Ransomware Group intelligence
Qilin
ActiveTrack Qilin with 2564 published victims and 5 known leak locations in a single intelligence view.
Overview
Qilin is tracked by Breach House as a ransomware group with 2564 published victims.
United States is currently the most targeted country in this dataset.
5 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 120 74.5%
- Pending 33 20.5%
- Deleted 8 5.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (5)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Up checked 1h ago | ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion |
| Leak location 5 | Onion service | Down checked 1h ago | ji57fr53anp7wb44tbbnp72qcgbhqywy4jmbncawdcrejj5amuvh3zqd.onion |
| Leak location 2 | Onion service | Down checked 1h ago | kbsqoivihgdmwczmxkbovk7ss2dcynitwhhfu5yw725dboqo5kthfaad.onion |
| Leak location 4 | Onion service | Down checked 1h ago | b4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion |
| Leak location 1 | Onion service | Down checked 1h ago | ozsxj4hwxub7gio347ac7tyqqozvfioty37skqilzo2oqfs4cw2mgtyd.onion |
Top Activity Sectors (18)
- Not identified 498
- Communication / Marketing 271
- Manufacturing / Engineering 201
- Services 201
- Finance / Legal / Insurance 171
- Construction / Real Estate 157
- Healthcare / Pharma 139
- IT 121
- Retail / E-commerce 88
- Education 73
- Public Sector 68
- Transportation / Travel / Logistics 53
- Energy 53
- Hospitality / Food & Beverage / Tourism 45
- Agriculture / Food 41
- Telecommunications 28
- NGOs / Associations 23
- Sports 1
Typical Attacks (52)
▼How Qilin typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Qilin.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: Qilin has been delivered through exploitation of exposed applications and interfaces including Citrix and RDP.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1566.001 Spearphishing Attachment Initial Access
What they do: Qilin has been delivered to victims through malicious email attachments.
What that means: Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems.
-
T1566.002 Spearphishing Link Initial Access
What they do: Qilin has been delivered via malicious links in spearphishing emails.
What that means: Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems.
-
T1047 Windows Management Instrumentation Execution
What they do: Qilin can use WMIC to change the Volume Shadow Copy Service (VSS) startup type to manual.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
What they do: Qilin has pushed scheduled tasks via Group Policy Objects (GPOs) for execution.
What that means: Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code.
-
T1059.001 PowerShell Execution
What they do: Qilin has been deployed on VMware vCenter and ESXi servers via custom PowerShell script.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Qilin has run `cmd /C [PsExec] -accepteula \\IP Address -c -f -h -d -i C:\Users\xxx\<encryptor_1>.exe --password [PASSWORD] --spread --spread-process` to execute its encryptor to target multiple network shares.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: Qilin can attempt to log on to the local computer via `LogonUserW` and use `GetLogicalDrives()` and `EnumResourceW()` for discovery.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1204.001 Malicious Link Execution
What they do: Qilin has been executed by luring victims into clicking links in spearphishing emails.
What that means: An adversary may rely upon a user clicking a malicious link in order to gain execution.
-
T1204.002 Malicious File Execution
What they do: Qilin has been delivered to victims through spearphishing emails with malicious attachments.
What that means: An adversary may rely upon a user opening a malicious file in order to gain execution.
-
What they do: Qilin can make Registry modifications to share networked drives between elevated and non-elevated processes and to increase the number of outstanding network requests per client.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: Qilin has created a RunOnce autostart entry at `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce*aster = %Public%\enc.exe` pointing to a dropped copy of itself in the Public folder.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
What they do: Qilin can configure a Winlogon registry entry.
What that means: Adversaries may abuse features of Winlogon to execute DLLs and/or executables when a user logs in.
-
What they do: Qilin can inject pwndll.dll, a patched DLL from the legitimate DLL WICloader.dll, into svchost.exe for continuous execution.
What that means: Adversaries may inject dynamic-link libraries (DLLs) into processes in order to evade process-based defenses as well as possibly elevate privileges.
-
What they do: Qilin can use an embedded Mimikatz module for token manipulation.
What that means: Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls.
-
What they do: Qilin has pushed a scheduled task via a Group Policy Object for payload execution.
What that means: Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain.
-
T1548.002 Bypass User Account Control Privilege Escalation
What they do: Qilin can bypass standard user access controls by using stolen tokens to launch processes at an elevated security context.
What that means: Adversaries may bypass UAC mechanisms to elevate process privileges on system.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: Qilin can employ several code obfuscation methods, including renaming functions, altering control flows, and encrypting strings.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1036.004 Masquerade Task or Service Stealth
What they do: Qilin has created a scheduled task named TVInstallRestore to mimic TeamViewer.
What that means: Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: Qilin has named its payload file TeamViewer_Host_Setup to disguise itself as a legitimate TeamViewer file.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1070.004 File Deletion Stealth
What they do: Qilin can delete itself from infected hosts after execution.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1480 Execution Guardrails Stealth
What they do: Qilin can require a specific password to be passed by command-line argument during execution which must match a pre-defined value in the configuration in order for it to continue execution.
What that means: Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
-
T1480.002 Mutual Exclusion Stealth
What they do: Qilin can create a mutex to ensure only one instance is running.
What that means: Adversaries may constrain execution or actions based on the presence of a mutex associated with malware.
-
T1678 Delay Execution Stealth
What they do: Qilin has the ability to delay execution.
What that means: Adversaries may employ various time-based methods to evade detection and analysis.
-
T1222 File and Directory Permissions Modification Defense Impairment
What they do: Qilin can use symbolic links to redirect file paths for remote and local objects and can use `chmod +x` to make its payload binary executable.
What that means: Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Qilin can terminate antivirus-related processes and services.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1685.005 Clear Windows Event Logs Defense Impairment
What they do: Qilin has the ability to clear Windows Event Logs.
What that means: Adversaries may clear Windows Event Logs to hide the activity of an intrusion.
-
T1688 Safe Mode Boot Defense Impairment
What they do: Qilin can reboot targeted systems in safe mode to avoid detection.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1003.001 LSASS Memory Credential Access
What they do: Qilin can employ an embedded Mimikatz module to dump LSASS memory.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1007 System Service Discovery Discovery
What they do: Qilin can identify specific services for termination or to be left running at execution.
What that means: Adversaries may try to gather information about registered local system services.
-
T1012 Query Registry Discovery
What they do: Qilin can check `HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control SystemStartOptions` to determine if a machine is running in safe mode.
What that means: Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
-
T1016 System Network Configuration Discovery Discovery
What they do: Qilin can accept a command line argument identifying specific IPs.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1018 Remote System Discovery Discovery
What they do: Qilin can enumerate domain-connected hosts during its discovery phase.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1057 Process Discovery Discovery
What they do: Qilin can define specific processes to be terminated or left alone at execution.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1069.002 Domain Groups Discovery
What they do: Qilin can run PowerShell cmdlets to discover domain groups.
What that means: Adversaries may attempt to find domain-level groups and permission settings.
-
T1082 System Information Discovery Discovery
What they do: Qilin can detect whether a system is running FreeBSD, VMkernel (ESXi), Nutanix AHV, or a standard Linux distribution to enable platform-specific encryption behaviors.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: Qilin can exclude specific directories and files from encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1087.001 Local Account Discovery
What they do: Qilin can list all local users found on a targeted system.
What that means: Adversaries may attempt to get a listing of local system accounts.
-
T1087.002 Domain Account Discovery
What they do: Qilin can use PowerShell cmdlets to enumerate domain users.
What that means: Adversaries may attempt to get a listing of domain accounts.
-
T1135 Network Share Discovery Discovery
What they do: Qilin has the ability to list network drives.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1673 Virtual Machine Discovery Discovery
What they do: Qilin can detect virtual machine environments including ESXi hosts, datacenters, and clusters within vCenter environments.
What that means: An adversary may attempt to enumerate running virtual machines (VMs) after gaining access to a host or hypervisor.
-
T1680 Local Storage Discovery Discovery
What they do: Qilin has used `GetLogicalDrives()` and `EnumResourceW()` to locate mounted drives and shares.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Qilin can embed a copy of PsExec within its payload and place it in the %Temp% directory under a randomly generated filename.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1021.004 SSH Lateral Movement
What they do: Qilin can enable SSH access on ESXi hosts.
What that means: Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH).
-
T1570 Lateral Tool Transfer Lateral Movement
What they do: Qilin has used PsExec to distribute a second encryptor, named encryptor_1.exe, across the targeted environment.
What that means: Adversaries may transfer tools or other files between systems in a compromised environment.
-
T1071.002 File Transfer Protocols Command and Control
What they do: Qilin can use WinSCP for the secure file transfer of the Linux ransomware binary to a targeted system.
What that means: Adversaries may communicate using application layer protocols associated with transferring files to avoid detection/network filtering by blending in with existing traffic.
-
T1219.002 Remote Desktop Software Command and Control
What they do: Qilin can use the Splashtop remote management service (SRManager.exe) to execute the Linux ransomware binary directly on Windows systems.
What that means: An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks.
-
T1486 Data Encrypted for Impact Impact
What they do: Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Qilin can terminate specific services on compromised hosts.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Qilin can execute `vssadmin.exe delete shadows /all /quiet` to remove volume shadow copies and can disable High Availability (HA) and Distributed Resource Scheduler (DRS) in vCenter clusters.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: Qilin can set the wallpaper on compromised hosts to display a ransom message in each encrypted folder.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
-
T1529 System Shutdown/Reboot Impact
What they do: Qilin can initiate a reboot of the backup server to hinder recovery.
What that means: Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.
Tools Observed (27)
▼Software Qilin has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README-RECOVER-[rand]_2.txt
-- Qilin We have 3.4TB of your data stored on our servers. Contact us or we will publish this data on our blog, in the media and pass it on to the relevant authorities. We are ready to offer you a discount in case of payment within a week. Your network/system was encrypted. Encrypted files have new extension. -- Compromising and sensitive data We have downloaded compromising and sensitive data from your system/network. Our group cooperates with the mass media. If you refuse to communicate with us and we do not come to an agreement, your data will be reviewed and published on our blog and on the media page (https://wikileaks2.site/) Blog links: http://kbsqoivihgdmwczmxkbovk7ss2dcynitwhhfu5yw725dboqo5kthfaad.onion http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion Data includes: - Employees personal data, CVs, DL , SSN. - Complete network map including credentials for local and remote services. - Financial information including clients data, bills, budgets, annual reports, bank statements. - Complete datagrams/schemas/drawings for manufacturing in solidworks format - And more... -- Warning 1) If you modify files - our decrypt software won't able to recover data 2) If you use third party software - you can damage/modify files (see item 1) 3) You need cipher key / our decrypt software to restore you files. 4) The police or authorities will not be able to help you get the cipher key. We encourage you to consider your decisions. -- Recovery 1) Download tor browser: https://www.torproject.org/download/ 2) Go to domain 3) Enter credentials Please note that communication with us is only possible via the website in the Tor browser, which is specified in this note. All other means of communication are not real and may be created by third parties, if such were not provided in this note or on the website specified in this note. -- Credentials Extension: 2ir53sQQAU Domain: [snip] login: [snip] password:[snip]
README-RECOVER-[rand].txt
-- Qilin Your network/system was encrypted. Encrypted files have new extension. -- Compromising and sensitive data We have downloaded compromising and sensitive data from you system/network If you refuse to communicate with us and we do not come to an agreement, your data will be published. Data includes: - Employees personal data, CVs, DL , SSN. - Complete network map including credentials for local and remote services. - Financial information including clients data, bills, budgets, annual reports, bank statements. - Complete datagrams/schemas/drawings for manufacturing in solidworks format - And more... -- Warning 1) If you modify files - our decrypt software won't able to recover data 2) If you use third party software - you can damage/modify files (see item 1) 3) You need cipher key / our decrypt software to restore you files. 4) The police or authorities will not be able to help you get the cipher key. We encourage you to consider your decisions. -- Recovery 1) Download tor browser: https://www.torproject.org/download/ 2) Go to domain 3) Enter credentials-- Credentials Extension: [snip] Domain: e3v6tjarcltwc4hdkn6fxnpkzq42ul7swf5cfqw6jzvic4577vxsxhid.onion login: [snip] password:[snip]
DtMXQFOCos-RECOVER-README.txt
-- Agenda
Your network/system was encrypted.
Encrypted files have new extension.
-- Compromising and sensitive data
We have downloaded compromising and sensitive data from you system/network
If you refuse to communicate with us and we do not come to an agreementyour data will be published.
Data includes:
- Employees personal dataCVsDLSSN.
- Complete network map including credentials for local and remote services.
- Financial information including clients databillsbudgetsannual reportsbank statements.
- Complete datagrams/schemas/drawings for manufacturing in solidworks format
- And more...
-- Warning
1) If you modify files - our decrypt software won't able to recover data
2) If you use third party software - you can damage/modify files (see item 1)
3) You need cipher key / our decrypt software to restore you files.
4) The police or authorities will not be able to help you get the cipher key. We encourage you to consider your decisions.
-- Recovery
1) Download tor browser: https://www.torproject.org/download/
2) Go to domain
3) Enter credentials
-- Credentials
Extension: DtMXQFOCos
Domain: wlh3dpptx2gt7nsxcor37a3kiyaiy6qwhdv7o6nl6iuniu5ycze5ydid.onion
login: [snip]
password: [snip]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (2564)
Search, filter and paginate the victim timeline for Qilin. Showing 101–200 of 2564.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Sanatorio Modelo de Caseros id32167 View details | Argentina | Healthcare / Pharma | — | ||
|
www.sanatoriomodelo.com.ar operates within the healthcare and medicine sector in Argentina, serving as a clinical or medical services entity based on its domain context and regional identifier. The entity is cataloged as a ransomware victim within a threat-intelligence index, with the associated threat actor identified as qilin. This listing type indicates that the organization was impacted by ransomware activity attributed to qilin, documented neutrally for intelligence and compliance reference. No specific incident details such as stolen data categories, record counts, ransom amounts, or confirmed breach specifics are included to maintain factual accuracy and avoid speculation. The entry provides authoritative context linking the entity, its sector, location, listing classification, and associated threat actor. |
||||||
| Ransomware | Sanatorio Modelo de Caseros id32167 View details | Argentina | Healthcare / Pharma | — | ||
|
N/A |
||||||
| Ransomware | KenEp Resources id32168 View details | Malaysia | IT | — | ||
|
www.kenep.com.my operates within the IT sector and is situated in Malaysia. The entity functions as an information technology organization, providing relevant digital services or infrastructure within its geographic and industry context. Within the threat-intelligence index, this listing type identifies www.kenep.com.my as a ransomware victim linked to the threat actor qilin. This designation reflects the cybersecurity context in which the entity appears, highlighting its association with malicious activity targeting IT infrastructure. The description remains factual and neutral, focusing on the entity's classification and its relationship to the specified threat actor without elaborating on unverified incident details. |
||||||
| Ransomware | KenEp Resources id32168 View details | Malaysia | IT | — | ||
|
N/A |
||||||
| Ransomware | Metal Conversions id32142 View details | United Kingdom | Manufacturing / Engineering | — | ||
|
www.metalconversions.com operates within the Manufacturing and Engineering sector from the United Kingdom. The entity provides conversion-focused services and solutions aligned with industrial production and engineering workflows. It is cataloged in this threat-intelligence index as a ransomware victim associated with the threat actor qilin. This listing reflects the cybersecurity event classification without disclosing unverified technical details, data scope, or financial impact. The record serves to contextualize the entity within active cyber threat landscapes affecting industrial sectors globally. |
||||||
| Ransomware | Metal Conversions id32142 View details | United Kingdom | Manufacturing / Engineering | — | ||
|
N/A |
||||||
| Ransomware | California Truck Equipment id32143 View details | United States | Manufacturing / Engineering | — | ||
|
www.ctec-truckbody.com operates within the United States manufacturing and engineering sector, providing specialized truck body fabrication and related industrial services. The entity is cataloged as a ransomware victim within the threat-intelligence index, associated with the threat actor qilin. This listing type indicates cybersecurity incident classification rather than confirmed breach details, avoiding speculation on stolen data, ransom demands, or operational impact. The record serves to contextualize the organization's sector, geographic presence, and its documented relationship to the identified threat actor for threat-intelligence analysis and risk assessment purposes. |
||||||
| Ransomware | California Truck Equipment id32143 View details | United States | Manufacturing / Engineering | — | ||
|
N/A |
||||||
| Ransomware | Northern Leasing Systems id32144 View details | Canada | Retail / E-commerce | — | ||
|
www.northerndirect.com operates within the retail and e-commerce sector, based in Canada, providing digital commerce solutions and online shopping services to customers and partners. In the threat-intelligence index, this entity is classified specifically as a ransomware victim associated with the threat actor qilin. The listing type indicates that the organization was impacted by ransomware activity, contextualized within the broader cyber threat landscape affecting retail and e-commerce sectors. This entry serves as a reference point for analysts tracking ransomware campaigns, threat actor methodologies, and victim profiles across industries. The description remains factual and neutral, noting the association without elaborating on unverified incident details. |
||||||
| Ransomware | Northern Leasing Systems id32144 View details | Canada | Retail / E-commerce | — | ||
|
N/A |
||||||
| Ransomware | Integrex RCM id32138 View details | United States | Healthcare / Pharma | — | ||
|
IntegrexHealth.com operates within the United States healthcare and pharmaceutical sector, providing clinical services and health-related solutions. As a ransomware victim, it appears in this threat-intelligence index linked to the Qilin threat actor. The listing type identifies the entity's status within cybersecurity threat reporting without disclosing unverified incident details. This catalog entry serves to inform defenders and analysts about potential attack pathways targeting healthcare infrastructure. The association reflects documented intelligence concerning Qilin's targeting patterns in critical sectors. |
||||||
| Ransomware | Integrex RCM id32138 View details | United States | Healthcare / Pharma | — | ||
|
N/A |
||||||
| Ransomware | ATF id32139 View details | United States | Public Sector | pending | ||
|
www.atf.gov is a United States government entity operating within the Public Sector, providing financial crime enforcement, asset recovery, and regulatory services for financial institutions and related entities. As documented in the threat-intelligence index, this entity is categorized as a ransomware victim linked to the qilin threat actor. The listing reflects observed security intelligence correlating the domain and organization with malicious activity targeting public infrastructure. This entry contributes to broader awareness of ransomware campaigns affecting government and public sector environments in the United States. The description remains factual and neutral, focusing solely on the indexed association without elaborating on unverified incident details. |
||||||
| Ransomware | ATF id32139 View details | United States | Public Sector | pending | ||
|
N/A |
||||||
| Ransomware | WireCo id32140 View details | United States | Manufacturing / Engineering | — | ||
|
www.wireco.com operates within the United States, serving the Manufacturing and Engineering sector with specialized technical and operational services. The entity has been cataloged in the threat-intelligence index with the listing type ransomware victim, associated with the threat actor qilin. This classification reflects the security context in which the organization appears within cyber threat datasets, without confirming specific incident details such as data accessed, operational impact, or recovery actions. The description maintains a neutral, encyclopedic tone consistent with premium catalog copy for threat-intelligence resources. It provides contextual clarity regarding the entity's sector, geographic origin, and its documented association with qilin as a ransomware victim. |
||||||
| Ransomware | WireCo id32140 View details | United States | Manufacturing / Engineering | — | ||
|
N/A |
||||||
| Ransomware | Air International Thermal Systems id32134 View details | United Kingdom | Manufacturing / Engineering | — | ||
|
ai-thermal.com operates within the manufacturing and engineering sector from the United Kingdom, providing technology-focused services aligned with industrial operations and engineering workflows. This entity is cataloged as a ransomware victim within the threat-intelligence index, associated with the threat actor qilin. The listing type indicates a cybersecurity incident context without disclosing confirmed details such as stolen data, affected systems, or financial impact. For threat analysts and security professionals, this entry contributes contextual intelligence regarding ransomware activity targeting manufacturing and engineering organizations in the GB region. The record is presented neutrally to support catalog-based monitoring and risk assessment. |
||||||
| Ransomware | Air International Thermal Systems id32134 View details | United Kingdom | Manufacturing / Engineering | — | ||
|
N/A |
||||||
| Ransomware | Brazosport College id32129 View details | United States | Education | — | ||
|
www.brazosport.edu is an educational institution located within the United States, operating within the education sector and providing academic and institutional services. The entity is cataloged in this threat-intelligence index as a ransomware victim linked to the threat actor qilin. This listing type indicates a cybersecurity incident context associated with the organization. The description avoids speculative details regarding breach specifics, data exposure, or financial impact, maintaining strict adherence to verified intelligence sources. Neutral and authoritative reporting ensures clarity for stakeholders monitoring education sector security risks. |
||||||
| Ransomware | Brazosport College id32129 View details | United States | Education | — | ||
|
N/A |
||||||
| Ransomware | SC PaderTeG Cabluri Electrice id32124 View details | Romania | Manufacturing / Engineering | — | ||
|
www.paderteg.ro is a company based in Romania operating within the manufacturing and engineering sectors, providing specialized technical and operational services relevant to industrial workflows. The entity is cataloged in this threat-intelligence index as a ransomware victim associated with the threat actor qilin. This listing type indicates that the organization was impacted by ransomware activity connected to qilin, without disclosing specific technical details, data exfiltration specifics, or confirmed incident metrics. The description focuses on the entity's sector, geographic origin, and its classification within the intelligence dataset for threat-aware analysis and context. It serves as a reference point for monitoring ransomware incidents within Romanian industrial sectors and tracking associations with identified threat actors. |
||||||
| Ransomware | SC PaderTeG Cabluri Electrice id32124 View details | Romania | Manufacturing / Engineering | — | ||
|
N/A |
||||||
| Ransomware | STRUCTURED SETTLEMENT CAPITAL LLC id32098 View details | United States | Services | leaked | ||
|
www.123lumpsum.com operates within the Services sector based in the United States, providing business and operational services. It is cataloged in this threat-intelligence index as a ransomware victim linked to the qilin threat actor. The listing type identifies the entity's role in a cyber incident involving this specific adversary group. This entry documents the association without disclosing unverified incident details such as data stolen, ransom demands, or precise timelines. The classification supports threat analysts monitoring ransomware activity across service-oriented organizations in the US. |
||||||
| Ransomware | STRUCTURED SETTLEMENT CAPITAL LLC id32098 View details | United States | Services | leaked | ||
|
N/A |
||||||
| Ransomware | AGROLAND S.A. id32095 View details | Romania | Agriculture / Food | — | ||
|
www.agroland.com operates within the Agriculture and Food sector and is situated in Romania. The entity provides offerings aligned with agricultural supply chain management, food production support services, and related commercial solutions serving regional and international markets. It has been documented in the threat-intelligence index under the classification ransomware victim, with the associated threat actor identified as qilin. This listing reflects observed cybersecurity intelligence data concerning the entity's exposure profile within the agricultural technology landscape. The entry serves to inform security professionals and stakeholders about potential risks facing organizations in this sector and region. |
||||||
| Ransomware | AGROLAND S.A. id32095 View details | Romania | Agriculture / Food | — | ||
|
N/A |
||||||
| Ransomware | Consultores de Seguros id32090 View details | France | Services | leaked | ||
|
www.consegsa.com operates within the Services sector and is headquartered in France (FR), providing professional consulting and related service offerings. The entity is documented within this threat-intelligence index under the listing type ransomware victim. Its association is specifically tied to the threat actor identified as qilin, indicating a cybersecurity event of this classification in the indexed dataset. No additional technical or operational incident details are asserted beyond the verified listing context. This description maintains neutrality and aligns with authoritative catalog standards for threat-intelligence reporting. |
||||||
| Ransomware | Consultores de Seguros id32090 View details | France | Services | leaked | ||
|
N/A |
||||||
| Ransomware | Coldfish Seafood id32067 View details | Canada | Retail / E-commerce | — | ||
|
www.coldfish.ca operates within the Canadian retail and e-commerce sector, providing digital commerce and customer-facing services. It is cataloged in the threat-intelligence index under the listing type ransomware victim, associated with the threat actor qilin. The entry documents the entity's involvement within this cybersecurity incident context without disclosing unverified technical details, data scope, or recovery specifics. This neutral profile supports threat-intelligence research and sector-focused risk assessment for retail and e-commerce environments in Canada. It was listed as a ransomware victim associated with qilin. |
||||||
| Ransomware | Coldfish Seafood id32067 View details | Canada | Retail / E-commerce | — | ||
|
N/A |
||||||
| Ransomware | A&E + SMA Design id32065 View details | United Arab Emirates | Services | — | ||
|
www.ae.design operates within the Services sector and is situated in the country AE. The entity functions as a service provider, offering professional design and related service offerings aligned with its geographic and sectoral positioning. Within the threat-intelligence index, www.ae.design is cataloged as a ransomware victim linked to the threat actor qilin. This listing reflects its inclusion in cyber threat records tied to this specific actor profile without disclosing unverified incident details. The entry serves to document the relationship between the entity, its sector context, and the associated threat actor for analytical and defensive reference. |
||||||
| Ransomware | A&E + SMA Design id32065 View details | United Arab Emirates | Services | — | ||
|
N/A |
||||||
| Ransomware | S.E.M.P. s.r.l. id32057 View details | Italy | IT | — | ||
|
www.semp.it operates within the IT sector and serves as a catalog entry under the ransomware victim listing type within this threat-intelligence index. Its inclusion reflects documented intelligence linking the entity to the qilin threat actor, providing context for security analysts monitoring ransomware campaigns in the IT domain. The entry captures the association between www.semp.it and qilin without disclosing unverified incident specifics such as data stolen, affected systems, or financial impact. This neutral description supports researchers and defenders in understanding ransomware exposure patterns within digital infrastructure sectors. The listing type and associated threat actor details are presented factually to aid threat-hunting and incident response workflows. |
||||||
| Ransomware | S.E.M.P. s.r.l. id32057 View details | Italy | IT | — | ||
|
N/A |
||||||
| Ransomware | Euroflora srl id32055 View details | Italy | Retail / E-commerce | — | ||
|
www.euroflorasrl.it represents a company operating within the IT sector, specifically within Retail and E-commerce. The domain identifier suggests an Italian-based business entity, though specific operational details remain limited to its classification in the threat-intelligence index. This listing type identifies the entity as a ransomware victim associated with the threat actor qilin. The catalog entry provides neutral context regarding the affected organization's sector and geographic classification without disclosing unverified incident specifics. This information supports threat analysts tracking ransomware campaigns and associated victim profiles across digital commerce environments. |
||||||
| Ransomware | Euroflora srl id32055 View details | Italy | Retail / E-commerce | — | ||
|
N/A |
||||||
| Ransomware | Tecnici Associati STP id32056 View details | Italy | Services | — | ||
|
www.Tecnici Associati STP.it operates within the IT Services sector, providing technical support and associated services based in Italy. The entity functions as a professional service provider focused on technology solutions and client assistance across service-oriented industries. Within the threat-intelligence index, this organization is categorized as a ransomware victim associated with the threat actor qilin. This listing type indicates its inclusion in cybersecurity records due to a ransomware-related incident connected to qilin's activity. The description remains factual and neutral, reflecting the entity's sector, location, and its documented association with the specified threat actor without disclosing unconfirmed incident details. |
||||||
| Ransomware | Tecnici Associati STP id32056 View details | Italy | Services | — | ||
|
N/A |
||||||
| Ransomware | Studio BOLDRIN PAOLO id32052 View details | Italy | IT | — | ||
|
www.paoloboldrin.it operates within the IT sector and is cataloged as a ransomware victim in the threat-intelligence index. The entity's domain and associated context align with the IT industry, reflecting infrastructure and service environments relevant to cyber threat analysis. Its listing type identifies it as directly affected by ransomware activity, with the associated threat actor designated as qilin. This entry serves as a reference point for threat-intelligence researchers tracking ransomware incidents across IT sectors and regions. The entity was listed as a ransomware victim associated with qilin. |
||||||
| Ransomware | Studio BOLDRIN PAOLO id32052 View details | Italy | IT | — | ||
|
N/A |
||||||
| Ransomware | Aurore Development S.p.A. id32053 View details | Italy | Construction / Real Estate | leaked | ||
|
www.auroredevelopment.it operates within the IT sector, specifically within the Construction and Real Estate domain, providing development and related digital services. The entity is catalogued in this threat-intelligence index under the listing type ransomware victim, linked to the threat actor qilin. This designation reflects its inclusion in intelligence records documenting cybersecurity incidents affecting organizations in this sector and geographic context. The entry serves to inform analysts and stakeholders about the association without disclosing unverified technical or operational details of the incident. |
||||||
| Ransomware | Aurore Development S.p.A. id32053 View details | Italy | Construction / Real Estate | leaked | ||
|
N/A |
||||||
| Ransomware | Clear Align id32047 View details | United States | IT | — | ||
|
www.clearalign.com operates within the IT sector and serves business clients requiring technology solutions and services. The entity is cataloged within this threat-intelligence index under the listing type ransomware victim, linked to the threat actor qilin. This designation reflects the intelligence assessment connecting ClearAlign to an incident attributed to qilin, without disclosing unverified technical or operational details. The record emphasizes the relationship between the entity, its sector context, and the associated threat actor for catalog and research purposes. |
||||||
| Ransomware | Clear Align id32047 View details | United States | IT | — | ||
|
N/A |
||||||
| Ransomware | Difor id32048 View details | Chile | Services | — | ||
|
www.difor.cl is an entity operating within the Services sector located in Chile (CL), providing commercial services to clients and stakeholders within its regional market. The organization has been cataloged within a threat-intelligence index specifically under the designation of ransomware victim. This listing reflects its association with the threat actor known as qilin, a sophisticated adversary operating in cyber threat landscapes. The catalog entry documents the entity's classification without disclosing specific technical incident details, maintaining strict adherence to factual reporting standards. Understanding such victim profiles enhances defensive strategies and threat modeling for service-sector organizations globally. |
||||||
| Ransomware | Difor id32048 View details | Chile | Services | — | ||
|
N/A |
||||||
| Ransomware | Black Cat Engineering & Construction WLL id32049 View details | Qatar | IT | deleted | ||
|
www.blackcat.com.qa operates within the IT sector and is situated in Qatar. The entity functions as a technology service provider or organization within the information technology domain. In the threat intelligence index under consideration, it is formally listed as a ransomware victim associated with the threat actor qilin. This classification reflects its inclusion within cybersecurity records documenting ransomware-related activity and entity exposure. The listing provides context for analysts tracking threat actor campaigns and victim profiles across sectors and geographies. |
||||||
| Ransomware | Black Cat Engineering & Construction WLL id32049 View details | Qatar | IT | deleted | ||
|
N/A |
||||||
| Ransomware | Quaker State Mexico id31963 View details | Mexico | — | — | ||
|
N/A |
||||||
| Ransomware | iPic id31964 View details | United States | — | — | ||
|
N/A |
||||||
| Ransomware | Cinépolis id31967 View details | Mexico | — | pending | ||
|
N/A |
||||||
| Ransomware | Gindre India id31969 View details | India | — | — | ||
|
N/A |
||||||
| Ransomware | The Pendas Law Firm id31973 View details | United States | — | — | ||
|
N/A |
||||||
| Ransomware | Blake Services id31974 View details | United States | — | — | ||
|
N/A |
||||||
| Ransomware | Professional id31975 View details | United States | — | — | ||
|
N/A |
||||||
| Ransomware | Questronix id31864 View details | Philippines | — | leaked | ||
|
N/A |
||||||
| Ransomware | Provite id31865 View details | Netherlands | — | — | ||
|
N/A |
||||||
| Ransomware | Trends And Concepts id31866 View details | South Africa | — | leaked | ||
|
N/A |
||||||
| Ransomware | Semana id31873 View details | Spain | — | — | ||
|
N/A |
||||||
| Ransomware | Thrifty Building Supply id31895 View details | United States | — | — | ||
|
N/A |
||||||
| Ransomware | Estech id31896 View details | Germany | — | — | ||
|
N/A |
||||||
| Ransomware | Constructora Jimenez id31897 View details | Mexico | — | — | ||
|
N/A |
||||||
| Ransomware | Movitecnica id31898 View details | Peru | — | — | ||
|
N/A |
||||||
| Ransomware | WIS LOGISTICS id31903 View details | United States | — | — | ||
|
N/A |
||||||
| Ransomware | InVentry id31904 View details | United Kingdom | — | — | ||
|
N/A |
||||||
| Ransomware | Philippe Hottinguer Finance id31905 View details | France | — | leaked | ||
|
N/A |
||||||
| Ransomware | Medochemie id31906 View details | Cyprus | — | leaked | ||
|
N/A |
||||||
| Ransomware | Smart Energies id31907 View details | Germany | — | — | ||
|
N/A |
||||||
| Ransomware | Integraduanas id31909 View details | Uruguay | — | pending | ||
|
N/A |
||||||
| Ransomware | Berlin Brandenburgische Wohnungsbaugenossenschaft id31827 View details | Germany | — | — | ||
|
N/A |
||||||
| Ransomware | GSW Gemeinschaftsstadtwerke GmbH id31805 View details | Germany | — | — | ||
|
N/A |
||||||
| Ransomware | White-Daters & Associates, Inc id31806 View details | United States | — | leaked | ||
|
N/A |
||||||
| Ransomware | The University of the West Indies id31807 View details | Trinidad and Tobago | — | pending | ||
|
N/A |
||||||
| Ransomware | EmpireWorks id31808 View details | — | — | |||
|
N/A |
||||||
| Ransomware | Teikoku USA id31777 View details | United States | Manufacturing / Engineering | — | ||
|
Teikoku USA is a company operating in the manufacturing and engineering sector, based in the United States. The company likely provides various products and services related to its sector. Teikoku USA was listed as a ransomware victim associated with qilin. |
||||||
| Ransomware | Teikoku USA id31777 View details | United States | Manufacturing / Engineering | — | ||
|
N/A |
||||||
| Ransomware | AGUNSA id31778 View details | Chile | Transportation / Travel / Logistics | — | ||
|
Agunsa is a Chile-based company operating in the transportation, travel, and logistics sector, providing services to facilitate the movement of goods and people. The company's offerings cater to the needs of various industries, including shipping and freight. Agunsa is listed as a ransomware victim associated with Qilin |
||||||
| Ransomware | AGUNSA id31778 View details | Chile | Transportation / Travel / Logistics | — | ||
|
N/A |
||||||
| Ransomware | Coface id31779 View details | Italy | — | — | ||
|
N/A |
||||||
| Ransomware | Spoonful of Comfort id31780 View details | United States | — | leaked | ||
|
N/A |
||||||
| Ransomware | Mulino Padano id31764 View details | Italy | Agriculture / Food | leaked | ||
|
Mulinopadano IT operates in the agriculture and food sector in Italy, providing various offerings to its customers. The company is involved in the production and distribution of food products. Mulinopadano IT was listed as a ransomware victim associated with qilin |
||||||
| Ransomware | Mulino Padano id31764 View details | Italy | Agriculture / Food | leaked | ||
|
N/A |
||||||
| Ransomware | WEBA Meubelen id31765 View details | Belgium | IT | — | ||
|
WebA BE is an IT company based in Belgium, providing various IT services. The company operates in the IT sector, offering its services to clients in Belgium. WebA BE was listed as a ransomware victim associated with Qilin |
||||||
| Ransomware | WEBA Meubelen id31765 View details | Belgium | IT | — | ||
|
N/A |
||||||
| Ransomware | MOSAID Technologies id31756 View details | Canada | IT | deleted | ||
|
Mosaid is an IT company based in Canada, providing various services within the information technology sector. The company operates in the Canadian market, offering its expertise to clients. Mosaid was listed as a ransomware victim associated with qilin. |
||||||
| Ransomware | MOSAID Technologies id31756 View details | Canada | IT | deleted | ||
|
N/A |
||||||
| Ransomware | INVENSITY id31757 View details | Germany | Finance / Legal / Insurance | — | ||
|
Invensity operates in the finance, legal, and insurance sectors, providing services in Germany. The company offers various financial and insurance solutions to its clients. Invensity was listed as a ransomware victim associated with Qilin |
||||||
| Ransomware | INVENSITY id31757 View details | Germany | Finance / Legal / Insurance | — | ||
|
N/A |
||||||
| Ransomware | Megawide id31758 View details | Philippines | — | leaked | ||
|
N/A |
||||||
| Ransomware | Desatera Sdn Bhd id31752 View details | Malaysia | Construction / Real Estate | — | ||
|
Desatera is a company based in Malaysia, operating in the construction and real estate sector. The company likely provides various services related to construction, property development, and real estate management. Desatera was listed as a ransomware victim associated with qilin |
||||||
| Ransomware | Desatera Sdn Bhd id31752 View details | Malaysia | Construction / Real Estate | — | ||
|
N/A |
||||||
| Ransomware | Loescher editore Torino id31753 View details | Italy | — | — | ||
|
N/A |
||||||
| Ransomware | Botek id31754 View details | Germany | — | — | ||
|
N/A |
||||||
| Ransomware | Zanichelli id31755 View details | Italy | — | — | ||
|
N/A |
||||||
| Ransomware | Jone Précision id31745 View details | France | Manufacturing / Engineering | leaked | ||
|
Joneprecision.com is a company based in France that operates in the manufacturing and engineering sector, providing various products and services. The company's offerings cater to the needs of its clients in the industry. Joneprecision.com was listed as a ransomware victim associated with qilin |
||||||
| Ransomware | Jone Précision id31745 View details | France | Manufacturing / Engineering | leaked | ||
|
N/A |
||||||
| Ransomware | Arnall Golden Gregory id31746 View details | United States | Finance / Legal / Insurance | — | ||
|
www.agg.com operates in the finance, legal, and insurance sector in the United States, providing various services to its clients. The company's specific offerings cater to the needs of its customers within these sectors. www.agg.com was listed as a ransomware victim associated with qilin |
||||||
| Ransomware | Arnall Golden Gregory id31746 View details | United States | Finance / Legal / Insurance | — | ||
|
N/A |
||||||
| Ransomware | ASCII Group id31747 View details | Japan | Construction / Real Estate | — | ||
|
N/A |
||||||
| Ransomware | DELTA WAYS id31748 View details | Germany | — | leaked | ||
|
N/A |
||||||