◇ SIGN IN
← all actors
ransomware

Qilin (fka Agenda)

activemedium confidence
Ransomware
QilinAgendaWater Galura (assessed)
Attribution
RaaS (Russian-speaking, unattributed to a state)
Origin
Unknown (Russian-speaking operators assessed)
First seen
2022
Last active
2026
Motivation
Financially motivated (ransomware)
Confidence
medium
MENA targeting
UAE, Egypt, Saudi Arabia
Sectors
Logistics, energy, IT services, healthcare

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting UAE, Egypt, Saudi Arabia (Logistics, energy, IT services sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Qilin (formerly Agenda) is a Russian-speaking ransomware-as-a-service operation that, following the decline of LockBit and ALPHV, became one of the most active ransomware brands globally through 2025-2026.

History

Qilin emerged in July 2022 as Agenda and rebranded to Qilin in late 2022. It operates a double-extortion RaaS with encryptors written in Go and Rust capable of targeting Windows, Linux and VMware ESXi. MITRE notes functionality overlaps with Black Basta, REvil and BlackCat. Affiliates typically gain access via phishing, exposed services and purchased access, exfiltrate data, and deploy ransomware across sectors including manufacturing, technology, financial services and healthcare.

As LockBit, ALPHV and RansomHub were disrupted or dissolved in 2024-2025, Qilin absorbed displaced affiliates and became one of the most prolific operations by victim count, with reporting citing hundreds of victims across 60+ countries and status as active and dominant into 2026. It also drew attention for high-profile healthcare disruption (e.g., the Synnovis/UK pathology incident attributed to a Qilin affiliate).

Qilin's leak site has listed victims in the UAE, Egypt and Saudi Arabia among its international claims. These listings are extortion allegations and should be treated as claims, not confirmed breaches, unless independently verified.

Notable campaigns

2024
Synnovis / NHS pathology disruption
A Qilin affiliate was linked to the Synnovis attack that disrupted London hospital pathology services.
2025
Rise to top of ransomware ecosystem
Qilin became one of the most active RaaS brands after absorbing affiliates from disrupted operations.
2025
Gulf leak-site listings
UAE, Egyptian and Saudi organizations appeared on Qilin's leak site (claimed, not independently confirmed).

Known tooling · Ransomware Tool Matrix

Tools observed in intrusions leading to Qilin (fka Agenda)'s ransomware, per the community Ransomware Tool Matrix — observed use, not exhaustive. Snapshot 2026-08-07.

Discovery · 2
NmapNping
RMM Tools · 1
ScreenConnect
Defense Evasion · 7
EDRSandBlastPCHunterPowerToolToshiba power management driver (BYOVD)Updater for Carbon Black’s Cloud Sensor AV (upd.exe)YDArkZemana Anti-Rootkit driver
Credential Theft · 1
Mimikatz
OffSec · 3
Cobalt StrikeEvilginxNetExec
Networking · 1
Proxychains
LOLBAS · 3
fsutilPsExecWinRM
Exfiltration · 1
EasyUpload

6 source reports · latest 25 April 2025

Claimed victims · 2120 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

Claim volume · last 12 months
SONDJFMAMJJA
DateVictimCountrySector
ClausingDEManufacturing
Impact Centre ChrétienFROther
CLLS Co LtdSG
Astro ElectroplatingUSManufacturing
FiltronicGBManufacturing
John C Saunders, CPAUSProfessional Services
EISNER ZT GMBHATProfessional Services
Nikan Awasisak AgencyCA
DeponaSETechnology
Crystal PharmatechUSHealthcare
AmSpecUSEnergy & Utilities
Jakle & AlexanderUS