Qiulong is a ransomware extortion group known for aggressive psychological pressure and public shaming tactics on its leak site. The group has been observed publishing the identities and contact details of CEOs and business owners, often accompanied by insults and accusations of negligence, in order to intensify reputational and personal pressure on victim organizations. It has also targeted secondary victims connected to executives, including exposing highly sensitive personal information relating to family members. These behaviors indicate an extortion model that goes beyond conventional data-leak threats and seeks to coerce payment through harassment, humiliation, and fear. Qiulong’s activity is consistent with modern ransomware operations that combine data theft with leak-site pressure tactics. Its observed conduct shows a willingness to publicize stolen sensitive information and to weaponize that exposure against both organizations and individuals associated with them. The group’s operations therefore align with data-theft-driven extortion and victim harassment, even where encryption behavior is not directly established in the available facts. No high-confidence attribution to a specific state or country is established in the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.