Overview

Platforms: Windows · Linux · VMware ESXi
Variants: Agenda · Qilin
Extensions: .qilin
ATT&CK software: Agenda
Initial access: Exploit Public-Facing Application · Spearphishing Attachment
Top countries: US · FR · CA · GB
Observed sectors: Manufacturing · Technology · Financial Services · Healthcare
Tracked victims: 2,263

Victims

Alicotrans CLAIMED
September 14, 2026 Transportation & Logistics 3 tracker sources
Transportation & Logistics organization.
Gilco Scaffolding CLAIMED
September 13, 2026 Construction 3 tracker sources
Construction organization.
CARIDRO VAL DE LOIRE CLAIMED
September 13, 2026 France Professional Services 3 tracker sources
Professional Services organization in France.
Imperial Healthcare Solutions CLAIMED
September 12, 2026 United States Healthcare 3 tracker sources
Healthcare organization in United States.
Mitsuwa Trading Co., Ltd CLAIMED
September 9, 2026 Japan Retail & E-Commerce 3 tracker sources
Retail & E-Commerce organization in Japan.
Show more victims (12)
Jet Specialty CLAIMED
September 9, 2026 United States Manufacturing 3 tracker sources
Manufacturing organization in United States.
Alaska Electrical Apprenticeship CLAIMED
September 8, 2026 United States Education 3 tracker sources
Education organization in United States.
Partners Group SK CLAIMED
September 7, 2026 Slovakia Financial Services 3 tracker sources
Financial Services organization in Slovakia.
JBC CLAIMED
September 7, 2026 Spain Manufacturing 3 tracker sources
Manufacturing organization in Spain.
Philippine Ports Authority CLAIMED
September 5, 2026 Philippines Transportation & Logistics 3 tracker sources
Transportation & Logistics organization in Philippines.
Bauman Law Group CLAIMED
September 5, 2026 United States Professional Services 3 tracker sources
Professional Services organization in United States.
Jouvet SAS CLAIMED
September 5, 2026 France Manufacturing 3 tracker sources
Manufacturing organization in France.
G&S Technologies CLAIMED
September 5, 2026 United States Technology 3 tracker sources
Technology organization in United States.
The Big Table CLAIMED
September 5, 2026 United Kingdom Hospitality 3 tracker sources
Hospitality organization in United Kingdom.
Commission de la construction du Québec CLAIMED
September 4, 2026 Canada Government
Government organization in Canada.
Tanner CLAIMED
September 2, 2026 Chile Other 3 tracker sources
Other organization in Chile.
Uşak University CLAIMED
September 2, 2026 Turkey Education
Education organization in Turkey.

Operational Activity

Recent Observations

Exploitation of edge device vulnerabilities
July 2026
Affiliates have been observed exploiting specific vulnerabilities in edge devices, such as CVE-2026-0257, to gain rapid initial access and transition to domain-wide ransomware deployment.
Credential access via spearphishing and stealers
Initial access is achieved through spearphishing campaigns delivering malicious attachments, stealers, and loaders, as well as the harvesting of VPN and browser credentials.
Moonstone Sleet deployment activity
February 2025
The North Korean state-sponsored actor Moonstone Sleet was observed deploying Qilin ransomware in limited attacks, marking a shift from their previously exclusive use of custom ransomware.
Synnovis ransomware incident
June 3, 2024
Qilin ransomware was deployed against Synnovis, a UK pathology provider, causing significant disruption to NHS pathology services. The group engaged in double extortion, threatening to leak stolen data.

TTPs

ATT&CK coverage: 11 techniques
T1190 Exploit Public-Facing Application
VERIFIED
Qilin actors exploit vulnerabilities in public-facing applications, such as Citrix and other remote-access infrastructure, to gain initial access.
T1566.001 Spearphishing Attachment
VERIFIED
Qilin has been observed using spearphishing emails containing malicious attachments to deliver the ransomware or initial access tools.
T1566.002 Spearphishing Link
VERIFIED
Qilin utilizes malicious links within spearphishing emails to direct victims to download initial access payloads.
Show more TTPs (8)
T1059.001 PowerShell
VERIFIED
PowerShell is frequently used by the group for reconnaissance, credential dumping, and lateral movement within compromised Windows and Active Directory environments.
T1003.001 LSASS Memory
VERIFIED
Qilin actors employ tools like Mimikatz to extract credentials from the Local Security Authority Subsystem Service (LSASS) memory.
T1021.002 SMB/Windows Admin Shares
VERIFIED
The group leverages PsExec and Windows administrative shares (SMB) to distribute and execute the ransomware payload across the network.
VERIFIED
Qilin enables and uses SSH to access and deploy ransomware on virtualized environments, specifically targeting ESXi hosts.
T1562.001 Disable or Modify Tools: Impair Defenses
VERIFIED
Qilin operators actively terminate endpoint protection, antivirus processes, and security services to facilitate encryption without interference.
T1490 Inhibit System Recovery
VERIFIED
The ransomware removes Volume Shadow Copies and targets VMware recovery features to prevent data restoration.
T1489 Service Stop
VERIFIED
Qilin stops various services related to backups, databases, and security to ensure effective encryption of host data.
T1486 Data Encrypted for Impact
VERIFIED
Qilin uses sophisticated encryption routines to target Windows, Linux, and VMware ESXi environments, often utilizing custom arguments for configuration.

CVEs

Microsoft reports that Qilin exploits CVE-2024-21762, a remote-code-execution vulnerability in FortiOS, as part of its intrusion activity.
Microsoft reports that Qilin exploits CVE-2023-27532, a credential-theft vulnerability affecting Veeam Backup & Replication.

Infrastructure

Dedicated Leak Site (DLS)
The group maintains a Tor-based dedicated leak site where stolen data is published to exert pressure on victims who do not pay ransom demands.
ONLINE

Attribution

Spikey Scorpius VERIFIED
Vendor tracking name
Palo Alto Networks Unit 42 tracks the Qilin ransomware operation and its affiliate program under the name Spikey Scorpius.
Water Galura VERIFIED
Vendor tracking name
Trend Micro tracks the group behind Qilin (formerly Agenda) ransomware as Water Galura.
Gold Feather VERIFIED
Vendor tracking name
Multiple CTI sources identify Gold Feather as an alias used to track the Qilin ransomware group.
Phantom Mantis VERIFIED
Vendor tracking name
Multiple CTI sources identify Phantom Mantis as an alias used to track the Qilin ransomware group.

Relationships

Moonstone Sleet VERIFIED
Reported RaaS relationship
Microsoft and other CTI sources have observed the North Korean-linked actor Moonstone Sleet deploying Qilin ransomware in limited attacks.

Affiliates

ArmCorp
Reported Qilin affiliate; identified in research connecting the actor to the subsequent emergence of The Gentlemen ransomware operation.
First seen: 2025

Timeline

2026-09
Continued operation
Qilin continues to maintain an active ransomware-as-a-service operation, consistently posting new victims to its leak site.
2025-03
Moonstone Sleet deployment
Microsoft identified the threat actor Moonstone Sleet utilizing Qilin ransomware in limited deployment scenarios.
2024-06
Synnovis ransomware incident
The Synnovis ransomware attack resulted in significant disruption to pathology services for multiple NHS organizations in London.
Show more events (1)
2022-07
Emergence of Agenda ransomware
The ransomware operation now known as Qilin was first publicly documented as Agenda, observed targeting corporate entities.

Sources