CARDS
CARDS
Qilin is a financially motivated ransomware-as-a-service (RaaS) operation that first emerged in June 2022 under the name "Agenda" and rebranded to "Qilin" by September 2022. The group shifted to a RaaS model in February 2023, offering its tools and infrastructure to affiliates. Qilin is assessed with moderate confidence to be of Russian or Eastern European origin, indicated by its policy of avoiding targets in Commonwealth of Independent States (CIS) countries and use of Russian-language forums for affiliate recruitment. Its primary motivation is financial gain through double extortion, involving both data encryption and exfiltration. What sets Qilin apart is its cross-platform capability, utilizing ransomware variants written in both Golang and Rust to target Windows, Linux, and VMware ESXi systems, along with a highly customizable approach that allows affiliates to tailor attacks, encryption methods, and evasion techniques to specific victims. The group's notable growth and activity in 2025 and 2026 have positioned it as one of the most prolific RaaS groups.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Identity
Aliases1
Source Boundary
SOCRadar is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Associated Activity1
ATT&CK IDs1
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| qilin Ransomware / Extortion Operations6 | qilin Ransomware / Extortion Operations is retained in the campaign database for qilin. Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data. |
Indicators
SOCRadar reports 2895 IOCs for this profile. IntelliOS currently retains 37 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 4 source groups tracked; 3 currently contribute retained observable or context rows.
Retained Observables
Showing 37 of 37
| Type | Value | Source |
|---|---|---|
| SHA-256 Hash | 0b9b0715a1ffb427a02e61ae8fd11c00b5d086eb76102d4b12634e57285c1aba3 | SophosLabs IoCs |
| SHA-256 Hash | 12fcde06ddadf1b48a61b12596e6286316fd33e850687fe4153dfd9383f0a4a04 | Cisco Talos |
| SHA-256 Hash | 16f83f056177c4ec24c7e99d01ca9d9d6713bd0497eeedb777a3ffefa99c97f04 | Cisco Talos |
| SHA-256 Hash | 45c8716c69f56e26c98369e626e0b47d7ea5e15d3fb3d97f0d5b6e8997299d1a3 | SophosLabs IoCs |
| SHA-256 Hash | 7787da25451f5538766240f4a8a2846d0a589c59391e15f188aa077e8b8884974 | Cisco Talos |
| SHA-256 Hash | 9da70c521b929725774c3980763a4aed9baf9de4e6f83fc8f668c3a365a55f823 | SophosLabs IoCs |
| SHA-256 Hash | b52917b0658cd2a9197e6bb62bade243ee1ad164f2bb566f3a1e09dfa580397f3 | SophosLabs IoCs |
| SHA-256 Hash | bd1f381e5a3db22e88776b7873d4d2835e9a1ec620571d2b1da0c58f81c84a564 | Cisco Talos |
| SHA-256 Hash | ef3e42e5fa24acaee2428ff0118feb2be925bfe6b1ea4eccce8b70a7ac5ab2cc3 | SophosLabs IoCs |
| SHA-256 Hash | fdf6b0560385a6445bd399eba03c8662be9e61928d6cbc268d550163a5a092853 | SophosLabs IoCs |
| SHA-1 Hash | 01d00d3dd8bc8fd92dae9e04d0f076cb3158dc9c4 | Cisco Talos |
| SHA-1 Hash | 82ed942a52cdcf120a8919730e00ba37619661a34 | Cisco Talos |
| SHA-1 Hash | 84e2d2084fe08262c2c378a377963a1482b35ac54 | Cisco Talos |
| SHA-1 Hash | ce1b9909cef820e5281618a7a0099a27a70643dc4 | Cisco Talos |
| MD5 Hash | 1305e8b0f9c459d5ed85e7e474fbebb14 | Cisco Talos |
| MD5 Hash | 6bc8e3505d9f51368ddf323acb6abc494 | Cisco Talos |
| MD5 Hash | 89ee7235906f7d12737679860264feaf4 | Cisco Talos |
| MD5 Hash | cf7cad39407d8cd93135be42b6bd258f4 | Cisco Talos |
| Import Hash | 05aa031a007e2f51e3f48ae2ed1e1fcb4 | Cisco Talos |
| TLSH | T1B4647C01B7E50CF9EE77C638C9614A06EA72BC425761DADF43A04A964F237D09E3DB124 | Cisco Talos |
| Filename | EDRKiller.exe4 | Cisco Talos |
| Filename | hlpdrv.sys4 | Cisco Talos |
| Filename | msimg32.dll4 | Cisco Talos |
| Filename | rwdrv.sys4 | Cisco Talos |
| File Path | C:\programdata\veeam.exe3 | SophosLabs IoCs |
| File Path | C:\README-RECOVER-<victim ID> .txt3 | SophosLabs IoCs |
| File Path | C:\Users\<username>\Documents\<MSPname>.exe3 | SophosLabs IoCs |
| File Path | C:\Windows\SystemTemp\ScreenConnect\24.3.7.9067\ru.msi3 | SophosLabs IoCs |
| Network Indicator | cloud.screenconnect.com.ms3 | SophosLabs IoCs |
| Network Indicator | hxxps[:]//b8dymnk3.r.us-east-1.awstrack[.]me/L0/https[:]%2F%2Fcloud.screenconnect[.]com.ms%2FsuKcHZYV/1/010001948f5ca748-c4d2fc4f-aa9e-40d4-afe9-bbe0036bc608-000000/mWU0NBS5qVoIVdXUd4HdKWrsBSI=4103 | SophosLabs IoCs |
| Network Indicator | hxxps[:]//cloud.screenconnect[.]com.ms/suKcHZYV/1/010001948f5ca748-c4d2fc4f-aa9e-40d4-afe9-bbe0036bc608-000000/mWU0NBS5qVoIVdXUd4HdKWrsBSI=4103 | SophosLabs IoCs |
| Network Indicator | 109.107.173.603 | SophosLabs IoCs |
| Network Indicator | 109.70.100.13 | SophosLabs IoCs |
| Network Indicator | 128.127.180.1563 | SophosLabs IoCs |
| Network Indicator | 186.2.163.103 | SophosLabs IoCs |
| Network Indicator | 92.119.159.303 | SophosLabs IoCs |
| Campaign Context | Thin Qilin row backfilled from the same SophosLabs, Cisco Talos, and SentinelOne source set as the SOCRadar Qilin card; IntelliOS retains duplicate-card boundaries for reader interpretation.5 | SentinelOne |
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar2 | 2895 | 0 | Reported IOC count retained; underlying SOCRadar feed values are not republished unless stored as cited public observables. |
| SentinelOne5 | N/A | 1 | Public filenames, paths, tool, or infrastructure observables retained and displayed. |
| SophosLabs3 | N/A | 18 | Public observables or source-context rows retained and displayed. |
| Cisco Talos4 | N/A | 18 | Public observables or source-context rows retained and displayed. |
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Qilin | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Qilin | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Baseline actor-card corpus source for retained profile fields. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/qilin | Per-actor SOCRadar profile source for ransomware profile metadata and IOC count when available. |
| 3 | SophosLabs IoCs: Ransomware-Qilin-STAC4365 https://raw.githubusercontent.com/sophoslabs/IoCs/master/Ransomware-Qilin-STAC4365.csv | IOC Source |
| 4 | Cisco Talos: Qilin EDR killer infection chain https://blog.talosintelligence.com/qilin-edr-killer/ | IOC Source |
| 5 | SentinelOne: Agenda/Qilin ransomware profile https://www.sentinelone.com/anthology/agenda-qilin/ | Threat Actor Profile |
| 6 | qilin - Ransomware.live group profile https://www.ransomware.live/group/qilin | Ransomware.live campaign row source for qilin Ransomware / Extortion Operations. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Qilin.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |