Ransomware Group intelligence
Qilin
ActiveTrack Qilin with 2564 published victims and 5 known leak locations in a single intelligence view.
Overview
Qilin is tracked by Breach House as a ransomware group with 2564 published victims.
United States is currently the most targeted country in this dataset.
5 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 120 74.5%
- Pending 33 20.5%
- Deleted 8 5.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (5)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Up checked 1h ago | ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion |
| Leak location 5 | Onion service | Down checked 1h ago | ji57fr53anp7wb44tbbnp72qcgbhqywy4jmbncawdcrejj5amuvh3zqd.onion |
| Leak location 2 | Onion service | Down checked 1h ago | kbsqoivihgdmwczmxkbovk7ss2dcynitwhhfu5yw725dboqo5kthfaad.onion |
| Leak location 4 | Onion service | Down checked 1h ago | b4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion |
| Leak location 1 | Onion service | Down checked 1h ago | ozsxj4hwxub7gio347ac7tyqqozvfioty37skqilzo2oqfs4cw2mgtyd.onion |
Top Activity Sectors (18)
- Not identified 498
- Communication / Marketing 271
- Manufacturing / Engineering 201
- Services 201
- Finance / Legal / Insurance 171
- Construction / Real Estate 157
- Healthcare / Pharma 139
- IT 121
- Retail / E-commerce 88
- Education 73
- Public Sector 68
- Transportation / Travel / Logistics 53
- Energy 53
- Hospitality / Food & Beverage / Tourism 45
- Agriculture / Food 41
- Telecommunications 28
- NGOs / Associations 23
- Sports 1
Typical Attacks (52)
▼How Qilin typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Qilin.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: Qilin has been delivered through exploitation of exposed applications and interfaces including Citrix and RDP.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1566.001 Spearphishing Attachment Initial Access
What they do: Qilin has been delivered to victims through malicious email attachments.
What that means: Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems.
-
T1566.002 Spearphishing Link Initial Access
What they do: Qilin has been delivered via malicious links in spearphishing emails.
What that means: Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems.
-
T1047 Windows Management Instrumentation Execution
What they do: Qilin can use WMIC to change the Volume Shadow Copy Service (VSS) startup type to manual.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
What they do: Qilin has pushed scheduled tasks via Group Policy Objects (GPOs) for execution.
What that means: Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code.
-
T1059.001 PowerShell Execution
What they do: Qilin has been deployed on VMware vCenter and ESXi servers via custom PowerShell script.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Qilin has run `cmd /C [PsExec] -accepteula \\IP Address -c -f -h -d -i C:\Users\xxx\<encryptor_1>.exe --password [PASSWORD] --spread --spread-process` to execute its encryptor to target multiple network shares.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: Qilin can attempt to log on to the local computer via `LogonUserW` and use `GetLogicalDrives()` and `EnumResourceW()` for discovery.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1204.001 Malicious Link Execution
What they do: Qilin has been executed by luring victims into clicking links in spearphishing emails.
What that means: An adversary may rely upon a user clicking a malicious link in order to gain execution.
-
T1204.002 Malicious File Execution
What they do: Qilin has been delivered to victims through spearphishing emails with malicious attachments.
What that means: An adversary may rely upon a user opening a malicious file in order to gain execution.
-
What they do: Qilin can make Registry modifications to share networked drives between elevated and non-elevated processes and to increase the number of outstanding network requests per client.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: Qilin has created a RunOnce autostart entry at `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce*aster = %Public%\enc.exe` pointing to a dropped copy of itself in the Public folder.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
What they do: Qilin can configure a Winlogon registry entry.
What that means: Adversaries may abuse features of Winlogon to execute DLLs and/or executables when a user logs in.
-
What they do: Qilin can inject pwndll.dll, a patched DLL from the legitimate DLL WICloader.dll, into svchost.exe for continuous execution.
What that means: Adversaries may inject dynamic-link libraries (DLLs) into processes in order to evade process-based defenses as well as possibly elevate privileges.
-
What they do: Qilin can use an embedded Mimikatz module for token manipulation.
What that means: Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls.
-
What they do: Qilin has pushed a scheduled task via a Group Policy Object for payload execution.
What that means: Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain.
-
T1548.002 Bypass User Account Control Privilege Escalation
What they do: Qilin can bypass standard user access controls by using stolen tokens to launch processes at an elevated security context.
What that means: Adversaries may bypass UAC mechanisms to elevate process privileges on system.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: Qilin can employ several code obfuscation methods, including renaming functions, altering control flows, and encrypting strings.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1036.004 Masquerade Task or Service Stealth
What they do: Qilin has created a scheduled task named TVInstallRestore to mimic TeamViewer.
What that means: Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: Qilin has named its payload file TeamViewer_Host_Setup to disguise itself as a legitimate TeamViewer file.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1070.004 File Deletion Stealth
What they do: Qilin can delete itself from infected hosts after execution.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1480 Execution Guardrails Stealth
What they do: Qilin can require a specific password to be passed by command-line argument during execution which must match a pre-defined value in the configuration in order for it to continue execution.
What that means: Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
-
T1480.002 Mutual Exclusion Stealth
What they do: Qilin can create a mutex to ensure only one instance is running.
What that means: Adversaries may constrain execution or actions based on the presence of a mutex associated with malware.
-
T1678 Delay Execution Stealth
What they do: Qilin has the ability to delay execution.
What that means: Adversaries may employ various time-based methods to evade detection and analysis.
-
T1222 File and Directory Permissions Modification Defense Impairment
What they do: Qilin can use symbolic links to redirect file paths for remote and local objects and can use `chmod +x` to make its payload binary executable.
What that means: Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Qilin can terminate antivirus-related processes and services.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1685.005 Clear Windows Event Logs Defense Impairment
What they do: Qilin has the ability to clear Windows Event Logs.
What that means: Adversaries may clear Windows Event Logs to hide the activity of an intrusion.
-
T1688 Safe Mode Boot Defense Impairment
What they do: Qilin can reboot targeted systems in safe mode to avoid detection.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1003.001 LSASS Memory Credential Access
What they do: Qilin can employ an embedded Mimikatz module to dump LSASS memory.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1007 System Service Discovery Discovery
What they do: Qilin can identify specific services for termination or to be left running at execution.
What that means: Adversaries may try to gather information about registered local system services.
-
T1012 Query Registry Discovery
What they do: Qilin can check `HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control SystemStartOptions` to determine if a machine is running in safe mode.
What that means: Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
-
T1016 System Network Configuration Discovery Discovery
What they do: Qilin can accept a command line argument identifying specific IPs.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1018 Remote System Discovery Discovery
What they do: Qilin can enumerate domain-connected hosts during its discovery phase.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1057 Process Discovery Discovery
What they do: Qilin can define specific processes to be terminated or left alone at execution.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1069.002 Domain Groups Discovery
What they do: Qilin can run PowerShell cmdlets to discover domain groups.
What that means: Adversaries may attempt to find domain-level groups and permission settings.
-
T1082 System Information Discovery Discovery
What they do: Qilin can detect whether a system is running FreeBSD, VMkernel (ESXi), Nutanix AHV, or a standard Linux distribution to enable platform-specific encryption behaviors.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: Qilin can exclude specific directories and files from encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1087.001 Local Account Discovery
What they do: Qilin can list all local users found on a targeted system.
What that means: Adversaries may attempt to get a listing of local system accounts.
-
T1087.002 Domain Account Discovery
What they do: Qilin can use PowerShell cmdlets to enumerate domain users.
What that means: Adversaries may attempt to get a listing of domain accounts.
-
T1135 Network Share Discovery Discovery
What they do: Qilin has the ability to list network drives.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1673 Virtual Machine Discovery Discovery
What they do: Qilin can detect virtual machine environments including ESXi hosts, datacenters, and clusters within vCenter environments.
What that means: An adversary may attempt to enumerate running virtual machines (VMs) after gaining access to a host or hypervisor.
-
T1680 Local Storage Discovery Discovery
What they do: Qilin has used `GetLogicalDrives()` and `EnumResourceW()` to locate mounted drives and shares.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Qilin can embed a copy of PsExec within its payload and place it in the %Temp% directory under a randomly generated filename.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1021.004 SSH Lateral Movement
What they do: Qilin can enable SSH access on ESXi hosts.
What that means: Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH).
-
T1570 Lateral Tool Transfer Lateral Movement
What they do: Qilin has used PsExec to distribute a second encryptor, named encryptor_1.exe, across the targeted environment.
What that means: Adversaries may transfer tools or other files between systems in a compromised environment.
-
T1071.002 File Transfer Protocols Command and Control
What they do: Qilin can use WinSCP for the secure file transfer of the Linux ransomware binary to a targeted system.
What that means: Adversaries may communicate using application layer protocols associated with transferring files to avoid detection/network filtering by blending in with existing traffic.
-
T1219.002 Remote Desktop Software Command and Control
What they do: Qilin can use the Splashtop remote management service (SRManager.exe) to execute the Linux ransomware binary directly on Windows systems.
What that means: An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks.
-
T1486 Data Encrypted for Impact Impact
What they do: Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Qilin can terminate specific services on compromised hosts.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Qilin can execute `vssadmin.exe delete shadows /all /quiet` to remove volume shadow copies and can disable High Availability (HA) and Distributed Resource Scheduler (DRS) in vCenter clusters.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: Qilin can set the wallpaper on compromised hosts to display a ransom message in each encrypted folder.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
-
T1529 System Shutdown/Reboot Impact
What they do: Qilin can initiate a reboot of the backup server to hinder recovery.
What that means: Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.
Tools Observed (27)
▼Software Qilin has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README-RECOVER-[rand]_2.txt
-- Qilin We have 3.4TB of your data stored on our servers. Contact us or we will publish this data on our blog, in the media and pass it on to the relevant authorities. We are ready to offer you a discount in case of payment within a week. Your network/system was encrypted. Encrypted files have new extension. -- Compromising and sensitive data We have downloaded compromising and sensitive data from your system/network. Our group cooperates with the mass media. If you refuse to communicate with us and we do not come to an agreement, your data will be reviewed and published on our blog and on the media page (https://wikileaks2.site/) Blog links: http://kbsqoivihgdmwczmxkbovk7ss2dcynitwhhfu5yw725dboqo5kthfaad.onion http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion Data includes: - Employees personal data, CVs, DL , SSN. - Complete network map including credentials for local and remote services. - Financial information including clients data, bills, budgets, annual reports, bank statements. - Complete datagrams/schemas/drawings for manufacturing in solidworks format - And more... -- Warning 1) If you modify files - our decrypt software won't able to recover data 2) If you use third party software - you can damage/modify files (see item 1) 3) You need cipher key / our decrypt software to restore you files. 4) The police or authorities will not be able to help you get the cipher key. We encourage you to consider your decisions. -- Recovery 1) Download tor browser: https://www.torproject.org/download/ 2) Go to domain 3) Enter credentials Please note that communication with us is only possible via the website in the Tor browser, which is specified in this note. All other means of communication are not real and may be created by third parties, if such were not provided in this note or on the website specified in this note. -- Credentials Extension: 2ir53sQQAU Domain: [snip] login: [snip] password:[snip]
README-RECOVER-[rand].txt
-- Qilin Your network/system was encrypted. Encrypted files have new extension. -- Compromising and sensitive data We have downloaded compromising and sensitive data from you system/network If you refuse to communicate with us and we do not come to an agreement, your data will be published. Data includes: - Employees personal data, CVs, DL , SSN. - Complete network map including credentials for local and remote services. - Financial information including clients data, bills, budgets, annual reports, bank statements. - Complete datagrams/schemas/drawings for manufacturing in solidworks format - And more... -- Warning 1) If you modify files - our decrypt software won't able to recover data 2) If you use third party software - you can damage/modify files (see item 1) 3) You need cipher key / our decrypt software to restore you files. 4) The police or authorities will not be able to help you get the cipher key. We encourage you to consider your decisions. -- Recovery 1) Download tor browser: https://www.torproject.org/download/ 2) Go to domain 3) Enter credentials-- Credentials Extension: [snip] Domain: e3v6tjarcltwc4hdkn6fxnpkzq42ul7swf5cfqw6jzvic4577vxsxhid.onion login: [snip] password:[snip]
DtMXQFOCos-RECOVER-README.txt
-- Agenda
Your network/system was encrypted.
Encrypted files have new extension.
-- Compromising and sensitive data
We have downloaded compromising and sensitive data from you system/network
If you refuse to communicate with us and we do not come to an agreementyour data will be published.
Data includes:
- Employees personal dataCVsDLSSN.
- Complete network map including credentials for local and remote services.
- Financial information including clients databillsbudgetsannual reportsbank statements.
- Complete datagrams/schemas/drawings for manufacturing in solidworks format
- And more...
-- Warning
1) If you modify files - our decrypt software won't able to recover data
2) If you use third party software - you can damage/modify files (see item 1)
3) You need cipher key / our decrypt software to restore you files.
4) The police or authorities will not be able to help you get the cipher key. We encourage you to consider your decisions.
-- Recovery
1) Download tor browser: https://www.torproject.org/download/
2) Go to domain
3) Enter credentials
-- Credentials
Extension: DtMXQFOCos
Domain: wlh3dpptx2gt7nsxcor37a3kiyaiy6qwhdv7o6nl6iuniu5ycze5ydid.onion
login: [snip]
password: [snip]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (2564)
Search, filter and paginate the victim timeline for Qilin. Showing 301–400 of 2564.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | WD Masonry & Concrete id31206 View details | United States | Construction / Real Estate | leaked | ||
|
N/A |
||||||
| Ransomware | Universitatea De Vest Vasile Goldi Din Arad id31198 View details | Romania | NGOs / Associations | — | ||
|
UVVG.ro is a Romanian-based organization operating in the NGOs and Associations sector. The entity provides various services and support to its members and the community. UVVG.ro is listed as a ransomware victim associated with Qilin |
||||||
| Ransomware | Universitatea De Vest Vasile Goldi Din Arad id31198 View details | Romania | NGOs / Associations | — | ||
|
N/A |
||||||
| Ransomware | Service Electric id31184 View details | United States | Finance / Legal / Insurance | — | ||
|
SECV operates in the finance, legal, and insurance sector in the US, providing various services to its clients. The company is involved in financial and legal services, catering to the needs of its customers. SECV was listed as a ransomware victim associated with qilin |
||||||
| Ransomware | Service Electric id31184 View details | United States | Finance / Legal / Insurance | — | ||
|
N/A |
||||||
| Ransomware | Freedom Claims Management id31168 View details | United States | Finance / Legal / Insurance | leaked | ||
|
Freedom Claims Inc is a US-based company operating in the finance, legal, and insurance sectors. The company likely provides claims-related services to its clients. Freedom Claims Inc was listed as a ransomware victim associated with qilin. |
||||||
| Ransomware | Freedom Claims Management id31168 View details | United States | Finance / Legal / Insurance | leaked | ||
|
N/A |
||||||
| Ransomware | INTERTRUST AUSTRALIA PTY LTD id31164 View details | Australia | Finance / Legal / Insurance | — | ||
|
Seed Outsourcing is a company based in Australia, operating in the finance, legal, and insurance sector. They provide outsourcing services to clients in these industries. Seed Outsourcing was listed as a ransomware victim associated with Qilin |
||||||
| Ransomware | INTERTRUST AUSTRALIA PTY LTD id31164 View details | Australia | Finance / Legal / Insurance | — | ||
|
N/A |
||||||
| Ransomware | Asset Flooring Group Australia id31165 View details | Australia | Construction / Real Estate | — | ||
|
Asset Flooring is a company based in Australia, operating in the construction and real estate sector, providing various flooring services. The company is involved in the installation and maintenance of flooring systems for residential and commercial properties. Asset Flooring was listed as a ransomware victim associated with qilin |
||||||
| Ransomware | Asset Flooring Group Australia id31165 View details | Australia | Construction / Real Estate | — | ||
|
N/A |
||||||
| Ransomware | Mairie de Drancy id31162 View details | France | Public Sector | leaked | ||
|
The official website of Drancy, a commune in the Seine-Saint-Denis department in the Île-de-France region of France, provides information and services to its residents and visitors. As a public sector entity, it offers various municipal services and resources. Drancy was listed as a ransomware victim associated with qilin. |
||||||
| Ransomware | Mairie de Drancy id31162 View details | France | Public Sector | leaked | ||
|
N/A |
||||||
| Ransomware | Wire Products id31153 View details | United States | Manufacturing / Engineering | — | ||
|
Wireproducts.us is a US-based company operating in the manufacturing and engineering sector. The company likely provides various wire products and engineering services to its clients. Wireproducts.us is listed as a ransomware victim associated with qilin |
||||||
| Ransomware | Wire Products id31153 View details | United States | Manufacturing / Engineering | — | ||
|
N/A |
||||||
| Ransomware | The Saturday Evening Post id31140 View details | United States | Communication / Marketing | leaked | ||
|
The Saturday Evening Post is a storied American magazine that has been in publication since 1821, focusing on topics such as lifestyle, culture, and current events. As a leading publication in the communication and marketing sector, it caters to a wide audience in the United States. The Saturday Evening Post offers a range of content, including articles, stories, and features on various subjects. It was listed as a ransomware victim associated with qilin. |
||||||
| Ransomware | The Saturday Evening Post id31140 View details | United States | Communication / Marketing | leaked | ||
|
N/A |
||||||
| Ransomware | Commercial Furniture Interiors id31141 View details | United States | Finance / Legal / Insurance | — | ||
|
CFI Office is a financial services company based in the US, operating in the finance, legal, and insurance sector. The company provides various financial services to its clients. CFI Office was listed as a ransomware victim associated with Qilin |
||||||
| Ransomware | Commercial Furniture Interiors id31141 View details | United States | Finance / Legal / Insurance | — | ||
|
N/A |
||||||
| Ransomware | Dienst Pack Systems id31142 View details | Germany | Manufacturing / Engineering | — | ||
|
Dienst PackSystems is a company based in Germany, operating in the manufacturing and engineering sector. The company likely provides packaging systems and related services to its clients. Dienst PackSystems was listed as a ransomware victim associated with Qilin. |
||||||
| Ransomware | Dienst Pack Systems id31142 View details | Germany | Manufacturing / Engineering | — | ||
|
N/A |
||||||
| Ransomware | Ceragres id31143 View details | Canada | Construction / Real Estate | — | ||
|
Ceragres is a Canadian company operating in the construction and real estate sector, offering various services related to these fields. Located in Canada, the company provides solutions for construction and real estate needs. Ceragres was listed as a ransomware victim associated with Qilin |
||||||
| Ransomware | Ceragres id31143 View details | Canada | Construction / Real Estate | — | ||
|
N/A |
||||||
| Ransomware | Pointe Property Group id31144 View details | United States | Construction / Real Estate | leaked | ||
|
PointeCre is a company operating in the construction and real estate sector in the United States. The company likely provides various services related to property development and management. PointeCre was listed as a ransomware victim associated with qilin. |
||||||
| Ransomware | Pointe Property Group id31144 View details | United States | Construction / Real Estate | leaked | ||
|
N/A |
||||||
| Ransomware | Schreiner Trockenbau GmbH id31145 View details | Austria | Construction / Real Estate | leaked | ||
|
Schreiner Trockenbau is an Austrian company operating in the construction and real estate sector, providing various services related to dry construction. The company is based in Austria and offers its services to clients in the region. Schreiner Trockenbau is listed as a ransomware victim associated with qilin |
||||||
| Ransomware | Schreiner Trockenbau GmbH id31145 View details | Austria | Construction / Real Estate | leaked | ||
|
N/A |
||||||
| Ransomware | Community Management Associates id31116 View details | United States | Finance / Legal / Insurance | — | ||
|
CMA Management is a financial services company based in the United States, operating within the finance, legal, and insurance sectors. The company provides various financial management and advisory services to its clients. CMA Management was listed as a ransomware victim associated with Qilin |
||||||
| Ransomware | Community Management Associates id31116 View details | United States | Finance / Legal / Insurance | — | ||
|
N/A |
||||||
| Ransomware | The Dcoop id31078 View details | Spain | Agriculture / Food | leaked | ||
|
Dcoop is a Spanish agricultural cooperative based in Spain, operating in the agriculture and food sector. The entity provides various services and offerings to its members and the agricultural community. Dcoop es was listed as a ransomware victim associated with qilin |
||||||
| Ransomware | The Dcoop id31078 View details | Spain | Agriculture / Food | leaked | ||
|
N/A |
||||||
| Ransomware | Hawaii Family Dental id31074 View details | United States | Healthcare / Pharma | — | ||
|
Hawaii Family Dental is a healthcare service provider based in the United States, offering dental care services to patients. As a part of the healthcare sector, the company operates in the medical field, providing essential services to the community. Hawaii Family Dental was listed as a ransomware victim associated with qilin. |
||||||
| Ransomware | Hawaii Family Dental id31074 View details | United States | Healthcare / Pharma | — | ||
|
N/A |
||||||
| Ransomware | Audio Precision, Inc id31066 View details | United States | Communication / Marketing | — | ||
|
The Associated Press, or AP.com, is a US-based news organization operating in the communication and marketing sector, providing fact-based news and journalism services. AP.com offers a wide range of news coverage, including national, international, sports, and entertainment news. AP.com is listed as a ransomware victim associated with Qilin |
||||||
| Ransomware | Audio Precision, Inc id31066 View details | United States | Communication / Marketing | — | ||
|
N/A |
||||||
| Ransomware | TenSparrows id31057 View details | United States | IT | leaked | ||
|
Tensparrows is an IT company based in the United States, operating in the information technology sector. The company likely provides various IT services and solutions to its clients. Tensparrows was listed as a ransomware victim associated with qilin |
||||||
| Ransomware | TenSparrows id31057 View details | United States | IT | leaked | ||
|
N/A |
||||||
| Ransomware | Db Tarimsal Enerji id31054 View details | Türkiye | Agriculture / Food | leaked | ||
|
DB Tarimsal Enerji is a Turkish company operating in the agriculture and food sector. The company is based in Turkey and is involved in activities related to agricultural products and energy. DB Tarimsal Enerji is listed as a ransomware victim associated with Qilin |
||||||
| Ransomware | Db Tarimsal Enerji id31054 View details | Türkiye | Agriculture / Food | leaked | ||
|
N/A |
||||||
| Ransomware | Byonyks id31056 View details | United States | IT | — | ||
|
Byonyks is an IT company based in the United States, operating in the information technology sector. The company provides various IT services and solutions to its clients. Byonyks was listed as a ransomware victim associated with qilin. |
||||||
| Ransomware | Byonyks id31056 View details | United States | IT | — | ||
|
N/A |
||||||
| Ransomware | Prenisac id31049 View details | Other | — | |||
|
Prenisac operates in the other sector, providing various services. The company's specific location and offerings are not well-documented. Prenisac was listed as a ransomware victim associated with qilin. |
||||||
| Ransomware | Prenisac id31049 View details | United States | Other | — | ||
|
N/A |
||||||
| Ransomware | Excel Consultores id31050 View details | Mexico | Finance / Legal / Insurance | leaked | ||
|
Excel.com.mx is a Mexican financial services company providing insurance and legal solutions. Located in Mexico, the company operates in the finance and insurance sector, offering various financial products. Excel.com.mx is listed as a ransomware victim associated with qilin |
||||||
| Ransomware | Excel Consultores id31050 View details | Mexico | Finance / Legal / Insurance | leaked | ||
|
N/A |
||||||
| Ransomware | Affinity Capital id31051 View details | United States | Finance / Legal / Insurance | — | ||
|
Affinitycorp net operates in the finance legal and insurance sector in the US providing various services to its clients. As a company in this sector it likely handles sensitive financial and personal data. Affinitycorp net was listed as a ransomware victim associated with qilin |
||||||
| Ransomware | Affinity Capital id31051 View details | United States | Finance / Legal / Insurance | — | ||
|
N/A |
||||||
| Ransomware | Adpo id31042 View details | Belgium | Transportation / Travel / Logistics | pending | ||
|
ADPO is a logistics and transportation company based in Belgium, operating in the transportation, travel, and logistics sector. The company provides various services to facilitate the movement of goods and people. ADPO was listed as a ransomware victim associated with Qilin |
||||||
| Ransomware | Adpo id31042 View details | Belgium | Transportation / Travel / Logistics | pending | ||
|
N/A |
||||||
| Ransomware | servitelco id31043 View details | Chile | Telecommunications | leaked | ||
|
Servitelco is a telecommunications company based in Chile, providing various services to its customers. The company operates in the telecommunications sector, offering services such as internet, phone, and other related services. Servitelco was listed as a ransomware victim associated with qilin |
||||||
| Ransomware | servitelco id31043 View details | Chile | Telecommunications | leaked | ||
|
N/A |
||||||
| Ransomware | Orimar id31044 View details | Belgium | Manufacturing / Engineering | — | ||
|
Orimar.be is a company based in Belgium, operating in the manufacturing and engineering sector. The company likely provides various services and products related to its sector. Orimar.be was listed as a ransomware victim associated with qilin |
||||||
| Ransomware | Orimar id31044 View details | Belgium | Manufacturing / Engineering | — | ||
|
N/A |
||||||
| Ransomware | Indian Motos Inmot id31045 View details | Ecuador | Construction / Real Estate | leaked | ||
|
Inmot.com.ec is a company based in Ecuador, operating in the construction and real estate sector, providing various services to clients. The company's website suggests a focus on property development and management. Inmot.com.ec is listed as a ransomware victim associated with qilin |
||||||
| Ransomware | Indian Motos Inmot id31045 View details | Ecuador | Construction / Real Estate | leaked | ||
|
N/A |
||||||
| Ransomware | Hoc id31020 View details | United Kingdom | Manufacturing / Engineering | leaked | ||
|
HOC Ltd is a company based in the United Kingdom, operating in the manufacturing and engineering sector. The company provides various services and products related to its sector. HOC Ltd was listed as a ransomware victim associated with Qilin |
||||||
| Ransomware | Hoc id31020 View details | United Kingdom | Manufacturing / Engineering | leaked | ||
|
N/A |
||||||
| Ransomware | Gran valle negocios id31006 View details | Argentina | Retail / E-commerce | — | ||
|
Granvallenegocios.com.ar operates in the retail and e-commerce sector in Argentina, providing various products and services to its customers. As an e-commerce platform, it likely offers online shopping experiences, allowing users to browse and purchase products remotely. Granvallenegocios.com.ar was listed as a ransomware victim associated with qilin |
||||||
| Ransomware | Gran valle negocios id31006 View details | Argentina | Retail / E-commerce | — | ||
|
N/A |
||||||
| Ransomware | Groupe Fenwick id30987 View details | France | Retail / E-commerce | — | ||
|
Fenwick.fr is a French company operating in the retail and e-commerce sector, offering various products and services to its customers. Located in France, the company caters to the needs of its clients through its online platform. Fenwick.fr is listed as a ransomware victim associated with qilin |
||||||
| Ransomware | Groupe Fenwick id30987 View details | France | Retail / E-commerce | — | ||
|
N/A |
||||||
| Ransomware | Savills France id30970 View details | France | Construction / Real Estate | — | ||
|
Savills is a global real estate company with operations in France, providing services such as property development, investment, and management. The company operates in the construction and real estate sector, offering a range of services to clients in France. Savills France was listed as a ransomware victim associated with qilin. |
||||||
| Ransomware | Savills France id30970 View details | France | Construction / Real Estate | — | ||
|
N/A |
||||||
| Ransomware | Wilbert's id30971 View details | United States | Hospitality / Food & Beverage / Tourism | — | ||
|
Wilberts.com is a US-based company operating in the hospitality and food and beverage sector, likely providing services to the tourism industry. As a business in this sector, Wilberts.com may offer various amenities and experiences to its customers. Wilberts.com was listed as a ransomware victim associated with qilin. |
||||||
| Ransomware | Wilbert's id30971 View details | United States | Hospitality / Food & Beverage / Tourism | — | ||
|
N/A |
||||||
| Ransomware | Contacto Garantido id30881 View details | Mexico | Retail / E-commerce | — | ||
|
Contactogarantido.com is a Mexican company operating in the retail and e-commerce sector, providing various online services to its customers. Based in Mexico, the company likely offers a range of products and services to cater to the local market. Contactogarantido.com was listed as a ransomware victim associated with qilin. |
||||||
| Ransomware | Contacto Garantido id30881 View details | Mexico | Retail / E-commerce | — | ||
|
N/A |
||||||
| Ransomware | Universitatea de Vest „Vasile Goldiș” din Arad id30882 View details | Romania | NGOs / Associations | leaked | ||
|
UVVG RO is a Romanian non-governmental organization operating in the country. The entity is involved in various activities related to NGOs and associations in Romania. UVVG RO was listed as a ransomware victim associated with Qilin |
||||||
| Ransomware | Universitatea de Vest „Vasile Goldiș” din Arad id30882 View details | Romania | NGOs / Associations | leaked | ||
|
N/A |
||||||
| Ransomware | Jubilee Jobs id30843 View details | Nigeria | NGOs / Associations | — | ||
|
Jubileejobs.org is a non-governmental organization based in Nigeria, focused on providing job opportunities and related services. The organization operates in the NGOs and associations sector, catering to the needs of the local community. Jubileejobs.org was listed as a ransomware victim associated with qilin |
||||||
| Ransomware | Jubilee Jobs id30843 View details | Nigeria | NGOs / Associations | — | ||
|
N/A |
||||||
| Ransomware | Plitvička Jezera Nacionalni Park id30844 View details | Croatia | Transportation / Travel / Logistics | — | ||
|
NP Plitvicka Jezera is a national park located in Croatia, known for its natural beauty and tourism offerings. As a prominent destination in the country's travel and logistics sector, it provides various services to visitors. The national park is situated in the Plitvice Lakes area, attracting numerous tourists each year. It was listed as a ransomware victim associated with Qilin. |
||||||
| Ransomware | Plitvička Jezera Nacionalni Park id30844 View details | Croatia | Transportation / Travel / Logistics | — | ||
|
N/A |
||||||
| Ransomware | The Myers Y Cooper id30845 View details | United States | Manufacturing / Engineering | — | ||
|
Cooper Co is a US-based company operating in the manufacturing and engineering sector, providing various products and services. The company is involved in the design, development, and production of engineered products. Cooper Co has a presence in the US market, serving customers across the country. It was listed as a ransomware victim associated with Qilin |
||||||
| Ransomware | The Myers Y Cooper id30845 View details | United States | Manufacturing / Engineering | — | ||
|
N/A |
||||||
| Ransomware | Guntert & Zimmerman id30841 View details | Switzerland | Manufacturing / Engineering | — | ||
|
Guntert is a company based in Switzerland, operating in the manufacturing and engineering sector. The company likely provides various products and services related to its sector. Guntert was listed as a ransomware victim associated with qilin |
||||||
| Ransomware | Guntert & Zimmerman id30841 View details | Switzerland | Manufacturing / Engineering | — | ||
|
N/A |
||||||
| Ransomware | Principle Diagnostics Laboratory id30842 View details | India | Healthcare / Pharma | leaked | ||
|
Principlediagnostics.com is a healthcare and pharma company based in India, offering various medical services. The company operates in the healthcare sector, providing diagnostic services. Principlediagnostics.com was listed as a ransomware victim associated with Qilin |
||||||
| Ransomware | Principle Diagnostics Laboratory id30842 View details | India | Healthcare / Pharma | leaked | ||
|
N/A |
||||||
| Ransomware | GURR Abdichtungstechnik GmbH id30839 View details | Germany | Manufacturing / Engineering | leaked | ||
|
Gurr Abdichtungstechnik is a German-based company operating in the manufacturing and engineering sector, providing sealing technology solutions. The company is located in Germany and offers various products and services related to sealing technology. Gurr Abdichtungstechnik is listed as a ransomware victim associated with qilin |
||||||
| Ransomware | GURR Abdichtungstechnik GmbH id30839 View details | Germany | Manufacturing / Engineering | leaked | ||
|
N/A |
||||||
| Ransomware | GOP id30833 View details | United Kingdom | Transportation / Travel / Logistics | — | ||
|
Go Ltd is a company operating in the transportation sector in Great Britain, providing logistics and travel services. The company is based in the United Kingdom and offers various services to its clients. Go Ltd was listed as a ransomware victim associated with qilin. |
||||||
| Ransomware | GOP id30833 View details | United Kingdom | Transportation / Travel / Logistics | — | ||
|
N/A |
||||||
| Ransomware | Stryker id30825 View details | United States | Manufacturing / Engineering | pending | ||
|
Stryker is a leading American manufacturer of medical and surgical equipment, operating in the manufacturing and engineering sector. The company, headquartered in the US, offers a wide range of products and services. Stryker was listed as a ransomware victim associated with Qilin |
||||||
| Ransomware | Stryker id30825 View details | United States | Manufacturing / Engineering | pending | ||
|
N/A |
||||||
| Ransomware | Ejército Argentino id30820 View details | Argentina | Public Sector | — | ||
|
The www.argentina.gob.ar/defensa/ejercito website is the official online presence of the Argentine Army, a branch of the Argentine Armed Forces, operating under the Ministry of Defense in Argentina. The Argentine Army is responsible for land-based military operations, and its website provides information on its structure, operations, and activities. The website is part of the public sector in Argentina, offering various services and information to citizens. It was listed as a ransomware victim associated with qilin. |
||||||
| Ransomware | Ejército Argentino id30820 View details | Argentina | Public Sector | — | ||
|
N/A |
||||||
| Ransomware | Kean University id30821 View details | United States | Education | — | ||
|
Kean University is a public university located in New Jersey, United States, offering a range of undergraduate and graduate degree programs in various fields. As an institution in the education sector, it provides academic and research opportunities to students. Kean University was listed as a ransomware victim associated with qilin. |
||||||
| Ransomware | Kean University id30821 View details | United States | Education | — | ||
|
N/A |
||||||
| Ransomware | Highline Community College id30822 View details | United States | Education | — | ||
|
Highline College, located in the United States, is a public college that offers various academic programs and services to students. As an educational institution, it provides opportunities for students to pursue higher education in different fields. Highline College was listed as a ransomware victim associated with qilin. |
||||||
| Ransomware | Highline Community College id30822 View details | United States | Education | — | ||
|
N/A |
||||||
| Ransomware | Machinerie P&W id30777 View details | Canada | Manufacturing / Engineering | — | ||
|
Machinerie PW is a company based in Canada, operating in the manufacturing and engineering sector. The company likely provides machinery and equipment to various industries. Machinerie PW was listed as a ransomware victim associated with qilin |
||||||
| Ransomware | Machinerie P&W id30777 View details | Canada | Manufacturing / Engineering | — | ||
|
N/A |
||||||
| Ransomware | ABM Enviro id30778 View details | Canada | Services | — | ||
|
ABM Environnement, a services company based in Canada, provides environmental solutions. The company operates in the services sector, offering various services to its clients. ABM Environnement was listed as a ransomware victim associated with Qilin. |
||||||
| Ransomware | ABM Enviro id30778 View details | Canada | Services | — | ||
|
N/A |
||||||
| Ransomware | WellPerf id30771 View details | United Kingdom | Healthcare / Pharma | — | ||
|
Wellperf is a UK-based company operating in the healthcare and pharmaceutical sector, providing various services and offerings. The company is likely involved in the development, distribution, or research of pharmaceutical products. Wellperf was listed as a ransomware victim associated with qilin |
||||||
| Ransomware | WellPerf id30771 View details | United Kingdom | Healthcare / Pharma | — | ||
|
N/A |
||||||
| Ransomware | Corporate 360 Business Solutions id30766 View details | Canada | IT | leaked | ||
|
Corporate360.ca is a Canadian company operating in the IT sector, providing various services to its clients. As an IT company, Corporate360.ca likely offers a range of services including software development, consulting, and technology solutions. Corporate360.ca was listed as a ransomware victim associated with qilin |
||||||
| Ransomware | Corporate 360 Business Solutions id30766 View details | Canada | IT | leaked | ||
|
N/A |
||||||
| Ransomware | Assos Pharmaceuticals id30767 View details | Türkiye | Healthcare / Pharma | — | ||
|
Assos Pharma is a Turkish company operating in the healthcare and pharmaceutical sector, providing various products and services. The company is based in Turkey and serves the local market with its offerings. Assos Pharma was listed as a ransomware victim associated with Qilin |
||||||