# Qilin

> As of 2026-09-18, Qilin is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 14 threats spanning threat intel, ransomware, data breach. Also known as MedusaLocker, NoName057(16), 05716nnm, LockBit. ATT&CK coverage spans 135 techniques across 15 tactics in 14 of 14 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1190 (Exploit Public-Facing Application), T1133 (External Remote Services).

- **Nation:** Russia
- **Tracked threats:** 14
- **Categories:** THREAT_INTEL, RANSOMWARE, DATA_BREACH, RANSOMWARE_HACKTIVISM, CAMPAIGN, VULNERABILITY
- **Also known as:** MedusaLocker, NoName057(16), 05716nnm, LockBit, ABCD ransomware, LockBit 5.0, Cl0p, Agenda, Hastalamuerte, CL0P^_- LEAKS, FIN11, Qilin Team
- **As of:** 2026-09-18

## ATT&CK techniques observed

135 techniques observed across 14 of 14 tracked threats. Tactics: Credential Access (16), Execution (14), Stealth (formerly Defense Evasion) (13), Discovery (12), Impact (12), Command and Control (11).

- [T1078](https://attack.mitre.org/techniques/T1078/) Valid Accounts — Initial Access — observed in 11 of 14 tracked threats
- [T1190](https://attack.mitre.org/techniques/T1190/) Exploit Public-Facing Application — Initial Access — observed in 11 of 14 tracked threats
- [T1133](https://attack.mitre.org/techniques/T1133/) External Remote Services — Initial Access — observed in 10 of 14 tracked threats
- [T1490](https://attack.mitre.org/techniques/T1490/) Inhibit System Recovery — Impact — observed in 10 of 14 tracked threats
- [T1003](https://attack.mitre.org/techniques/T1003/) OS Credential Dumping — Credential Access — observed in 8 of 14 tracked threats
- [T1486](https://attack.mitre.org/techniques/T1486/) Data Encrypted for Impact — Impact — observed in 8 of 14 tracked threats
- [T1685](https://attack.mitre.org/techniques/T1685/) Disable or Modify Tools — Defense Impairment — observed in 8 of 14 tracked threats
- [T1027](https://attack.mitre.org/techniques/T1027/) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 7 of 14 tracked threats
- [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration Over Web Service — Exfiltration — observed in 7 of 14 tracked threats
- [T1005](https://attack.mitre.org/techniques/T1005/) Data from Local System — Collection — observed in 6 of 14 tracked threats
- [T1021](https://attack.mitre.org/techniques/T1021/) Remote Services — Lateral Movement — observed in 6 of 14 tracked threats
- [T1021.001](https://attack.mitre.org/techniques/T1021/001/) Remote Desktop Protocol — Lateral Movement — observed in 6 of 14 tracked threats
- [T1555](https://attack.mitre.org/techniques/T1555/) Credentials from Password Stores — Credential Access — observed in 6 of 14 tracked threats
- [T1566](https://attack.mitre.org/techniques/T1566/) Phishing — Initial Access — observed in 6 of 14 tracked threats
- [T1657](https://attack.mitre.org/techniques/T1657/) Financial Theft — Impact — observed in 6 of 14 tracked threats

## Tracked threats

- [France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Months](https://intel.threadlinqs.com/threat/TL-2026-2564) — HIGH
- [Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed](https://intel.threadlinqs.com/threat/TL-2026-2546) — HIGH
- [Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices](https://intel.threadlinqs.com/threat/TL-2026-2517) — HIGH
- [Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations System](https://intel.threadlinqs.com/threat/TL-2026-2201) — HIGH
- [Ransomware Attack Vectors: Cyble Maps Five Endpoint Blind Spots Behind the 2025-2026 Ransomware Surge](https://intel.threadlinqs.com/threat/TL-2026-2110) — MEDIUM
- [Rapid7 Q2 2026 Threat Landscape Report: Vulnerability Disclosures Double, AI-Assisted Exploitation Compresses Patch Timelines](https://intel.threadlinqs.com/threat/TL-2026-2058) — HIGH
- [France Threat Landscape: Qilin/MedusaLocker/LockBit Ransomware and NoName057(16) Hacktivist DDoS Campaign Amid 4x Dark Web Activity Surge](https://intel.threadlinqs.com/threat/TL-2026-1652) — HIGH
- [ASEC June 2026 Financial Sector Threat Roundup: Phishing-to-Infostealer Chains and Ransomware Dark Web Sales (LAPSUS$, MORPHEUS, Qilin)](https://intel.threadlinqs.com/threat/TL-2026-1597) — MEDIUM
- [Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer via Weaponized ThrottleStop Driver (CVE-2025-7771)](https://intel.threadlinqs.com/threat/TL-2026-1453) — HIGH
- [Qilin Ransomware Abuses DCSync (MS-DRSR) to Harvest AD Domain Credentials Including KRBTGT](https://intel.threadlinqs.com/threat/TL-2026-1310) — HIGH
- [Black Kite 2026 European Cyber Risk Report: Ransomware Surges 55.1% as Third-Party Supply Chains Become Europe's Primary Attack Path (Qilin-Led)](https://intel.threadlinqs.com/threat/TL-2026-0958) — HIGH
- [Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass Exploitation](https://intel.threadlinqs.com/threat/TL-2026-0758) — CRITICAL
- [Check Point Remote Access & Mobile Access VPN IKEv1 Authentication Bypass (CVE-2026-50751) Exploited by Qilin Ransomware Affiliate](https://intel.threadlinqs.com/threat/TL-2026-0718) — CRITICAL
- [Qilin (Agenda) Ransomware Hits Romanian Oil Pipeline Operator Conpet — 4,000km Critical Infrastructure, ~1TB Exfiltrated, Chrome Credential Harvesting via GPO](https://intel.threadlinqs.com/threat/TL-2026-0096) — CRITICAL

## Related CVEs

15 CVEs referenced by tracked Qilin activity.

- [CVE-2026-50752](https://intel.threadlinqs.com/cve/CVE-2026-50752)
- [CVE-2026-50751](https://intel.threadlinqs.com/cve/CVE-2026-50751)
- [CVE-2025-7771](https://intel.threadlinqs.com/cve/CVE-2025-7771)
- [CVE-2025-61884](https://intel.threadlinqs.com/cve/CVE-2025-61884)
- [CVE-2025-61882](https://intel.threadlinqs.com/cve/CVE-2025-61882)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-30406](https://intel.threadlinqs.com/cve/CVE-2025-30406)
- [CVE-2025-24799](https://intel.threadlinqs.com/cve/CVE-2025-24799)
- [CVE-2025-2479](https://intel.threadlinqs.com/cve/CVE-2025-2479)
- [CVE-2025-14611](https://intel.threadlinqs.com/cve/CVE-2025-14611)
- [CVE-2025-11371](https://intel.threadlinqs.com/cve/CVE-2025-11371)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Qilin
