Qilin — Ransomware Profile
Qilin (Agenda) is a ransomware group targeting VMware ESXi environments, notably disrupting London NHS blood testing services in 2024.Also tracked as
Agenda
IntelFusions coverage (25)
- Gentlemen ransomware ends Qilin's 13-month reign on top 2026-08-02 · Ransomware
- Qilin claims one of America's oldest magazines 2026-08-02 · Ransomware
- Ransomware crew Kyber claims US defense giant L3Harris 2026-08-01 · Ransomware
- Low-profile crew CMD keeps adding schools to its leak site 2026-08-01 · Ransomware
- Colombia warns on Gentlemen ransomware as 30 victims land in a day 2026-07-26 · Ransomware
- Qilin lists Stryker four months after the medtech giant ruled out ransomware 2026-07-26 · Ransomware
- Qilin ransomware lists Argentina's army on its leak site 2026-07-25 · Ransomware
- Nova ransomware outpaces rivals with a global wave of leak claims 2026-07-22 · Ransomware
- Smaller ransomware brands crowd the leak sites as Blackout debuts 2026-07-20 · Ransomware
- Qilin ransomware sweeps up US churches, schools and small businesses 2026-07-19 · Ransomware
- INC Ransom floods its leak site with Asia-Pacific victims 2026-07-18 · Ransomware
- DragonForce ransomware posts more than 20 victims in three days 2026-07-17 · Ransomware
- Ransomware crew D1R claims Synopsys breach reaching ARM and Bosch 2026-07-14 · Ransomware
- Qilin ransomware claims 31 victims in a week across 15 countries 2026-07-11 · Ransomware
- The Gentlemen ransomware lures affiliates with rare 90 percent payouts 2026-07-11 · Ransomware
- ShinyHunters claims to hit test gear maker Fluke and distributor Ingram Content 2026-07-02 · Ransomware
- Qilin ransomware adds dentist referral and tolling firms to leak site 2026-06-29 · Ransomware
- Ransomware gang claims to hit German submarine builder Thyssenkrupp 2026-06-28 · Ransomware
- Newer ransomware crews claim diagnostics maker Hologic and an Australian fire service 2026-06-28 · Ransomware
- Ransomware crew Gentlemen arms affiliates with custom EDR killers 2026-06-19 · Ransomware
- New ransomware crew The Gentlemen claims 20 victims in one week 2026-06-12 · Ransomware
- LockBit floods its leak site with 26 victims in two days 2026-06-12 · Ransomware
- Check Point VPN zero-day lets attackers bypass login, now actively exploited 2026-06-12 · Vulnerabilities
- Handala Claims Breach of Clalit, Israel's Largest Healthcare Network 2026-02-26 · Cyber Incidents
- LockBit 5.0 Cross-Platform Analysis: ChaCha20 Encryption, ESXi VM Shutdown Automation, and Near-Zero VirusTotal Detection 2026-02-16 · Ransomware
Tools & malware
- Cobalt Strike Post-exploitation / C2 framework
- NETXLOADER Loader (.NET, protected with .NET Reactor 6)
- PsExec Lateral movement / propagation tool
- Qilin (Agenda) ransomware Ransomware encryptor (Rust and Golang variants; Windows, Linux, ESXi)
- SmokeLoader Loader
Recent claimed victims
- Nolan Consulting Group 2026-09-05
- Colonial Hyundai 2026-09-05
- The Big Table 2026-09-05
- Complete Packaging Solutions 2026-09-04
- Tanner 2026-09-04
- Commission de la construction du Quebec (CCQ) 2026-09-04
- AP CAPITAL PARTNERS LIMITED 2026-09-04
- Grayson Rural Electric Cooperative 2026-09-02
- Uak University 2026-09-02
- Commission de la construction du Quebec 2026-09-01
- Allied Recycling 2026-08-31
- Inmac 2026-08-31
- Crystalpharmatech 2026-08-30
- Absolute Consultancy Services 2026-08-30
- Black Cat Engineering Construction Wll 2026-08-30
- AFSARD 2026-08-30
- The Frame Group 2026-08-29
- La Maison Des Travaux 2026-08-29
- BLISS 1041 2026-08-29
- CareClinics 2026-08-29
- AUM Construction 2026-08-29
- Neumaticos Corral S.A. 2026-08-29
- Bandit Industries 2026-08-29
- LAPoco Architects 2026-08-29
- Infinnium 2026-08-28
Vendor research
- Agenda Ransomware Group Adds SmokeLoader and NETXLOADER to Their Arsenal Trend Micro
- The Qilin Ransomware: Analysis and Protection Strategies Group-IB
- Researchers infiltrate Qilin ransomware group, finding lucrative affiliate payouts The Record (Recorded Future News)
- Qilin Ransomware (Agenda): A Deep Dive Check Point Software
- The Evolution of Qilin RaaS SANS Institute
- Revisiting the Versatile Qilin Ransomware AttackIQ
Countries linked to this actor
- United Kingdom targets
- Kenya targets