Cyber Threat Intelligence

Inside the Ecosystem, Operations: Qilin Ransomware

2026.10.08

✅ Report Title: Inside the Ecosystem, Operations: Qilin

✅ Executive Summary

📌 Who Is the Qilin Ransomware Group?

  • The Qilin ransomware group began its activities in May 2022, operating a RaaS (Ransomware-as-a-Service) model, and significantly expanded its attack operations after October 2024 through a ransomware update (Qilin.B).
  • Qilin ransomware focuses on reputation management to secure the trust of its Affiliates and maintain long-term collaborative relationships. It employs a unique revenue-sharing structure in which Affiliates directly handle ransom negotiations, receive ransom payments, and distribute the profits to Qilin.
  • Although its name originates from the Chinese mythological creature Qilin (麒麟, qilin), the group's main operators are presumed to be Russian-backed, as they have a history of communicating in Russian on dark web forums.

📌 Victims

  • A total of 669 victim cases were identified in 2026 H1 — the highest number of disclosed victim companies among all ransomware groups in the first half of 2026 — and Qilin was also rated as having the highest activity level overall.
  • The Qilin ransomware group attacked conducted widespread attacks across a broad range of industries, with the Manufacturing sector being the most heavily affected.

📌 Group Profiling

  • The Qilin ransomware group is active on several dark web forums, such as RAMP, Exploit, XSS, and DarkForums.
  • The Qilin group has expanded its scale, with a small number of Operators promoting RaaS and recruiting Affiliates.
    • The users Haise and XORacle were identified as Qilin's Operators.
  • Qilin is known as a group that has expanded its threatening activities by recruiting multiple Affiliates in the RaaS ecosystem and operating them to carry out various attack activities.
    • The users hex040816, Hunters0p3r4ti0n, and kawei were identified as Qilin's Affiliates.
  • Groups revealed to have an association with Qilin include Scattered Spider, FIN12, Moonstone Sleet, STAC4365, Devman, Arkana, LockBit, and DragonForce.

📌 Affiliate Infiltration Findings

  • Qilin's operating organization was confirmed to consist of Haise, the Operator, and a Support Team that assists with Affiliate management and operations.
  • Panel features were confirmed to include Target management, DDoS, Blog creation, Guest addition, Support Chat, News, and FAQ.

📌 Binary Analysis

  • The Qilin ransomware is divided into a Loader and Ransomware, and their respective functions are as follows.
    • Loader: Decrypts the Ransomware payload through simple calculations and loads it into memory.
    • Ransomware: The payload responsible for the actual encryption, which encrypts files using AES-256-CTR or ChaCha20 algorithms depending on AES-NI (AES New Instructions) support.

✅ Threat Detection Recommendations and Mitigation Measures:

  • The Qilin ransomware group performs RaaS promotion and Affiliate recruitment on dark web forums, and either purchases access for initial penetration or sells stolen data from victim companies, necessitating continuous dark web monitoring.
  • In particular, since Qilin was confirmed to have exploited Check Point VPN's CVE-2026-50751 and CVE-2026-50752 as zero-days in the first half of 2026, abnormal access and administrator account usage history should be reviewed before and after the disclosure of new vulnerabilities.
  • The groups associated with the Qilin ransomware group are expanding their scope of activity using constantly evolving attack tactics, requiring continuous monitoring of Qilin and its collaborative groups.

🧑‍💻 Report Author: S2W TALON

👉 Contact us: https://s2w.inc/en/contact

*For detailed inquiries about this report, please contact us.