Skip to content

Qilin

Ransomware Group9 claimsLast activity:
Also known as:
  • Agenda · Alias
  • Water Galura · Alias

Overview

Qilin is a financially motivated ransomware-as-a-service operation also known as Agenda and tracked by TrendAI Research as Water Galura. TrendAI dates its emergence to mid-2022, initially with customizable Go-based ransomware and later Rust, Linux and VMware ESXi variants. The operation expanded substantially in 2024 and 2025. Affiliates conduct many intrusions, so a Qilin listing, payload or tactic requires incident-specific corroboration and does not by itself identify the person or team responsible.

Activity and targeting

Qilin has operated across regions and industries rather than maintaining a narrow victim set. TrendAI’s monitoring through January 2026 found the largest share of claimed victims in North America, followed by Europe and the Asia-Pacific region, with manufacturing the most represented industry and significant healthcare and technology activity. These figures derive heavily from the operation’s leak site and should be treated as observed claims rather than confirmed incident totals.

The operation became one of the most active ransomware services in 2025. Check Point Research observed increased affiliate recruitment after RansomHub’s closure and described Qilin as the most active group in the third quarter. Check Point also noted that operator statements suggesting ideology conflicted with broad opportunistic targeting and a profit-focused affiliate model.

Methods and operational characteristics

Qilin combines file encryption with data theft and leak-based pressure. Its Tor data-leak site supports proof-of-compromise material, countdowns, staged releases and publication when demands are not met. TrendAI observed stolen-credential access, initial-access brokers and deceptive browser-verification social engineering, followed by PowerShell and Active Directory discovery, propagation through vCenter or ESXi environments, PsExec-based remote execution and bring-your-own-vulnerable-driver defense evasion.

The malware’s configurable builds let affiliates select encryption, propagation, file targeting and ransom-note behavior. Cross-platform variants and affiliate-supplied loaders or legitimate remote-management tools create meaningful variation between incidents. A technique observed in one campaign should therefore not be generalized to all Qilin activity.

What type of group is it?

Qilin is best characterized as a financially motivated ransomware group operating a service and affiliate ecosystem. Core operators provide malware, infrastructure, leak-site operations and negotiation support, while affiliates may obtain access, exfiltrate data and deploy the ransomware. Public reporting has described isolated state-linked or politically motivated affiliates using the ecosystem, but that does not establish state sponsorship or a unified political motive for Qilin itself. The reviewed evidence supports profit as the primary operating model and leaves the core operators and jurisdiction unidentified.

Incident claims

Newton County Schools cyber incident disrupts district systems

View public claim
Incident date: Source: ransomware.livePublished: Discovered:

Claim details

Qilin listed “Newton County School System” and the district’s correct domain on August 28, 2026. Ransomware.live’s archived image shows a Qilin-branded entry with four purported proof thumbnails, but the tracker blurs them and the page description is N/A. The listing is stable claim evidence but does not independently prove ransomware deployment, encryption, data theft, a ransom demand or Qilin responsibility.

ATF cyberattack and investigative system shutdown

View public claim
Incident date: Source: otherPublished: Discovered:

Claim details

Qilin listed ATF on its data-leak site Aug. 26 and threatened to publish a full leak unless an agency representative made contact through the provided channels. On Aug. 31, the group began releasing files that CNN and independent cybersecurity researcher Ron Fabela said appeared to include ATF investigative targets, phone-communication analyses, agent-specific files and case material. ATF confirmed a breach of a standalone system but has not attributed the incident to Qilin or confirmed the files’ authenticity, nature or scope. No public evidence establishes ransomware encryption or deployment of Qilin malware in the affected environment.

Brazosport College cybersecurity incident

View public claim
Incident date: Source: otherPublished: Discovered:

Claim details

Qilin listed Brazosport College and claimed internal data on August 25, 2026. An accessible tracker characterized the allegation as unverified and said the listing supplied no proof, sample, record count or data categories. The claim does not independently prove ransomware deployment, encryption, data theft or Qilin responsibility.

Stryker global destructive cyberattack

View public claim
Incident date: Source: ransomware.livePublished: Discovered:

Claim details

Qilin listed Stryker and stryker.com July 24. The monitored page contains no description, alleged data volume, deadline, sample or other supporting detail and marks the entry as a possible duplicate because the same domain appears in Handala’s March listing. No reviewed source ties Qilin to the March disruption or documents a later confirmed Stryker intrusion or outage. The entry may be a duplicate, misattribution or separate unconfirmed claim.

Alamo Heights ISD ransomware and data breach

View public claim
Incident date: Source: ransomware.livePublished: Discovered:

Claim details

Ransomware.live recorded a Qilin victim listing naming Alamo Heights School District on May 28. The stable listing identifies the claimant and victim name but does not authenticate alleged files, prove data theft or establish that Qilin caused the March ransomware disruption. The earlier WorldLeaks listing creates unresolved conflicting attribution.

Rusk County cybersecurity incident

View public claim
Incident date: Source: otherPublished:

Claim details

Qilin claimed responsibility for Rusk County’s March 2026 incident. The county confirmed a cyber incident but did not name Qilin; a separate Lynx claim concerned a November 2025 outage and is not attributed to this incident.

Aroostook Mental Health Center cyber incident

View public claim
Incident date: Source: ransomware.livePublished:

Claim details

Qilin listed Aroostook Mental Health Services on March 24, 2026. AMHC said the group was likely behind the network attack and described the posting as following its decision not to deal with the criminals. DeXpose reproduced a Qilin threat to publish information unless a representative made contact, but associated the victim with amhservices.com rather than AMHC’s canonical amhc.org domain. The stable name match, AMHC’s response and later confirmation of file theft support the claim, while the domain mismatch and absence of public forensic artifacts remain contrary evidence. The claim does not independently confirm ransomware deployment, encryption, payment or verified attribution.

Impacted organizations

Impacted locations

Sources