Qilin
Also known as Agenda, Pestilent Mantis
Reports
378
First seen
Aug 19, 2025
Last seen
Aug 14, 2026
Motivation
Financial
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
×3×69
United States×69
Germany×13
France×10
Malaysia×4
Australia×4
Canada×4
Italy×3
Argentina×3
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1486 Data Encrypted for Impact ×22T1190 Exploit Public-Facing Application ×21T1566 Phishing ×17T1195 Supply Chain Compromise ×10T1059 Command and Scripting Interpreter ×9T1041 Exfiltration Over C2 Channel ×8T1021 Remote Services ×7T1078 Valid Accounts ×7T1219 Remote Access Software ×7T1133 External Remote Services ×7T1005 Data from Local System ×6T1567 Exfiltration Over Web Service ×5
Indicators
domain ×359cve ×175filename ×77ip_v4 ×2hash_sha256 ×1hash_sha1 ×1
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2026-50751 (exploited)CVE-2026-50752CVE-2026-35616 (exploited)CVE-2026-35273 (exploited)CVE-2026-21509 (exploited)CVE-2026-1340 (exploited)CVE-2026-0257 (exploited)CVE-2026-41091 (exploited)CVE-2022-40684 (exploited)CVE-2024-21762 (exploited)CVE-2022-27925 (exploited)CVE-2024-24919 (exploited)CVE-2024-36401 (exploited)CVE-2024-40766 (exploited)CVE-2021-27076 (exploited)CVE-2023-46747 (exploited)CVE-2025-37899CVE-2023-32315 (exploited)CVE-2021-36260 (exploited)CVE-2025-3248 (exploited)
Recent reports
High