Skip to main content
Rethinking Email Security for the AI Era, August 25th
Blog
Email Security

Qilin Ransomware: How It Attacks, Who It Has Hit, and How to Defend Against It

SEPTEMBER 6, 202626 MIN READ
Adaptive TeamAdaptive Team
Qilin Ransomware: How It Attacks, Who It Has Hit, and How to Defend Against It

Key takeaways

  • Qilin ransomware claimed 1,358 victims between April 2025 and March 2026, a 443% increase over the prior 12 months. That made it roughly one in every five to six publicly disclosed ransomware victims worldwide
  • No arrest, indictment, sanction, or joint government advisory has targeted Qilin ransomware as of August 2026. CISA and the FBI have published #StopRansomware advisories for Akira, Black Basta, BianLian, RansomHub, and Gunra
  • Qilin ransomware intrusions frequently begin with valid credentials leaked on criminal channels between roughly one week and three months before use. In 2025 incident response casework, the ransomware executed an average of 6.1 days after the intrusion was first detected
  • The June 2024 Qilin ransomware attack on Synnovis left 161,560 pathology reports still unentered into NHS patient records as of January 2026, alongside 122 recorded patient-safety incidents
  • No free decryptor exists for any Qilin ransomware variant as of August 2026, and the variant tracked as Qilin.B uses an encryption scheme designed to make recovery without the cyberattacker's key impossible

Qilin ransomware claimed 1,358 victims between April 2025 and March 2026, according to the Black Kite 2026 Ransomware Report. That is a 443% increase over the prior 12 months. No government has charged anyone for any of it.

The operation has run since July 2022 on a ransomware-as-a-service model. A core team builds and maintains the malware while recruited affiliates run the intrusions and split the proceeds. As of August 2026, no arrest, indictment, sanction, or joint government advisory has been issued against the group.

That gap matters for planning. Risk registers that quietly assume a takedown is coming have nothing here to support the assumption. The only variables a security team controls sit inside its own environment.

Qilin ransomware intrusions usually start with valid credentials obtained through a criminal marketplace. Someone then signs into a remote access system with them.

That puts the first line of defense on employee credential habits, well ahead of detection tooling. Security awareness training reaches the attacker at the lowest point.

Qilin ransomware incident response team reviewing threat data on monitors in a corporate security operations center.

Qilin Ransomware at a Glance

Entity name Qilin
Also known as Agenda, Water Galura, GOLD FEATHER, and the Qilin.B variant. MITRE ATT&CK tracks the operators as Water Galura (G1050) and the malware as Qilin (S1242)
First observed Launched as Agenda in July 2022, rebranded as Qilin in September 2022
Status Active as of August 2026
Threat actor Water Galura, the core operators, working with affiliates recruited on Russian-language cybercrime forums
Operating model Ransomware-as-a-service. Group-IB documented in 2023 that affiliates received 80% of payments totaling $3 million or less and 85% of payments above that figure
Initial access vector Valid credentials on remote access systems, reported by Cisco Talos, alongside exploitation of edge device vulnerabilities
Encryption method AES-256-CTR with AES-NI hardware acceleration, ChaCha20 as a fallback, and RSA-4096 with OAEP padding, as analyzed by Halcyon in the Qilin.B variant
File extension appended A random character string unique to each victim. The same string doubles as that victim's company identifier
Ransom note filename README-RECOVER-[extension].txt, dropped in nearly every directory on the system, per AhnLab analysis
Organizations affected 1,358 victims claimed between April 2025 and March 2026
Systems affected Windows, Linux, VMware ESXi, and Nutanix AHV hyperconverged infrastructure, per Trend Micro
Attribution A Russian-speaking operation that HHS HC3 assessed likely originates from Russia
Free decryptor available No, for any variant, verified against the No More Ransom decryption tools index in August 2026

What Is Qilin Ransomware?

Qilin ransomware, also known as Agenda, is a ransomware-as-a-service operation that encrypts data on victim networks and exfiltrates copies. Payment then buys two options: a decryption key, and silence about the stolen files on a public leak site.

The operation launched as Agenda in July 2022 and rebranded to Qilin that September, according to the HHS HC3 threat profile. The malware started in Go, a programming language also called Golang. Trend Micro records Rust-based variants arriving later in 2022, extending the encryptor across Windows, Linux, and VMware ESXi.

Reach is what separates Qilin ransomware from most competing operations. Its encryptors extend beyond ordinary servers and workstations to virtualization platforms, including VMware ESXi and, as Trend Micro documented in October 2025, Nutanix AHV. One deployment can take down dozens of virtual machines sitting on a single physical host.

The affiliate program sells more than malware. It markets a catalog of support services alongside the encryptor, broadening what a single affiliate can accomplish without additional skill.

Qilin Ransomware Timeline: 2022 to 2026

Date Event Source
July 2022 Operation launches as Agenda HHS HC3
September 2022 Rebrands under the name Qilin HHS HC3
Late 2022 Rust-based variants extend the encryptor to Windows, Linux, and ESXi Trend Micro
May 2023 Researchers infiltrate the affiliate program and document the payout structure Group-IB
June 3, 2024 Attack on Synnovis disrupts pathology services across London NHS trusts NHS England
June 18, 2024 HHS HC3 publishes the first and only US government threat profile on the group HHS HC3
September 2024 Harvesting of browser-stored credentials through a logon Group Policy Object documented CERT Santé
October 2024 Qilin.B variant appears with strengthened encryption and evasion Halcyon
March 2025 Moonstone Sleet, a North Korean state actor, begins deploying Qilin BleepingComputer
April 1, 2025 RansomHub goes offline, and its affiliates disperse The Hacker News
June 2025 Affiliate panel adds a "Call Lawyer" negotiation feature The Register
August 2025 A fake Europol reward for Qilin administrators circulates, and Europol disavows it BleepingComputer
August 2025 Nissan confirms a design data breach at contractor Creative Box Inc. BleepingComputer
September 29, 2025 Asahi Group Holdings suffers an attack halting Japanese ordering and shipping Asahi Group Holdings
October 2025 Linux encryptor deployed on Windows hosts, with Nutanix AHV added as a target Trend Micro
November 2025 One South Korean managed service provider breach produces 28 downstream victims The Hacker News
April 2026 Multi-stage loader capable of disabling more than 300 security drivers documented Cisco Talos
June 2026 A VPN zero-day, CVE-2026-50751, is linked to Qilin activity Check Point
August 26, 2026 The ATF confirms a cybersecurity incident after a Qilin leak-site listing ATF

Who Is Behind Qilin Ransomware?

Qilin ransomware is run by a Russian-speaking cybercriminal group that MITRE ATT&CK tracks as Water Galura. The core team builds the malware, handles ransom negotiations, and publishes stolen data. Meanwhile, recruited affiliates break in. The HHS HC3 threat profile, assessed in June 2024, found that the group likely originates from Russia.

The Names Qilin Ransomware Is Tracked Under

Qilin ransomware appears in threat intelligence reports under several names. The fragmentation makes research harder than it should be. MITRE ATT&CK separates the people from the software. The group is cataloged as Water Galura under G1050. The malware sits under S1242 as Qilin, with Agenda recorded as the software alias. GOLD FEATHER is the only other group name MITRE lists. Searches for any of those terms lead to the same operation.

Where the Qilin Name Comes From, and Why It Misleads

The qilin is a beast from Chinese mythology, part dragon and part horned animal. The name has sent readers to the wrong country for years.

Graham Cluley, writing for Tripwire in June 2024, took the confusion head-on and said the group behind the operation appears to be linked to Russia. Ransomware brand names carry no reliable signal about nationality. Operators typically pick them for effect.

What Is Actually Known About Qilin's Operators

Public evidence pinpoints the operation's working language and infrastructure, but it stops short of naming anyone. Group-IB infiltrated the affiliate program in 2023 and found recruitment advertisements posted in Russian on the RAMP underground forum.

Those advertisements carried a stated rule: the group "does not work in CIS countries," meaning the Commonwealth of Independent States, the grouping of former Soviet republics. Resecurity reported in October 2025 that the bulletproof hosting behind Qilin leak sites and command servers runs through several entities. One of them is Red Bytes LLC, registered in Saint Petersburg. The record indicates only where the operation runs. Who runs it is still unknown.

Inside the Qilin Ransomware Affiliate Program

Group-IB documented the payout terms in 2023. Affiliates kept 80% of ransoms totaling $3 million or less and 85% of any amount above that. The same research found an affiliate control panel with six sections: Targets, Blogs, Stuffers, News, Payments, and FAQs.

The operation has since grown into a service catalog. By June 2025, the panel carried a "Call Lawyer" button that drops a lawyer into ransom negotiations. Affiliates could also draw on in-house writers for pressure blog posts, distributed denial-of-service (DDoS) capabilities, and spam-tooling for email and phone. Each one got a petabyte of storage, as reported by The Register.

The purpose is not subtle. Researcher Graham Cluley stated that "their goal is just to attract more affiliates, increase the success rate of ransomware attacks."

How Does a Qilin Ransomware Attack Work?

A Qilin ransomware attack runs in a predictable order. Affiliates infiltrate in using valid credentials or an exploited edge device, then harvest additional credentials and disable security software. From there, they move across the network, exfiltrate the data, and encrypt what remains. Every stage has a defesive measure that stops it.

Qilin ransomware attack chain begins with a remote employee signing into a corporate VPN using stolen credentials.

Initial Access: Credentials Bought Before They Are Used

Qilin ransomware affiliates buy their way in. Working credentials come off criminal marketplaces, so nobody has to crack anything. The JSAC 2026 analysis by JPCERT/CC traced credentials used in Qilin intrusions to Telegram channels, breach forums, and the MEGA file-sharing service. Exposure ranged from roughly one week to three months ahead of the intrusion.

Cisco Talos documented a case in which cyberattackers used leaked administrative credentials from the dark web to access the VPN. That VPN had no multi-factor authentication (MFA) configured. A stolen password alone was enough to sign in.

Phishing is the second route. The HHS HC3 threat profile lists phishing and spear phishing emails as initial access methods. Trend Micro found a third: endpoints in a compromised environment calling out to fake CAPTCHA pages. Those prompts mimic a routine human-verification check and instead deliver malware.

Phishing-resistant MFA on every remote access path shuts this stage down. A stolen password is no longer enough.

Vulnerabilities Linked to Qilin Ransomware Affiliates

CVE Product CVSS Attribution
CVE-2026-50751 Check Point Remote Access and Mobile Access VPN 9.3 Check Point assesses with medium confidence that exploitation occurred from May 7, 2026
CVE-2025-31324 SAP NetWeaver Visual Composer 9.8 Halcyon
CVE-2024-27198 JetBrains TeamCity 9.8 Halcyon

Every entry in that table is an internet-facing device or application. That is why edge infrastructure patching should come before general patching in the queue.

Credential Harvesting: Passwords Saved in Browsers

One foothold becomes an organization-wide credential compromise through the passwords employees saved in their browsers. Cisco Talos documented SharpDecryptPwd run against credentials stored in Google Chrome, alongside WebBrowserPassView, a NirSoft password recovery utility, and Mimikatz reading Chrome's password database directly.

The worst documented variant works through Group Policy, the Windows mechanism that pushes settings to every machine in a domain. CERT Santé, the French health ministry's CERT, described cyberattackers reaching a domain controller and editing a Group Policy so that a credential-collecting script would fire on every employee logon.

The script ran for three days before anyone removed it, harvesting Chrome-stored passwords across the whole domain. The consequence outlives the ransomware. Every credential any employee has ever saved in a browser must be treated as compromised.

Disabling browser password storage by policy removes the prize. An alert on any change to the default domain policy catches the delivery method.

Defense Evasion: Turning Security Software Off With a Signed Driver

Endpoint detection and response (EDR) software goes down before anything gets encrypted. Those are the monitoring agents that flag malicious activity. Cisco Talos analysis published in April 2026 traced a multi-stage loader hidden in a file named msimg32.dll.

That file loads a driver called rwdrv.sys. rwdrv.sys is a renamed copy of ThrottleStop.sys, a legitimate utility with a valid digital signature from TechPowerUp LLC. A second driver, hlpdrv.sys, then kills protected security processes. Talos found the tooling capable of disabling more than 300 different EDR drivers across a wide range of vendors.

The technique has a name: bring your own vulnerable driver, or BYOVD. A valid signature provides a single confirmation: that the file came from the vendor that signed it, and nothing about whether the code holds flaws a cyberattacker can exploit.

Vulnerable driver blocklists blunt this. So does an alert whenever a new kernel driver service appears.

Discovery, Lateral Movement, and Remote Access Tooling

Affiliates map the network with NetScan, then move with PsExec, Cobalt Strike, and the SystemBC proxy tool, according to Cisco Talos and Trend Micro. They also install commercial remote management software: AnyDesk, Splashtop, the Atera agent. Cyberattacker traffic then blends into whatever the administrators are already doing.

An allowlist of approved remote management tools makes everything else stand out. Anything off the list deserves an alert.

Qilin Ransomware Exfiltration Before Encryption

Data is exfiltrated before even a single file gets encrypted. That is what makes backups an incomplete answer. Cisco Talos documented WinRAR packaging the targeted data and Cyberduck moving it to cloud servers. The JSAC analysis adds s5cmd for cloud object storage transfers. Egress monitoring decides this one. Blocking unsanctioned cloud storage destinations closes the route.

Qilin Ransomware Encryption and Impact

Qilin ransomware encrypts across Windows, Linux, VMware ESXi, and Nutanix AHV. Trend Micro documented affiliates running the Linux encryptor directly on Windows machines through Windows Subsystem for Linux, a built-in Windows feature that runs Linux programs. One payload covers both environments and slips past Windows-focused detection.

Recovery gets attacked on purpose. MITRE ATT&CK records Qilin removing volume shadow copies, the local snapshots Windows keeps for file restoration. The malware also disables High Availability and Distributed Resource Scheduler functions in VMware vCenter clusters.

It clears Windows event logs and can delete itself after execution. Operators can also select a mode that reboots systems into Safe Mode, where most security software does not load. AhnLab and Group-IB describe that switch differently.

Immutable backups, isolated and held outside the domain, survive this stage.

Qilin Ransomware Mapped to MITRE ATT&CK

Attack Stage What Qilin Does Techniques Control That Breaks It
Initial Access Valid credentials on remote access, exploited edge devices, phishing T1190, T1566 Phishing-resistant MFA, edge patching
Credential Access Dumps LSASS memory and browser-stored passwords T1003.001 Disable browser password storage
Defense Impairment Disables security tools, clears event logs, modifies Group Policy, Safe Mode boot T1685, T1685.005, T1484.001, T1688 Driver blocklists, GPO change alerting
Discovery Enumerates hosts, shares, and virtual machines T1018, T1135, T1673 Network segmentation
Lateral Movement Uses admin shares and transfers tools between hosts T1021.002, T1570 Tiered admin accounts
Command and Control Runs commercial remote desktop software T1219.002 Remote tool allowlisting
Exfiltration Archives data and transfers it to cloud storage Not mapped by MITRE as of August 2026 Egress monitoring
Impact Encrypts data, deletes shadow copies, stops services T1486, T1490, T1489 Immutable offline backups

How Long Qilin Ransomware Sits Before Encrypting

Ransomware was executed an average of 6.1 days after the intrusion was first spotted across a Japanese incident response casework analyzed by JPCERT/CC in 2025. Qilin accounted for 16.4% of the 134 incidents reported that year, roughly 22 cases. Respondents who engaged within 1 to 2 days of first seeing cyberattacker activity avoided a more severe outcome in about a third of cases.

Who Has Qilin Ransomware Attacked, and What Was the Impact?

Qilin ransomware victims span healthcare, food and beverage manufacturing, automotive design, and financial services. Public documentation runs deep enough to compare in four of them. In each case, the confirmed impact was lower than Qilin claimed, and the recovery outlasted the outage by a wide margin.

Synnovis and the NHS: A Recovery Measured in Years

The Synnovis attack landed on June 3, 2024, and disrupted blood testing across seven organizations in south London, according to NHS England. Synnovis is the pathology partnership serving Guy's and St Thomas' and King's College Hospital NHS Foundation Trusts.

Pathology sits underneath surgery, transfusion, and cancer care. Thousands of procedures were postponed. In June 2025, King's College Hospital NHS Foundation Trust confirmed that a patient passed away as a consequence of the attack. The trust named a long wait for a blood test result caused by the attack as a contributing factor, reported by The Record.

Synnovis did not pay. Its forensic review closed in November 2025, and notifications to affected organizations ran from November 10 to November 21, according to Synnovis.

Breach specialists CaseMatrix put the number affected above 900,000, a third-party estimate Synnovis has never confirmed. Qilin told Bloomberg in June 2024 that it demanded $50 million. That figure rests entirely on the cyberattacker's own account.

The aftermath outlasted the outage by years. As of January 2026, 161,560 pathology reports were still not entered into patient records at South London and Maudsley NHS Foundation Trust. Another 122 patient-safety incidents had been logged over results that came back incorrect, unavailable, or late, based on internal NHS documents reviewed by The Record.

That trust was still working on paper roughly 22 months after the attack. NHS England had said that services would be restored by the end of 2024.

Notification lagged further still. Mid and South Essex NHS Foundation Trust learned only toward the end of 2025 that roughly 2,380 of its patient records had been caught in the June 2024 breach. Bedfordshire Hospitals NHS Foundation Trust reported just under 30,000 affected patients, per Computer Weekly.

Asahi Group Holdings: Six Facilities Stopped

Asahi Group Holdings disclosed a cyberattack on September 29, 2025. Order and shipment operations across its Japanese business stopped, and so did call center functions. Six Japan-based production facilities halted, and the company went back to ordering its main products by hand, as reported by BleepingComputer.

Asahi's final investigation results, published November 27, 2025, put the number of affected individuals at roughly 1,914,000. The count covers customer service contacts, employees, retirees, and family members. No credit card information was involved. Qilin claimed 9,300 files totaling 27 GB, and Asahi has never confirmed Qilin as the party responsible.

Nissan Creative Box: Design Data Taken From a Subsidiary

Nissan confirmed suspicious access to the data server of Creative Box Inc., a design contractor subsidiary of Nissan, on August 16, 2025. Qilin claimed 4 TB of vehicle design models, internal reports, and financial documents, and posted sample images. Nissan confirmed neither the volume nor the contents.

Korean Leaks: One Supplier Breach, 28 Victims

One South Korean managed service provider was breached, and 28 Qilin ransomware victims were identified, including 24 in the financial sector. The haul included over 1 million files and roughly 2 TB of data, as reported by The Hacker News in November 2025. The original research suggested possible involvement by Moonstone Sleet, a North Korean state actor, but did not confirm it.

What the Qilin Ransomware Case Files Have in Common

In two of the four cases, the intrusion came through a supplier before it reached the named victim. Third-party risk sits at the center of Qilin ransomware exposure. Confirmed figures came in under claimed figures in every case where both exist.

Victims routinely declined to confirm attribution. Public counts of Qilin activity therefore rest largely on the group's own leak-site posts. Recovery, where anyone measured it, ran to months for operations and years for records.

Qilin Ransomware, North Korea, and the Payment Decision

Qilin ransomware occupies an unusual position among criminal operations. A North Korean state actor has deployed its payload. That moves a ransom payment out of purely criminal territory and into United States sanctions territory.

Moonstone Sleet Deploys Qilin Ransomware

Microsoft Threat Intelligence observed Moonstone Sleet, a North Korean state actor, deploying Qilin ransomware against a small number of organizations starting in late February 2025. Microsoft stated that the group "has previously exclusively deployed their own custom ransomware in their attacks, and this represents the first instance they are deploying ransomware developed by a RaaS operator," as reported by BleepingComputer on March 7, 2025. MITRE ATT&CK lists Moonstone Sleet, cataloged as G1036, among the groups that use Qilin.

Why a Qilin Ransomware Payment Carries Sanctions Exposure

An organization paying a Qilin ransom cannot establish which affiliate encrypted its systems. The Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments was issued by the US Treasury's Office of Foreign Assets Control (OFAC) on September 21, 2021. It states that US persons are generally prohibited from transacting with entities on the Specially Designated Nationals list.

The advisory goes further. OFAC "may impose civil penalties for sanctions violations based on strict liability, meaning that a person subject to U.S. jurisdiction may be held civilly liable even if such person did not know or have reason to know that it was engaging in a transaction that was prohibited." OFAC designated the North Korean Lazarus Group and its Bluenoroff and Andariel subgroups in September 2019.

The platform recruits affiliates broadly, excludes targets in CIS countries, and serves operators working for a sanctioned state. That combination collapses the line between criminal and state activity. It collapses at the exact moment a payment decision comes up.

Exposure does not depend on knowing who ends up with the money. The payment decision, therefore, belongs with legal counsel and sanctions expertise, beyond what the security team can own alone.

Why Has Qilin Ransomware Never Been Indicted?

No arrest, indictment, sanction, seizure, or joint advisory has been issued against Qilin ransomware as of August 2026. The group has been running at the top of the volume tables for four years. Anyone maintaining a risk register has to plan around that.

No Arrests, No Indictments, No Sanctions for Qilin Ransomware

CISA and the FBI publish #StopRansomware joint advisories on ransomware operations of consequence. Akira, Black Basta, BianLian, and RansomHub all have one. Gunra got one on August 10, 2026. Qilin ransomware does not.

The only United States government product on the group is still the HHS HC3 threat profile from June 18, 2024. It predates the period in which Qilin became the highest-volume operation in the sector. No individual has been publicly charged. No Qilin infrastructure has been seized in any announced action.

The Fake Europol Qilin Ransomware Reward

The one Europol-adjacent item was a hoax. In August 2025, a Telegram channel impersonating a Europol cyber threat intelligence unit circulated a poster offering $50,000 for information on two Qilin administrators.

Europol disavowed it, telling BleepingComputer that "we were also surprised to see this story gaining traction. The announcement didn't come from us." The channel operator later admitted the poster was fabricated.

What the Enforcement Gap Means for Risk Registers

Most ransomware risk models carry an unstated assumption. Law enforcement eventually disrupts a major operation, and exposure drops over time. Qilin ransomware gives that assumption nothing to stand on.

The record runs to four years of operation, more than a thousand claimed victims in one year, including a federal agency on the leak site. None of it has produced a public enforcement action. Planning that treats disruption as a matter of time runs against that record.

Can Qilin Ransomware Be Decrypted, and How Do Organizations Recover?

No free decryptor exists for any Qilin ransomware variant as of August 2026, verified against the No More Ransom decryption tools index. That index does carry tools for contemporaries including Akira and BianLian. Organizations without usable backups have nowhere technical to go.

Why No Free Qilin Ransomware Decryptor Exists

Qilin's encryption is built to foreclose recovery. Halcyon analyzed the Qilin.B variant in October 2024. It found AES-256-CTR encryption with hardware acceleration where available, ChaCha20 as a fallback, and RSA-4096 with OAEP padding protecting the keys.

Halcyon concluded that decryption without the cyberattacker's private key or the captured seed values is not possible. AhnLab reached the same conclusion in an October 2025 analysis. Qilin ransomware also removes volume shadow copies and disables VMware vCenter high-availability features, so local recovery options are lost along with the files.

How to Recover From a Qilin Ransomware Attack

Contain without destroying evidence. Isolating affected systems from the network preserves the forensic record. Powering machines down throws away memory-resident evidence that establishes what was taken. Data exfiltration comes before encryption in Qilin ransomware attacks, so determining what was exfiltrated matters as much as restoring what stayed.

Confirm the ransomware family before acting. Remediation and negotiation differ by family, and public identification tools misclassify samples. Qilin ransomware drops a ransom note named README-RECOVER followed by a character string. The same string gets appended to encrypted files as the extension, as documented by Cisco Talos. That gives responders a reliable check.

Treat commercial decryption offers with caution. Services advertising Qilin decryption rank well on recovery searches. However, no known decryption tool exists. Any such service is likely either to pay the ransom on the victim's behalf without saying so or to fail to deliver what it advertises.

Involve legal, regulatory, and insurance functions immediately. Sanctions exposure, breach notification deadlines, and policy conditions all attach from day one. The payment question, in particular, falls outside the security team's authority.

Plan for a disclosure tail measured in years. The Synnovis case shows that downstream organizations were notified of a compromise more than 18 months after it occurred. Incident response budgets and communications plans built around a few weeks will run out long before the obligations do.

How Can Organizations Prevent a Qilin Ransomware Attack?

Qilin ransomware defense works best when each control is matched to the stage it interrupts. An intrusion that beats one control can still be caught at the next. The ransomware prevention measures that follow are ordered by attack stage.

Qilin ransomware defense relies on security awareness training for employees managing credentials and MFA.

Shutting the Door on Initial Access

Phishing-resistant MFA is the highest-value control on this list, and the qualifier does the work. Push notifications and one-time codes fall to a cyberattacker who already holds a valid password. That is exactly where a Qilin affiliate starts after buying credentials. Hardware security keys and passkeys cannot be relayed by a proxy. Coverage has to be total. One VPN gateway, legacy protocol, or contractor account left outside the policy puts the entry route back in place.

Edge devices deserve a patching clock of their own, shorter than the one for internal systems. Every vulnerability tied to Qilin affiliates affects an internet-facing appliance or application. Emergency patching windows for firewalls, VPN concentrators, and internet-facing business applications should be scheduled ahead of regular cycles.

Credential exposure monitoring closes the remaining gap. Leaked credentials sit on criminal channels for weeks or months before anyone uses them. An organization watching for its own domains has a window to force resets first.

Removing the Passwords Worth Stealing

Browser password storage should be disabled via Group Policy across the estate, with an enterprise password manager in its place. One setting removes the payload of the most damaging documented Qilin technique. A script that harvests browser-stored credentials from every workstation finds nothing.

Changes to the default domain policy warrant an alert to the security team. A change-log entry is not enough. Legitimate edits are rare and planned, so unexpected ones make a high-fidelity signal.

Keeping Security Tools Alive

Vulnerable driver blocklisting ships natively in Windows and is maintained by Microsoft. It blocks the signed drivers that BYOVD attacks depend on. Windows Defender Application Control (WDAC) extends the same enforcement to unapproved executables. Neither works in audit mode, and that's where many deployments sit.

A new kernel-level driver service is an uncommon event on production servers and workstations. Alerting on it captures the EDR-disabling stage within the narrow window before detection capability is lost.

Containing Movement Across the Network

Administrative accounts should be tiered so credentials used on workstations cannot authenticate to domain controllers, hypervisors, or backup infrastructure. Segmentation between user, server, and management networks limits how far a compromised host can reach. Virtualization management interfaces should not be reachable from user networks at all.

Stopping Data Before It Leaves

Data leaves before encryption begins, so egress controls determine whether an incident becomes a public breach. Blocking unsanctioned cloud storage and file transfer destinations helps. So does alerting on large outbound transfers from servers that have no business initiating them.

Backups That Survive the Attack

Backups must be immutable, isolated from the production domain, and restored on a fixed schedule. Verification alone leaves the restore path untested. Qilin ransomware goes after backup infrastructure directly, and a backup server joined to the same domain as its clients offers no protection at all.

Fallback capacity needs measuring. Documentation of a process establishes nothing about its throughput. A contingency process running at a small fraction of normal volume will not carry operations through a multi-week outage, and the shortfall shows up mid-incident. Throughput under realistic volume belongs in business continuity testing.

Detection Opportunities: What to Hunt For

A handful of behaviors give defenders early warning. Each one happens before encryption, and each is rare enough in normal operations to alert on directly.

  • Creation of new kernel driver services
  • Modification of the default domain policy
  • Remote management software appearing outside the approved list
  • Mass archive creation on file servers
  • Sustained outbound transfers to cloud storage
  • Clearing of Windows event logs

The Human Layer: Where Qilin Ransomware Attacks Start

Qilin ransomware intrusions start with credentials an employee created, reused, or parked somewhere convenient. Technical controls matter. None of them operates upstream of that fact.

Credential reuse turns an unrelated consumer breach into corporate exposure. It is why credentials surface on criminal channels months before anyone points them at the organization that issued them. Browser-stored passwords turn one compromised workstation into an organization-wide credential reset.

Help desk identity verification decides whether a cyberattacker holding partial information walks away with a password reset or an MFA re-enrollment. The process is only as strong as the standard the staff are trained to apply.

Tooling has a hard limit here. Qilin's loaders can disable more than 300 endpoint security drivers. Detection capability cannot be assumed to survive contact.

The controls that hold get applied before a cyberattacker has credentials at all. That means employees who do not reuse or store corporate passwords, MFA that a stolen password cannot bypass, and a help desk that properly verifies identity. Security awareness training turns those into daily practice.

How Big a Cyberthreat Is Qilin Ransomware in 2026?

Qilin ransomware is still among the highest-volume ransomware operations in the world in 2026. The published numbers describing it differ widely. Working out why they diverge comes before using any of them.

How to Read Ransomware Victim Statistics

Almost every public count of Qilin ransomware activity measures posts on the group's own leak site. Those posts record what the group claims. Confirmation is a separate exercise.

The spread between credible sources is wide. Black Kite recorded 1,358 victims claimed between April 2025 and March 2026. Check Point counted 338 leak-site victims in Q1 2026 alone. Comparitech logged 641 across the first half of 2026. Each figure is defensible, and each counts something different over a different window.

Leak-site volume doubles as Qilin's affiliate recruitment advertising. The group has a commercial reason to claim widely and overstate what it holds. Victims, meanwhile, rarely confirm attribution, as the Asahi and Nissan cases both show. A figure quoted without its measurement period and its method says very little.

Qilin Ransomware Volume and Market Share

Qilin ransomware grew more than fivefold in one reporting year. The starting point was 250 claimed victims. Check Point recorded it as the most active group globally for a third straight quarter in Q1 2026.

Much of that growth came out of a rival's collapse. RansomHub went offline on April 1, 2025, and DragonForce claimed on a criminal forum that it had absorbed its infrastructure. Stranded affiliates scattered. Group-IB observed Qilin's leak-site postings doubling from February onward, as reported by The Hacker News.

The pitch was simple. Qilin offered high payout terms, a stable platform, and a service catalog that reduces the skills required to run an extortion campaign.

The wider market consolidated at the same time. Active groups fell from 85 to 71 between Q3 2025 and Q1 2026. The top 10 groups took 71.1% of all victims, the highest concentration since Q1 2024.

Which Industries and Regions Qilin Ransomware Targets

MITRE ATT&CK records Qilin affiliates hitting organizations worldwide. Most victims sit in the United States, France, Canada, and the United Kingdom, concentrated in manufacturing, technology, financial services, and healthcare. The HHS HC3 profile found a comparable spread: manufacturing at 21%, legal and professional services at 15%, financial services at 14%, healthcare at 7%.

Is Qilin Ransomware Still the Most Active Group?

Qilin ransomware does not consistently hold the top spot. That matters for anyone leaning on rankings. Comparitech recorded The Gentlemen claiming 115 victims in June 2026 against 78 from Qilin, the first month a rival came out ahead. Qilin still led the half-year, 641 to 464. Leadership now changes month to month.

Activity has not slowed. On August 26, 2026, the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed it was responding to a cybersecurity incident affecting a standalone system. Senior Department of Justice officials designated it a "major incident." Qilin had listed the agency on its leak site.

ATF has not confirmed the incident involved ransomware and has not attributed it to Qilin. The listing carried no proof samples. Three other victims Qilin posted the same day did include them, according to Cybernews. The gap between a claim and a confirmed breach shows up right there.

Frequently Asked Questions

What Is Qilin Ransomware?

Qilin ransomware, also tracked as Agenda, is a ransomware-as-a-service operation that has been running since July 2022. A core team builds and maintains the malware, while recruited affiliates carry out the intrusions. The operation encrypts data and steals a copy, demanding payment for a decryption key and for keeping the stolen files off a public leak site.

Who Is Behind Qilin Ransomware?

Qilin ransomware is run by a Russian-speaking cybercriminal group that MITRE ATT&CK tracks as Water Galura. The core team builds the malware, handles ransom negotiations, and publishes stolen data. Affiliates recruited on Russian-language criminal forums do the intrusions. As of August 2026, no government has publicly named, charged, or sanctioned any individual.

Is Qilin Ransomware Russian or Chinese?

Qilin ransomware is a Russian-speaking operation with a Chinese-derived name. The qilin is a creature in Chinese mythology, and the mismatch has led to recurring misattribution. The HHS HC3 threat profile, assessed in June 2024, found that the group likely originates from Russia. Its affiliate recruitment advertisements are written in Russian.

How Does Qilin Ransomware Get Into Networks?

Qilin ransomware affiliates commonly use valid credentials bought or downloaded from criminal marketplaces, including Telegram channels and breach forums, and then sign in to remote access systems. They also exploit unpatched internet-facing devices such as VPN appliances and business applications. Phishing emails and fake CAPTCHA pages also appear.

What Industries Does Qilin Ransomware Target?

Qilin ransomware most often targets manufacturing, technology, financial services, and healthcare. Most victims sit in the United States, France, Canada, and the United Kingdom, according to MITRE ATT&CK. The HHS HC3 profile recorded manufacturing at 21%, legal and professional services at 15%, and financial services at 14%.

Is There a Free Qilin Ransomware Decryptor?

No free decryptor exists for any variant as of August 2026, and the group is not listed on the No More Ransom decryption tools index. Analysis of the Qilin.B variant found that decryption without the cyberattacker's private key is not possible. Tested offline backups are the only reliable route back.

Adaptive Team

Adaptive Team

As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.

Get started with Adaptive Security

Human and agent security for the AI era.