Credential Theft
- Mimikatz
Qilin, formerly known as Agenda and also tracked as Water Galura, is a Russian-speaking ransomware-as-a-service operation active since mid-2022.
Profile source: Mallory opens in a new tabQilin
Qilin, formerly known as Agenda and also tracked as Water Galura, is a Russian-speaking ransomware-as-a-service operation active since mid-2022. It provides configurable ransomware payloads to affiliates and uses double-extortion tactics, combining file encryption with threats to publish stolen data through a Tor-based leak portal. Qilin has used both Go- and Rust-based lockers, including Windows-focused variants and cross-platform variants targeting Linux and VMware ESXi environments. Its payloads are commonly customized for individual victims, including encryption configuration, ransom-note content, file extensions, cryptographic material, and lists of processes or services to terminate.
Qilin ransomware encrypts data using hybrid cryptography and has used intermittent encryption in Rust variants to accelerate impact. It impairs recovery and security operations by deleting shadow copies and stopping backup, endpoint-security, database, virtualization, and enterprise-application processes and services. Observed Windows functionality includes Safe Mode encryption, modification of login settings, use of embedded credentials to impersonate users, access to mapped drives from elevated contexts, UAC-related privilege bypass, and persistence through injected auxiliary components.
Affiliates have obtained access through phishing, valid remote-access credentials, exposed VPN or RDP services, and exploitation of public-facing applications. Post-compromise activity has included network discovery, credential theft from backup infrastructure, lateral movement using remote-management tools and administrative protocols, deployment through Group Policy, abuse of vulnerable drivers to disable security products, DLL sideloading, and use of proxy backdoors for command-and-control. Qilin activity has affected organizations globally, with substantial targeting of manufacturing, construction, professional services, healthcare, education, technology, and industrial organizations.
d6e7547ad7dfd1fbc62e8282aebcc391f588802958c35fe18eb87bc36651a3d12bb209ccfc5103eccab523c875050cfaa7e7d00d531cb7ca27d0f3bee448573f964c13b68dc6b6b918b66a9a10469d2a3b10127e65fa3e215d21e0a2e7fd32bed1c331c17ddd4abe0d53755461c1ec9a417ad60624345ef85e648038e18902abb04e8ee43aba85fa5c585b9335c953c259d756280b06cf113ca43abc0050edd5176.113.115.97176.113.115.20985.209.11.4931.41.244.100188.119.66.189ftp://176.113.115.97/ftp://176.113.115.209/Reported operators
Qilin ransomware-as-a-service (RaaS) group, also tracked as Water Galura and historically known as Agenda, since its emergence in 2022.
In recent months, the Lazarus Group and its related intrusion set Moonstone Sleet have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.
In recent months, the Lazarus Group and its related intrusion set Moonstone Sleet have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.
Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS, which Unit 42 tracks as Spikey Scorpius.
Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.
According to VX-Underground, DragonForce proposed establishing communication channels with the LockBit and the Qilin group.
Our Threat Hunter Team has separately observed ModeloRAT used in attacks that deployed Qilin ransomware, linking this tool to ransomware deployment.
Our Threat Hunter Team has separately observed ModeloRAT used in attacks that deployed Qilin ransomware, linking this tool to ransomware deployment.
Qilin is a Ransomware-as-a-Service program that has been in operation since 2022, previously operating under the name “Agenda.”
The financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while leveraging resources from various ransomware-as-a-service (RaaS) schemes like LockBit (aka Tenacious Mantis), Qilin (aka Pestilent Mantis), and Medusa (aka Venomous Mantis).
The Gentlemen - не стартап с нуля. Ядро группы работало как ArmCorp - affiliate-команда внутри Qilin RaaS.
By June 2022, DEV-0237 was still primarily deploying Hive and sometimes Nokoyawa but was seen experimenting with other ransomware payloads, including Agenda and Mindware.
Qilin maintained its position as the most prominent ransomware operation for the third consecutive quarter, posting 338 victims.
Researchers last year tied MuddyWater to the Qilin ransomware ecosystem after the strain was used to attack an Israeli organization.
Qilin is a Russian-speaking ransomware-as-a-service (RaaS) operation first observed in July 2022 under the "Agenda" name and rebranded as Qilin in September 2022.
Qilin is a Russian-speaking ransomware-as-a-service (RaaS) operation first observed in July 2022 under the "Agenda" name and rebranded as Qilin in September 2022.
“Qilin (AKA Agenda) ransomware was first observed in July 2022 and operates it the double extortion method, where victims’ data is stolen and leaked via a data leak site if the ransom demand is not paid.”
“Qilin (AKA Agenda) ransomware was first observed in July 2022 and operates it the double extortion method, where victims’ data is stolen and leaked via a data leak site if the ransom demand is not paid.”
"... led to the deployment of Qilin ransomware"
Exploited software
MITRE ATT&CK
Reporting
Researchers reported that the Agenda ransomware operation, also tracked as Qilin, is conducting highly customized enterprise attacks across Asia and Africa and has now been linked to a victim in South Africa. A recent victim listing identified Trends And Concepts in South Africa, associated with the domain www.trendsandconceptsinteriors.com, as impacted by the Qilin group. Trend researchers said Agenda operators build victim-specific Go-based payloads that can include leaked account credentials, unique company identifiers, customized RSA keys, and ransom demands ranging from $50,000 to $800,000, with observed targeting of healthcare and education organizations in Indonesia, Saudi Arabia, South Africa, and Thailand. The intrusion methods described across the reports show a flexible and increasingly sophisticated playbook. In one case, attackers accessed a public-facing Citrix server using a valid account, moved laterally with RDP and leaked Active Directory credentials, scanned networks with Nmap and Nping, and deployed ransomware through Group Policy in under two days. A separate Trend investigation found Agenda actors using fake Google CAPTCHA pages to deliver credential stealers, then abusing legitimate remote-management tools including ATERA, AnyDesk, ScreenConnect, and Splashtop, while deploying COROXY SOCKS proxies, targeting Veeam backup infrastructure, and using BYOVD techniques with vulnerable drivers such as eskle.sys; the final ransomware payload was reportedly a Linux variant executed on Windows, likely through Windows Subsystem for Linux.
Ransomware activity intensified in 2026 as the criminal ecosystem expanded to 146 active groups by midyear, with 61 new groups emerging and public victim counts rising sharply across multiple regions and sectors. Black Kite reported 7,551 victims globally, a 55.1% year-over-year increase in Europe during the first four months of the year, and continued dominance by a small number of operators despite broader fragmentation. Qilin remained the leading ransomware-as-a-service operation across much of the market, benefiting from the decline of rivals such as LockBit and ALPHV, while researchers said attackers frequently gained initial access by exploiting critical vulnerabilities with CVSS >= 9 and, in some cases, through phishing and supply-chain compromise. At the same time, The Gentlemen emerged as one of the fastest-growing threats, especially against higher education. Comparitech counted 104 ransomware attacks against the global education sector in the first half of 2026, with attacks increasingly concentrated on colleges and universities and the United States recording the most confirmed victims. ESET said The Gentlemen equipped affiliates with the GentleKiller framework, a bring-your-own-vulnerable-driver toolkit designed to disable endpoint defenses before encryption, targeting more than 400 processes across roughly 48 security products. The group was also linked to steep growth in university attacks, including a case at Mount Royal University involving a $1.9 million ransom demand, alleged theft of more than 10TB of data, and destructive deletion of drives.
The Qilin ransomware group claimed multiple new victims across the United States, Canada, Austria, and Germany, hitting organizations in manufacturing, professional services, financial services, media, retail, property management, and utilities. Named victims included Community Management Associates, Pointe Property Group, Ceragres, Dienst Pack Systems, Schreiner Trockenbau GmbH, Commercial Furniture Interiors, The Saturday Evening Post, Wire Products, Freedom Claims Management, and Service Electric. Several reports described the incidents as both ransomware attacks and associated data breaches, indicating continued emphasis on extortion through stolen data as well as operational disruption. Separate reporting tied Qilin affiliates to active exploitation of Internet-facing VPN and firewall infrastructure, including Palo Alto GlobalProtect CVE-2026-0257 and Check Point VPN CVE-2026-50751, as part of broader mid-2026 ransomware access campaigns. That activity was reported alongside common post-compromise tradecraft such as Impacket, NTLM relay, Mimikatz, PsExec, RDP, WMI, browser credential theft, and use of WSL for EDR evasion. A weekly ransomware trend report counted Qilin among the most active groups, with 31 claimed victims during the period, reinforcing its position as a leading extortion threat affecting organizations across sectors and regions.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.