Qilin
From extortion.wiki, the ransomware notes archive
3 archived notes associated with the upstream family directory qilin. The family label follows ThreatLabz; any link to negotiation records uses an explicit archive alias mapping.
Archived note files
3 supported · 0 skipped| Original filename | File type | Content hash | Source | Internal archive |
|---|---|---|---|---|
| DtMXQFOCos-RECOVER-README.txt | Plain text (.txt) | 33ec857658355309… | Upstream file | Read archived source |
| README-RECOVER-[rand]_2.txt | Plain text (.txt) | 64d535c6f51d772f… | Upstream file | Read archived source |
| README-RECOVER-[rand].txt | Plain text (.txt) | f18a811db350910c… | Upstream file | Read archived source |
Negotiation records
Threat actor page: QilinAn explicit archive alias maps the ThreatLabz family Qilin to the Ransomchats actor label Qilin. Note and negotiation counts remain separate.
| Participants | Source | Archive status | |||
|---|---|---|---|---|---|
| 20250203 - from @RakeshKrish12 | 36 | Qilin, Victim | JSON | Indexed | |
| 20240429 | 3 | Qilin, Victim | JSON | Indexed |
Dataset provenance and citation
| Upstream collector | Zscaler ThreatLabz |
|---|---|
| Source repository | ThreatLabz/ransomware_notes |
| Source directory | qilin |
| Snapshot commit | 2bbf5b4ecda84837c4a71af1a99c6821920f051a |
| Dataset snapshot | Jun 26, 2026, 10:27 PM |
| Synchronization time | Jul 22, 2026, 11:47 AM |
| Source status | Complete |
| License | MIT; preserved notice |
| Stable internal citation | extortion.wiki. Qilin ransomware notes. ThreatLabz/ransomware_notes snapshot 2bbf5b4ecda84837c4a71af1a99c6821920f051a. https://extortion.wiki/notes/qilin/. |