Qilin
As of 2026-09-18, Qilin is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 14 threats spanning threat intel, ransomware, data breach. Also known as MedusaLocker, NoName057(16), 05716nnm, LockBit. ATT&CK coverage spans 135 techniques across 15 tactics in 14 of 14 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1190 (Exploit Public-Facing Application), T1133 (External Remote Services).
Also known as: MedusaLocker, NoName057(16), 05716nnm, LockBit, ABCD ransomware, LockBit 5.0, Cl0p, Agenda, Hastalamuerte, CL0P^_- LEAKS, FIN11, Qilin Team
ATT&CK techniques observed
- T1078 Valid Accounts — Initial Access — observed in 11 of 14 tracked threats
- T1190 Exploit Public-Facing Application — Initial Access — observed in 11 of 14 tracked threats
- T1133 External Remote Services — Initial Access — observed in 10 of 14 tracked threats
- T1490 Inhibit System Recovery — Impact — observed in 10 of 14 tracked threats
- T1003 OS Credential Dumping — Credential Access — observed in 8 of 14 tracked threats
- T1486 Data Encrypted for Impact — Impact — observed in 8 of 14 tracked threats
- T1685 Disable or Modify Tools — Defense Impairment — observed in 8 of 14 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 7 of 14 tracked threats
- T1567 Exfiltration Over Web Service — Exfiltration — observed in 7 of 14 tracked threats
- T1005 Data from Local System — Collection — observed in 6 of 14 tracked threats
- T1021 Remote Services — Lateral Movement — observed in 6 of 14 tracked threats
- T1021.001 Remote Desktop Protocol — Lateral Movement — observed in 6 of 14 tracked threats
- T1555 Credentials from Password Stores — Credential Access — observed in 6 of 14 tracked threats
- T1566 Phishing — Initial Access — observed in 6 of 14 tracked threats
- T1657 Financial Theft — Impact — observed in 6 of 14 tracked threats
Tracked threats
- France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Months — HIGH
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed — HIGH
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices — HIGH
- Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations System — HIGH
- Ransomware Attack Vectors: Cyble Maps Five Endpoint Blind Spots Behind the 2025-2026 Ransomware Surge — MEDIUM
- Rapid7 Q2 2026 Threat Landscape Report: Vulnerability Disclosures Double, AI-Assisted Exploitation Compresses Patch Timelines — HIGH
- France Threat Landscape: Qilin/MedusaLocker/LockBit Ransomware and NoName057(16) Hacktivist DDoS Campaign Amid 4x Dark Web Activity Surge — HIGH
- ASEC June 2026 Financial Sector Threat Roundup: Phishing-to-Infostealer Chains and Ransomware Dark Web Sales (LAPSUS$, MORPHEUS, Qilin) — MEDIUM
- Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer via Weaponized ThrottleStop Driver (CVE-2025-7771) — HIGH
- Qilin Ransomware Abuses DCSync (MS-DRSR) to Harvest AD Domain Credentials Including KRBTGT — HIGH
- Black Kite 2026 European Cyber Risk Report: Ransomware Surges 55.1% as Third-Party Supply Chains Become Europe's Primary Attack Path (Qilin-Led) — HIGH
- Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass Exploitation — CRITICAL
- Check Point Remote Access & Mobile Access VPN IKEv1 Authentication Bypass (CVE-2026-50751) Exploited by Qilin Ransomware Affiliate — CRITICAL
- Qilin (Agenda) Ransomware Hits Romanian Oil Pipeline Operator Conpet — 4,000km Critical Infrastructure, ~1TB Exfiltrated, Chrome Credential Harvesting via GPO — CRITICAL
Related CVEs
CVE-2026-50752, CVE-2026-50751, CVE-2025-7771, CVE-2025-61884, CVE-2025-61882, CVE-2025-33073, CVE-2025-32433, CVE-2025-30406, CVE-2025-24799, CVE-2025-2479, CVE-2025-14611, CVE-2025-11371, CVE-2024-55591, CVE-2024-40766, CVE-2020-1472