Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

Qilin: the RaaS that ran H1 2026 ransomware

Jesse William McGrawBy Jesse William McGrawJuly 15, 2026Updated:July 18, 2026No Comments4 Mins Read74 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Qilin: the RaaS that ran H1 2026 ransomware, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Qilin is the ransomware-as-a-service operation that dominated the first half of 2026, with roughly 641 claimed victims across the period and a run of high-impact attacks including the shutdown of about 30 Asahi brewery factories in Japan. Active since 2022 under the name Agenda, Qilin runs an affiliate model with cross-platform encryptors for Windows, Linux, and VMware ESXi. By mid-2026 it faced a fast-rising rival in The Gentlemen, but its half-year totals kept it at the top tier of the extortion economy.

Who is Qilin?

Qilin, previously branded Agenda, is a Russian-speaking ransomware-as-a-service group first observed in 2022. It leases its encryptor and infrastructure to affiliates who carry out intrusions, splitting proceeds. The group practices double extortion: it steals data before encrypting and threatens to publish it on a leak site if the victim refuses to pay. Qilin sits alongside The Gentlemen, Akira, and DragonForce as one of the most active operations of 2026. For the broader landscape, see the Ransomnews threat-group catalogue and the live Ransomtracker feed.

How active is Qilin in 2026?

By victim volume, Qilin led the first half of 2026. Tracking by NordStellar put its H1 total around 641 claimed victims, the highest of any group over that window. In monthly figures, Qilin held roughly 11% of June 2026 attacks even as The Gentlemen overtook it for the number-one monthly slot. The competition is the story: Qilin lost affiliates to a rival offering higher payouts, yet its cumulative reach kept it dominant across the half year.

QILIN (AGENDA) // PROFILE CARD Active since 2022 | RaaS, double extortion | Russian-speaking ~641H1 2026 victims ~11%of June 2026 attacks ASAHI~30 factories hit WIN / LINUX / ESXicross-platform encryptors TYPICAL ATTACK CHAIN Phishing / edge-device exploitation → credential theft → lateral movement → data exfiltration → encrypt Windows/Linux/ESXi → leak-site extortion Rivalry: lost affiliates to The Gentlemen (higher payout) through mid-2026

What are Qilin’s tactics?

Qilin affiliates gain initial access through phishing and the exploitation of internet-facing edge devices, then harvest credentials and move laterally before deploying the encryptor. The group maintains encryptors written in Rust and Go, giving it reliable builds across Windows, Linux, and ESXi. Targeting the hypervisor is a force multiplier: encrypting one ESXi host can take down every virtual machine it runs, which is how a single intrusion translated into roughly 30 shuttered Asahi factories.

The Asahi attack and why it mattered

The Asahi incident showed what Qilin’s model does at scale against a manufacturer. By reaching virtualization infrastructure, the attack disrupted around 30 factories, halting production for one of Japan’s largest brewers. It was, in the researchers’ framing, a standard ransomware attack that nonetheless shut down an industrial operation, precisely because modern manufacturing runs on virtualized IT that a hypervisor-aware encryptor can paralyze in one move.

How to defend against Qilin

The defensive priorities map to the attack chain. Reduce edge exposure by patching internet-facing appliances and removing unnecessary services, because that is where affiliates get in. Protect the hypervisor as a crown-jewel asset: isolate ESXi management, enforce strong authentication, and keep it off flat networks. Maintain offline, tested backups so an ESXi encryption event is recoverable, and monitor for the credential-theft and lateral-movement activity that precedes deployment. Practitioner-grade endpoint controls, covered in our business ransomware protection guide, raise the cost of the pre-encryption phase.

Frequently asked questions

What is Qilin ransomware?

Qilin, formerly Agenda, is a ransomware-as-a-service operation active since 2022. It leases its encryptor to affiliates and uses double extortion, stealing data before encrypting Windows, Linux, and ESXi systems.

How many victims has Qilin claimed in 2026?

Tracking put Qilin’s first-half 2026 total at roughly 641 claimed victims, the highest of any group over that window, with about 11% of June 2026 attacks.

Did Qilin attack Asahi?

Yes. A Qilin attack disrupted around 30 Asahi brewery factories in Japan by reaching virtualization infrastructure, one of the most impactful industrial ransomware incidents of the period.

Is Qilin still the top ransomware group?

Qilin led the first half of 2026 by cumulative victims, but The Gentlemen overtook it for the top monthly slot by June. The two groups are the defining rivalry of the year.

What operating systems does Qilin target?

Qilin maintains encryptors for Windows, Linux, and VMware ESXi. Its ability to encrypt hypervisors lets a single intrusion take down many virtual machines at once.

Sources and further reading

  • Infosecurity Magazine: Qilin dominates the ransomware market
  • Citalid: Qilin and Asahi, when a standard attack shuts 30 factories
  • ReliaQuest: Ransomware and cyber extortion in Q2 2026 (July 16, 2026)
  • Ransomnews threat-group catalogue
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleThe week the West went after ransomware’s plumbing
Next Article 570 flaws, 2 exploited: July Patch Tuesday hits identity
Jesse William McGraw

Jesse William McGraw, also known as GhostExodus, is a former insider threat and threat actor. He became the first person in recent U.S. history to be convicted of corrupting industrial control systems. Today he focuses on threat intelligence, OSINT, and public speaking, using his knowledge to bring awareness to the security risks that organisations and individuals face.

Related Posts

Deadlock: ransomware that hides its C2 on the blockchain

July 18, 2026

Clover Health discloses social-engineering breach in 8-K

July 18, 2026

DragonForce: the cartel that absorbed its rivals

July 17, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.