Qilin is a prolific ransomware-as-a-service operation, also known as Agenda, Gold Feather, Water Galura, Qiling, and Qirin. The operation is widely characterized as Russian-based or Russian-speaking and uses an affiliate model; the former affiliate ArmCorp reportedly split from Qilin after disputes over ransom-payment handling, later contributing to the formation of The Gentlemen ransomware operation. Qilin conducts financially motivated ransomware and extortion operations against organizations worldwide, including government entities, energy and utilities providers, health care organizations, manufacturers, retailers, and professional-services firms. It operates a public data-leak site to pressure victims and has claimed responsibility for breaches involving theft and threatened publication of sensitive data. Qilin claimed responsibility for an intrusion at the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives; the agency confirmed an incident affecting a standalone system containing investigative information, although it did not publicly attribute the intrusion to Qilin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
10 CVEs this actor has used in observed campaigns. 10 of them exploited in the wild.
Check Point has linked zero-day exploitation of CVE-2026-50751 to the Qilin ransomware group. The critical vulnerability affects Check Point Remote Access VPN and Mobile Access. Attackers began exploiting the flaw as a zero-day on May 7, with activity spiking sharply in early June. While several dozen organizations have been targeted, at least one incident has been definitively tied to Qilin.
Qilin (aka Agenda and Phantom Mantis) ransomware operators have launched a coordinated intrusion campaign targeting several organizations between May and June 2025 by weaponizing Fortinet FortiGate vulnerabilities (e.g., CVE-2024-21762 and CVE-2024-55591) for initial access.
Qilin (aka Agenda and Phantom Mantis) ransomware operators have launched a coordinated intrusion campaign targeting several organizations between May and June 2025 by weaponizing Fortinet FortiGate vulnerabilities (e.g., CVE-2024-21762 and CVE-2024-55591) for initial access.
Attackers exploited a command injection vulnerability in LiteLLM's MCP server test endpoints. The configured command is passed directly to subprocess execution without validation, enabling a malicious MCP configuration to download and launch a cryptominer while returning a valid MCP handshake.
CVE-2026-42271 can be chained with a Starlette host header validation bypass, CVE-2026-48710, to achieve fully unauthenticated remote code execution. External researchers linked the Qilin ransomware group to active exploitation of this chain.
5 more CVEs tied to this actor tracked in Mallory.
120 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as one of several ransomware families tied to Woodgnat/KongTuke.
Conducted a ransomware attack against Grayson Rural Electric Cooperative, a U.S. energy and utilities organization.
Conducted a ransomware and data-extortion attack against the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). After ransom negotiations failed, it published 6.3 GB of allegedly stolen sensitive agency data.
Most active ransomware group in the week ending 30 August 2026, with 44 claimed victims, a roughly 26% increase from 35 claims in the prior week.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.