Qilin is a financially motivated ransomware-as-a-service (RaaS) operation also tracked under aliases including Agenda, Gold Feather, Phantom Mantis, Qirin, Qiling, and Water Galura. It operates through an affiliate model in which core operators provide ransomware tooling and extortion infrastructure while affiliates conduct intrusions and victim negotiations. Qilin has been one of the most prolific ransomware actors observed in 2026 and has been linked to sustained global victimization across North America, Europe, Asia, the Middle East, Africa, and Latin America. Qilin conducts multi-sector targeting, with reported victims spanning manufacturing, healthcare, education, professional services, retail, government-related entities, and other commercial organizations. Reporting indicates especially high activity against organizations in the United States and Europe, with additional notable victimization in Italy and other regions. The operation is associated with double extortion, combining data theft with encryption and leak-site pressure. Qilin affiliates have been tied to exploitation of internet-facing edge infrastructure as an initial access vector, including authentication-bypass flaws affecting remote-access and perimeter security products such as Palo Alto Networks GlobalProtect and Check Point VPN. In these intrusions, affiliates were observed obtaining credential-free or low-friction access to corporate environments and then conducting post-compromise activity including credential theft, NTLM relay, lateral movement, remote execution, and broader environment takeover. Observed tradecraft includes use of Impacket, Mimikatz, PsExec, RDP, WMI, credential harvesting from browsers, and evasion through Windows Subsystem for Linux. More broadly, Qilin activity aligns with common ransomware intrusion patterns such as exploitation of public-facing applications, abuse of valid accounts, data exfiltration, and encryption for impact. Qilin is widely regarded as a mature and highly active criminal enterprise rather than a state-sponsored actor. Its scale, affiliate reach, and repeated appearance at or near the top of ransomware victim-claim rankings indicate a well-developed operational ecosystem and strong access to intrusion capability. Some actors have reportedly worked as Qilin affiliates before moving to other ransomware programs or launching their own operations, underscoring Qilin’s role within the broader ransomware affiliate marketplace.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
In June, CISA ordered federal agencies to secure their Check Point Remote Access VPN and Mobile Access deployments against another authentication bypass vulnerability (CVE-2026-50751) that was exploited in zero-day attacks by the Qilin ransomware gang.
Qilin (aka Agenda and Phantom Mantis) ransomware operators have launched a coordinated intrusion campaign targeting several organizations between May and June 2025 by weaponizing Fortinet FortiGate vulnerabilities (e.g., CVE-2024-21762 and CVE-2024-55591) for initial access.
Qilin (aka Agenda and Phantom Mantis) ransomware operators have launched a coordinated intrusion campaign targeting several organizations between May and June 2025 by weaponizing Fortinet FortiGate vulnerabilities (e.g., CVE-2024-21762 and CVE-2024-55591) for initial access.
Known Exploited Vulnerabilities: CVE-2023-27532 — Missing Authentication for Critical Function Vulnerability — Veeam Backup & Replication Cloud Connect — CVSS 7.5
CVE-2025-31324 (CVSS 10.0): A missing authorization check in the Visual Composer Metadata Uploader was actively exploited as a zero day by multiple threat actor groups, including Russian ransomware operators (BianLian, RansomEXX/Storm-2460), the Qilin ransomware as a service operation, and the China nexus APT group Earth Lamia.
3 more CVEs tied to this actor tracked in Mallory.
72 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack resulting in a data breach against Savills France.
Conducting a ransomware attack against Wilbert’s, a US-based organization in the retail and e-commerce sector.
Ransomware affiliates exploiting edge VPN and firewall vulnerabilities for initial access, then conducting lateral movement, data exfiltration, and double-extortion ransomware deployment. The group is directly linked in the content to exploitation of Palo Alto GlobalProtect CVE-2026-0257 and Check Point VPN CVE-2026-50751.
A ransomware group leading claimed attacks against Italian organizations in H1 2026, operating steadily across all six months and systematically targeting small and medium businesses according to Italy's CSIRT advisory.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.