Qilin is the ransomware-as-a-service operation that dominated the first half of 2026, with roughly 641 claimed victims across the period and a run of high-impact attacks including the shutdown of about 30 Asahi brewery factories in Japan. Active since 2022 under the name Agenda, Qilin runs an affiliate model with cross-platform encryptors for Windows, Linux, and VMware ESXi. By mid-2026 it faced a fast-rising rival in The Gentlemen, but its half-year totals kept it at the top tier of the extortion economy.
Who is Qilin?
Qilin, previously branded Agenda, is a Russian-speaking ransomware-as-a-service group first observed in 2022. It leases its encryptor and infrastructure to affiliates who carry out intrusions, splitting proceeds. The group practices double extortion: it steals data before encrypting and threatens to publish it on a leak site if the victim refuses to pay. Qilin sits alongside The Gentlemen, Akira, and DragonForce as one of the most active operations of 2026. For the broader landscape, see the Ransomnews threat-group catalogue and the live Ransomtracker feed.
How active is Qilin in 2026?
By victim volume, Qilin led the first half of 2026. Tracking by NordStellar put its H1 total around 641 claimed victims, the highest of any group over that window. In monthly figures, Qilin held roughly 11% of June 2026 attacks even as The Gentlemen overtook it for the number-one monthly slot. The competition is the story: Qilin lost affiliates to a rival offering higher payouts, yet its cumulative reach kept it dominant across the half year.
What are Qilin’s tactics?
Qilin affiliates gain initial access through phishing and the exploitation of internet-facing edge devices, then harvest credentials and move laterally before deploying the encryptor. The group maintains encryptors written in Rust and Go, giving it reliable builds across Windows, Linux, and ESXi. Targeting the hypervisor is a force multiplier: encrypting one ESXi host can take down every virtual machine it runs, which is how a single intrusion translated into roughly 30 shuttered Asahi factories.
The Asahi attack and why it mattered
The Asahi incident showed what Qilin’s model does at scale against a manufacturer. By reaching virtualization infrastructure, the attack disrupted around 30 factories, halting production for one of Japan’s largest brewers. It was, in the researchers’ framing, a standard ransomware attack that nonetheless shut down an industrial operation, precisely because modern manufacturing runs on virtualized IT that a hypervisor-aware encryptor can paralyze in one move.
How to defend against Qilin
The defensive priorities map to the attack chain. Reduce edge exposure by patching internet-facing appliances and removing unnecessary services, because that is where affiliates get in. Protect the hypervisor as a crown-jewel asset: isolate ESXi management, enforce strong authentication, and keep it off flat networks. Maintain offline, tested backups so an ESXi encryption event is recoverable, and monitor for the credential-theft and lateral-movement activity that precedes deployment. Practitioner-grade endpoint controls, covered in our business ransomware protection guide, raise the cost of the pre-encryption phase.
Frequently asked questions
What is Qilin ransomware?
Qilin, formerly Agenda, is a ransomware-as-a-service operation active since 2022. It leases its encryptor to affiliates and uses double extortion, stealing data before encrypting Windows, Linux, and ESXi systems.
How many victims has Qilin claimed in 2026?
Tracking put Qilin’s first-half 2026 total at roughly 641 claimed victims, the highest of any group over that window, with about 11% of June 2026 attacks.
Did Qilin attack Asahi?
Yes. A Qilin attack disrupted around 30 Asahi brewery factories in Japan by reaching virtualization infrastructure, one of the most impactful industrial ransomware incidents of the period.
Is Qilin still the top ransomware group?
Qilin led the first half of 2026 by cumulative victims, but The Gentlemen overtook it for the top monthly slot by June. The two groups are the defining rivalry of the year.
What operating systems does Qilin target?
Qilin maintains encryptors for Windows, Linux, and VMware ESXi. Its ability to encrypt hypervisors lets a single intrusion take down many virtual machines at once.
