qilin
Known ransomware group ACTIVEAlso known as: Agenda
Qilin (also tracked as Agenda) is a ransomware-as-a-service operation active since 2022, written in Rust and Go for cross-platform encryption of Windows, Linux, and VMware ESXi systems. It runs a double-extortion model, leaking stolen data on its dark-web site when victims refuse to pay, and rose to prominence after high-impact attacks on healthcare and critical-services targets.
83
Total Claims
72
Critical
—
Records Claimed
14
Industries Hit
Active span: Apr 10, 2026 – Jun 8, 2026 · 83 organizations targeted
Actor Threat Profile
Activity Timeline
Peak: Apr 2026 (51)Top Targeted Industries
Tradecraft & Infrastructure
25
Documented tools
14 / 55
MITRE tactics / techniques
4
Known leak sites