Qilin, also known as Agenda, is a ransomware family and ransomware-as-a-service operation active since 2022. Its Russian-speaking operators supply affiliates with customizable encryptors, attack tooling, and infrastructure for negotiations and publication of stolen data. Affiliates generally retain 80–85% of ransom proceeds. Qilin conducts double extortion, combining data theft and encryption with threats to disclose sensitive information. It targets organizations worldwide across healthcare, manufacturing, financial services, professional services, government, and other sectors. Its June 2024 attack on pathology provider Synnovis significantly disrupted hospital services in London.
Originally developed in Go and subsequently implemented in Rust, Qilin supports Windows, Linux, and VMware ESXi environments. Its Rust-based Qilin.B variant uses AES-256-CTR with AES-NI acceleration where available, or ChaCha20, and protects encryption keys with RSA-4096. Configurable full and partial encryption modes allow affiliates to balance speed and impact. The ransomware can encrypt local storage and network shares, terminate selected processes and services, delete Volume Shadow Copies, clear event logs, and remove its own executable. It supports network propagation through PsExec and VMware vCenter, and Windows variants can impersonate privileged accounts and execute encryption in Safe Mode.
Qilin intrusion chains involve phishing, compromised remote-access credentials, exposed VPN or RDP services, and exploitation of vulnerable internet-facing systems. Operators have exploited Fortinet vulnerabilities and CVE-2023-27532 in Veeam Backup & Replication, using recovered credentials to compromise backup infrastructure and obstruct recovery. Campaigns include credential theft, network reconnaissance, lateral movement, abuse of legitimate remote-administration software, and data exfiltration through file-transfer utilities. Qilin attackers have also deployed Killer Ultra, a separate defense-impairment tool that abuses a vulnerable Zemana driver through CVE-2024-1853 to terminate security processes. Symantec tracks the core operation as Stinkbug; the North Korean state-sponsored actor Moonstone Sleet has also deployed Qilin.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
They have been observed exploiting vulnerabilities in edge devices, including Citrix ADC (CVE-2019-19781).
Recent intelligence also links them to the exploitation of the "React2Shell" vulnerability.
Malware, Tools, Vulnerabilities, and TTPs Used in Qilin Campaigns — Vulnerabilities: CVE-2023-27532, CVE-2024-21762, CVE-2024-55591
Malware, Tools, Vulnerabilities, and TTPs Used in Qilin Campaigns — Vulnerabilities: CVE-2023-27532, CVE-2024-21762, CVE-2024-55591
The Qilin Ransomware Group report lists CVE-2025-31324 under “MITRE CONTEXT — Exploits Vulnerabilities.”
They have been observed exploiting vulnerabilities in edge devices, including Citrix ADC (CVE-2019-19781), Fortinet VPNs, and the critical "ZeroLogon" vulnerability (CVE-2020-1472) in Windows Domain Controllers.
Malware, Tools, Vulnerabilities, and TTPs Used in Qilin Campaigns — Vulnerabilities: CVE-2023-27532, CVE-2024-21762, CVE-2024-55591
The Qilin Ransomware Group report lists CVE-2023-4966 under “MITRE CONTEXT — Exploits Vulnerabilities.”
Le evidenze analizzate confermano lo sfruttamento attivo di vulnerabilità note su appliance di Mobile Device Management (MDM) Ivanti (CVE-2026-1281 e CVE-2026-1340). | Il gruppo ha evoluto il proprio codice originario (scritto in Go) in una variante più robusta basata su Rust ... Qilin adotta una strategia di doppia estorsione, esfiltrando dati sensibili prima della cifratura.
Ivanti Endpoint Manager Mobile (EPMM): identificata tramite la CVE-2026-1281 di tipo “Code Injection” e con score CVSS v3.1 pari a 9.8. | Il gruppo ha evoluto il proprio codice originario (scritto in Go) in una variante più robusta basata su Rust ... Qilin adotta una strategia di doppia estorsione, esfiltrando dati sensibili prima della cifratura.
Killer Ultra is packed with a vulnerable version of Zemana AntiLogger leveraging CVE-2024-1853 for Arbitrary Process Termination.
In June this year, Qilin was exploiting a critical authentication bypass vulnerability in Check Point VPN and firewall products, tracked as CVE-2026-50751. | Also known as Agenda, Qilin has been active since August 2022 and has become one of the most prolific ransomware-as-a-service (RaaS) operations, hitting hundreds of organizations worldwide and causing millions of dollars in damages.
The third one, suspected to be the work of a Qilin ransomware operator, starts with the attackers logging in with the static credentials (CVE-2026-20316), then performing network and endpoint reconnaissance, stealing credentials, establishing additional access, deploying AV killers, and delivering the ransomware.
The report notes that extortion and ransomware actors such as Qilin have increasingly exploited CVE-2026-0257 outside Operation Master.
Active exploitation of Cisco Secure Firewall Management Center (FMC) vulnerabilities CVE-2026-20079 and CVE-2026-20316, enabling authentication bypass, unauthorized access, and privilege escalation.
26 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Germany has arrested a Russian national believed to be a leading figure in the Qilin ransomware group.
The article investigates a leaked Qilin ransomware affiliate panel and the tooling interests of affiliate “hastalamuerte.”
A pivotal moment in Qilin’s technical evolution was the transition from the original Golang codebase to a new variant written in Rust, often referred to by researchers as Qilin.B.
Qilin ransomware has been active since at least May 2022. Qilin operates under a Ransomware-as-a-Service (RaaS) model.
A pivotal moment in Qilin’s technical evolution was the transition from the original Golang codebase to a new variant written in Rust, often referred to by researchers as Qilin.B.
Qilin ransomware has been active since at least May 2022. Qilin operates under a Ransomware-as-a-Service (RaaS) model.
39 distinct techniques documented for this family, organized by ATT&CK tactic.
However, there is no confirmed evidence that Qilin operators have utilized these exploits.
The ransomware first deletes all system logs before initiating data encryption.
However, there is no confirmed evidence that Qilin operators have utilized these exploits.
The malware begins by encrypting all data on the host and any attached drives, including network shares.
Post-encryption activities include ... terminating specified services or processes.
322 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service operation active since 2022 that enables affiliates to deploy customized payloads. It uses double extortion, encrypting data and threatening publication through Tor-based leak portals. The article describes phishing and exploitation of unspecified known vulnerabilities, global bulletproof hosting infrastructure, and continued attacks after a suspected leader's detention in Japan and extradition to Germany.
Ransomware associated with a double-extortion operation that steals data before encrypting victims' systems. The article reports more than 2,350 known victim organizations across 62 countries. Germany arrested a suspected leading member of the operation following extradition from Japan, but the group continued operating, listing more than 450 victims since June.
Qilin encrypts victims' computer systems to extort cryptocurrency payments. The operation emerged in 2022 and uses a ransomware-as-a-service model in which developers supply malware and infrastructure to affiliates in exchange for a share of attack proceeds. This report concerns a suspected participant's arrest and extradition to Germany over an alleged September 2024 attack against a logistics company. It also describes links to the disruptive 2024 Synnovis healthcare attack and reports exploitation of an unspecified critical Check Point vulnerability in 2026.
A ransomware operation whose affiliates use multiple legitimate remote-management tools for access and redundancy. One affiliate used Atera to deploy AnyDesk, maintained ScreenConnect alongside it, and invoked Splashtop's management service to execute Linux ransomware on Windows through WSL.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.