Qilin (cybercrime group)

Qilin is a Russian-speaking cybercrime organisation that has been linked to a number of incidents, including a ransomware attack on hospitals in London.

The group was detected by Trend Micro in August 2022 promoting ransomware called Agenda, which affiliates could tailor. The software at the time was written in Go and Trend Micro noted similarity of the source code with Black Basta, Black Matter and REvil families of malware.

In December 2022 the Agenda ransomware was rewritten in Rust.

Group-IB said they had infiltrated the group in March 2023 and that affiliates earn about 80 to 85% of each ransom payment.

In 2023, Qilin attacks included the following: In 2024, Qilin was named in the following attacks:
 * Thailand battery manufacturer, Thornburi Energy Storage Systems, a battery manufacturer in Thailand
 * Construction consultancy WT Partnership Asia
 * Chinese car parts manufacturer Yanfen, which affected operations at US car maker Stellantis
 * Upper Merion Township in the United States was the victim of a ransomware attack where they claimed to have stolen 500GB including information on staff and private contracts.
 * Felda Global Ventures Holdings Berhad in Malaysia was also attacked.
 * UK-based charity, the Big Issue had 550GB of data stolen including personnel information, contracts and partner data
 * US business Skender Construction had 651GB of data stolen impacting 1,067 people including names, addresses, dates of birth, payment details passports and potentially health information.
 * Several London hospitals declared a critical incident when a ransomware attack affected their systems.