Qilin (cybercrime group)

Qilin is a Russian-speaking cybercrime organisation that has been linked to a number of incidents, including a ransomware attack on hospitals in London.[1][2]

The group was detected by Trend Micro in August 2022 promoting ransomware called Agenda, which affiliates could tailor.[3] The software at the time was written in Go and Trend Micro noted similarity of the source code with Black Basta, Black Matter and REvil families of malware.[3]

History

[edit]

In December 2022 the Agenda ransomware was rewritten in Rust.[4]

Group-IB said they had infiltrated the group in March 2023 and that affiliates earn about 80 to 85% of each ransom payment.[4]

In 2023, Qilin attacks included the following:

  • Thornburi Energy Storage Systems, a battery manufacturer in Thailand
  • Construction consultancy WT Partnership Asia
  • Chinese car parts manufacturer Yanfen, which affected operations at US car maker Stellantis

In 2024, Qilin was named in the following attacks:

  • Upper Merion Township in the United States was the victim of a ransomware attack where they claimed to have stolen 500 GB including information on staff and private contracts.[5]
  • Felda Global Ventures Holdings Berhad in Malaysia was also attacked.[5]
  • UK-based charity, the Big Issue had 550 GB of data stolen including personnel information, contracts and partner data.[5]
  • US business Skender Construction had 651 GB of data stolen impacting 1,067 people including names, addresses, dates of birth, payment details, passports and potentially health information.[5]
  • Several London hospitals declared a critical incident when a ransomware attack affected their systems.[1][2]

In 2025, Qilin was named in the following attacks:

  • US business Inotiv had 178 GB of data stolen, impacting multiple systems and data.[6]
  • In October 2025, Qilin claimed responsibility for a ransomware attack on Asahi, a major Japanese brewery.[7]
  • On October 10, the Qilin group attacked infrastructure in the Hauts-de-France region in northern France targeting the Académie d'Amiens. More than 1TB of data was stolen. This is currently the largest attack carried out by the Qilin group. IT services were impacted for several months and still are recovering to this day (10 nov 2025), including high schools computers, and other school related services.

References

[edit]
  1. ^ a b Hern, Alex (2024-06-05). "Who are Qilin, the cybercriminals thought behind the London hospitals hack?". The Guardian. The Guardian. ISSN 0261-3077. Retrieved 2024-06-05.
  2. ^ a b "Qilin ransomware gang likely behind crippling NHS attack | Computer Weekly". ComputerWeekly.com. Retrieved 2024-06-05.
  3. ^ a b Lakshmanan, Ravi (2022-08-29). "New Golang-based 'Agenda Ransomware' Can Be Customized For Each Victim". The Hacker News. Retrieved 2024-06-25.
  4. ^ a b Lakshmanan, Ravie (2023-05-16). "Inside Qilin Ransomware: Affiliates Take Home 85% of Ransom Payouts". The Hacker News. Retrieved 2024-06-25.
  5. ^ a b c d "The State of Ransomware 2024 | BlackFog". 2024-06-01. Retrieved 2024-06-05.
  6. ^ "Pharma firm Inotiv says ransomware attack impacted operations". Bleeping Computer. August 19, 2025.
  7. ^ "Japan's Asahi hack that halted beer production claimed by Qilin ransomware group". The Asahi Shimbun Company. October 8, 2025.