Qilin is a financially motivated ransomware-as-a-service operation also known as Agenda and tracked by TrendAI Research as Water Galura. TrendAI dates its emergence to mid-2022, initially with customizable Go-based ransomware and later Rust, Linux and VMware ESXi variants. The operation expanded substantially in 2024 and 2025. Affiliates conduct many intrusions, so a Qilin listing, payload or tactic requires incident-specific corroboration and does not by itself identify the person or team responsible.
Activity and targeting
Qilin has operated across regions and industries rather than maintaining a narrow victim set. TrendAI’s monitoring through January 2026 found the largest share of claimed victims in North America, followed by Europe and the Asia-Pacific region, with manufacturing the most represented industry and significant healthcare and technology activity. These figures derive heavily from the operation’s leak site and should be treated as observed claims rather than confirmed incident totals.
The operation became one of the most active ransomware services in 2025. Check Point Research observed increased affiliate recruitment after RansomHub’s closure and described Qilin as the most active group in the third quarter. Check Point also noted that operator statements suggesting ideology conflicted with broad opportunistic targeting and a profit-focused affiliate model.
Methods and operational characteristics
Qilin combines file encryption with data theft and leak-based pressure. Its Tor data-leak site supports proof-of-compromise material, countdowns, staged releases and publication when demands are not met. TrendAI observed stolen-credential access, initial-access brokers and deceptive browser-verification social engineering, followed by PowerShell and Active Directory discovery, propagation through vCenter or ESXi environments, PsExec-based remote execution and bring-your-own-vulnerable-driver defense evasion.
The malware’s configurable builds let affiliates select encryption, propagation, file targeting and ransom-note behavior. Cross-platform variants and affiliate-supplied loaders or legitimate remote-management tools create meaningful variation between incidents. A technique observed in one campaign should therefore not be generalized to all Qilin activity.
What type of group is it?
Qilin is best characterized as a financially motivated ransomware group operating a service and affiliate ecosystem. Core operators provide malware, infrastructure, leak-site operations and negotiation support, while affiliates may obtain access, exfiltrate data and deploy the ransomware. Public reporting has described isolated state-linked or politically motivated affiliates using the ecosystem, but that does not establish state sponsorship or a unified political motive for Qilin itself. The reviewed evidence supports profit as the primary operating model and leaves the core operators and jurisdiction unidentified.