ZeroHour

qilin

ransomware group · aka Qilin, Agenda, Water Galura (Microsoft designation) · Unknown; vendors believe the operation is Russian-speaking, though this is unconfirmed · active since Mid-2022 (initially tracked as Agenda; the Qilin branding emerged in 2023)

Victims · 7d
30▲18 vs prev. week
Victims · 30d
113active targets
Victims · 90d
364
All-time (tracked)
2.3Ksince 2022-10-08
Last post
09-18 13:53UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Qilin is a ransomware-as-a-service and data-extortion group first observed in mid-2022 and initially tracked as Agenda, with the Qilin name appearing in 2023. It operates a double-extortion model, encrypting systems and publishing stolen data from non-paying victims, and targets organizations across a broad range of sectors and geographies, including critical infrastructure. Publicly reported incidents include optical manufacturer Hoya (2023), Toyota Financial Services (2023), Nissan's Australian dealer association via a third-party compromise (2023), US newspaper publisher Lee Enterprises (2025), and a 2023 supply-chain intrusion through a Yamaha motorcycle dealer affecting Philippine customers. The group has exploited vulnerable public-facing software such as Zimbra and Cisco IOS XE, and uses both Windows and Linux/ESXi encryptors. Vendor tracking consistently ranked Qilin among the most active ransomware brands through 2024-2025, and it remains active as of late 2025.

Tactics & tooling
  • RaaS affiliate operation with double extortion; victim data posted to a leak site if no ransom is paid
  • Initial access via stolen VPN/RDP credentials, frequently in environments lacking MFA, per incident reporting
  • Exploitation of unpatched public-facing services, including Zimbra and Cisco IOS XE
  • BYOVD technique using vulnerable drivers to disable or evade security tooling, per Sophos incident analysis
  • Metasploit/Meterpreter stager (TinyMet) used for tool delivery and privilege escalation
  • Go- and later Rust-based Windows encryptors, with separate Linux/ESXi builds used in some attacks
  • Supply-chain access through compromised service providers, dealers, or third-party platforms
  • Published affiliate rules and 'legal agreements' governing affiliate conduct, per 2024-2025 reporting
Targeted sectors
manufacturingautomotivefinancial servicesIT serviceslegalmedia and publishinghealthcareeducation
Notable public victims

Hoya Corporation (2023), Toyota Financial Services (2023), Nissan Dealer Association Australia (2023, via third-party compromise), Yamaha Motor Philippines customers (2023, via dealer supply-chain intrusion), Synoptek (2025), Lee Enterprises (2025), Philippine Ports Authority, Jouvet SAS, G&S Technologies, Colonial Hyundai

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
wannago.cloud · Feb 9, 2024
Commonwealth Sign · Feb 4, 2024
mordfin · Jan 28, 2024
wannagocloud · Jan 26, 2024
neafidi · Jan 26, 2024
PROJECTSW · Jan 19, 2024
F J O'Hara & Sons · Jan 16, 2024
hotelcontinental.no · Jan 12, 2024
molnar&partner · Jan 10, 2024
Corinth Coca-Cola Bottling Works · Jan 9, 2024
HALLEONARD · Jan 8, 2024
EPS.RS · Dec 27, 2023
Ware Manufacturing · Dec 7, 2023
Neurology Center of Nevada · Dec 7, 2023
CMS Communications · Dec 4, 2023
Great Lakes Technologies · Dec 4, 2023
Yanfeng · Nov 27, 2023
HAESUNG DS CO Ltd · Nov 17, 2023
Epstein Law · Nov 16, 2023
Assurius.be · Nov 5, 2023
unique-relations.at · Nov 5, 2023
SG World · Oct 26, 2023
Paul-Alexandre Doïcesco, Notaires Associés · Oct 25, 2023
Cardiovascular Consultants Ltd · Oct 25, 2023
WT PARTNERSHIP · Oct 9, 2023
DiTRONICS Financial Services · Oct 5, 2023
Siamese Asset · Sep 27, 2023
CORTEL Technologies · Sep 12, 2023
PAUL-ALEXANDRE DOICESCO · Sep 8, 2023
WACOAL · Sep 8, 2023
GYP New Tree SA · Aug 28, 2023
Thonburi Energy Storage Systems (TESM) · Aug 8, 2023
Better System Co.,Ltd · Jul 12, 2023
MicroPort Scientific / LivaNova · Jul 11, 2023
ASIC Soluciones · Jul 6, 2023
Daiwa House Industry Co. · Jun 23, 2023
Printmarksolution · Jun 21, 2023
ASZ GmbH & Co · Jun 15, 2023
iECM Company Limited · Jun 14, 2023
Del Bono Hotel · Jun 9, 2023
Clarity Water Technologies, LLC · Jun 8, 2023
AWM Global Advisors · Jun 7, 2023
Ascentia Group Pty Ltd · Jun 5, 2023
Conley & Wirick, P.A. · Jun 4, 2023
SMDEA · May 23, 2023
Oppida Estates Limited · May 23, 2023
Maier Sanitär-Technik GmbH · May 19, 2023
Kannangara Thomson · May 19, 2023
HECTOR MARTINEZ SOSA Y CIA SA · May 19, 2023
eyeDOCS Ottawa · May 5, 2023

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .