Qilin (cybercrime group)

Last updated

Qilin is a Russian-speaking cybercrime organisation that has been linked to a number of incidents, including a ransomware attack on hospitals in London. [1] [2]

The group was detected by Trend Micro in August 2022 promoting ransomware called Agenda, which affiliates could tailor. [3] The software at the time was written in Go and Trend Micro noted similarity of the source code with Black Basta, Black Matter and REvil families of malware. [3]

History

In December 2022 the Agenda ransomware was rewritten in Rust. [4]

Group-IB said they had infiltrated the group in March 2023 and that affiliates earn about 80 to 85% of each ransom payment. [4]

In 2023, Qilin attacks included the following:

In 2024, Qilin was named in the following attacks:

In 2025, Qilin was named in the following attacks:

References

  1. 1 2 Hern, Alex (2024-06-05). "Who are Qilin, the cybercriminals thought behind the London hospitals hack?". The Guardian. The Guardian. ISSN   0261-3077 . Retrieved 2024-06-05.
  2. 1 2 "Qilin ransomware gang likely behind crippling NHS attack | Computer Weekly". ComputerWeekly.com. Retrieved 2024-06-05.
  3. 1 2 Lakshmanan, Ravi (2022-08-29). "New Golang-based 'Agenda Ransomware' Can Be Customized For Each Victim". The Hacker News. Retrieved 2024-06-25.
  4. 1 2 Lakshmanan, Ravie (2023-05-16). "Inside Qilin Ransomware: Affiliates Take Home 85% of Ransom Payouts". The Hacker News. Retrieved 2024-06-25.
  5. 1 2 3 4 "The State of Ransomware 2024 | BlackFog". 2024-06-01. Retrieved 2024-06-05.
  6. "Pharma firm Inotiv says ransomware attack impacted operations". Bleeping Computer. August 19, 2025.
  7. "Japan's Asahi hack that halted beer production claimed by Qilin ransomware group". The Asahi Shimbun Company. October 8, 2025.