Qilin is a Russian-speaking ransomware-as-a-service operation also tracked under aliases including Agenda, Gold Feather, Water Galura, Qirin, and Qiling. The operation uses an affiliate model in which operators lease ransomware tooling to partners in exchange for a share of ransom payments. Qilin has been one of the most active ransomware threats in Europe and the United Kingdom, and has also heavily targeted organizations in North America. Qilin is known for double-extortion operations that combine data theft with encryption and subsequent pressure via a leak site. Victims have been publicly named on the group’s data leak infrastructure, and the operation has repeatedly been associated with data-breach activity in addition to disruptive ransomware deployment. Reported victimology spans construction, manufacturing, professional services, healthcare, financial services, technology, education, energy and utilities, and other small and mid-sized enterprises. The group has been linked to the 2024 attack on Synnovis, which disrupted NHS services in the United Kingdom, and later disclosures tied that incident to large-scale patient-data exfiltration. In 2026, Qilin was assessed as the most active ransomware group in Europe during the first half of the year and the leading ransomware actor affecting UK organizations by number of published victims. Observed tradecraft includes initial access through exploitation of internet-facing systems and VPN gateways, including abuse of known vulnerabilities and, in at least one reported case, claimed zero-day exploitation. Qilin has also been associated with the use of stolen credentials as an intrusion vector. For defense evasion, the group has been reported to use BYOVD techniques to disable or bypass endpoint security controls such as EDR and antivirus. Its operations reflect a mature affiliate-driven intrusion lifecycle with rapid exploit weaponization, data exfiltration, encryption, and public extortion through leak-site publication.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
특히 이번 분기 Qilin 제휴조직(affiliate)은 Check Point VPN 제로데이 취약점(CVE-2026-50751)을 초기 침투 경로로 악용한 정황이 확인되었습니다. 이 취약점은 CVSS 9.3의 인증 우회 결함으로, 5월 7일부터 패치 이전까지 약 한 달간 실제 공격에 악용되었으며 미국 CISA는 이를 긴급 조치 대상(KEV)으로 등재했습니다.
Qilin (aka Agenda and Phantom Mantis) ransomware operators have launched a coordinated intrusion campaign targeting several organizations between May and June 2025 by weaponizing Fortinet FortiGate vulnerabilities (e.g., CVE-2024-21762 and CVE-2024-55591) for initial access.
Qilin (aka Agenda and Phantom Mantis) ransomware operators have launched a coordinated intrusion campaign targeting several organizations between May and June 2025 by weaponizing Fortinet FortiGate vulnerabilities (e.g., CVE-2024-21762 and CVE-2024-55591) for initial access.
Known Exploited Vulnerabilities: CVE-2023-27532 — Missing Authentication for Critical Function Vulnerability — Veeam Backup & Replication Cloud Connect — CVSS 7.5
CVE-2025-31324 (CVSS 10.0): A missing authorization check in the Visual Composer Metadata Uploader was actively exploited as a zero day by multiple threat actor groups, including Russian ransomware operators (BianLian, RansomEXX/Storm-2460), the Qilin ransomware as a service operation, and the China nexus APT group Earth Lamia.
3 more CVEs tied to this actor tracked in Mallory.
112 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prolific ransomware operation that claimed 125 victims in July and was identified as behind the 2024 Synnovis attack that disrupted NHS services in the UK.
Conducting a ransomware attack against Depona, a technology-sector organization in Sweden.
Conducting a ransomware attack against Nikan Awasisak Agency.
Conducting a ransomware attack against EISNER ZT GMBH.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.