ZeroHour

qilin

ransomware group · aka Qilin, Agenda, Water Galura (Microsoft designation) · Unknown; vendors believe the operation is Russian-speaking, though this is unconfirmed · active since Mid-2022 (initially tracked as Agenda; the Qilin branding emerged in 2023)

Victims · 7d
18▲2 vs prev. week
Victims · 30d
117active targets
Victims · 90d
359
All-time (tracked)
2.2Ksince 2022-10-08
Last post
09-15 16:47UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Qilin is a ransomware-as-a-service and data-extortion group first observed in mid-2022 and initially tracked as Agenda, with the Qilin name appearing in 2023. It operates a double-extortion model, encrypting systems and publishing stolen data from non-paying victims, and targets organizations across a broad range of sectors and geographies, including critical infrastructure. Publicly reported incidents include optical manufacturer Hoya (2023), Toyota Financial Services (2023), Nissan's Australian dealer association via a third-party compromise (2023), US newspaper publisher Lee Enterprises (2025), and a 2023 supply-chain intrusion through a Yamaha motorcycle dealer affecting Philippine customers. The group has exploited vulnerable public-facing software such as Zimbra and Cisco IOS XE, and uses both Windows and Linux/ESXi encryptors. Vendor tracking consistently ranked Qilin among the most active ransomware brands through 2024-2025, and it remains active as of late 2025.

Tactics & tooling
  • RaaS affiliate operation with double extortion; victim data posted to a leak site if no ransom is paid
  • Initial access via stolen VPN/RDP credentials, frequently in environments lacking MFA, per incident reporting
  • Exploitation of unpatched public-facing services, including Zimbra and Cisco IOS XE
  • BYOVD technique using vulnerable drivers to disable or evade security tooling, per Sophos incident analysis
  • Metasploit/Meterpreter stager (TinyMet) used for tool delivery and privilege escalation
  • Go- and later Rust-based Windows encryptors, with separate Linux/ESXi builds used in some attacks
  • Supply-chain access through compromised service providers, dealers, or third-party platforms
  • Published affiliate rules and 'legal agreements' governing affiliate conduct, per 2024-2025 reporting
Targeted sectors
manufacturingautomotivefinancial servicesIT serviceslegalmedia and publishinghealthcareeducation
Notable public victims

Hoya Corporation (2023), Toyota Financial Services (2023), Nissan Dealer Association Australia (2023, via third-party compromise), Yamaha Motor Philippines customers (2023, via dealer supply-chain intrusion), Synoptek (2025), Lee Enterprises (2025), Philippine Ports Authority, Jouvet SAS, G&S Technologies, Colonial Hyundai

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Montana Civil Contractors · 4h agoCivil Engineering Construction
Taurus Ibérica · 4h agoReal Estate
ADM · 6h agoFood & Beverage
Resolve Law Group · 6h agoLaw Firms & Legal Services
Incrys · 8h agoBusiness Services
Bravo Group · 8h agoFreight & Logistics Services
Geieg · 14h agoFitness & Dance Facilities
RoadEx America · 1d agoFreight & Logistics Services
Foremost Mfg · 1d agoBuilding Materials
Winston Contracting, LLC · 1d agoBusiness Services
Minmer Global · 1d agoFreight & Logistics Services
Vitar Group · 1d agoElectronics
Alicotrans · 1d agoFreight & Logistics Services
Gilco Scaffolding · 2d agoConstruction
CARIDRO VAL DE LOIRE · 2d agoBusiness Services
Imperial Healthcare Solutions · 3d agoHealthcare Services
Mitsuwa Trading Co., Ltd · 5d agoBusiness Services
Jet Specialty · 6d agoIndustrial Machinery & Equipment
Alaska Electrical Apprenticeship · 7d agoEducation
Partners Group SK · 7d agoFinance
Jbc · 8d agoHand, Power & Lawn-care Tools
Philippine Ports Authority · 10d agoBusiness Services
Bauman Law Group · 10d agoLaw Firms & Legal Services
Jouvet SAS · 10d agoConstruction
G&S Technologies · 10d agoEnergy, Utilities & Waste
Nolan Consulting Group · 10d agoBusiness Services
Colonial Hyundai · 10d agoAutomotive Parts
The Big Table · 10d agoHospitality
AP CAPITAL PARTNERS LIMITED · 11d agoBusiness Services
Commission de la construction du Quebec (CCQ) · 11d agoGovernment
Complete Packaging Solutions · 12d agoBusiness Services
Tanner · 12d agoFinance
Uak University · 13d agoEducation
Grayson Rural Electric Cooperative · 13d agoElectricity, Oil & Gas
Commission de la construction du Quebec · 14d agoGovernment
Inmac · 14d agoArchitecture, Engineering & Design
Allied Recycling · 15d agoEnergy, Utilities & Waste
AFSARD · 16d agoFinance
Crystalpharmatech · 16d agoBusiness Services
Absolute Consultancy Services · 16d agoBusiness Services
Black Cat Engineering Construction Wll · 16d agoCivil Engineering Construction
Bandit Industries · 16d agoAccounting Services
LAPoco Architects · 17d agoArchitecture, Engineering & Design
Neumaticos Corral S.A. · 17d agoAutomotive Parts
AUM Construction · 17d agoElectricity, Oil & Gas
The Frame Group · 17d agoBusiness Services
La Maison Des Travaux · 17d agoBusiness Services
BLISS 1041 · 17d agoAccounting Services
CareClinics · 17d ago0
Alter Consultores Legales · 17d agoLaw Firms & Legal Services

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .