Qilin, formerly known as Agenda and also tracked as GOLD FEATHER, Phantom Mantis, and Water Galura, is a financially motivated ransomware-as-a-service operation active since 2022. Its operators provide ransomware, affiliate infrastructure, and negotiation services in exchange for a share of ransom proceeds. Qilin conducts double extortion by stealing sensitive information, encrypting systems, and threatening publication through a Tor-based leak site. Its victims span healthcare, manufacturing, professional services, technology, financial services, retail, transportation, media, and government organizations worldwide. The June 2024 attack against pathology provider Synnovis significantly disrupted NHS hospital services in London. Qilin evolved from Go-based Agenda ransomware into Rust-based payloads, with variants targeting Windows, Linux, and VMware ESXi environments. Affiliates obtain initial access through phishing, compromised remote-access credentials, brute-force attacks against VPN services, and exploitation of internet-facing appliances. Documented exploitation includes Fortinet vulnerabilities and CVE-2023-27532 in Veeam Backup & Replication, which enables theft of stored credentials and subsequent compromise of backup infrastructure. Post-compromise activity includes browser credential theft, privileged token impersonation, Active Directory discovery, and lateral movement using legitimate administrative tools. The ransomware supports propagation through PsExec and VMware vCenter. Qilin attacks systematically undermine recovery by deleting shadow copies, disabling backup jobs, and compromising online backup systems. Defense-evasion techniques include clearing event logs, stopping security services, and deploying Killer Ultra, an endpoint-defense impairment tool that abuses a vulnerable Zemana driver through CVE-2024-1853. Scheduled tasks and legitimate remote-administration software support persistence and continued access. Affiliates exfiltrate data using tools such as Rclone, WinSCP, and FileZilla. Qilin's ransomware supports configurable, multithreaded and intermittent encryption, using AES-256-CTR or ChaCha20 with RSA-4096 protection for encryption material.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
18 CVEs this actor has used in observed campaigns. 18 of them exploited in the wild.
In June this year, Qilin was exploiting a critical authentication bypass vulnerability in Check Point VPN and firewall products, tracked as CVE-2026-50751.
The third one, suspected to be the work of a Qilin ransomware operator, starts with the attackers logging in with the static credentials (CVE-2026-20316), then performing network and endpoint reconnaissance, stealing credentials, establishing additional access, deploying AV killers, and delivering the ransomware.
L’attaccante provvede allo sfruttamento di vulnerabilità specifiche - tra cui la CVE-2023-27532 presente in Veeam Backup & Replication - per l’estrazione di credenziali e la successiva neutralizzazione preventiva delle infrastrutture di backup online.
FortiOS e FortiProxy: identificata tramite la CVE-2024-21762 di tipo “Out-of-bounds Write” e con score CVSS v3.1 pari a 9.8.
FortiOS e FortiProxy: identificata tramite la CVE-2024-55591 di tipo “Authentication Bypass” e con score CVSS v3.1 pari a 9.8.
13 more CVEs tied to this actor tracked in Mallory.
154 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The report attributes a ransomware attack and data breach affecting Sweden-based Vadeto Group to Qilin. It lists the breach time as October 9, 2026, at 20:07 UTC and discovery at 20:08 UTC. No attack mechanics, malware family, exploited vulnerabilities, or victim industry are provided.
Reportedly conducted a ransomware attack against Tepcomp, a Finnish organization in the technology sector. The report lists both the breach and discovery time as October 9, 2026, at 18:05 UTC, but provides no technical attack details.
A Qilin leak-site listing identifies Vadeto Group in Sweden as a victim, discovered on October 9, 2026. The supplied post contains no substantive claim details, stolen-data volume, proof of compromise, ransom demand, or deadline.
A ransomware-as-a-service operation active since 2022 that enables affiliates to deploy customized ransomware and conduct double extortion. Its victims include Japanese organizations Nissan and Asahi, a German ransomware victim, and allegedly Dow Inc. The group continued listing hundreds of victims after the suspected leader's detention in May. The article also describes its alliance with DragonForce and LockBit.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.