Overview
Platforms:
Windows · Linux · VMware ESXi
Variants:
Agenda · Qilin
Extensions:
.qilin
ATT&CK software:
Agenda
Initial access:
Exploit Public-Facing Application · Spearphishing Attachment
Top countries:
US · FR · CA · GB
Observed sectors:
Manufacturing · Technology · Financial Services · Healthcare
Tracked victims:
2,263
Victims
Alicotrans
CLAIMED
Transportation & Logistics organization.
Gilco Scaffolding
CLAIMED
Construction organization.
CARIDRO VAL DE LOIRE
CLAIMED
Professional Services organization in France.
Imperial Healthcare Solutions
CLAIMED
Healthcare organization in United States.
Mitsuwa Trading Co., Ltd
CLAIMED
Retail & E-Commerce organization in Japan.
Show more victims (12)
Jet Specialty
CLAIMED
Manufacturing organization in United States.
Alaska Electrical Apprenticeship
CLAIMED
Education organization in United States.
Partners Group SK
CLAIMED
Financial Services organization in Slovakia.
JBC
CLAIMED
Manufacturing organization in Spain.
Philippine Ports Authority
CLAIMED
Transportation & Logistics organization in Philippines.
Bauman Law Group
CLAIMED
Professional Services organization in United States.
Jouvet SAS
CLAIMED
Manufacturing organization in France.
G&S Technologies
CLAIMED
Technology organization in United States.
The Big Table
CLAIMED
Hospitality organization in United Kingdom.
Commission de la construction du Québec
CLAIMED
Government organization in Canada.
Tanner
CLAIMED
Other organization in Chile.
Uşak University
CLAIMED
Education organization in Turkey.
Operational Activity
Recent Observations
Exploitation of edge device vulnerabilities
July 2026
Affiliates have been observed exploiting specific vulnerabilities in edge devices, such as CVE-2026-0257, to gain rapid initial access and transition to domain-wide ransomware deployment.
Credential access via spearphishing and stealers
Initial access is achieved through spearphishing campaigns delivering malicious attachments, stealers, and loaders, as well as the harvesting of VPN and browser credentials.
Moonstone Sleet deployment activity
February 2025
The North Korean state-sponsored actor Moonstone Sleet was observed deploying Qilin ransomware in limited attacks, marking a shift from their previously exclusive use of custom ransomware.
Synnovis ransomware incident
June 3, 2024
Qilin ransomware was deployed against Synnovis, a UK pathology provider, causing significant disruption to NHS pathology services. The group engaged in double extortion, threatening to leak stolen data.
TTPs
ATT&CK coverage:
11 techniques
T1190
Exploit Public-Facing Application
VERIFIEDQilin actors exploit vulnerabilities in public-facing applications, such as Citrix and other remote-access infrastructure, to gain initial access.
T1566.001
Spearphishing Attachment
VERIFIEDQilin has been observed using spearphishing emails containing malicious attachments to deliver the ransomware or initial access tools.
T1566.002
Spearphishing Link
VERIFIEDQilin utilizes malicious links within spearphishing emails to direct victims to download initial access payloads.
Show more TTPs (8)
T1059.001
PowerShell
VERIFIEDPowerShell is frequently used by the group for reconnaissance, credential dumping, and lateral movement within compromised Windows and Active Directory environments.
T1003.001
LSASS Memory
VERIFIEDQilin actors employ tools like Mimikatz to extract credentials from the Local Security Authority Subsystem Service (LSASS) memory.
T1021.002
SMB/Windows Admin Shares
VERIFIEDThe group leverages PsExec and Windows administrative shares (SMB) to distribute and execute the ransomware payload across the network.
T1021.004
SSH
VERIFIEDQilin enables and uses SSH to access and deploy ransomware on virtualized environments, specifically targeting ESXi hosts.
T1562.001
Disable or Modify Tools: Impair Defenses
VERIFIEDQilin operators actively terminate endpoint protection, antivirus processes, and security services to facilitate encryption without interference.
T1490
Inhibit System Recovery
VERIFIEDThe ransomware removes Volume Shadow Copies and targets VMware recovery features to prevent data restoration.
T1489
Service Stop
VERIFIEDQilin stops various services related to backups, databases, and security to ensure effective encryption of host data.
T1486
Data Encrypted for Impact
VERIFIEDQilin uses sophisticated encryption routines to target Windows, Linux, and VMware ESXi environments, often utilizing custom arguments for configuration.
CVEs
Microsoft reports that Qilin exploits CVE-2024-21762, a remote-code-execution vulnerability in FortiOS, as part of its intrusion activity.
Microsoft reports that Qilin exploits CVE-2023-27532, a credential-theft vulnerability affecting Veeam Backup & Replication.
Infrastructure
Dedicated Leak Site (DLS)
The group maintains a Tor-based dedicated leak site where stolen data is published to exert pressure on victims who do not pay ransom demands.
ONLINE
Attribution
Spikey Scorpius
VERIFIED
Vendor tracking name
Palo Alto Networks Unit 42 tracks the Qilin ransomware operation and its affiliate program under the name Spikey Scorpius.
Water Galura
VERIFIED
Vendor tracking name
Trend Micro tracks the group behind Qilin (formerly Agenda) ransomware as Water Galura.
Gold Feather
VERIFIED
Vendor tracking name
Multiple CTI sources identify Gold Feather as an alias used to track the Qilin ransomware group.
Phantom Mantis
VERIFIED
Vendor tracking name
Multiple CTI sources identify Phantom Mantis as an alias used to track the Qilin ransomware group.
Relationships
Moonstone Sleet
VERIFIED
Reported RaaS relationship
Microsoft and other CTI sources have observed the North Korean-linked actor Moonstone Sleet deploying Qilin ransomware in limited attacks.
Affiliates
ArmCorp
Reported Qilin affiliate; identified in research connecting the actor to the subsequent emergence of The Gentlemen ransomware operation.
First seen:
2025
Timeline
2026-09
Continued operation
Qilin continues to maintain an active ransomware-as-a-service operation, consistently posting new victims to its leak site.
2025-03
Moonstone Sleet deployment
Microsoft identified the threat actor Moonstone Sleet utilizing Qilin ransomware in limited deployment scenarios.
2024-06
Synnovis ransomware incident
The Synnovis ransomware attack resulted in significant disruption to pathology services for multiple NHS organizations in London.
Show more events (1)
2022-07
Emergence of Agenda ransomware
The ransomware operation now known as Qilin was first publicly documented as Agenda, observed targeting corporate entities.
Sources
Threat Actor Groups Tracked by Palo Alto Networks Unit 42
Palo Alto Networks Unit 42
Ransom:Linux/Qilin!rfn
Microsoft Security Intelligence
Show more sources (17)
Moonstone Sleet Deploys Qilin Ransomware
Microsoft Threat Intelligence
Qilin Ransomware: Analysis and TTPs
SentinelOne
Qilin: Top Ransomware Threat to SLTTs in Q2 2025
CIS Center for Internet Security
Ransomware Spotlight: Agenda
Trend Micro
Qilin Ransomware - Blackpoint Cyber
Blackpoint Cyber
Qilin Ransomware: Evolution and Affiliate Transitions
Palo Alto Networks Unit 42
Qilin
RansomLook
Ransomware Spotlight: Agenda
TrendAI Research
Qilin ransomware group tracker
Ransomware.live