Qilin is a financially motivated ransomware operation best known for running a ransomware-as-a-service model with an affiliate structure. It is also tracked under aliases including Agenda, Gold Feather, Water Galura, Qiring, and Qiling. The operation has been among the most active ransomware groups globally, with victim disclosures spanning dozens of countries and a broad cross-sector victim set. Qilin’s activity is characterized by ransomware deployment combined with data theft and public leak-site pressure, reflecting the broader shift in the ransomware ecosystem toward extortion through stolen-data exposure as well as encryption. The group has publicly claimed large numbers of victims over sustained periods and has demonstrated the scale and resilience typical of mature affiliate-driven criminal enterprises. Victimology associated with Qilin includes organizations in manufacturing, transportation, financial services, technology, retail, hospitality, education, and professional services. Reported victims span North America, Europe, Asia, and Latin America, indicating broad international targeting rather than a narrow regional focus. Available reporting indicates that Qilin operates as a decentralized criminal enterprise rather than a state-directed actor. Its use of affiliates and its apparent ability to absorb participants displaced from other ransomware operations are consistent with the modular ransomware market in which access brokers, operators, negotiators, and infrastructure providers play specialized roles. High-confidence evidence in this dataset supports ransomware and extortion activity, but does not directly establish specific intrusion tradecraft beyond those extortion-stage behaviors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
Check Point has linked zero-day exploitation of CVE-2026-50751 to the Qilin ransomware group. The critical vulnerability affects Check Point Remote Access VPN and Mobile Access. Attackers began exploiting the flaw as a zero-day on May 7, with activity spiking sharply in early June. While several dozen organizations have been targeted, at least one incident has been definitively tied to Qilin.
Qilin (aka Agenda and Phantom Mantis) ransomware operators have launched a coordinated intrusion campaign targeting several organizations between May and June 2025 by weaponizing Fortinet FortiGate vulnerabilities (e.g., CVE-2024-21762 and CVE-2024-55591) for initial access.
Qilin (aka Agenda and Phantom Mantis) ransomware operators have launched a coordinated intrusion campaign targeting several organizations between May and June 2025 by weaponizing Fortinet FortiGate vulnerabilities (e.g., CVE-2024-21762 and CVE-2024-55591) for initial access.
Known Exploited Vulnerabilities: CVE-2023-27532 — Missing Authentication for Critical Function Vulnerability — Veeam Backup & Replication Cloud Connect — CVSS 7.5
CVE-2025-31324 (CVSS 10.0): A missing authorization check in the Visual Composer Metadata Uploader was actively exploited as a zero day by multiple threat actor groups, including Russian ransomware operators (BianLian, RansomEXX/Storm-2460), the Qilin ransomware as a service operation, and the China nexus APT group Earth Lamia.
3 more CVEs tied to this actor tracked in Mallory.
112 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Described as the most active ransomware group for the fourth consecutive quarter, with 279 listed victims in Q2 2026.
Presented as a highly active ransomware operation whose scale is attributed to its affiliate structure and ability to absorb participants displaced from other ransomware organizations.
Conducting a ransomware attack against Coface.
Conducting a ransomware attack against AGUNSA.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.