ZeroHour

qilin

ransomware group · aka Qilin, Agenda, Water Galura (Microsoft designation) · Unknown; vendors believe the operation is Russian-speaking, though this is unconfirmed · active since Mid-2022 (initially tracked as Agenda; the Qilin branding emerged in 2023)

Victims · 7d
21▲6 vs prev. week
Victims · 30d
116active targets
Victims · 90d
359
All-time (tracked)
2.3Ksince 2022-10-08
Last post
09-16 18:43UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Qilin is a ransomware-as-a-service and data-extortion group first observed in mid-2022 and initially tracked as Agenda, with the Qilin name appearing in 2023. It operates a double-extortion model, encrypting systems and publishing stolen data from non-paying victims, and targets organizations across a broad range of sectors and geographies, including critical infrastructure. Publicly reported incidents include optical manufacturer Hoya (2023), Toyota Financial Services (2023), Nissan's Australian dealer association via a third-party compromise (2023), US newspaper publisher Lee Enterprises (2025), and a 2023 supply-chain intrusion through a Yamaha motorcycle dealer affecting Philippine customers. The group has exploited vulnerable public-facing software such as Zimbra and Cisco IOS XE, and uses both Windows and Linux/ESXi encryptors. Vendor tracking consistently ranked Qilin among the most active ransomware brands through 2024-2025, and it remains active as of late 2025.

Tactics & tooling
  • RaaS affiliate operation with double extortion; victim data posted to a leak site if no ransom is paid
  • Initial access via stolen VPN/RDP credentials, frequently in environments lacking MFA, per incident reporting
  • Exploitation of unpatched public-facing services, including Zimbra and Cisco IOS XE
  • BYOVD technique using vulnerable drivers to disable or evade security tooling, per Sophos incident analysis
  • Metasploit/Meterpreter stager (TinyMet) used for tool delivery and privilege escalation
  • Go- and later Rust-based Windows encryptors, with separate Linux/ESXi builds used in some attacks
  • Supply-chain access through compromised service providers, dealers, or third-party platforms
  • Published affiliate rules and 'legal agreements' governing affiliate conduct, per 2024-2025 reporting
Targeted sectors
manufacturingautomotivefinancial servicesIT serviceslegalmedia and publishinghealthcareeducation
Notable public victims

Hoya Corporation (2023), Toyota Financial Services (2023), Nissan Dealer Association Australia (2023, via third-party compromise), Yamaha Motor Philippines customers (2023, via dealer supply-chain intrusion), Synoptek (2025), Lee Enterprises (2025), Philippine Ports Authority, Jouvet SAS, G&S Technologies, Colonial Hyundai

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Swim-Mor Pools · Jun 5, 2026Civil Engineering Construction
INTERSPA Betriebsverwaltungsgesellschaft · Jun 5, 2026Advertising & Marketing
Trican · Jun 5, 2026Energy, Utilities & Waste
SKUPINA Don Don · Jun 5, 2026Food & Beverage
Avcon Jet · Jun 5, 2026Business Services
MEISA - Sines · Jun 3, 2026Business Services
JNP ENG · Jun 3, 2026Industrial Machinery & Equipment
MarketJoy · Jun 3, 2026Advertising & Marketing
Eat Salad · Jun 3, 2026Hospitality
Nova Medical Products · Jun 2, 2026Retail · Pennsylvania
Clinica Maitenes · Jun 2, 20260
Otthon Centrum · May 28, 2026Real Estate
William Davis Homes · May 27, 2026Construction
Mainstreet Organization of REALTORS · May 27, 2026Membership Organizations
Shocco Springs · May 27, 2026Hospitality
Roofing Solutions · May 27, 2026Construction
Hamister Group · May 26, 2026Holding Companies & Conglomerates
ExpoCredit · May 24, 2026Finance
Global Retool Group · May 24, 2026Industrial Machinery & Equipment
Sponseller Group · May 24, 2026Architecture, Engineering & Design
Branded Products · May 24, 2026Retail · Pennsylvania
Alpha Group Holdings · May 24, 2026Healthcare Services
Alpert Slobin & Rubenstein · May 24, 2026Law Firms & Legal Services
P & G Trading · May 24, 2026Grocery Retail
Semgrep · May 22, 2026Software
ROTO Immobilien · May 21, 2026Real Estate
Snyder Packaging · May 21, 2026Manufacturing
Vernon & Ginsburg · May 21, 2026Law Firms & Legal Services
Hamer Childs · May 20, 2026Law Firms & Legal Services
Porter W Yett · May 20, 2026Civil Engineering Construction
Vial Agro · May 20, 2026Civil Engineering Construction
WNS Lowery · May 20, 2026Industrial Machinery & Equipment
Cz Collections · May 20, 2026Software
CJ Architects · May 20, 2026Architecture, Engineering & Design
Air Conditioning Florida & Mrdsllc & RTE Stucco & MR Drywall Services · May 20, 2026Construction
Gartengestaltung Muller eU · May 18, 2026Construction
RCR Industrial Flooring · May 18, 2026Construction
The Taylor Provisions · May 17, 2026Food & Beverage
Buckeye Paper · May 17, 2026Manufacturing
Musée du Bas-Saint-Laurent · May 17, 2026Hospitality
Fruits Queralt · May 17, 2026Grocery Retail
Salter HealthCare · May 17, 2026Healthcare Services
Majlis Perbandaran Alor Gajah · May 17, 2026Government
Monir Precision Monitoring · May 17, 2026Business Services
PNSB Insurance Brokers Sdn Bhd · May 17, 2026Insurance
Comercial Echave Turri Limitada · May 17, 2026Business Services
CLINICA AVELLANEDA MEDICAL CENTER · May 16, 20260
Turner Supply · May 15, 2026Home Improvement & Hardware Retail
NR Engineering Co., Ltd. · May 15, 2026Electricity, Oil & Gas
Australian College of Business Intelligence · May 15, 2026Education

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .