← All actors

Qilin

Aliases: Agenda, Qilin ransomware, Agenda ransomware

Source profile review date: 2026-05-31

Added to the source registry: 2022-10-08 · Source snapshot: 2026-09-15

Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.

Research status: Existing researched dossier

Locally generated translation; linguistic review is still pending.

Executive summary

Qilin, previously also called Agenda, is a RaaS operation with strong emphasis on double extortion, care impact, Linux/ESXi payloads and defense avoidance.

Qilin should be investigated as a continuity and data risk, especially when identity, remote access, virtualization, backups and sensitive data are not sufficiently separated.

Latest five known victim claims

Loading stored claims…

    These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.

    Management summary

    Qilin, also known as Agenda, is a ransomware-as-a-service operation that has been in public reporting since 2022. The group received broad attention from incidents with major societal impact, including the attack on Synnovis, a pathology service provider for NHS- hospitals in London. Therefore, Qilin for Amuneth is not only a technical profile, but also an example of ransomware as social continuity risk.

    Microsoft describesQilin /Linux -detections as part of a RaaS operation whichLinux /ESXi -targets may hit andBYOVD- can use techniques to disable antivirus software.Qilin relevant for organisations with virtualization, Linux servers, hypervisors and central backup platforms.Windows Endpoints.

    For the board, the key question is whether an organisation can quickly determine which critical processes depend on the affected systems. In the case of care, production, logistics and public services, diagnostics, planning, files, ERP or file services may have direct social or operational consequences. Qilin claims must therefore be assessed on data storage and process impact.

    Grouping and development

    Qilin/Agenda is described in public sources as RaaS with affiliates and customizable payloads. The name Calendar is returned to earlier reports; Qilin is the later, more famous brand name. As with other RaaS operations, exact access may vary per incident, while extortion infrastructure and publication printing remain recognizable.

    The group is relevant to sector impact. HC3 warned in 2024 of Qilin in relation to the Healthcare and Public Health sector, including after the Synnovis attack. Care environments are attractive for extortion because uptime, privacy and social pressure come together. This logic also applies to other organisations where operational standstill becomes rapidly visible.

    For organisations, Qilin should be managed as a living profile. New claims may indicate changing affiliate preferences, new Linux or ESXi focus, other EDR-kill techniques or sector shift. Add updates only with clear source and date.

    Operation and attack chain

    Investigation starts with access. Collect VPN, firewall, RDP, SSO, identity, EDR, proxy and mail security logs. Check valid accounts, MFA- changes, password resets, remote access from unusual locations, vulnerable edge systems and old service accounts. Qilin-like incidents can start with seemingly normal login activity.

    After access follows exploration, privilege building and preparation. Search for domain discovery, share enumeration, credential access, admin group changes, PowerShell, WMI, RDP- jumps, remote service creation, access to hypervisors, Linux servers and backup platforms. Check that management interfaces were accessible from regular workstations.

    TheLinux /ESXi -dimension requires special attention. Collect hypervisorlogs,SSH- authentication, shell history where forensically sound, management console events,VM- stop actions, snapshots, datastore access and backup repository logs. If the actor hits virtualization, recovery can be delayed on a large scale.

    Data diode and encryption should be examined separately. Search for large file entries, compression, staging directories, cloud uploads, unknown outbound traffic, EDR-tampering and ransomware payloads. BYOVD-context means that security tool impairment should not only be seen as a side effect but as an active incident phase.

    Attack pattern from public cases

    Qilin, previously Calendar, is a RaaS operation that received extra attention due to healthcare impact and Linux/ESXi-focused payloads. Microsoft describes Ransom:Linux/Qilin!rfn as a payload for Linux/ESXi systems that encrypts files with .qilin extensions and places ransom notes with Tor payment instructions.

    Microsoft also mentions BYOVD- tactics to disable antivirus software and refers to abuse of known vulnerabilities such as CVE-2024-21762 and CVE-2023-27532. This makes Qilin relevant for organisations with vulnerable edge systems and weak management of Linux or virtualization.

    The victim pattern shows that chain impact can be large. Synnovis case made clear that an attack on a service provider could have direct consequences for healthcare processes, diagnostics and planning.

    Defense against Qilin should therefore be wider than Windows endpoints: SSH, ESXi, backups, privileged accounts, security drivers and emergency processes are all in play.

    Known IOCs and artifacts

    Microsoft mentions .qilin as file extension to Ransom:Linux /Qilin !rfn. A sudden wave files with this extension indicates the impact phase and should lead directly to isolation and control of hypervisors and Linux servers.

    Microsoft describes ransom notes with Tor payment instructions as part of theQilin /Linux -payload. The exact notename may vary by variant, but presence of such notes onLinux /ESXi -systems is an important artifact.

    BYOVD- signals are important: unexpected volnerable drivers, discontinued security services, EDR-policy changes and logholes. These are defense avoidance artifacts that can be visible before or during encryption.

    CVE-2024-21762 and CVE-2023-27532 are mentioned by Microsoft in Qilin-context. Organisations that have Fortinet or backup related exposure must check patch status and logs around these vulnerabilities.

    Victims and historical context

    The Synnovis case shows that Qilin impact can go beyond IT. Disruption of pathology services affects diagnosis, planning, hospital processes and patient care. Such examples should be used in management briefings to explain why backup separation, crisis processes and supplier dependence are part of ransomware weability.

    Register per Qilin-claim sector, country, process impact, data types, claim date, publication status and source. For care and public service, additional records should be made to determine whether chain partners or citizens may be affected indirectly.

    Detection and follow-up

    Priorities: strong MFA, cutting of remote access, patching of edge systems, segmenting of hypervisors, restriction of SSH and management interfaces, separate admin accounts, EDR-hardening, driver control, backup separation and recovery tests for virtualization. Save logs outside the primary domain.

    In a Qilin-hit triage should look directly at process impact. Is there care, production, logistics or public service dependent on the victim? Are there suppliers relationships? Have Linux/ESXi or backup systems been affected? These questions determine urgency.

    Deep forensic file

    Qilin research should take process impact from the start. In case of a healthcare provider or other critical service provider, a technical incident can lead directly to delayed appointments, disturbed diagnoses, manual emergency processes or disruption of chain partners. Therefore, in addition to systems, the investigator must also identify processes: which service fell out, what data was needed, what alternatives existed and what dependencies became visible.

    The Linux and ESXi components require other log sources than classic Windows ransomware. Collect SSH- authentication, sudo or shell activity, hypervisor management, datastore access, VM- stop actions, snapshot changes, storage events and backup logs. If these resources are not centrally logged, it is a structural risk. Qilin shows that virtualization should not be treated as a technical side issue.

    BYOVD and security tool impairment need to be carefully investigated. Look for suspicious drivers, unexpected kernel components, discontinued security processes, EDR-policy changes and logholes. Determine whether the actor deliberately disabled defences or caused disruption due to recovery actions. This difference is important for scope and for assessing if the actor still had control.

    Identity remains the binding layer. Even when Linux or ESXi is affected, the route often starts with accounts, management consoles or remote access. Therefore check SSO, VPN, privileged accounts, service accounts, SSH keys, break-glass accounts and password safes. Document which accounts had access to Windows, Linux, hypervisors and backups. Overlap between those layers increases impact.

    In data collection, extra attention should be paid to sensitive care, staff or customer data. Qilin claims can use publication pressure where data types are more important than volume. Record whether data samples exist, which departments or systems contain the data, and whether suppliers or citizens may have been indirectly affected. This makes the report useful for communication and reporting obligations.

    Recovery validation should go beyond systems online. Test whether virtual machines are reliable, whether backups are clean, or credentials have been rotated, whether hypervisor administrators have been refurbished and if logging has improved. A Qilin incident without recovery validation can leave behind risk in management layers that are needed quickly again during the crisis.

    What to look for

    Qilin, earlier Calendar, deserves attention through double extortion, Linux/ESXi impact and major process disruption attacks. Note remote access, valid accounts, access to hypervisors, Linux servers, backups, EDR- interference and large data transfers.

    Important signals include suspicious VPN or SSH-logins, new privileged accounts, management actions on ESXi or vCenter, VM- stop actions, datastore access, backup console logs, security tool impairment, suspicious drivers, staging directories and cloud uploads.

    Qilin is particularly dangerous for organisations where technical failure has direct social or operational consequences. Care, logistics, production, education and public services should not only look at encrypted systems but also at process impact.

    How to arm yourself against Qilin

    Protect virtualization and Linux management. Limit SSH, vCenter, ESXi, storage management and backup platforms to separate management accounts and management networks. Log these systems centrally; many organizations lack visibility right here.

    Make sure that recovery is possible outside the primary domain. Use separate credentials, immutable or offline backups, virtual environment recovery tests and critical process emergency procedures. Qilin-like impact often hits more than endpoints.

    Monitor defense avoidance. Note stopped security services, suspicious drivers, EDR-policy changes and logholes. BYOVD--like signals need to be investigated immediately as they can indicate preparation for wider impact.

    Victim pattern and lessons

    Qilin received broad attention from incidents with care impact, including Synnovis. The lesson is that an attack on a service provider can have direct consequences for hospitals, patients, planning and diagnostics.

    For visitors, the most important lesson is that Linux, ESXi and backups should not fall outside ransomware weasurability. If you only monitor Windows endpoints, you may miss the layer where continuity is actually hit.

    Use Qilin as a business continuity test: which processes should be considered when hypervisors, laboratory systems, fileshares or suppliers fail? Technical hardening and emergency processes should be assessed together.

    A practical check is to test whether hypervisor management, SSH- access and backup consoles can only be accessed via separate management accounts. If ordinary domain accounts can touch these layers, the impact of Qilin-like behaviour is much greater.

    Also check if critical processes have an emergency route. If diagnostics, production planning or logistics processing fail through a single IT- layer, that risk should be known in advance and not only discovered during a ransomware crisis.

    Indicators of compromise (IOCs)

    Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.

    TypeValueSourceContext
    extension.qilinMicrosoft Security Intelligence Ransom:Linux/Qilin!rfnLinux /ESXi encrypted file extension
    behaviorransom note with Tor payment instructions on Linux/ESXi systemsMicrosoft Security Intelligence Ransom:Linux/Qilin!rfnImpact phase artifact
    techniqueBYOVD to deactivate antivirus/security toolsMicrosoft Security Intelligence Ransom:Linux/Qilin!rfnDefense evacuation pattern
    cveCVE-2024-21762Microsoft Security Intelligence Ransom:Linux/Qilin!rfnKnown vulnerability guided in Qilin context
    cveCVE-2023-27532Microsoft Security Intelligence Ransom:Linux/Qilin!rfnCredential-theft vulnerability guided in Qilin context

    Sources

    Evidence and limitations

    Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.