Threat Intelligence / Actor / Qilin

Qilin

As of 2026-09-18, Qilin is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 14 threats spanning threat intel, ransomware, data breach. Also known as MedusaLocker, NoName057(16), 05716nnm, LockBit. ATT&CK coverage spans 135 techniques across 15 tactics in 14 of 14 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1190 (Exploit Public-Facing Application), T1133 (External Remote Services).

Nation: Russia · 14 tracked threat(s) · Categories: THREAT_INTEL, RANSOMWARE, DATA_BREACH, RANSOMWARE_HACKTIVISM, CAMPAIGN, VULNERABILITY

Also known as: MedusaLocker, NoName057(16), 05716nnm, LockBit, ABCD ransomware, LockBit 5.0, Cl0p, Agenda, Hastalamuerte, CL0P^_- LEAKS, FIN11, Qilin Team

ATT&CK techniques observed

135 techniques observed across 14 of 14 tracked threats · Credential Access (16), Execution (14), Stealth (formerly Defense Evasion) (13), Discovery (12), Impact (12), Command and Control (11)

Tracked threats

Related CVEs

15 CVEs referenced by tracked Qilin activity

CVE-2026-50752, CVE-2026-50751, CVE-2025-7771, CVE-2025-61884, CVE-2025-61882, CVE-2025-33073, CVE-2025-32433, CVE-2025-30406, CVE-2025-24799, CVE-2025-2479, CVE-2025-14611, CVE-2025-11371, CVE-2024-55591, CVE-2024-40766, CVE-2020-1472

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence