Sentrix

Actor · RaaS · since 2022

Qilin: the most prolific RaaS of 2026

Born as Agenda in 2022, Qilin is the most prolific ransomware operation of 2026 according to Check Point. Entry points, incidents and the controls that stop it.

Model
RaaS · since 2022-07
Aliases
Agenda, Water Galura
Ways in
VPN credentials without MFA · Initial access brokers · Credentials bought on markets · Spear phishing
Targets
Manufacturing · Healthcare · Technology · North American SMBs · Windows, Linux and ESXi

By Sentrix · Published 2026-09-20

Qilin is, according to Check Point Research, the ransomware-as-a-service program that lists the most victims in the world in 2026. It has no North American government advisory to its name, which paradoxically makes it better known to incident responders than to boards.

Who they are

The ransomware surfaced in the summer of 2022 under the name Agenda: on August 25, 2022, Trend Micro described a Windows binary written in Go, customized for each victim with a company ID and stolen accounts, able to reboot the machine in safe mode, and distributed by an underground forum user named Qilin. The TrendAI report of March 2026 dates the first observation to July 2022 and documents the move to Rust variants between December 2022 and February 2023, which added Linux and VMware ESXi to the targets, followed by more recent obfuscated .NET builds.

The model is a classic double-extortion RaaS: the operators supply the encryptor, the leak site and the negotiation, the affiliates run the intrusion. According to the same TrendAI report, the leak site listed almost 1,400 victims as of January 2026, more than half of them in North America, and most of them small businesses. That growth came from affiliate movements: RansomHub affiliates migrating to the Agenda infrastructure in mid-2025, and an alliance with DragonForce and LockBit announced on September 15, 2025, again per TrendAI. Check Point Research, in its second-quarter 2026 review, ranks Qilin first among operators for a fourth straight quarter with 279 published victims, down 17% from the previous quarter.

How they get in

The intrusion analyzed by Sophos X-Ops in July 2024 is representative: compromised credentials used on a VPN portal that lacked multi-factor authentication, eighteen days of quiet presence, then lateral movement to the domain controllers. There, the affiliate used a group policy to deploy a PowerShell script that ran at every logon and harvested passwords saved in Chrome, potentially exposing credentials for dozens of third-party sites. The 2026 TrendAI report adds initial access brokers and stolen credentials as the dominant entry routes.

Extortion combines encryption with the threat of publication. The encryptors cover Windows, Linux and ESXi, and the affiliate panel lets operators set the encryption mode, extensions and processes to kill for each victim, as Trend Micro noted as early as 2022.

What they have done

  • June 2024: attack on Synnovis, a laboratory services provider to NHS hospitals in London, which brought the group to public attention, according to Sophos X-Ops.
  • July 2024: the intrusion described by Sophos in which the Chrome credentials of an entire fleet were harvested through a group policy.
  • September 15, 2025: announcement of an alliance with DragonForce and LockBit, reported by TrendAI.
  • September 4, 2026: claim against the Commission de la construction du Québec, published on the group's leak site. It is a claim, not a fact confirmed by the organization.

What stops them

The following controls answer the techniques documented by Sophos and TrendAI.

  1. Phishing-resistant MFA on every remote access: VPN, gateways, administration consoles. This is the exact gap exploited in the Sophos case. ISO 27001:2022 A.8.5 and SOC 2 CC6.1.
  2. Inventory and rotation of exposed credentials: monitor credential leaks and force rotation, since access brokers sell valid accounts. ISO 27001:2022 A.5.17.
  3. Control over group policies: alert on any new GPO that deploys a script or scheduled task, and restrict who can create one. ISO 27001:2022 A.8.2 and A.8.16, SOC 2 CC6.3.
  4. Block password saving in browsers and deploy an enterprise password manager.
  5. Tested offline backups, including for ESXi, because the Rust variants target hypervisors. ISO 27001:2022 A.8.13, SOC 2 A1.2.
  6. Detection of lateral movement toward domain controllers over SMB, RDP and WMI, with a reaction time shorter than the observed dwell time.

Sources

Frequently asked questions

Are Qilin and Agenda the same group?
Yes. In August 2022 Trend Micro documented a Go-based ransomware named Agenda, distributed by an underground forum user called Qilin. The Qilin name took over with the leak site and the affiliate program. TrendAI reports still use Agenda, and sometimes Water Galura, for the same operation, so the three names in threat reports all point to one program.
Why does Qilin list so many victims in 2026?
Because it absorbed the affiliates of other programs. TrendAI notes that RansomHub affiliates migrated to its infrastructure in mid-2025 and that an alliance with DragonForce and LockBit was announced in September 2025. Check Point Research ranked it the most prolific operator for a fourth consecutive quarter in the second quarter of 2026, ahead of every other leak site.
How does Qilin usually get in?
Through valid credentials on a VPN portal without multi-factor authentication. In the case Sophos analyzed in July 2024, the attacker stayed eighteen days in the network before moving to the domain controllers, then harvested passwords saved in Chrome through a group policy. Initial access brokers and stolen credentials from criminal markets supply the rest of the intrusions.

Let's talk about your compliance program.

Last updated: 2026-09-20