ZeroHour

qilin

ransomware group · aka Qilin, Agenda, Water Galura (Microsoft designation) · Unknown; vendors believe the operation is Russian-speaking, though this is unconfirmed · active since Mid-2022 (initially tracked as Agenda; the Qilin branding emerged in 2023)

Victims · 7d
25▲11 vs prev. week
Victims · 30d
119active targets
Victims · 90d
360
All-time (tracked)
2.3Ksince 2022-10-08
Last post
09-17 23:46UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Qilin is a ransomware-as-a-service and data-extortion group first observed in mid-2022 and initially tracked as Agenda, with the Qilin name appearing in 2023. It operates a double-extortion model, encrypting systems and publishing stolen data from non-paying victims, and targets organizations across a broad range of sectors and geographies, including critical infrastructure. Publicly reported incidents include optical manufacturer Hoya (2023), Toyota Financial Services (2023), Nissan's Australian dealer association via a third-party compromise (2023), US newspaper publisher Lee Enterprises (2025), and a 2023 supply-chain intrusion through a Yamaha motorcycle dealer affecting Philippine customers. The group has exploited vulnerable public-facing software such as Zimbra and Cisco IOS XE, and uses both Windows and Linux/ESXi encryptors. Vendor tracking consistently ranked Qilin among the most active ransomware brands through 2024-2025, and it remains active as of late 2025.

Tactics & tooling
  • RaaS affiliate operation with double extortion; victim data posted to a leak site if no ransom is paid
  • Initial access via stolen VPN/RDP credentials, frequently in environments lacking MFA, per incident reporting
  • Exploitation of unpatched public-facing services, including Zimbra and Cisco IOS XE
  • BYOVD technique using vulnerable drivers to disable or evade security tooling, per Sophos incident analysis
  • Metasploit/Meterpreter stager (TinyMet) used for tool delivery and privilege escalation
  • Go- and later Rust-based Windows encryptors, with separate Linux/ESXi builds used in some attacks
  • Supply-chain access through compromised service providers, dealers, or third-party platforms
  • Published affiliate rules and 'legal agreements' governing affiliate conduct, per 2024-2025 reporting
Targeted sectors
manufacturingautomotivefinancial servicesIT serviceslegalmedia and publishinghealthcareeducation
Notable public victims

Hoya Corporation (2023), Toyota Financial Services (2023), Nissan Dealer Association Australia (2023, via third-party compromise), Yamaha Motor Philippines customers (2023, via dealer supply-chain intrusion), Synoptek (2025), Lee Enterprises (2025), Philippine Ports Authority, Jouvet SAS, G&S Technologies, Colonial Hyundai

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Zecher · Nov 25, 2025Business Services
Blue Projects · Nov 25, 2025Commercial & Residential Construction
HYTORC · Nov 24, 2025Industrial Machinery & Equipment
NovAtel (belongs to Hexagon) · Nov 24, 2025Electronics
Maheu&Maheu · Nov 23, 2025Business Services
Cal-Comp Electronics Public · Nov 23, 2025Electronics
Cayuga Milk Ingredients · Nov 23, 2025Grocery Retail
The Hunnicutt Law Group · Nov 23, 2025Law Firms & Legal Services
Berts Electric · Nov 23, 2025Commercial & Residential Construction
Capp Shupak · Nov 23, 2025Law Firms & Legal Services
Nissan Capital · Nov 23, 2025Business Services
Mmlk · Nov 22, 2025Law Firms & Legal Services
Interlink Trade Services · Nov 22, 2025Banking
Kajima Europe · Nov 22, 2025Civil Engineering Construction
Alma Realty · Nov 21, 2025Real Estate
XOX Mobile · Nov 21, 2025Electronics
Sakol Energy Public · Nov 20, 2025Electricity, Oil & Gas
Mae Krathing Power Company · Nov 20, 2025Electricity, Oil & Gas
N15 Technology · Nov 20, 2025Energy, Utilities & Waste
Cimertex · Nov 20, 2025Banking
Fayette County · Nov 20, 2025Government
IGT · Nov 20, 2025Gambling & Gaming
Marine Foods Express LTD · Nov 19, 2025Food & Beverage
Spark Innovation · Nov 18, 2025Business Services
Regional Business Systems · Nov 18, 2025Business Services
Kensington Court · Nov 18, 2025Government
QuaLex Manufacturing · Nov 18, 2025Industrial Machinery & Equipment
Kdr Real Estate Services · Nov 17, 2025Real Estate
Maresa Logística · Nov 16, 2025Business Services
SES Société Energies Services · Nov 15, 2025Energy, Utilities & Waste
FREEDL GROUP s.r.l. · Nov 15, 2025Grocery Retail
Spark Power · Nov 15, 2025Business Services
Sol Trading · Nov 14, 2025Grocery Retail
Trigg Laboratories · Nov 14, 2025Business Services
Viabizzuno · Nov 13, 2025Business Services
Muskoka Brewery · Nov 13, 2025Manufacturing
Fundidora de Cananea, S.A · Nov 13, 2025Business Services
Cornerstone Staffing Solutions · Nov 13, 2025Business Services
Brian-Kyles Construction · Nov 11, 2025Commercial & Residential Construction
Yaesu · Nov 10, 2025Manufacturing
OMS · Nov 10, 2025Manufacturing
Mciver Engineering & Controls · Nov 10, 2025Industrial Machinery & Equipment
Gullco International · Nov 9, 2025Consumer Services
Hitzinger · Nov 9, 2025Industrial Machinery & Equipment
JC Auto Accident Law Firm · Nov 8, 2025Law Firms & Legal Services
Gadge USA · Nov 8, 2025Manufacturing
SHRM New Mexico · Nov 8, 2025Non-Profit & Charitable Organizations
Scouts Canada · Nov 8, 2025Membership Organizations
Advanced Delivery Services · Nov 8, 2025Freight & Logistics Services
Wasserverband Wulkatal · Nov 8, 2025Hospitality

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .