Qilin

THREAT ACTOR PROFILE

Qilin

Qilin

Qilin

Qilin, also tracked as Agenda, is one of the most active ransomware-as-a-service operations in 2026. It recruits affiliates to breach organizations through edge devices and stolen access, then runs double extortion with a cross-platform encryptor that targets Windows, Linux and ESXi.

Russian-speaking operation

Ransomware (cross-sector)

First seen

2022

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

Qilin, Agenda and the Phantom Mantis affiliates

Qilin is tracked under the brand name, its original name and affiliate cluster names. They map to one entry among the active threat actors we track, so an Agenda report and a Qilin advisory read as one operation.

-

-

-

-

-

GROUP PROFILE

A top RaaS built on edge-device access

Qilin runs a ransomware-as-a-service model and has climbed to the top of the leak-site rankings in 2026. The core team maintains the Rust and Go encryptors and the affiliate program, while affiliates handle intrusions.

Our record ties it to ransomware across many sectors, with a Russian-speaking operation by most assessments. It competes with peers like RansomHub for affiliates and victims.

Qilin's recent edge is speed to exploit. Affiliates have weaponized VPN and firewall zero-days, including a Check Point VPN flaw and Fortinet bugs, to get into networks fast, then deploy ransomware within the same intrusion.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

-

-

-

-

ATTACK LIFECYCLE

VPN and firewall zero-days into fast encryption

The stages below come from 2026 Qilin activity in posts we track on our IOC Hunter feed.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

The Qilin encryptor and an affiliate toolkit

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

CVES EXPLOITED

VPN and firewall flaws for entry

CVE-2026-21509

A Microsoft Office security bypass used to open the fileless chain in Operation Neusploit, and again in the PixyNetLoader intrusion chain. Both campaigns paired the exploit with spear-phishing from compromised accounts rather than mass exploitation.

CVE-2026-21509

A Microsoft Office security bypass used to open the fileless chain in Operation Neusploit, and again in the PixyNetLoader intrusion chain. Both campaigns paired the exploit with spear-phishing from compromised accounts rather than mass exploitation.

CVE-2026-21509

A Microsoft Office security bypass used to open the fileless chain in Operation Neusploit, and again in the PixyNetLoader intrusion chain. Both campaigns paired the exploit with spear-phishing from compromised accounts rather than mass exploitation.

Qilin

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

Qilin

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

Qilin

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

Qilin

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

The firewall as the front door

Recent reporting tracks an operation that moves fast from edge exploit to encryption.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

Qilin

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

Qilin

IOC set, full IP, host and hash history.