Netskope Threat Labs

Qilin

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Qilin (a.k.a. Agenda) is a ransomware as a service operation first observed in July 2022, and its name references a Chinese mythological creature symbolizing power and prosperity despite the group's links to Russian speaking cybercriminals. Its tooling includes Go and Rust variants that encrypt Windows, Linux, and VMware ESXi systems, and its affiliates have targeted organizations worldwide, with the majority of victims in the United States, France, Canada, and the United Kingdom, primarily in manufacturing, technology, financial services, and healthcare.

First seen
October 2023
Last seen
October 2026
Agenda

52 techniques across 11 tactics.

TA0001 Initial Access

TA0002 Execution

TA0003 Persistence

TA0004 Privilege Escalation

  • T1548Abuse Elevation Control Mechanism

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

TA0008 Lateral Movement

TA0011 Command and Control

TA0040 Impact

TA0112 Defense Impairment

Alert Name
Gen:Variant.Ransom.Agenda.1
Gen:Variant.Ransom.Qilin.1
Gen:Variant.Ransom.Qilin.18
Gen:Variant.Ransom.Qilin.21
Gen:Variant.Ransom.Qilin.3
Gen:Variant.Ransom.Qilin.4
Gen:Variant.Ransom.Qilin.7
Gen:Variant.Ransom.Qilin.9
Linux.Ransomware.Qilin
Trojan.Linux.Ransom.Qilin.1