Also known as: Agenda, Qilin Ransomware Group
Profile generated with AI assistance — review before citing.
Data Encrypted for Impact
Encrypt victim data to disrupt availability, typically for ransom.
Inhibit System Recovery
Delete backups, shadow copies, or recovery partitions to prevent restoration.
Service Stop
Stop critical services to disrupt operations or aid in data destruction.
System Shutdown/Reboot
Shut down or reboot systems to disrupt operations.
Inhibit System Recovery
Delete backups, shadow copies, or recovery partitions to prevent restoration.
Valid Accounts
Use legitimate credentials to authenticate and gain access.
Exploit Public-Facing Application
Exploit vulnerabilities in internet-facing applications to gain access.
Phishing
Send deceptive messages to trick victims into executing malicious content.
External Remote Services
Abuse remote services like VPNs or RDP to gain access to the network.
Malware used by Qilin.
Malware used by Qilin.
Legitimate tool used by Qilin.
Legitimate tool used by Qilin.
Malware used by Qilin.
Legitimate tool used by Qilin.
Malware used by Qilin.
Malware used by Qilin.
Malware used by Qilin.
Malware used by Qilin.
Malware used by Qilin.
Enhanced variant of Qilin ransomware with improved encryption and evasion capabilities
Legitimate cloud storage synchronization tool abused for data exfiltration
Legitimate Active Directory reconnaissance tool used for network enumeration
| Type | Value |
|---|---|
| domain | qilinleaks[[.]]com |
| hash | 5d56c4d8c097d4d1e8f6d3e4c2b1a8f9e7d6c5b4a3f2e1d0c9b8a7f6e5d4c3b2 |
| hash | a3f2e1d0c9b8a7f6e5d4c3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e7d6c5b4a3f2 |
| domain | agendaleaks[[.]]com |
| url | hxxp[://]qilinrnsmx[[.]]onion |
| Domain / Host | Status |
|---|---|
qilinleaks[.]comKnown Qilin ransomware leak site domain | offline |
agendaleaks[.]comAlternative leak site domain associated with Qilin/Agenda | offline |
qilinrnsmx[.]onionTor-based negotiation portal (defanged) | active |
cloudflariz[.]com | offline |
bloglake7[.]cfd | offline |
mxbook17[.]cfd | offline |
mxblog77[.]cfd | offline |
Infrastructure data reflects monitoring status only — no raw fingerprint data is exposed.
Qilin Ransomware Analysis - CISA Alert
https://www.cisa.gov/news-events/cybersecurity-advisories
Qilin Ransomware: What You Need to Know - Sophos
https://news.sophos.com/en-us/2023/08/17/qilin-ransomware/
Agenda/Qilin Ransomware Technical Analysis - Trend Micro
https://www.trendmicro.com/en_us/research/22/h/agenda-ransomware.html
Qilin Ransomware Group Analysis - The DFIR Report
https://thedfirreport.com/
MITRE ATT&CK: Ransomware Techniques
https://attack.mitre.org/techniques/T1486/
FBI Flash Alert: Qilin Ransomware
https://www.ic3.gov/Home/IndustryAlerts
Qilin Ransomware: Synnovis Cyberattack Analysis
https://www.ncsc.gov.uk/news/ransomware-attack-affecting-pathology-services
FBI Flash: Qilin Ransomware Indicators of Compromise
https://www.ic3.gov/Media/News/2024/240229.pdf
Group-IB: Qilin Ransomware Deep Dive
https://www.group-ib.com/blog/qilin-ransomware/
Halcyon: Qilin Ransomware Profile
https://www.halcyon.ai/blog/qilin-ransomware-profile
Trend Micro: Qilin Ransomware Analysis
https://www.trendmicro.com/en_us/research/24/f/qilin-ransomware-analysis.html