Ransomware group profile · #1 by claimed victims
Qilin ransomware
Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
Victimology
Who Qilin claims to have breached, from 2,310 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 12 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| Reddrop Group | — | — | 16 Sep 2026 |
| In The Company of Huskies | — | — | 16 Sep 2026 |
| Thorndale Foundation | — | — | 16 Sep 2026 |
| Thema Foundries | — | — | 16 Sep 2026 |
| Aarsleff | — | — | 16 Sep 2026 |
| Aarsleff aarsleff.se | Manufacturing | SE | 16 Sep 2026 |
| Montana Civil Contractors | — | — | 15 Sep 2026 |
| Taurus Ibérica | — | — | 15 Sep 2026 |
| Taurus Ibérica taurusiberica.com | Manufacturing | ES | 15 Sep 2026 |
| ADM | — | — | 15 Sep 2026 |
| Resolve Law Group | — | — | 15 Sep 2026 |
| Montana Civil Contractors montanacivil.com | Manufacturing | US | 15 Sep 2026 |
All 2,310 Qilin victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
ATT&CK technique mapping for Qilin is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is Qilin ransomware still active?
How many victims has Qilin claimed?
Which industries does Qilin target?
Which countries are most affected by Qilin?
Where does VULONE get Qilin victim data?
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].