Qilin
From extortion.wiki, the ransomware negotiation research archive
Negotiation records classified under Qilin in the current Ransomchats snapshot. This page indexes the source label; it does not independently verify attribution.
Classification follows the source dataset. Metadata is useful. It is not testimony.
Actor lineage
Global lineage directoryOverview
HHS documents the Agenda-to-Qilin rebrand. MITRE separately identifies Water Galura as the operator cluster for the Qilin RaaS; that explicit mapping is displayed without treating every Qilin affiliate as Water Galura.
Documentary media

Known aliases
| Alias | Type | First observed | Last observed | Confidence | Sources |
|---|---|---|---|---|---|
| AgendaHHS HC3 reports that the operation launched as Agenda in July 2022 and had rebranded as Qilin by September 2022. | Former name | July 2022 | September 2022 | Confirmed | MITRE ATT&CK · U.S. Department of Health and Human Services, Health Sector Cybersecurity Coordination Center |
Historical timeline
-
Qilin operation launched
Operation launches as Agenda
HHS HC3 reports that the operation initially launched as Agenda in July 2022.
Evidence status: officially confirmed Confirmed -
Qilin rebrand
Agenda rebrands as Qilin
HHS HC3 reports that the operation had rebranded from Agenda to Qilin by September 2022.
Evidence status: officially confirmed Confirmed
Lineage and relationships
No evidence-backed relationship is currently recorded. Similar code, language, infrastructure style, or negotiation behavior is not enough on its own.
Predecessors
None established.
Successors
None established.
Splits and mergers
None established.
Suspected affiliate relationships
None established.
MITRE ATT&CK integration
G1050: Water Galura · mapping status confirmed · Confirmed
MITRE explicitly identifies Water Galura as the operators of the Qilin RaaS. This mapping does not assign every Qilin affiliate to Water Galura.
MITRE associated groups: GOLD FEATHER
Associated software
Associated campaigns
None listed.
MITRE ATT&CK 19.1, synchronized 2026-07-23. MITRE enrichment remains separate from extortion.wiki lineage claims.
External intelligence references
- Water Galura, Group G1050MITRE ATT&CK · MITRE ATTACK · authoritative secondary
- Qilin, Software S1242MITRE ATT&CK · MITRE ATTACK · authoritative secondary
- Qilin, aka Agenda RansomwareU.S. Department of Health and Human Services, Health Sector Cybersecurity Coordination Center · government advisory · primary authoritative
Confidence and evidence notes
Confidence applies to each individual alias, event, or relationship—not to the actor page as a whole. “Confirmed” requires explicit authoritative attribution or multiple strong independent sources. Moderate, low, disputed, and unknown entries retain the source's uncertainty. A malware-family name is not automatically an actor identity, and shared code or affiliates do not prove shared leadership.
Ransomware notes
Browse Qilin notesThe explicit archive alias mapping connects this Ransomchats actor label to the ThreatLabz family Qilin. Its 3 archived notes are counted and searched separately from the negotiation records below.
Search within this collection
Negotiation records
| Participants | Source | Archive status | |||
|---|---|---|---|---|---|
| 20250203 - from @RakeshKrish12 | 36 | Qilin, Victim | JSON | Indexed | |
| 20240429 | 3 | Qilin, Victim | JSON | Indexed |
No matching records
No records match the current filters. Remove one before blaming the archive.