Arkana is a ransomware and data-extortion threat actor that emerged in March 2024 and has been publicly associated with the broader Qilin ransomware ecosystem. Reporting in 2024 and 2025 places Arkana among newer ransomware brands that claimed multiple high-profile victims, including large multinational enterprises, and indicates a focus on high-value global brands in the entertainment sector. Arkana has also been linked to victims in telecommunications, mining, and information technology. Multiple sources indicate a relationship between Arkana and Qilin, a Russian-speaking ransomware-as-a-service operation also known as Agenda or AgendaCrypt. Arkana has been identified as a reported Qilin affiliate, and its data extortion infrastructure in 2025 displayed Qilin branding, suggesting operational alignment or affiliate status within the Qilin network. Based on that association, Arkana is best understood as part of the affiliate-driven ransomware ecosystem surrounding Qilin rather than as a fully independent, well-profiled intrusion set. Available reporting supports Arkana’s involvement in extortion operations centered on victim shaming and publication pressure via a data extortion site. Publicly attributed activity indicates targeting of prominent commercial organizations to maximize leverage and reputational impact. However, detailed public technical reporting on Arkana’s standalone intrusion tradecraft, malware lineage, initial access methods, persistence mechanisms, lateral movement, or post-compromise tooling remains limited. High-confidence assessment therefore supports characterizing Arkana primarily as a financially motivated ransomware or extortion actor operating in association with the Qilin affiliate network.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reported Qilin affiliate named in the affiliate roster.
Named as a new ransomware variant/gang emerging in 2024 and associated with victim claims posted in March 2024.
Ransomware actor targeting high-value global entertainment brands to maximize leverage and reputational damage.
Ransomware actor listed as active in Q1 2025 targeting industrial sectors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.