qilin
ransomware group · aka Qilin, Agenda, Water Galura (Microsoft designation) · Unknown; vendors believe the operation is Russian-speaking, though this is unconfirmed · active since Mid-2022 (initially tracked as Agenda; the Qilin branding emerged in 2023)
Qilin is a ransomware-as-a-service and data-extortion group first observed in mid-2022 and initially tracked as Agenda, with the Qilin name appearing in 2023. It operates a double-extortion model, encrypting systems and publishing stolen data from non-paying victims, and targets organizations across a broad range of sectors and geographies, including critical infrastructure. Publicly reported incidents include optical manufacturer Hoya (2023), Toyota Financial Services (2023), Nissan's Australian dealer association via a third-party compromise (2023), US newspaper publisher Lee Enterprises (2025), and a 2023 supply-chain intrusion through a Yamaha motorcycle dealer affecting Philippine customers. The group has exploited vulnerable public-facing software such as Zimbra and Cisco IOS XE, and uses both Windows and Linux/ESXi encryptors. Vendor tracking consistently ranked Qilin among the most active ransomware brands through 2024-2025, and it remains active as of late 2025.
- RaaS affiliate operation with double extortion; victim data posted to a leak site if no ransom is paid
- Initial access via stolen VPN/RDP credentials, frequently in environments lacking MFA, per incident reporting
- Exploitation of unpatched public-facing services, including Zimbra and Cisco IOS XE
- BYOVD technique using vulnerable drivers to disable or evade security tooling, per Sophos incident analysis
- Metasploit/Meterpreter stager (TinyMet) used for tool delivery and privilege escalation
- Go- and later Rust-based Windows encryptors, with separate Linux/ESXi builds used in some attacks
- Supply-chain access through compromised service providers, dealers, or third-party platforms
- Published affiliate rules and 'legal agreements' governing affiliate conduct, per 2024-2025 reporting
Hoya Corporation (2023), Toyota Financial Services (2023), Nissan Dealer Association Australia (2023, via third-party compromise), Yamaha Motor Philippines customers (2023, via dealer supply-chain intrusion), Synoptek (2025), Lee Enterprises (2025), Philippine Ports Authority, Jouvet SAS, G&S Technologies, Colonial Hyundai
No public figure.
Leak-site victims2,262 posts · newest first
| Victim | Discovered | Details |
|---|---|---|
| Gropper & Nejat, PLLC | · May 4, 2023 | — |
| GIGATRON.RS | · Apr 30, 2023 | — |
| fsmsolicitors.co.uk | · Apr 30, 2023 | — |
| Attent Zorg en Behandeling | · Apr 30, 2023 | — |
| Sippex | · Apr 30, 2023 | — |
| SIIX Corporation | · Apr 30, 2023 | — |
| Dialog Information Technology | · Oct 8, 2022 | — |
| ScinoPharm Taiwan | · Oct 8, 2022 | — |
| Robert Bernard | · Oct 8, 2022 | — |
| Contempo Card | · Oct 8, 2022 | — |
| Lojas Torra | · Oct 8, 2022 | — |
| EMTELCO | · Oct 8, 2022 | — |