Qilin, also known as Agenda, is a ransomware family operated through a ransomware-as-a-service model in which core developers provide malware and infrastructure to affiliates who conduct intrusions and share ransom proceeds. It is a prominent and highly active ransomware brand that has targeted organizations across North America, Europe, South America, Africa, and Asia, with repeated reporting of activity against manufacturing, construction, professional services, healthcare, education, and industrial organizations. Qilin has also been linked to attacks on critical sectors including healthcare systems, power utilities, and educational institutions.
Qilin is a Windows-focused ransomware family that has existed in both Go and Rust implementations. The Rust variant introduced intermittent encryption options intended to accelerate file encryption and reduce detection opportunities. Samples have been observed requiring execution parameters, terminating numerous processes and services before encryption, appending victim-specific extensions to encrypted files, and dropping ransom notes in affected directories. The malware is designed to maximize impact by stopping security products, backup tooling, databases, virtualization components, mail and web infrastructure, and productivity applications so that files are unlocked and defenses are weakened prior to encryption.
The family demonstrates strong defense-evasion and privilege-related tradecraft. Reported behavior includes bypassing Windows User Account Control through use of stolen tokens to launch processes in an elevated security context. The Rust branch has also been associated with disabling AppInfo-related protections as part of its pre-encryption workflow. Qilin operators and affiliates have additionally been associated with post-compromise exploitation of edge and VPN infrastructure vulnerabilities, including campaigns involving authentication bypass flaws in enterprise remote-access products.
Qilin is commonly associated with double-extortion operations in which data is stolen before encryption and victims are threatened with public release if payment is not made. Its ecosystem uses anonymized infrastructure for operator or victim communications, and reporting consistently describes affiliate-driven intrusions leveraging compromised credentials, vulnerable internet-facing systems, and other post-compromise access pathways. Security reporting has repeatedly linked Qilin to Russian-speaking cybercriminal activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Check Point has urged customers to patch a critical zero-day vulnerability in its Remote Access VPN and Mobile Access solutions that is being actively exploited. CVE-2026-50751 is an authentication bypass flaw that affects deployments configured to use the deprecated IKEv1 key exchange protocol. | Check Point said that in one case, an affiliate of the Qilin ransomware group exploited the flaw in post-compromise activity, and assessed with medium confidence that the actor behind exploitation of CVE-2026-50751 is financially motivated and uses Qilin ransomware.
References: Exploitation of CVE-2026-0257 Leads to Qilin Ransomware – Arctic Wolf. | Qilin remained the most active ransomware brand targeting industrial organizations, a position it has held since March 2025.
Recently, the group have been observed exploiting CVE-2025-31324, (SAP NetWeaver Visual Composer vulnerability) and have previously exploited CVE-2023-27532 (Veeam Backup and Replication vulnerability). | Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.
Recently, the group have been observed exploiting CVE-2025-31324, (SAP NetWeaver Visual Composer vulnerability) and have previously exploited CVE-2023-27532 (Veeam Backup and Replication vulnerability). | Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.
CVE-2024–21762 and CVE-2024–55591: Critical vulnerabilities in Fortinet’s FortiGate and FortiProxy devices, enabling authentication bypass and remote code execution. CVE-2024–21762, patched in February 2025, remains a major concern with tens of thousands of exposed systems. | Qilin ransomware, also known as Agenda, has emerged as one of the most significant and evolving cyber threats globally, rapidly ascending to become a top-tier ransomware-as-a-service (RaaS) operation.
CVE-2024–21762 and CVE-2024–55591: Critical vulnerabilities in Fortinet’s FortiGate and FortiProxy devices, enabling authentication bypass and remote code execution. | Qilin ransomware, also known as Agenda, has emerged as one of the most significant and evolving cyber threats globally, rapidly ascending to become a top-tier ransomware-as-a-service (RaaS) operation.
On June 8th 2026, Check Point Research identified two CVEs (CVE-2026-50751, CVE-2026-50752) which can be abused to bypass Checkpoint VPN Authentication services, allowing threat actors to access network devices and traffic behind the VPN. | Check Point Research has medium confidence that the attacker is affiliated with Qilin as they use the Qilin ransomware toolkit.
18 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In recent months, the Lazarus Group and its related intrusion set Moonstone Sleet have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.
In recent months, the Lazarus Group and its related intrusion set Moonstone Sleet have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.
Exploitation confirmée dès le 17 mai 2026 ; affiliés Qilin confirmés en juillet 2026 ... Affilié Qilin confirmé dans des activités post-compromission
Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS, which Unit 42 tracks as Spikey Scorpius.
Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.
According to VX-Underground, DragonForce proposed establishing communication channels with the LockBit and the Qilin group.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Another common theme from Qilin's Ransomware Tool Matrix Group Profile is their regular abuse of Bring Your Own Vulnerable Driver (BYOVD) tactics to bypass Endpoint Detection and Response (EDR) and Antivirus software.
An attacker can bypass user authentication by exploiting a logic flow weakness in the Remote Access and Mobile Access certificate validation and establish a remote access VPN connection without a valid user password.
KONNI has bypassed UAC by performing token impersonation... Qilin can bypass standard user access controls by using stolen tokens to launch processes at an elevated security context.
The Agenda ransomware is also known to deploy customized ransomware for each victim, and we have seen that its Rust variants have an allocated space for adding accounts in their configuration to be used mostly for privilege escalation.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
The Gentlemen’s developers are systematically reverse-engineering samples from other groups, such as Babuk, Qilin, LockBit 5.0 and Medusa, to select the strongest encryption routines, code-obfuscation techniques and EDR evasion methods to incorporate into their own codebase.
Stade Français also acknowledged that a sample of data allegedly stolen in the attack had been published online, adding that it was investigating the scope of the breach and working to identify anyone whose information may have been compromised.
On 1 June 2026, the Bedfordshire Hospitals NHS Foundation Trust disclosed that over 32,000 patient data records related to Synnovis tests were exfiltrated... One key face to also note about Tor data leak sites operated by ransomware groups is that they include victims who failed to pay the ransom.
280 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-Service operation described as the most active ransomware threat in the Americas, using a compartmentalized affiliate model with initial access brokers, lateral movement operators, and dedicated encryption/exfiltration crews.
Ransomware-as-a-Service operation described as the most prolific in the Americas, using a compartmentalized affiliate model with initial access brokers, lateral movement operators, and dedicated encryption/exfiltration crews.
Ransomware group/family associated with industrial victim claims and access via compromised credentials and vulnerable internet-facing infrastructure.
Ransomware family mentioned as part of separate recent attacks attributed to Lazarus Group and Moonstone Sleet.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.