RaqibCTI Search the threat graph — actor, CVE, technique, victim…⌘K
Qilin (fka Agenda) · Ransomware · RaqibCTI
Knowledge / Actors / Qilin (fka Agenda) Corpus Ransomware
Qilin Agenda Water Galura (assessed)
Attribution
RaaS (Russian-speaking, unattributed to a state)
Origin
Unknown (Russian-speaking operators assessed)
Motivation
Financially motivated (ransomware)
Attribution confidence
medium
MENA targeting
UAE, Egypt, Saudi Arabia
Sectors
Logistics, energy, IT services, healthcare
Corpus activity · 6mo 2 mentions
Aug 2026: 1 Sep 2026: 1 A M J J A S
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it matters Ransomware actor, medium confidence, documented targeting UAE, Egypt, Saudi Arabia (Logistics, energy, IT services sectors).
What's next No pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.
Diamond Model The four features of this adversary's intrusions under the Diamond Model — adversary, capability, infrastructure, victim — assembled from tracked data; pivot from any vertex to the others.
Adversary 4
Who is behind the activity — operator vs. customer.
Qilin (fka Agenda) Qilin Agenda Water Galura (assessed)
Capability 70
Tradecraft, techniques, and tooling the adversary employs.
51 ATT&CK techniques Defense Evasion Discovery Execution Impact Nmap Nping ScreenConnect EDRSandBlast PCHunter
Infrastructure
Physical/logical infrastructure used to deliver capability (C2, domains, relays).
No infrastructure indicators correlated in Radar yet.
Victim 7
Targeting — sectors and geographies in scope.
Logistics energy IT services healthcare UAE Egypt Saudi Arabia
Honesty note Attribution ≠ confirmation. Qilin (fka Agenda) is linked here via TTP overlap and shared infrastructure — not confirmed by original-source reporting. Treat this as a working hypothesis, not a settled fact.
Technique overlap
← Cl0p actor Technique overlap ← Lynx actor Technique overlap ← APT33 actor Technique overlap → WIRTE actor Technique overlap ← Nova actor Technique overlap ← 8Base actor Technique overlap ← Monti actor Technique overlap ← Gunra actor Technique overlap The actor's techniques grouped into kill-chain phases — a partial order across phases; techniques within a phase are co-occurring, not sequenced . Export opens in CTID's Attack Flow Builder.
51 techniques across 5 of 7 stages · 4 of 6 pre-objective stages show known tradecraft — each a chance to break the chain before Actions on Objectives.
3 Delivery 3
T1566.002 T1190 T1566.001
4 Exploitation 7
T1047 T1204.002 T1059.003 T1059.001 T1204.001 T1106 T1053.005
5 Installation 17
T1480 T1480.002 T1484.001 T1685.005 T1685 T1070.004 T1112 T1134 +9
6 Command & Control 2
T1071.002 T1219.002
7 Actions on Objectives 22
T1003.001 T1680 T1087.002 T1007 T1016 T1082 T1083 T1087.001 +14
Honesty note Phase groupings reflect ATT&CK tactic classification, not a confirmed operational timeline for Qilin (fka Agenda) — see the competing-hypotheses breakdown for how confident this attribution really is.
See the analysis →
Analysis of Competing Hypotheses No competing-hypotheses matrix filed yet
Attribution here rests on the Diamond Model and Kill Chain evidence above.
Start a formal ACH matrix to stress-test the leading hypothesis.
Suggested · co-occurring (unverified)
These entities are frequently mentioned together in source material; co-occurrence is not a verified relationship.
Malware Qilin co-mentioned in 2 items Country United States co-mentioned in 2 items Country Japan co-mentioned in 1 item Malware AiLock co-mentioned in 1 item Malware Responder co-mentioned in 1 item Malware impacket-partial-mic co-mentioned in 1 item Country Taiwan co-mentioned in 1 item Malware RansomEXX co-mentioned in 1 item CVE CVE-2020-1472 co-mentioned in 1 item Sector transportation and warehousing co-mentioned in 1 item Malware RustHound co-mentioned in 1 item Malware NetRunner co-mentioned in 1 item Sector
Manufacturing
co-mentioned in 1 item
Sector health care/social assistance co-mentioned in 1 item
Sector finance and insurance co-mentioned in 1 item
Sector professional, scientific, and technical services co-mentioned in 1 item
Sector services co-mentioned in 1 item
Malware The Gentlemen co-mentioned in 1 item
Sector retail trade co-mentioned in 1 item
CVE CVE-2025-24799 co-mentioned in 1 item
Malware Stormous co-mentioned in 1 item
Sector Construction co-mentioned in 1 item
Sector wholesale trade co-mentioned in 1 item
Sector educational services co-mentioned in 1 item
Malware LockBit 5.0 co-mentioned in 1 item
Country Philippines co-mentioned in 1 item
CVE CVE-2025-2479 co-mentioned in 1 item
Malware SafePay co-mentioned in 1 item
Sector information and communications co-mentioned in 1 item
Malware NightSpire co-mentioned in 1 item