RussiaWidely attributedUnknown

Qilin

Russian-speaking ransomware group detected in 2022, originally using the Agenda ransomware. Known for attacks on NHS hospitals in London. Operates RaaS model with Go-based ransomware.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
7.8
Moderate signal strength
Mentions12
Sources5
High conf.6
Last seenJun 2026
First observed
Last active
Origin
Russia
Aliases
2
Techniques
0
Campaigns
0
Russia
TargetsHealthcareCritical Infrastructure
RegionsGlobal

Attribution signals

12 mentions · 5 sources
#1confirmedhigh
Unspecified
zack-whittaker
Jun 2026

"it had confirmed the bug was being exploited by a known ransomware group called Qilin to hack into "a few dozen targeted organizations globally""

#2attributed tohigh
Unspecified
socradar
Jun 2026

"~30% of all LATAM ransomware victims attributed to Qilin"

#3taken responsibilityhigh
Unspecified
checkpoint
May 2026

"Ransomware group Qilin has taken responsibility for a cyber-attack targeting German political party Die Linke"

#4has exploitedhigh
Unspecified
infosecurity-magazine
Jun 2026

"an affiliate of the Qilin ransomware group has exploited the flaw in "post-compromise activity.""

#5actively targetedhigh
TTP matchVictimology
mandiant
May 2026

"ransomware operators, including prolific groups using REDBIKE (Akira) and AGENDA (Qilin), actively targeted backup infrastructure"

#6we assess with medium confidencemoderate
Geopolitical
infosecurity-magazine
Jun 2026

"we assess with medium confidence that the actor behind the exploitation of CVE-2026-50751 is financially motivated, uses Qilin ransomware"

#7with medium confidencemoderate
Unspecified
socradar
Jun 2026

"One case involved post-compromise activity linked to a Qilin ransomware affiliate with medium confidence."

#8led bymoderate
Unspecified
checkpoint
May 2026

"ransomware activity was led by Akira, Qilin, and Safepay"

#9assesses with medium confidencemoderate
Unspecified
rapid7
Jun 2026

"At least one incident has been linked to a Qilin ransomware affiliate, which Check Point assesses with medium confidence."

#10with medium confidencemoderate
Unspecified
security-affairs
Jun 2026

"at least one incident has been linked, with medium confidence, to a Qilin ransomware affiliate."

#11unspecified
Malware
cyberscoop
May 2026
#12unspecifiedhigh
Malware
coveware
Jun 2026

"various members of the Scattered Spider group utilizing an encryptor from the Qilin group when they had previously relied on the encryptor used by BlackCat/ALPHV"

Hedge terms observed

actively targetedassesses with medium confidenceattributed toconfirmedhas exploitedled bytaken responsibilityunspecifiedwe assess with medium confidencewith medium confidence