« All threats

Ransomware groupMITRE S1242

Qilin

Also known as: agenda

Profile

Qilin is a ransomware-as-a-service (RaaS) operation run through affiliates that, in 2026, ranked second in the number of incidents observed by Cisco Talos, behind only The Gentlemen. According to Talos, the group is adopting artificial intelligence to improve the efficiency of its operations. Microsoft Threat Intelligence has tracked an affiliate identified as Storm-2570 since April 2025 that works across several RaaS ecosystems, including Qilin, with highly uniform tradecraft based on legitimate remote access tooling and data exfiltration to cloud services. Victims linked to that affiliate span healthcare, education, government, finance, energy and utilities, retail, technology, agriculture and food, nonprofits, pharmaceuticals and chemicals, and construction across the United States, Canada, the United Kingdom, Spain, the Netherlands, and Puerto Rico. Its defining trait is the shared-affiliate model: a single operator may deploy Qilin or other ransomware families while keeping the same tactics and tools.

Active since: 2022-10

Tools

Atera, MeshAgent, ScreenConnect, Splashtop, Remotely

What defenders should watch

Victims in the last 90 days360

Most affected countries

  1. United States34
  2. Germany15
  3. Italy10
  4. France9
  5. Spain6
  6. Romania4
  7. Japan3
  8. Canada3

Most affected sectors

  1. Professional services72
  2. Manufacturing47
  3. Construction43
  4. Finance & insurance22
  5. Retail19
  6. Hospitality & tourism16
  7. Technology15
  8. Healthcare14

Priority mitigations

MITRE ATT&CK mitigations that cover the most techniques used by this group.

  1. User Account Management (11 techniques covered)
  2. Privileged Account Management (10 techniques covered)
  3. Execution Prevention (10 techniques covered)
  4. Behavior Prevention on Endpoint (7 techniques covered)
  5. Operating System Configuration (6 techniques covered)
  6. Audit (6 techniques covered)
  7. User Training (5 techniques covered)
  8. Restrict File and Directory Permissions (5 techniques covered)

MITRE ATT&CK techniques

T1027.013 · Encrypted/Encoded FileT1082 · System Information DiscoveryT1134 · Access Token ManipulationT1480.002 · Mutual ExclusionT1547.004 · Winlogon Helper DLLT1529 · System Shutdown/RebootT1071.002 · File Transfer ProtocolsT1087.001 · Local AccountT1489 · Service StopT1566.002 · Spearphishing LinkT1047 · Windows Management InstrumentationT1106 · Native APIT1036.004 · Masquerade Task or ServiceT1673 · Virtual Machine DiscoveryT1548.002 · Bypass User Account ControlT1480 · Execution GuardrailsT1021.002 · SMB/Windows Admin SharesT1036.005 · Match Legitimate Resource Name or LocationT1057 · Process DiscoveryT1053.005 · Scheduled TaskT1112 · Modify RegistryT1135 · Network Share DiscoveryT1685.005 · Clear Windows Event LogsT1007 · System Service DiscoveryT1570 · Lateral Tool TransferT1055.001 · Dynamic-link Library InjectionT1059.003 · Windows Command ShellT1012 · Query RegistryT1069.002 · Domain GroupsT1016 · System Network Configuration DiscoveryT1680 · Local Storage DiscoveryT1222 · File and Directory Permissions ModificationT1486 · Data Encrypted for ImpactT1204.001 · Malicious LinkT1190 · Exploit Public-Facing ApplicationT1547.001 · Registry Run Keys / Startup FolderT1484.001 · Group Policy ModificationT1021.004 · SSHT1003.001 · LSASS MemoryT1678 · Delay ExecutionT1204.002 · Malicious FileT1083 · File and Directory DiscoveryT1688 · Safe Mode BootT1685 · Disable or Modify ToolsT1018 · Remote System DiscoveryT1566.001 · Spearphishing AttachmentT1087.002 · Domain AccountT1490 · Inhibit System RecoveryT1070.004 · File DeletionT1491.001 · Internal DefacementT1059.001 · PowerShellT1219.002 · Remote Desktop Software

Recent victims

OrganisationCountrySectorClaimedStatus
Dynamic Office Solutions—Retail10/1/2026◌ Claimed (unverified)
Arnold Center—Education9/28/2026◌ Claimed (unverified)
SKLG—Transport & logistics9/28/2026◌ Claimed (unverified)
New World Diagnostics—Healthcare9/28/2026◌ Claimed (unverified)
Nissho Electric Manufacturing Co., Ltd.JapanManufacturing9/28/2026◌ Claimed (unverified)
XICO—Construction9/27/2026◌ Claimed (unverified)
Island—Professional services9/27/2026◌ Claimed (unverified)
Revenga Smart Solutions—Professional services9/27/2026◌ Claimed (unverified)
Willatt & Flickinger—Legal9/27/2026◌ Claimed (unverified)
Iberia Compositech ManufacturingSpainManufacturing9/25/2026◌ Claimed (unverified)
Dao Group—Technology9/24/2026◌ Claimed (unverified)
All Tech Machine & Engineering—Manufacturing9/24/2026◌ Claimed (unverified)
Inversiones Bolívar—Finance & insurance9/24/2026◌ Claimed (unverified)
Zig Inge Group—Real estate9/24/2026◌ Claimed (unverified)
GDM Pipelines—Technology9/24/2026◌ Claimed (unverified)
Agora coopérative agricole—Agriculture & food9/24/2026◌ Claimed (unverified)
🔒 Empresa de software—Technology9/23/2026◌ Claimed (unverified)
Textile City—Retail9/22/2026◌ Claimed (unverified)
The Fifty/50—Hospitality & tourism9/22/2026◌ Claimed (unverified)
Columbus Informatica—Technology9/22/2026◌ Claimed (unverified)
Telrad Networks—Manufacturing9/21/2026◌ Claimed (unverified)
Ikegami Tsushinki Company LimitedJapanTechnology9/21/2026◌ Claimed (unverified)
Zorlu HoldingTürkiyeOther9/20/2026◌ Claimed (unverified)
ShopDunk—Professional services9/20/2026◌ Claimed (unverified)
KMLS—Construction9/20/2026◌ Claimed (unverified)

Sources analysed

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, GDELT.