Skip to main content
Mallory
Financially Motivated3 malware familiesExploits CVEs in the wild

Qilin

Also known asagendaGOLD FEATHERqilinqilin_gangqilin_ransomwareqilin_ransomware_gangqilin_ransomware_groupqirinWater Galura

Qilin is a ransomware-as-a-service (RaaS) cybercrime operation, also known as Agenda, Qirin, Gold Feather, and Water Galura. The operation emerged in 2022, initially launched as Agenda in August 2022 and rebranded to Qilin by September 2022. Multiple sources in the content describe it as a Russian-speaking or Russia-based ransomware group. Qilin is one of the most active ransomware groups in the reporting period, including being described as the highest-volume operation in a 24-month leak-site dataset with 1,690 victims over 731 days, averaging 2.3 leak posts per day; the most prolific group in Q1 2026 with 353 attack claims; the most active group targeting organizations in Asia in 2025; and estimated by Rapid7 to have earned $193 million between July 2025 and March 2026. Qilin operates an affiliate-based model and maintains a proprietary data leak site. It conducts double-extortion attacks, stealing data and encrypting systems, and threatens to publish stolen data even after payment. The group has also been described as shifting back toward encryption as a primary pressure mechanism. Its ransomware is Rust-based and highly customizable, with support for Windows and ESXi, and reporting also describes Linux ELF64 encryptors for Linux, FreeBSD, and VMware ESXi. The malware supports multiple encryption modes, configurable file extensions, process and service termination, VM shutdown, and snapshot deletion. On ESXi, it enumerates and force-stops virtual machines, removes snapshots, encrypts targeted files, and drops ransom notes with Tor negotiation links and victim-specific credentials. Reported ransom demands ranged from $25,000 to millions of dollars. Reported tactics and tradecraft in the content include phishing emails with malicious links for initial access, lateral movement after compromise, data exfiltration, use of SmokeLoader and NETXLOADER in a November 2024 campaign, and acquisition of initial access from actors associated with the ZipLine phishing campaign. Talos incident response reported previously unreported Qilin tools, TTPs, and a new data exfiltration method. The content also states Qilin may terminate server-specific processes, reboot systems into normal mode, and place ransom notes in each infected directory. One source says Qilin offered affiliates in-house legal consultations to pressure victims. The group targets organizations across sectors and geographies. The content specifically mentions impacts in healthcare, emergency services, manufacturing, financial services, government and court systems, and other business sectors. Named or claimed victims/incidents in the content include Synnovis in the UK healthcare sector; Court Services Victoria; Asahi in Japan; Inotiv; Mindpath College Health in the United States; Hikari Seiko in Japan; Yanfeng Automotive Interiors; and a U.S. financial advisory firm. The content also notes links between Qilin-enabled activity and the Fox Tempest malware-signing service, and states that Scattered Spider/Octo Tempest added Qilin to its ransomware toolkit in 2024 and has partnered with Qilin in some operations. Known aliases and related names in the content include Agenda, Qilin Gang, Qilin Ransomware, Qilin Ransomware Gang, Qilin Ransomware Group, Qirin, Gold Feather, and Water Galura.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

14 of 15 tactics54 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1598
Phishing for Information
TA0001
Initial Access
3 techniques
T1078×4
Valid Accounts
T1133×3
External Remote Services
T1566×4
Phishing
T1566.002
Spearphishing Link
T1566.004×2
Spearphishing Voice
TA0002
Execution
2 techniques
T1059
Command and Scripting Interpreter
T1059.001×2
PowerShell
T1574
Hijack Execution Flow
TA0003
Persistence
2 techniques
T1078×4
Valid Accounts
T1133×3
External Remote Services
TA0004
Privilege Escalation
3 techniques
T1068
Exploitation for Privilege Escalation
T1078×4
Valid Accounts
T1484
Domain or Tenant Policy Modification
T1484.001
Group Policy Modification
TA0005
Stealth
8 techniques
T1027
Obfuscated Files or Information
T1036
Masquerading
T1070
Indicator Removal
T1070.001
Clear Windows Event Logs
T1070.004
File Deletion
T1078×4
Valid Accounts
T1211
Exploitation for Stealth
T1497
Virtualization/Sandbox Evasion
T1574
Hijack Execution Flow
T1622
Debugger Evasion
TA0112
Defense Impairment
2 techniques
T1484
Domain or Tenant Policy Modification
T1484.001
Group Policy Modification
T1553
Subvert Trust Controls
T1553.002
Code Signing
TA0006
Credential Access
1 technique
T1555
Credentials from Password Stores
TA0007
Discovery
4 techniques
T1018
Remote System Discovery
T1497
Virtualization/Sandbox Evasion
T1580
Cloud Infrastructure Discovery
T1622
Debugger Evasion
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.001×2
Remote Desktop Protocol
TA0009
Collection
1 technique
T1074
Data Staged
TA0011
Command and Control
4 techniques
T1071
Application Layer Protocol
T1090
Proxy
T1105
Ingress Tool Transfer
T1572
Protocol Tunneling
TA0010
Exfiltration
4 techniques
T1041×4
Exfiltration Over C2 Channel
T1048×2
Exfiltration Over Alternative Protocol
T1537×2
Transfer Data to Cloud Account
T1567×5
Exfiltration Over Web Service
TA0040
Impact
8 techniques
T1486×29
Data Encrypted for Impact
T1489×2
Service Stop
T1490×2
Inhibit System Recovery
T1491
Defacement
T1491.001
Internal Defacement
T1499
Endpoint Denial of Service
T1529
System Shutdown/Reboot
T1531
Account Access Removal
T1657×6
Financial Theft
IOCS

Observables

15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping44

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs3

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables15

Domains, IPs, and hashes tied to this actor, refreshed continuously.