Qilin ransomware has emerged as one of the most active cybercrime threats, with NCC Group identifying it as the most prolific ransomware group for the fifth consecutive quarter as global ransomware incidents climbed to 2,229 in Q2 2026. The group, also tracked as Agenda or Qilin Locker, operates a double-extortion RaaS model and has concentrated on high-GDP Western countries while reportedly avoiding CIS member states. Manufacturing and other industrial sectors have been hit hardest, alongside business services, technology, healthcare, and finance, with North America remaining the most affected region and Belgium reporting at least 15 alleged Qilin compromises that disrupted operations and exposed sensitive corporate data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
The Centre for Cybersecurity Belgium published a threat intelligence report on Qilin ransomware, describing it as a significant and evolving threat and stating that 15 Belgian organizations had allegedly been compromised.
NCC Group highlighted a sharp rise in software supply chain attacks in 2026 affecting ecosystems including GitHub Actions, npm, PyPI, Docker Hub, Open VSX, and the Visual Studio Code Marketplace. It linked TeamPCP to major activity including the Mini Shai-Hulud worm and derivative campaigns Miasma and Hades.
NCC Group said 665 ransomware attacks were recorded in June alone as part of the broader Q2 2026 increase in global ransomware activity.
NCC Group reported that global ransomware incidents increased 3% in Q2 2026, rising from 2,165 in Q1 to 2,229 in Q2. The industrials sector was the most targeted and North America remained the most affected region.
CSIRT.SK reported observed Qilin attacks in Slovakia affecting the energy sector and public administration, indicating the campaign had reached Slovak organizations.
CSIRT.SK described Qilin as one of the most active ransomware groups in 2025, with more than 40 successful attacks per month and over 700 documented attacks during the year.
The Centre for Cybersecurity Belgium reported that Qilin, also known as Agenda or Qilin Locker, emerged in 2022 as a double-extortion ransomware-as-a-service operation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
itsecurityguru.org
Open sourceccb.belgium.be
Open sourcecsirt.sk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.