Qilin
Also known as: agenda
Profile
Qilin is a ransomware-as-a-service (RaaS) operation run through affiliates that, in 2026, ranked second in the number of incidents observed by Cisco Talos, behind only The Gentlemen. According to Talos, the group is adopting artificial intelligence to improve the efficiency of its operations. Microsoft Threat Intelligence has tracked an affiliate identified as Storm-2570 since April 2025 that works across several RaaS ecosystems, including Qilin, with highly uniform tradecraft based on legitimate remote access tooling and data exfiltration to cloud services. Victims linked to that affiliate span healthcare, education, government, finance, energy and utilities, retail, technology, agriculture and food, nonprofits, pharmaceuticals and chemicals, and construction across the United States, Canada, the United Kingdom, Spain, the Netherlands, and Puerto Rico. Its defining trait is the shared-affiliate model: a single operator may deploy Qilin or other ransomware families while keeping the same tactics and tools.
Active since: 2022-10
Tools
Atera, MeshAgent, ScreenConnect, Splashtop, Remotely
What defenders should watch
- Monitor unauthorised installation or execution of remote access tools (Atera, MeshAgent, ScreenConnect, Splashtop, Remotely) and maintain an allowlist of approved RMM software.
- Watch for bulk data transfers to cloud storage services, a recurring technique of the affiliate tracked by Microsoft prior to encryption.
- Because the same affiliate operates multiple ransomware families, detection should focus on behaviour and tooling (TTPs) rather than on indicators tied solely to the Qilin brand.
- Qilin's incident volume in 2026 and its use of AI to speed up operations make early detection and fast response critical, alongside verified, isolated and restorable backups.
- Targeted sectors are highly varied (healthcare, education, public sector, finance, energy, industry), so no vertical should assume it is out of scope.
Most affected countries
- United States34
- Germany15
- Italy10
- France9
- Spain6
- Romania4
- Japan3
- Canada3
Most affected sectors
- Professional services72
- Manufacturing47
- Construction43
- Finance & insurance22
- Retail19
- Hospitality & tourism16
- Technology15
- Healthcare14
Priority mitigations
MITRE ATT&CK mitigations that cover the most techniques used by this group.
- User Account Management (11 techniques covered)
- Privileged Account Management (10 techniques covered)
- Execution Prevention (10 techniques covered)
- Behavior Prevention on Endpoint (7 techniques covered)
- Operating System Configuration (6 techniques covered)
- Audit (6 techniques covered)
- User Training (5 techniques covered)
- Restrict File and Directory Permissions (5 techniques covered)
MITRE ATT&CK techniques
Recent victims
| Organisation | Country | Sector | Claimed | Status |
|---|---|---|---|---|
| Dynamic Office Solutions | — | Retail | 10/1/2026 | ◌ Claimed (unverified) |
| Arnold Center | — | Education | 9/28/2026 | ◌ Claimed (unverified) |
| SKLG | — | Transport & logistics | 9/28/2026 | ◌ Claimed (unverified) |
| New World Diagnostics | — | Healthcare | 9/28/2026 | ◌ Claimed (unverified) |
| Nissho Electric Manufacturing Co., Ltd. | Japan | Manufacturing | 9/28/2026 | ◌ Claimed (unverified) |
| XICO | — | Construction | 9/27/2026 | ◌ Claimed (unverified) |
| Island | — | Professional services | 9/27/2026 | ◌ Claimed (unverified) |
| Revenga Smart Solutions | — | Professional services | 9/27/2026 | ◌ Claimed (unverified) |
| Willatt & Flickinger | — | Legal | 9/27/2026 | ◌ Claimed (unverified) |
| Iberia Compositech Manufacturing | Spain | Manufacturing | 9/25/2026 | ◌ Claimed (unverified) |
| Dao Group | — | Technology | 9/24/2026 | ◌ Claimed (unverified) |
| All Tech Machine & Engineering | — | Manufacturing | 9/24/2026 | ◌ Claimed (unverified) |
| Inversiones Bolívar | — | Finance & insurance | 9/24/2026 | ◌ Claimed (unverified) |
| Zig Inge Group | — | Real estate | 9/24/2026 | ◌ Claimed (unverified) |
| GDM Pipelines | — | Technology | 9/24/2026 | ◌ Claimed (unverified) |
| Agora coopérative agricole | — | Agriculture & food | 9/24/2026 | ◌ Claimed (unverified) |
| 🔒 Empresa de software | — | Technology | 9/23/2026 | ◌ Claimed (unverified) |
| Textile City | — | Retail | 9/22/2026 | ◌ Claimed (unverified) |
| The Fifty/50 | — | Hospitality & tourism | 9/22/2026 | ◌ Claimed (unverified) |
| Columbus Informatica | — | Technology | 9/22/2026 | ◌ Claimed (unverified) |
| Telrad Networks | — | Manufacturing | 9/21/2026 | ◌ Claimed (unverified) |
| Ikegami Tsushinki Company Limited | Japan | Technology | 9/21/2026 | ◌ Claimed (unverified) |
| Zorlu Holding | Türkiye | Other | 9/20/2026 | ◌ Claimed (unverified) |
| ShopDunk | — | Professional services | 9/20/2026 | ◌ Claimed (unverified) |
| KMLS | — | Construction | 9/20/2026 | ◌ Claimed (unverified) |
Sources analysed
- Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments (Microsoft Threat Intelligence, 9/24/2026)
- Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use (Cisco Talos, 9/17/2026)
Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.
Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, GDELT.