Research page reference

Archived note files

3 supported · 0 skipped
Qilin ransomware note files
Original filenameFile typeContent hashSourceInternal archive
DtMXQFOCos-RECOVER-README.txt Plain text (.txt) 33ec857658355309… Upstream file Read archived source
README-RECOVER-[rand]_2.txt Plain text (.txt) 64d535c6f51d772f… Upstream file Read archived source
README-RECOVER-[rand].txt Plain text (.txt) f18a811db350910c… Upstream file Read archived source

Negotiation records

Threat actor page: Qilin

An explicit archive alias maps the ThreatLabz family Qilin to the Ransomchats actor label Qilin. Note and negotiation counts remain separate.

Canonical lineage: Qilin. View aliases, timeline, evidence, and confidence notes.

Negotiation records explicitly mapped to Qilin
Participants Source Archive status
20250203 - from @RakeshKrish12 36 Qilin, Victim JSON Indexed
20240429 3 Qilin, Victim JSON Indexed

Dataset provenance and citation

Stable family archive information
Upstream collectorZscaler ThreatLabz
Source repositoryThreatLabz/ransomware_notes
Source directoryqilin
Snapshot commit2bbf5b4ecda84837c4a71af1a99c6821920f051a
Dataset snapshotJun 26, 2026, 10:27 PM
Synchronization timeJul 22, 2026, 11:47 AM
Source statusComplete
LicenseMIT; preserved notice
Stable internal citationextortion.wiki. Qilin ransomware notes. ThreatLabz/ransomware_notes snapshot 2bbf5b4ecda84837c4a71af1a99c6821920f051a. https://extortion.wiki/notes/qilin/.