Qilin is a financially motivated ransomware and extortion operation best known as a ransomware-as-a-service group active by at least 2024 and prominent through 2026. It is widely associated with the Agenda ransomware lineage and is also tracked under aliases including Agenda, Qilin Gang, Qilin Group, Qirin, Qiling, Gold Feather, and Water Galura. The operation has been one of the most active leak-site ransomware brands in 2026, with reporting indicating it led public victim disclosures for multiple consecutive quarters. Qilin conducts double-extortion operations, combining data theft with encryption and public shaming on a leak site to pressure victims into payment. Victimology is broad rather than sector-specific, with organizations across manufacturing, healthcare, education, technology, business services, consumer services, hospitality, agriculture, and other industries affected. Reported victims span multiple regions, including North America, Europe, and Latin America, indicating an opportunistic global targeting model focused on revenue generation rather than a narrow geopolitical mission. The group is associated with modern ransomware tradecraft and has been linked to Rust-based malware development, reflecting a broader trend among ransomware operators toward cross-platform, harder-to-analyze tooling. Qilin has also been reported exploiting edge-device vulnerabilities for initial access, including use of a Check Point Security Gateway IKEv1 authentication bypass as a zero-day in 2026. As with other mature ransomware programs, likely intrusion activity includes credential abuse, exploitation of internet-facing systems, lateral movement, privilege escalation, data exfiltration, and rapid enterprise-wide deployment of encryptors once sufficient access is obtained. Operationally, Qilin appears to function as a criminal service ecosystem with affiliates or partner operators conducting intrusions under a common brand. Public reporting and victim disclosures indicate sustained tempo, broad affiliate reach, and a mature extortion model centered on leak-site publication and negotiation pressure. No credible evidence in the available information supports attribution to a nation state; Qilin is best characterized as a cybercriminal ransomware enterprise.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
CVE-2026-50751 (Check Point Security Gateway) : bypass d’authentification IKEv1, exploité par Qilin en zero-day depuis le 7 mai 2026
Qilin (aka Agenda and Phantom Mantis) ransomware operators have launched a coordinated intrusion campaign targeting several organizations between May and June 2025 by weaponizing Fortinet FortiGate vulnerabilities (e.g., CVE-2024-21762 and CVE-2024-55591) for initial access.
Qilin (aka Agenda and Phantom Mantis) ransomware operators have launched a coordinated intrusion campaign targeting several organizations between May and June 2025 by weaponizing Fortinet FortiGate vulnerabilities (e.g., CVE-2024-21762 and CVE-2024-55591) for initial access.
Known Exploited Vulnerabilities: CVE-2023-27532 — Missing Authentication for Critical Function Vulnerability — Veeam Backup & Replication Cloud Connect — CVSS 7.5
CVE-2025-31324 (CVSS 10.0): A missing authorization check in the Visual Composer Metadata Uploader was actively exploited as a zero day by multiple threat actor groups, including Russian ransomware operators (BianLian, RansomEXX/Storm-2460), the Qilin ransomware as a service operation, and the China nexus APT group Earth Lamia.
1 more CVE tied to this actor tracked in Mallory.
62 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against Bolt & Nut Manufacturing, a manufacturing organization in Great Britain.
Mentioned only as another ransomware operator using Rust.
Conducting a ransomware attack against Synergy Products.
Conducting a ransomware attack against Eana.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.