- Also known as: Agenda
- First observed: July 2022 (as "Agenda"); rebranded "Qilin" in September 2022
- Suspected origin: Russia
- Model: Ransomware-as-a-Service (RaaS)
- Status: Active
Origins
Qilin first surfaced in mid-2022 under the name "Agenda," running Go-based ransomware against enterprise targets in Africa and Asia. By September 2022 it had rebranded to Qilin.
Daily Security Review, in a March 2025 profile of the group, offered an explanation of the group’s name suggesting that it may be deliberate act of covering their origin. Daily Security Review also flagged that a single U.S. healthcare victim has appeared on both Qilin's and LockBit's data leak sites, but they found no evidence of an operational connection between the two groups, attributing the overlap to multiple RaaS operations separately claiming the same stolen data rather than any coordination or re-victimization.
Furthermore, the U.S. Department of Health and Human Services' HC3 reported that back in 2023, Qilin's ransom demand ran only between $50,000 and $800,000, with affiliates keeping 15–20% of the proceeds. HC3 also noted that Qilin's attacks increased in 2024, with the group claiming responsibility for more than 60 ransomware attacks in the first months of that year.
Why Qilin keeps coming back to hospitals
Qilin isn't a healthcare-only operation, it has hit manufacturing, education, media, and financial services but hospitals and clinics have been a recurring target since the group's earliest days. In fact, HC3's own tracking of Qilin's data leak site as of June 2024 found that healthcare made up just over 7% of the more than 100 victims posted there, behind Manufacturing (21%), Legal and Professional Services (15%), and Financial Services (14%).
The U.S. Department of Health and Human Services' Health Sector Cybersecurity Coordination Center (HC3) issued a formal threat profile on the group in mid-2024, warning that Qilin is a ransomware-as-a-service operation in operation since 2022 that continues to target healthcare organizations and other industries worldwide, gaining initial access through spear phishing and abusing remote monitoring and management tools, and practicing double extortion by threatening to leak stolen data.
Research firm Daily Security Review noted that at least fifteen incidents involving Qilin/Agenda ransomware were identified in the Healthcare and Public Health Sector worldwide since October 2022, with roughly half impacting U.S. organizations. HC3's own review of those U.S. victims found they were generally mid-sized organizations, with annual revenues ranging from roughly $6 million to $40 million.
The Synnovis Attack
In early June 2024, Qilin attacked Synnovis, a pathology and diagnostics partner for multiple NHS hospital trusts across London. According to a June 25, 2025 report from BBC News, the June 3, 2024 attack disrupted more than 10,000 appointments across the two worst-affected London trusts, with some GP practices in the capital left unable to order blood tests for patients. NHS England's London region later put a more precise figure on that disruption, in an October 4, 2024 update, the region reported that 10,152 acute outpatient appointments and 1,710 elective procedures had been postponed at the two most-affected trusts, King's College Hospital NHS Foundation Trust and Guy's and St Thomas' NHS Foundation Trust, over the course of the recovery.
According to "Qilin ransomware attack on NHS supplier contributed to patient fatality," a year later, King's College Hospital NHS Foundation Trust confirmed that the disruption had contributed to a patient's death. A trust spokesperson told The Register, "One patient sadly died unexpectedly during the cyberattack. As is standard practice when this happens, we undertook a detailed review of their care." The spokesperson added that the review "identified a number of contributing factors that led to the patient's death. This included a long wait for a blood test result due to the cyberattack impacting pathology services at the time."
The Register reported in mid-2026 that hospitals were still working through the consequences, hospitals are still trying to identify and warn patients whose data was exposed, and the breach remains one of the most disruptive cyber incidents ever to hit the NHS.
The target list
Daily Security Review's March 2025 attack log shows how Qilin's affiliates operate across sectors and geographies. In January 2025, the group was linked to an attack on the city government of West Haven, Connecticut, which disrupted municipal IT systems and triggered a data breach investigation. Roughly a year earlier, between November and December 2023, Qilin affiliates were tied to a breach of an Australian court system, stealing audio-visual recordings of court hearings and in August 2024, The Hacker News reported that Qilin had begun harvesting credentials stored in victims' Chrome browsers.
Qilin's healthcare targeting didn't stop with Synnovis, according to "Qilin ransomware attack on NHS supplier contributed to patient fatality," published by The Register, the group claimed responsibility in March 2025 for attacks on a cancer clinic in Japan and a women's healthcare facility in the US. According to BleepingComputer, Qilin claimed responsibility for a May 2025 attack on Covenant Health, a Catholic healthcare provider operating hospitals, nursing and rehabilitation centers, and elder care organizations, with the breach affecting approximately 478,000 patients across the provider's affiliated facilities. Paubox's coverage of the ApolloMD breach settlement also ties that incident to Qilin, noting the group added the company to its dark web leak site in June 2025 after the attack exposed thousands of additional patient records.
In Georgia, Qilin claimed a November 2024 attack on Good Samaritan Health Center of Cobb, a federally qualified health center serving low-income patients in the Marietta area. The group accessed Social Security numbers, financial data, and medical records, and the organization didn't finish identifying every affected individual until July 2025, eight months after detection. In Texas, Central Texas Pediatric Orthopedics disclosed a March 2025 intrusion tied to Qilin that affected 140,000 patients, exposing names, government ID numbers, medical information, and health insurance details. The organization's initial state filing had put the figure at just 90,000 before the final count came in a month later. In Utah, Rocky Mountain Care, a provider of skilled nursing and home health services for seniors, was posted to Qilin's leak site in February 2026 after unauthorized access to its network in late January. Qilin also claimed a breach of MedImpact, a pharmacy benefit manager serving more than 50 million members, posting financial summaries and commission reports in late 2025, researchers noted the leaked files did not appear to include personal health information, though investigators cautioned more sensitive data could still surface. In August 2025, the group attacked Inotiv, an Indiana-based pharmaceutical contract research organization specializing in drug development and safety assessment, encrypting company systems and allegedly stealing roughly 162,000 files (176GB).
Related: Two ransomware gangs targeting healthcare
Absorbing the competition
When international operations disrupted LockBit and ALPHV/BlackCat, many of their affiliates didn't retire, they migrated to Qilin. The SANS Institute's threat research team observed this, noting that Qilin's affiliates range from state-sponsored North Korean threat actors to members of Scattered Spider, as well as groups like Devman and Arkana, and that Qilin has been taking in affiliates from disrupted groups like LockBit and ALPHV/BlackCat. SANS also flagged healthcare as a continuing thread running through that affiliate base, noting healthcare remains a target, consistent with the past focus of longtime affiliate FIN12 on hospitals.
Tactics
Technically, Qilin's operators favor spear-phishing for initial access, alongside abuse of legitimate remote monitoring and management (RMM) tools and Cobalt Strike for lateral movement inside a network. HC3 has also documented the group exploiting exposed Citrix instances and remote desktop protocol (RDP). Daily Security Review's March 2025 technical rundown supports this initial-access profile, listing spear phishing, exploitation of exposed applications and interfaces such as Citrix and RDP, abuse of RMM tooling, and Cobalt Strike–assisted deployment as Qilin's principal methods of access.
Qilin practices "double extortion" which is encrypting files to disrupt operations while also stealing sensitive data, then threatening to publish that data on its dark web leak site if the ransom isn't paid.
The SANS Institute's research also outlined a negotiation process. Investigators reviewing a leaked negotiation chat found that Qilin's negotiators offered victims a decryption tool, a list of stolen files, proof the data was deleted, an explanation of how the network was infiltrated, security recommendations, and a promise not to attack the victim again. The group has also reportedly begun using legal intimidation tactics against victims and researchers through what SANS describes as a "call lawyer" feature built into its affiliate infrastructure.
FAQs
What is ransomware-as-a-service (RaaS)?
It's a business model where the ransomware developers license their malware to affiliates who carry out the actual attacks, splitting the ransom proceeds between them.
What does "double extortion" mean?
It's a tactic where attackers both encrypt a victim's files and steal a copy of the data beforehand, so they can pressure the victim with the threat of a public leak even if backups make decryption unnecessary.
What is a dark web leak site?
It's a site, normally hosted on the Tor network, where ransomware groups publish stolen data from victims who refuse to pay, as proof of the breach and added pressure.
