All threat actors

Threat actor profile

Qilin aka Agenda

Likely Russia-based · GlobalRansomware-as-a-service; double extortionUpdated

Qilin is a ransomware-as-a-service operation that, according to the US Department of Health and Human Services, launched as Agenda in July 2022 and rebranded as Qilin by that September. HHS says the group likely originates from Russia and that affiliates use its tools and infrastructure in exchange for 15-20% of the proceeds. Its encryptors exist in Go and Rust, including a Linux build for VMware ESXi seen in December 2023. Affiliates gain access through phishing and exposed services such as Citrix and RDP, and use remote monitoring tools and Cobalt Strike. Qilin was behind the June 2024 attack on NHS pathology supplier Synnovis, which disrupted London hospitals.

LatestOn 26 August 2026 the US ATF confirmed a 'major incident' on a standalone system, the same day Qilin listed the agency on its leak site; on 31 August ATF said the claims concerned its legacy CALEA system, and Qilin posted about 6.3GB of alleged ATF files before removing the links. ATF has not attributed the breach to Qilin or confirmed the files are authentic.

Timeline

  1. Launched as the Agenda ransomware operation in July 2022, rebranding as Qilin by September, according to HHS.

    HHS HC3 — Qilin, aka Agenda Ransomware threat profile (18 Jun 2024)

  2. A Linux variant targeting VMware ESXi servers was identified in December 2023.

    HHS HC3 — Qilin, aka Agenda Ransomware threat profile (18 Jun 2024)

  3. Qilin ransomware hit NHS pathology supplier Synnovis, disrupting services at major London hospitals; King's College Hospital later said the disruption contributed to a patient's death.

    The Register — NHS supplier ends probe into ransomware attack that contributed to patient death (13 Nov 2025)

  4. HHS's HC3 published a threat profile warning that Qilin continues to target healthcare.

    HHS HC3 — Qilin, aka Agenda Ransomware threat profile (18 Jun 2024)

  5. Check Point Research said Qilin became the dominant group in Q2 2025, rising from about 35 to almost 70 victims a month and offering affiliates extras such as legal review of stolen data and DDoS.

    Check Point Research — The State of Ransomware, Q2 2025 (31 Jul 2025)

  6. Cyble reported Qilin led all ransomware groups for the fifth time in six months, with 99 claimed victims in September 2025.

    Cyble — Ransomware attacks surge 50% in 2025, Qilin leads wave (24 Oct 2025)

  7. Barracuda said Qilin claimed more than 1,000 victims on its leak site in 2025 and posted 55 more in the first weeks of 2026.

    Barracuda — Qilin ransomware surges into 2026 (15 Jan 2026)

  8. Qilin listed the ATF on its leak site; ATF confirmed a 'major incident' affecting a standalone system separate from its enterprise network.

    BleepingComputer — ATF confirms 'major incident' after recent Qilin breach claims (27 Aug 2026)

  9. ATF said the claims concerned its legacy, standalone CALEA system; Qilin posted about 6.3GB of alleged ATF files and pulled the links within a day.

    HackRead — Qilin leaks 6.3GB of alleged ATF files, then pulls download links (1 Sep 2026)

Who is exposed, and what holds

Who is exposed

  • Healthcare providers and suppliers, which HHS says Qilin continues to target
  • Manufacturers, which Barracuda says made up about 23% of Qilin's 2025 leak-site listings
  • Organisations with exposed RDP, Citrix or other remote access lacking MFA

Recommended controls

  • Enforce MFA on remote access and disable unused RDP ports, as HHS and the FBI recommend
  • Keep offline, air-gapped and tested backups, including of ESXi hosts
  • Audit for new accounts, unexpected RMM tools and disabled antivirus

Sources