emphasis on extortion through stolen data as well as operational disruption. Separate reporting tied Qilin affiliates to active exploitation of Internet-facing VPN and firewall infrastructure, including Palo Alto GlobalProtect CVE-2026-0257 and Check Point VPN CVE-2026-50751, as part of broader mid-2026 ransomware access campaigns. That activity was reported alongside common post-compromise tradecraft such as Impacket, NTLM relay, Mimikatz, PsExec, RDP, WMI, browser credential theft, and use of WSL for EDR evasion. A weekly ransomware trend report counted Qilin among the most active groups, with 31 claimed victims during the period, reinforcing its position as a leading extortion threat affecting organizations across sectors and regions.

Aug 3
Cyberveille

Tendances ransomware - Semaine 31/2026 | CyberVeille

Aug 3
Hookphish

Ransomware Group qilin Hits: Service Electric

Aug 3
Hookphish

Ransomware Group qilin Hits: Freedom Claims Management

Aug 2
Hookphish

Ransomware Group shinyhunters Hits: Questel SAS

Aug 2
Hookphish

Ransomware Group qilin Hits: Wire Products

Aug 1
Cyberveille

Vague d'exploitation VPN : Palo Alto, Fortinet, Citrix et Check Point ciblés par des ransomwares | CyberVeille

Aug 1
Hookphish

Ransomware Group qilin Hits: Schreiner Trockenbau GmbH

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.