Qilin is a ransomware-as-a-service (RaaS) operation active by 2025 and one of the most prolific ransomware brands observed in 2026. It is also tracked under aliases including Agenda, Qiling, Qirin, Gold Feather, Water Galura, and by Palo Alto Networks Unit 42 as Spikey Scorpius. Qilin conducts double-extortion ransomware operations, publicly naming victims and claiming data theft across a wide range of sectors and geographies, including healthcare, education, manufacturing, business services, hospitality, transportation, consumer services, and food production. Qilin operates through an affiliate model in which intrusion activity and victimization are carried out by partners using the Qilin ransomware platform. Reporting has linked at least some later ransomware operators to prior activity as Qilin affiliates, indicating that the ecosystem has functioned as a feeder for other criminal operations. The group has remained highly active in public leak-site postings and ransomware claim tracking throughout 2026, although by mid-2026 it was overtaken in victim volume by competing RaaS programs such as The Gentlemen. Observed tradecraft includes credential theft and privilege escalation in Windows enterprise environments. In at least one intrusion, operators abused Active Directory replication rights to perform DCSync-style credential harvesting, enabling access to domain password material including KRBTGT-related secrets and NTLM hashes. This reflects a focus on identity compromise and lateral movement rather than encryption alone. The technique relied on misuse of legitimate directory replication mechanisms, underscoring Qilin’s ability to blend malicious actions with normal administrative protocols. Qilin has also been associated in reporting with the broader ransomware support ecosystem, including use of anonymizing infrastructure services favored by cybercriminals. The group is financially motivated and should be treated as an organized eCrime actor rather than a confirmed nation-state threat. Its operations are characterized by opportunistic targeting, affiliate-driven scale, data theft, extortion, and continued adaptation of post-compromise techniques to improve stealth and access persistence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
CVE-2026-50751 is a critical vulnerability (CVSS 9.3) in Check Point Remote Access VPN, Mobile Access, and Spark Firewall products using the deprecated IKEv1 key exchange protocol. The flaw is due to a logic error in certificate validation during the IKEv1 handshake that enables unauthenticated attackers to bypass user authentication entirely and initiate VPN connections.
Known Exploited Vulnerabilities: CVE-2023-27532 — Missing Authentication for Critical Function Vulnerability — Veeam Backup & Replication Cloud Connect — CVSS 7.5
Known Exploited Vulnerabilities: CVE-2024-21762 — Out-of-Bound Write Vulnerability — Fortinet FortiOS — CVSS 9.8
Known Exploited Vulnerabilities: CVE-2024-55591 — Authentication Bypass Vulnerability — Fortinet FortiOS — CVSS 9.8
CVE-2025-31324 (CVSS 10.0): A missing authorization check in the Visual Composer Metadata Uploader was actively exploited as a zero day by multiple threat actor groups, including Russian ransomware operators (BianLian, RansomEXX/Storm-2460), the Qilin ransomware as a service operation, and the China nexus APT group Earth Lamia.
1 more CVE tied to this actor tracked in Mallory.
61 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against International Delights.
Conducting a ransomware attack against Danone (International Delights).
Conducting a ransomware attack against Feliubadaló.
Conducting a ransomware attack against Levin Furniture.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.