Grupo de ransomware

Qilin

Qilin (also widely reported under its earlier name “Agenda”) is a ransomware-as-a-service (RaaS) operation active since mid-2022 and repeatedly described in public reporting as a high-throughput affiliate platform combining data theft with encryption (“double extortion”). The group operates an extortion ecosystem that includes victim negotiation, leak-site publication pressure, and a mature affiliate program where the core operators reportedly take a percentage of ransom proceeds (commonly cited as ~15–20%).

From a defender’s perspective, Qilin’s distinguishing risk is not a single “novel” exploit chain but an increasingly professionalized operating model: affiliates leverage common entry vectors (phishing, exposed remote services, credential abuse) and then rely on fast lateral movement, tool-assisted deployment (including remote monitoring/management tools), and recovery inhibition prior to encryption. Public reporting highlights cross-platform capability (Windows + Linux/ESXi) and repeated use of legitimate administrative tooling to reduce friction and blend into enterprise operations.

Operational sophistication appears uneven across incidents (typical of RaaS). Some campaigns show advanced tradecraft (backup targeting, defense evasion techniques such as BYOVD, proxying, and multi-tool orchestration), while others resemble “opportunistic big-game hunting.” This variability is a key analytic point: Qilin should be modeled as an ecosystem with a shared payload/platform but heterogeneous affiliate behaviors.

Confidence: High that Qilin/Agenda is an active RaaS brand with double-extortion behavior and cross-platform targeting referenced by multiple reputable sources. Medium regarding specific technical “signatures” being globally consistent (affiliate variability). Medium-high that the operator/affiliate base is connected to Russian-speaking cybercrime communities (based on multiple sources citing forum recruitment and CIS-avoidance patterns).

Creado por iQBlack CTI Team
Colaboradores 1
Última actualización 2026-08-19

ATT&CK

MITRE ATT&CK

T1003OS Credential Dumping
T1021.002SMB/Windows Admin Shares
T1021.004SSH
T1041Exfiltration Over C2 Channel
T1078Valid Accounts
T1105Ingress Tool Transfer
T1190Exploit Public-Facing Application
T1219Remote Access Tools
T1486Data Encrypted for Impact
T1490Inhibit System Recovery
T1562.001Disable or Modify Tools
T1566Phishing

Research

OSINT seleccionado