WikiLeaksV2 is a data-leak and extortion brand associated with the Qilin ransomware ecosystem. It has been linked to Qilin through overlap in published victims and cross-promotion between Qilin leak postings and the WikiLeaksV2 leak page. Qilin, also known as Agenda, is a ransomware-as-a-service operation first observed in 2022 that conducts double extortion by combining file encryption with theft of victim data and threats to publish stolen information. Through this association, WikiLeaksV2 is tied to a criminal extortion model centered on leak-site publication and ransomware affiliate activity. Qilin operations have targeted both Windows and Linux environments and have used malware variants written in Golang and Rust. Reported intrusion methods used by the broader Qilin ecosystem include phishing with malicious attachments, use of valid or stolen credentials, exploitation of public-facing vulnerabilities, and abuse of external remote services. Post-compromise activity has included credential harvesting, modification of domain policy to deploy logon scripts, termination of security-related services, event log clearing, self-deletion, DLL sideloading, and use of tools intended to disable endpoint defenses, including BYOVD-style tradecraft. Qilin is widely characterized as a financially motivated ransomware-as-a-service program with affiliates and a leak-site component, and WikiLeaksV2 appears to function as part of that extortion and publicity infrastructure rather than as a distinct nation-state intrusion set. The most directly supported relationship is operational alignment with Qilin via victim overlap and cross-promotion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.