Ransomware Group intelligence
Qilin
ActiveTrack Qilin with 2209 published victims and 5 known leak locations in a single intelligence view.
Overview
Qilin is tracked by Breach House as a ransomware group with 2209 published victims.
United States is currently the most targeted country in this dataset.
5 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (5)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Unknown | ozsxj4hwxub7gio347ac7tyqqozvfioty37skqilzo2oqfs4cw2mgtyd.onion |
| Leak location 2 | Onion service | Unknown | kbsqoivihgdmwczmxkbovk7ss2dcynitwhhfu5yw725dboqo5kthfaad.onion |
| Leak location 3 | Onion service | Unknown | ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion |
| Leak location 4 | Onion service | Unknown | b4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion |
| Leak location 5 | Onion service | Unknown | ji57fr53anp7wb44tbbnp72qcgbhqywy4jmbncawdcrejj5amuvh3zqd.onion |
Top Activity Sectors
No sector intelligence available.
Ransom Notes (0)
▼No ransom notes available for this group.
Tools Used
▼No tools used available.
YARA Rules (0)
▼No YARA rules available.
Indicators of Compromise (0)
▼No IoCs available for this group.
Negotiation Chats (0)
▼No negotiation chats available.
Research Sources
No external research sources linked yet.
Victims (2209)
Search, filter and paginate the victim timeline for Qilin. Showing 2201–2209 of 2209.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Emtelco id6345 View details | Colombia | Services | ||
|
EMTELCO SA is a company that operates in the Outsourcing/Offshoring industry. It employs 101-250 people and has $25M-$50M of revenue. We also have several hundred gigabytes of data. Data of all large clients (corporate), non-disclosure docume ... |
|||||
| Ransomware | fsmsolicitors.co.uk id6344 View details | United Kingdom | Other | ||
|
DB Backups: FSM_backup Isokon2_backup Isokon2CGT_backup Partner_backup PartnerTCDatabase_backup TCDatabase_backup Dept_data - internal data including accounts, commercial information, ligitation etc. Isocon documents Client's data ... |
|||||
| Ransomware | eyeDOCS Ottawa id6341 View details | Other | |||
|
The company has decided not to care about its customers' data. Therefore, we are forced to publish their data. You can download the first part at the link below pass for archive: ys5YHSpkbp;sYT5&^%,FPERLHP |
|||||
| Ransomware | Gropper & Nejat, PLLC id6329 View details | Services | |||
|
Another company that decided it was a good idea to ignore our team. We will now post their customer data in pieces. Pass for archive: moR~?HHJ%IqTymMH7XHv$o7fi |
|||||
| Ransomware | SIIX Corporation id6295 View details | Japan | Services | ||
|
In 3 days we will publish all the data taken from their servers. |
|||||
| Ransomware | Sippex id6108 View details | Other | |||
|
Another company that does not care about the data of its employees and customers at all. Publishing another leak |
|||||
| Ransomware | Attent Zorg en Behandeling id5556 View details | Netherlands | Telecommunications | ||
|
Dear friends decided to deceive us and their customers, saying that everything works fine for them and there were no serious leaks in the network. https://www.attentzorgenbehandeling.nl/nieuws/update-ongeautoriseerde-toegang-it-systemen W ... |
|||||
| Ransomware | GIGATRON.RS id5495 View details | Serbia | Retail / E-commerce | ||
|
Gigatron downloaded data overview: From 172.31.244.50: DB backups of shops: G1-G69, G88, G89 From 172.31.248.10: DB backups: CTRetail_backup CTRetailWSRepl_backup GigatronWMS_Sync_backup From 192.168.2.144: employee disability ... |
|||||
| Ransomware | scinopharm.com id4305 View details | Other | — | ||
|
No additional victim description available. |
|||||