← All ransomware groups
Qilin logo

Ransomware group profile · #1 by claimed victims

Qilin ransomware

Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.

Active First seen Oct 2022
2,310Victims claimed on leak sites
141Victims in the last 30 days
380Victims in the last 90 days
103Countries hit
633Leak-site URLs tracked, 3 online
16 Sep 2026Latest claim recorded

Victimology

Who Qilin claims to have breached, from 2,310 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 210OctNov 2025: 107Dec 2025: 178Jan 2026: 109JanFeb 2026: 115Mar 2026: 140Apr 2026: 108AprMay 2026: 113Jun 2026: 78Jul 2026: 127JulAug 2026: 164Sep 2026: 61

Top sectors

Manufacturing484
Professional Services391
Technology256
Healthcare196
Retail & E-Commerce166
Financial Services149
Agriculture and Food Production106
Government & Defense95

Top countries

United States978
United Kingdom110
Canada108
France107
Germany89
Spain74
Italy67
Australia40

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
Reddrop Group 16 Sep 2026
In The Company of Huskies 16 Sep 2026
Thorndale Foundation 16 Sep 2026
Thema Foundries 16 Sep 2026
Aarsleff 16 Sep 2026
Aarsleff aarsleff.se Manufacturing SE 16 Sep 2026
Montana Civil Contractors 15 Sep 2026
Taurus Ibérica 15 Sep 2026
Taurus Ibérica taurusiberica.com Manufacturing ES 15 Sep 2026
ADM 15 Sep 2026
Resolve Law Group 15 Sep 2026
Montana Civil Contractors montanacivil.com Manufacturing US 15 Sep 2026

All 2,310 Qilin victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Qilin is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Qilin ransomware still active?
Qilin is tracked as active. The most recent leak-site claim VULONE recorded is dated 16 September 2026. 141 victims were claimed in the last 30 days.
How many victims has Qilin claimed?
VULONE has recorded 2,310 leak-site victim claims attributed to Qilin since October 2022, across 103 countries and 14 sectors.
Which industries does Qilin target?
The sectors most often named on the Qilin leak site are Manufacturing, Professional Services, Technology.
Which countries are most affected by Qilin?
Most Qilin victims recorded by VULONE are located in United States, United Kingdom, Canada.
Where does VULONE get Qilin victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].