Home/Threat Actor/Qilin
Threat Actor

Qilin

qilin_ransomware · russia_speaking_cybercrime · active since 2022

Qilin (Agenda / Water Galura / G1057) is one of the more operationally consequential ransomware operations of the 2022- 2024 period, a financially-motivated organized cyber-criminal cluster operating predominantly from Russia and adjacent post- Soviet states, operating under the Agenda brand identity from August 2022 through approximately mid-2023 before rebranding to Qilin with the rebrand maintained through 2024-2025 (vendor consensus widely treats Agenda and Qilin as operationally- continuous cluster identities)

defining cluster operational signature the affiliate-controlled monetization with "publish- or-pay" tradecraft where affiliates control the leak-site publication decisions for their respective victim operations rather than central administrator control, operationally distinctive among ransomware-as-a-service operations where most peer operations operate with central-administrator control.

most operationally consequential single operation the June 2024 Synnovis UK NHS pathology services attack, most operationally consequential UK healthcare-sector ransomware operation of the 2022-2024 period disrupting UK NHS blood testing and pathology services for weeks across multiple UK NHS hospital trusts (Guy's and St Thomas' + King's College Hospital), substantial cascading impact on patient care including cancelled surgeries + blood shortages + delayed diagnoses, triggering UK government declaration of national-scale healthcare-sector cyber-incident, Qilin published ~400GB of stolen Synnovis data including patient information after Synnovis refused ~$50M USD ransom demand; additional high-profile documented victims including Royal Berkshire NHS Foundation Trust (May 2024 targeting attempt), Yanfeng Chinese automotive interior parts supplier (November 2023), Big Issue UK media (April 2024), Brunet Canada pharmacy chain (October 2023), numerous US K-12 school district targets; operates Rust-language ransomware variants alongside earlier Golang variants (consistent with broader Rust-pivot patterns following ALPHV / BlackCat introduction November 2021), Linux + ESXi ransomware variants alongside Windows variant.

Russian- language affiliate-recruitment advertisements on underground forums with explicit avoidance of CIS-state targets including Russia / Belarus / Kazakhstan / other former Soviet states.

russia_speaking_cybercrime confidence: high 16 aliases MITRE ATT&CK G1050 ↗

Profile

Qilin (also tracked as Agenda, Water Galura [Trend Micro], and MITRE ATT&CK G1057) is one of the more operationally consequential ransomware operations of the 2022-2024 period, a financially- motivated organized cyber-criminal cluster operating predominantly from Russia and adjacent post-Soviet states. The cluster operated under the Agenda brand identity from August 2022 through approximately mid-2023, then rebranded to Qilin with the rebrand maintained through 2024-2025. Modern vendor consensus widely treats Agenda and Qilin as operationally-continuous cluster identities under different brand identities.

The cluster operates as a ransomware-as-a-service operation with affiliate-controlled monetization, defining cluster operational signature: "publish-or-pay" affiliate-controlled tradecraft where affiliates control the leak-site publication decisions for their respective victim operations rather than central administrator control. The pattern is operationally distinctive among ransomware-as-a-service operations, most peer operations operate with central-administrator control over leak-site publication decisions. The Qilin affiliate-controlled model represents an operational-doctrine signal about cluster organizational structure, affiliates have substantial operational autonomy and the central cluster operates more as service-provider-to-affiliates than as centralized cluster operations.

The model has implications for victim-organization- response decisions because negotiation counterparties are the operator affiliates rather than centralized cluster administrators. The cluster operates Rust-language ransomware variants alongside earlier Golang variants, consistent with broader contemporary cybercrime-cluster patterns following the ALPHV / BlackCat Rust- language ransomware introduction in November 2021. The cluster operates Linux + ESXi ransomware variants alongside the Windows variant.

The cluster's most operationally consequential single operation was the June 2024 Synnovis UK NHS pathology services attack , the most operationally consequential UK healthcare-sector ransomware operation of the 2022-2024 period. Synnovis (a private pathology services provider serving multiple UK NHS hospital trusts including Guy's and St Thomas' NHS Foundation Trust and King's College Hospital NHS Foundation Trust) disruption affected UK NHS blood testing and pathology services for weeks with substantial cascading impact on patient care including cancelled surgeries, blood shortages, and delayed diagnoses. The attack triggered UK government declaration of national-scale healthcare-sector cyber-incident.

Qilin published approximately 400 gigabytes of stolen Synnovis data including patient information on the Qilin leak site after Synnovis refused the approximately $50M USD ransom demand. The attack contributed substantially to elevated UK parliamentary and government attention to NHS-supply-chain ransomware risk. Black Basta involvement in the Synnovis attack was also reported in selected vendor analysis, though primary cluster attribution has been to Qilin.

Additional high-profile documented victims include Royal Berkshire NHS Foundation Trust (UK, May 2024 targeting attempt), Yanfeng (Chinese automotive interior parts supplier, November 2023), Big Issue UK media (April 2024), Brunet Canada pharmacy chain (October 2023), numerous US K-12 school district targets across 2022-2024, and many other commercial and government- sector targets. Operationally the cluster operates Russian-language affiliate- recruitment advertisements on underground forums and explicit avoidance of CIS-state targets including Russia, Belarus, Kazakhstan, and other former Soviet states (the standard operational pattern of Russia-speaking organized cybercrime operations consistent with Russian jurisdictional tolerance of cybercrime targeting Western victims). A handful of operational notes: First, the cluster represents one of the more sustained operationally-consistent ransomware operations of the 2022-2024 period with the Agenda-to-Qilin rebrand pattern demonstrating cluster-brand-management sophistication.

The cluster has remained one of the more consistent operational performers among contemporary ransomware-as-a-service operations. Second, the affiliate-controlled monetization tradecraft represents one of the more operationally interesting business- model variations in the publicly-tracked ransomware-as-a-service ecosystem. The "publish-or-pay" affiliate-controlled tradecraft contrasts with centralized-administrator-control patterns common among peer operations and represents a meaningful operational- doctrine data point about contemporary RaaS organizational diversity.

Third, the Synnovis attack (June 2024) represents one of the most operationally consequential UK healthcare-sector ransomware operations in the publicly-tracked record alongside the May 2021 Ireland Health Service Executive attack (Conti-attributed, already covered as wizard_spider_conti.yaml) and the May 2024 Ascension Health attack (Black Basta-attributed, already covered as black_basta.yaml). The three healthcare-sector ransomware operations collectively represent substantial Western-healthcare- sector operational impact from contemporary cybercrime clusters. Fourth, no formal individual-operator attribution at the named- Russian-national tier has been publicly issued for Qilin / Agenda administrators, consistent with the broader pattern of absence of similar named-individual-attribution for Cl0p, ALPHV / BlackCat, Black Basta, Akira, Play, Medusa, Rhysida, Royal / BlackSuit, RansomHub, and several other contemporary cybercrime clusters.

Only LockBit (Khoroshev), Evil Corp (Yakubets / Turashev), and FIN7 (Dunaev / Hladyr / Kolpakov / Witte) have received named-Russian-national-tier formal attribution among the major contemporary cybercrime clusters covered in this corpus.

Aliases

16
qilinqilin ransomwareqilin_ransomwareqilinransomwareqilin gangqilin_gangagendaagenda ransomwareagenda_ransomwareagendaransomwarewater galurawater_galurawatergalurag1057atk 279atk279

MITRE ATT&CK aliases

1
Additional names MITRE lists for G1050.
GOLD FEATHER

Notable Campaigns

6
2024-2025Continued Operations (2024-2025)
2024Synnovis UK NHS Pathology Services Attack (June 2024), Most Operationally Consequential Cluster Operation
2023-2025Publish-or-Pay Affiliate-Controlled Monetization Tradecraft (2023-2025)
2023Agenda to Qilin Rebrand (Mid-2023)
2022-2024Additional High-Profile Victims (2022-2024)
2022Agenda Emergence (August 2022)

Attribution & Reporting

Attributed by
FBI Cyber DivisionCISA (US Cybersecurity and Infrastructure Security Agency)HHS Health Sector Cybersecurity Coordination Center (HC3)UK National Cyber Security Centre (NCSC)UK National Health Service (NHS) cybersecurity teamsMandiant / Google Cloud Threat IntelligenceMicrosoft Threat Intelligence CenterCrowdStrikeRecorded Future Insikt GroupSentinelOneSophosTrend MicroKaspersky GReATGroup-IBPRODAFTCovewareHalcyonCybereasonIBM X-ForceTrustwave SpiderLabsPalo Alto Networks Unit 42Symantec (Broadcom)TrellixDFIR ReportBitdefenderGuidePoint Security
Key reporting
reportTrend Micro: New Golang Ransomware Agenda Customizes Attacks (August 2022), earliest seminal cluster disclosure under Agenda brand identity
reportTrend Micro: Agenda Ransomware Uses Rust to Target More Vital Industries (September 2023), Rust-language variant documentation
reportMicrosoft Threat Intelligence: Qilin Synnovis Attack Analysis (June 2024), Synnovis UK NHS attack disclosure
reportSophos: Qilin Ransomware Synnovis NHS (June 2024)
reportCrowdStrike: Qilin Ransomware Tracking (multiple years)
reportMandiant: Qilin Ransomware Continued Tracking
reportPalo Alto Networks Unit 42: Agenda Qilin Ransomware Operational Analysis
reportCisco Talos: Qilin Ransomware Deep Dive
reportBitdefender: Qilin Ransomware Tracking
reportRecorded Future Insikt Group: Qilin Ransomware Tracking
reportSentinelOne Labs: Qilin Ransomware Affiliate-Driven Operations
reportCoveware: Qilin Ransomware Affiliate Tracking
reportHalcyon: Qilin Operational Profile
reportPRODAFT: Qilin Detailed Operational Analysis
reportGroup-IB: Qilin Continued Tracking
reportTrustwave SpiderLabs: Qilin Tracking
reportTrellix: Qilin Operational Analysis
reportSymantec (Broadcom): Qilin Ransomware Tracking
reportDFIR Report: Qilin Operational Analysis
reportGuidePoint Security: Qilin Incident Response Tracking
reportIBM X-Force: Qilin Continued Tracking
reportMalpedia Actor Profile: Qilin
reportMITRE ATT&CK Group G1057, Qilin

Operational

State sponsor

Qilin is a financially-motivated organized cyber-criminal cluster , not a state-aligned cluster, operating predominantly from Russia and adjacent post-Soviet states. The cluster operated under the Agenda brand identity from August 2022 through approximately mid-2023, then rebranded to Qilin with the rebrand maintained through 2024-2025. Modern vendor consensus widely treats Agenda and Qilin as operationally-continuous cluster identities under different brand identities, Trend Micro, IBM X-Force, and selected other vendors initially tracked the cluster under the Agenda naming and subsequently transitioned to Qilin naming following the cluster's brand identity update.

The cluster operates as a ransomware-as-a-service operation with affiliate-controlled monetization including "publish-or-pay" tradecraft (affiliates control the leak-site publication decisions for their respective victim operations rather than central administrator control, operationally distinctive among ransomware-as-a-service operations). The cluster has documented Russian-language affiliate-recruitment advertisements on underground forums and operates with explicit avoidance of CIS- state targets including Russia, Belarus, Kazakhstan, and other former Soviet states (the standard operational pattern of Russia-speaking organized cybercrime operations). The cluster executed the highest-profile UK healthcare-sector ransomware operation of the 2022-2024 period, the June 2024 Synnovis UK NHS pathology services attack disrupting UK NHS blood testing and pathology services for weeks.

The cluster has documented operations across more than 150 organizations globally with sustained operational tempo across 2022-2025. No formal individual-operator attribution at the named-Russian-national tier has been publicly issued for Qilin / Agenda administrators.

Motivations
financial_gain, financially_motivated, cybercrime, ransomware_deployment, extortion, double_extortion, ransomware_as_a_service_operations, affiliate_controlled_monetization, healthcare_sector_targeting
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)30/60 · 50%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MEGA NZMETERPRETERMSHTASHARPHOUNDSPLASHTOP ABUSE
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin