01
Qilin, formerly Agenda, is a mature Ransomware-as-a-Service operation.1
The operators supply adaptable ransomware and infrastructure while affiliates conduct intrusions, so access methods and dwell behavior can vary across incidents.
CARDS
Qilin is a financially motivated ransomware-as-a-service (RaaS) operation that first emerged in June 2022 under the name "Agenda" and rebranded to "Qilin" by September 2022. The group shifted to a RaaS model in February 2023, offering its tools and infrastructure to affiliates. Qilin is assessed with moderate confidence to be of Russian or Eastern European origin, indicated by its policy of avoiding targets in Commonwealth of Independent States (CIS) countries and use of Russian-language forums for affiliate recruitment. Its primary motivation is financial gain through double extortion, involving both data encryption and exfiltration. What sets Qilin apart is its cross-platform capability, utilizing ransomware variants written in both Golang and Rust to target Windows, Linux, and VMware ESXi systems, along with a highly customizable approach that allows affiliates to tailor attacks, encryption methods, and evasion techniques to specific victims. The group's notable growth and activity in 2025 and 2026 have positioned it as one of the most prolific RaaS groups.
Directory Briefing
01
The operators supply adaptable ransomware and infrastructure while affiliates conduct intrusions, so access methods and dwell behavior can vary across incidents.
02
Affiliates steal sensitive information before encryption and use the threat of publication to preserve pressure even when a victim can restore systems.
03
The retained record includes stolen credentials, phishing, exposed RDP and VPN services, and exploitation of Internet-facing appliances rather than dependence on one exploit path.
04
Qilin affiliates perform reconnaissance, steal credentials, move laterally, stage data, and prepare high-value systems before the ransomware payload becomes visible.
05
Cross-platform encryptors let affiliates concentrate impact on virtual infrastructure and server estates rather than limiting damage to Windows endpoints.
06
PowerShell, PsExec, SSH, RMM utilities, WinSCP, Splashtop, and archive tools can support execution, lateral movement, and staging with fewer obvious malware signals.
07
Documented behavior includes EDR impairment, vulnerable-driver abuse, service termination, and event-log clearing, which can reduce both prevention and forensic visibility.
08
Deletion of volume shadow copies and other recovery-inhibition behavior means domain-connected or mutable backups should not be assumed trustworthy after compromise.
09
The retained record spans Construction of Buildings, Food Manufacturing, Other Information Services, Software Publishers, and Real Estate, so no single sector defines the risk.
10
System restoration does not close notification, contractual, privilege, insurance, communications, or reputational questions created by exfiltration.
Bottom Line Up Front
The operators supply adaptable ransomware and infrastructure while affiliates conduct intrusions, so access methods and dwell behavior can vary across incidents.
Affiliates steal sensitive information before encryption and use the threat of publication to preserve pressure even when a victim can restore systems.
The retained record includes stolen credentials, phishing, exposed RDP and VPN services, and exploitation of Internet-facing appliances rather than dependence on one exploit path.
Qilin affiliates perform reconnaissance, steal credentials, move laterally, stage data, and prepare high-value systems before the ransomware payload becomes visible.
Cross-platform encryptors let affiliates concentrate impact on virtual infrastructure and server estates rather than limiting damage to Windows endpoints.
PowerShell, PsExec, SSH, RMM utilities, WinSCP, Splashtop, and archive tools can support execution, lateral movement, and staging with fewer obvious malware signals.
Documented behavior includes EDR impairment, vulnerable-driver abuse, service termination, and event-log clearing, which can reduce both prevention and forensic visibility.
Deletion of volume shadow copies and other recovery-inhibition behavior means domain-connected or mutable backups should not be assumed trustworthy after compromise.
The retained record spans Construction of Buildings, Food Manufacturing, Other Information Services, Software Publishers, and Real Estate, so no single sector defines the risk.
System restoration does not close notification, contractual, privilege, insurance, communications, or reputational questions created by exfiltration.
Decision Context
Qilin is a financially motivated ransomware-as-a-service (RaaS) operation that first emerged in June 2022 under the name "Agenda" and rebranded to "Qilin" by September 2022. The group shifted to a RaaS model in February 2023, offering its tools and infrastructure to affiliates. Qilin is assessed with moderate confidence to be of Russian or Eastern European origin, indicated by its policy of avoiding targets in Commonwealth of Independent States (CIS) countries and use of Russian-language forums for affiliate recruitment. Its primary motivation is financial gain through double extortion, involving both data encryption and exfiltration. What sets Qilin apart is its cross-platform capability, utilizing ransomware variants written in both Golang and Rust to target Windows, Linux, and VMware ESXi systems, along with a highly customizable approach that allows affiliates to tailor attacks, encryption methods, and evasion techniques to specific victims. The group's notable growth and activity in 2025 and 2026 have positioned it as one of the most prolific RaaS groups.1,2
Actor Card Detail
Victimology
No named victim organizations are retained in the cited source artifacts for this profile. Countries and sectors are targeting context, not victim identities.
Identity
Aliases1
Source Boundary
SOCRadar is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Target Countries / Exposure1,2
Associated Activity1
ATT&CK IDs1
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| qilin Ransomware / Extortion Operations6 | qilin Ransomware / Extortion Operations is retained in the campaign database for qilin. Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data. |
Indicators
SOCRadar reports 2895 IOCs for this profile. IntelliOS currently retains 37 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 4 source groups tracked; 3 currently contribute retained observable or context rows.
Retained Observables
Showing 37 of 37
| Type | Value | Source |
|---|---|---|
| SHA-256 Hash | 0b9b0715a1ffb427a02e61ae8fd11c00b5d086eb76102d4b12634e57285c1aba3 | SophosLabs IoCs |
| SHA-256 Hash | 12fcde06ddadf1b48a61b12596e6286316fd33e850687fe4153dfd9383f0a4a04 | Cisco Talos |
| SHA-256 Hash | 16f83f056177c4ec24c7e99d01ca9d9d6713bd0497eeedb777a3ffefa99c97f04 | Cisco Talos |
| SHA-256 Hash | 45c8716c69f56e26c98369e626e0b47d7ea5e15d3fb3d97f0d5b6e8997299d1a3 | SophosLabs IoCs |
| SHA-256 Hash | 7787da25451f5538766240f4a8a2846d0a589c59391e15f188aa077e8b8884974 | Cisco Talos |
| SHA-256 Hash | 9da70c521b929725774c3980763a4aed9baf9de4e6f83fc8f668c3a365a55f823 | SophosLabs IoCs |
| SHA-256 Hash | b52917b0658cd2a9197e6bb62bade243ee1ad164f2bb566f3a1e09dfa580397f3 | SophosLabs IoCs |
| SHA-256 Hash | bd1f381e5a3db22e88776b7873d4d2835e9a1ec620571d2b1da0c58f81c84a564 | Cisco Talos |
| SHA-256 Hash | ef3e42e5fa24acaee2428ff0118feb2be925bfe6b1ea4eccce8b70a7ac5ab2cc3 | SophosLabs IoCs |
| SHA-256 Hash | fdf6b0560385a6445bd399eba03c8662be9e61928d6cbc268d550163a5a092853 | SophosLabs IoCs |
| SHA-1 Hash | 01d00d3dd8bc8fd92dae9e04d0f076cb3158dc9c4 | Cisco Talos |
| SHA-1 Hash | 82ed942a52cdcf120a8919730e00ba37619661a34 | Cisco Talos |
| SHA-1 Hash | 84e2d2084fe08262c2c378a377963a1482b35ac54 | Cisco Talos |
| SHA-1 Hash | ce1b9909cef820e5281618a7a0099a27a70643dc4 | Cisco Talos |
| MD5 Hash | 1305e8b0f9c459d5ed85e7e474fbebb14 | Cisco Talos |
| MD5 Hash | 6bc8e3505d9f51368ddf323acb6abc494 | Cisco Talos |
| MD5 Hash | 89ee7235906f7d12737679860264feaf4 | Cisco Talos |
| MD5 Hash | cf7cad39407d8cd93135be42b6bd258f4 | Cisco Talos |
| Import Hash | 05aa031a007e2f51e3f48ae2ed1e1fcb4 | Cisco Talos |
| TLSH | T1B4647C01B7E50CF9EE77C638C9614A06EA72BC425761DADF43A04A964F237D09E3DB124 | Cisco Talos |
| Filename | EDRKiller.exe4 | Cisco Talos |
| Filename | hlpdrv.sys4 | Cisco Talos |
| Filename | msimg32.dll4 | Cisco Talos |
| Filename | rwdrv.sys4 | Cisco Talos |
| File Path | C:\programdata\veeam.exe3 | SophosLabs IoCs |
| File Path | C:\README-RECOVER-<victim ID> .txt3 | SophosLabs IoCs |
| File Path | C:\Users\<username>\Documents\<MSPname>.exe3 | SophosLabs IoCs |
| File Path | C:\Windows\SystemTemp\ScreenConnect\24.3.7.9067\ru.msi3 | SophosLabs IoCs |
| Network Indicator | cloud.screenconnect.com.ms3 | SophosLabs IoCs |
| Network Indicator | hxxps[:]//b8dymnk3.r.us-east-1.awstrack[.]me/L0/https[:]%2F%2Fcloud.screenconnect[.]com.ms%2FsuKcHZYV/1/010001948f5ca748-c4d2fc4f-aa9e-40d4-afe9-bbe0036bc608-000000/mWU0NBS5qVoIVdXUd4HdKWrsBSI=4103 | SophosLabs IoCs |
| Network Indicator | hxxps[:]//cloud.screenconnect[.]com.ms/suKcHZYV/1/010001948f5ca748-c4d2fc4f-aa9e-40d4-afe9-bbe0036bc608-000000/mWU0NBS5qVoIVdXUd4HdKWrsBSI=4103 | SophosLabs IoCs |
| Network Indicator | 109.107.173.603 | SophosLabs IoCs |
| Network Indicator | 109.70.100.13 | SophosLabs IoCs |
| Network Indicator | 128.127.180.1563 | SophosLabs IoCs |
| Network Indicator | 186.2.163.103 | SophosLabs IoCs |
| Network Indicator | 92.119.159.303 | SophosLabs IoCs |
| Campaign Context | Thin Qilin row backfilled from the same SophosLabs, Cisco Talos, and SentinelOne source set as the SOCRadar Qilin card; IntelliOS retains duplicate-card boundaries for reader interpretation.5 | SentinelOne |
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar2 | 2895 | 0 | Reported IOC count retained; underlying SOCRadar feed values are not republished unless stored as cited public observables. |
| SentinelOne5 | N/A | 1 | Public filenames, paths, tool, or infrastructure observables retained and displayed. |
| SophosLabs3 | N/A | 18 | Public observables or source-context rows retained and displayed. |
| Cisco Talos4 | N/A | 18 | Public observables or source-context rows retained and displayed. |
Actor Chronology
No source-backed actor-activity dates are currently retained. Publication and record-maintenance dates are not promoted into activity dates.
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Qilin | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Qilin | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Qilin.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Threat actor directory source for profile fields and reported activity. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/qilin | Actor-specific source for ransomware profile metadata and reported IOC counts when available. |
| 3 | SophosLabs IoCs: Ransomware-Qilin-STAC4365 https://raw.githubusercontent.com/sophoslabs/IoCs/master/Ransomware-Qilin-STAC4365.csv | IOC Source |
| 4 | Cisco Talos: Qilin EDR killer infection chain https://blog.talosintelligence.com/qilin-edr-killer/ | IOC Source |
| 5 | SentinelOne: Agenda/Qilin ransomware profile https://www.sentinelone.com/anthology/agenda-qilin/ | Threat Actor Profile |
| 6 | qilin - Ransomware.live group profile https://www.ransomware.live/group/qilin | Ransomware.live campaign row source for qilin Ransomware / Extortion Operations. |