QILIN A.I CyberSecurity Scoring
QILIN
Company Information
Website:http://www.qilin.fr/
Employees number:5
Number of followers:0
NAICS:5112
Industry Type:Software Development
Homepage:qilin.fr
QILIN Risk Score (AI oriented)
Between 0 and 549
QILINSoftware Development
Updated:
24/06/2026
24/06/2026
100/1000
Critical
C
QILIN Global Score (TPRM)
xxxx
QILINSoftware Development
Score locked

QILINCritical
Current Score
100C (CRITICAL)
01000
8 incidents
-68 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
100
JULY 2026
100
JUNE 2026
100
MAY 2026
100
APRIL 2026
100
Ransomware
01 Apr 2026 • QILIN
Qilin and Black Basta: ModeloRAT and Mistic Backdoor Activity Linked to Ransomware Initial Access Broker
New Python-Based RAT and Stealth Backdoor Linked to Ransomware Access Broker Woodgnat
100
CRITICAL0
QILBLA1782311333
New Python-Based RAT and Stealth Backdoor Linked to Ransomware Access Broker Woodgnat
A recent cybersecurity investigation has uncovered a sophisticated campaign involving ModeloRAT, a Python-based remote access trojan (RAT), and Backdoor.Mistic, a newly identified stealth backdoor. Both tools are tied to Woodgnat (also known as KongTuke), an initial access broker (IAB) that facilitates ransomware deployments for multiple threat groups, including Qilin, Rhysida, Akira, 8Base, and Black Basta.
### Backdoor.Mistic: Stealth and Persistence
First observed in April 2026 and documented by Zscaler, Backdoor.Mistic is designed for long-term, low-visibility access. It employs DLL sideloading via a legitimate executable (MpExtMs.exe), loading a malicious DLL (EndpointDlp.dll) that mimics Microsoft security components. The backdoor uses API hooking to evade detection, executing payloads in-memory without writing files to disk. Additional evasion tactics include a kill switch for self-deletion and adaptive command-and-control (C2) mechanisms, such as domain generation for non-domain hosts.
Functionally, Mistic supports file manipulation, scheduled command checks, and in-memory execution of C2-delivered code, making it a versatile tool for maintaining covert access. Targets have been opportunistic, spanning insurance, education, IT, and professional services, suggesting the operators prioritize saleable enterprise access over industry-specific attacks.
### ModeloRAT: A Hallmark of Woodgnat Activity
ModeloRAT, a long-standing tool in Woodgnat’s arsenal, is typically delivered via a portable WinPython package and executed through signed pythonw.exe. It employs RC4-encrypted C2 communications and multi-path resiliency to maintain persistence. Symantec’s Threat Hunter Team linked ModeloRAT to Qilin ransomware deployments, reinforcing its role in final-stage ransomware operations.
### Intrusion Chain and Tradecraft
The observed attack chain combines multiple stages and tools, including:
- A .NET credential stealer with a fake login prompt
- Living-off-the-land binaries (LOLBins) such as curl, reg.exe, net.exe, certutil, WMIC, and PowerShell for reconnaissance and lateral movement
- Loaders like WinPython and Node.exe to host ModeloRAT and other scripts
- Social engineering lures (e.g., ClickFix, FileFix, CrashFix) tricking victims into executing malicious PowerShell commands
- Microsoft Teams helpdesk pretexts coercing victims into running attacker-supplied commands for rapid persistence
Woodgnat’s tradecraft emphasizes evasion, leveraging signed carriers, in-memory execution, redundant persistence mechanisms, and credential theft to establish durable footholds for ransomware affiliates.
### Defensive Priorities
Key indicators of compromise (IOCs) include:
- Unexpected loading of EndpointDlp.dll by MpExtMs.exe
- Anomalous in-memory execution activities
- Run-key persistence entries mimicking remote-support tools
- Evidence of WinPython or signed pythonw.exe running unknown scripts
As Woodgnat continues to evolve, tracking its infrastructure and the development of ModeloRAT and Mistic remains critical for defenders combating ransomware-enabled access brokering.
INCIDENT DETAILS -
TYPE
MOTIVATION
DATA BREACH
REFERENCES
MARCH 2026
100
FEBRUARY 2026
100
JANUARY 2026
104
Ransomware
01 Jan 2026 • QILIN
DragonForce and Play: Ransomware Attacks Against the US: 2026 Insights
Ransomware Surge in Early 2026: Key Trends and Evolving Threat Tactics
100
CRITICAL-4
PLADRA1774449041
Ransomware Surge in Early 2026: Key Trends and Evolving Threat Tactics
A recent analysis by Bitdefender reveals a sharp rise in ransomware attacks targeting U.S. organizations in the first two months of 2026, with 53 active groups claiming victims seven of which have dominated the threat landscape for over four months. Among the most prolific are Qilin, Akira, Clop, INC Ransom, Play, DragonForce, and Sinobi, though Qilin likely leads in confirmed U.S. victims after excluding inflated claims from 0APT, a group notorious for false reporting. Between January and February, 750–800 U.S. organizations were impacted, with construction and manufacturing bearing the brunt of attacks, followed by technology, healthcare, and legal sectors.
Despite the surge in attacks, ransom payments are declining, a shift attributed to stricter cyber insurance requirements, regulatory pressures, and improved incident response practices bolstered by guidance from agencies like CISA, the FBI, and the NSA.
### Evolving Attack Patterns
Ransomware groups are refining their tactics to evade detection and maximize impact:
1. Identity-First Compromise
Attackers are prioritizing credential theft such as browser session tokens over brute-force methods to bypass multi-factor authentication (MFA) and reduce detection noise. Encrypting authentication tokens and enforcing strict session lifetimes could mitigate this risk.
2. Supply Chain Exploitation
Groups are increasingly targeting vendors and SaaS platforms to compromise multiple downstream victims. High-profile examples include ShinyHunters, which orchestrated large-scale supply chain attacks in 2025. While MFA and patch management remain critical, they are no longer sufficient against identity-based breaches.
3. Automated Exploitation
The time-to-exploit window has shrunk dramatically, with attackers leveraging AI-driven tools like CyberStrukeAI to automate vulnerability exploitation within hours of a proof-of-concept (PoC) release down from days in 2024–2025. This acceleration allows threat actors to rapidly scale attacks before defenses can react.
4. BYOVD (Bring Your Own Vulnerable Driver) Attacks
A resurgence in defense evasion tactics has seen ransomware groups weaponize legitimate drivers to gain kernel-level access, bypassing EDR and antivirus solutions. Unlike past multi-stage attacks, modern ransomware now embeds vulnerable drivers directly, syncing evasion and encryption in a single phase. By Q2 2026, BYOVD attacks are projected to account for 75% of ransomware incidents, posing a severe challenge for defenders.
### Emerging Threat Landscape
The ransomware ecosystem is undergoing structural shifts:
- RaaS (Ransomware-as-a-Service) platforms are expanding, with some groups offering low-cost or free access to attract affiliates.
- Hacktivist messaging is being co-opted by ransomware groups amid geopolitical tensions, particularly in the context of the Iran conflict.
- Specialized roles such as initial access brokers (IABs), penetration testers, and negotiators are becoming more defined, reflecting a maturing criminal economy.
- Living Off the Cloud (LOTC) tactics are rising, with attackers repurposing cloud management tools (e.g., AWS, Box) to exfiltrate or lock data. Traditional whitelisting is ineffective, as even approved applications can be abused.
### Future Targets
Ransomware groups are diversifying their initial access points, with growing focus on:
- Edge devices (VPNs, firewalls) as low-effort entry points.
- Hypervisors and cloud services, where modern encryptors (e.g., ESXi-targeting malware) can cripple virtualized environments.
- Proactive reconnaissance, with attackers scanning for exposed data and vulnerabilities before striking.
As the threat landscape evolves, behavior-based detection and dual-control security measures are becoming essential to counter LOTL/LOTC attacks, while BYOVD tactics demand heightened scrutiny of driver vulnerabilities. The first half of 2026 signals a more automated, evasive, and supply-chain-focused ransomware threat one that prioritizes speed and stealth over traditional brute-force methods.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
104
NOVEMBER 2025
100
OCTOBER 2025
232
Ransomware
01 Oct 2025 • QILIN
Qilin: Ransomware hackers say NO to Data Exfiltration and YES to Encryption
Ransomware Tactics Shift: Operators Drop Double Extortion in Favor of Encryption-Only Attacks
100
CRITICAL-132
QIL1770796893
Ransomware Tactics Shift as Operators Drop Double Extortion in Favor of Encryption-Only Attacks
A recent study by incident response firm Coveware reveals a strategic pivot among ransomware operators, with many moving away from data exfiltration and returning to encryption-focused attacks. While established cybercriminal syndicates like Clop, LockBit 3.0, and Qilin continue to employ "double extortion" encrypting systems while also stealing and threatening to leak sensitive data smaller or less sophisticated groups are increasingly abandoning this approach.
The shift stems from the operational and financial challenges of data exfiltration. Extracting, transferring, and storing stolen data requires significant infrastructure, including dark web leak sites, and incurs costs even if victims refuse to pay. Additionally, the market value of stolen data has plummeted, with up to 78% of exfiltrated datasets deemed low-value or redundant due to oversaturation. Much of this data often outdated personally identifiable information (PII) is already available in bulk on underground marketplaces, reducing its leverage in extortion schemes.
For victims, paying a ransom does not mitigate regulatory or reputational risks. Data protection laws like GDPR mandate breach notifications regardless of ransom settlement, and attackers offer no guarantees that stolen data will be deleted or unused. This uncertainty weakens the coercive power of double extortion.
Improved cybersecurity defenses have also contributed to the decline. Organizations have bolstered resilience through zero-trust architectures, immutable backups, and enhanced awareness training, while law enforcement agencies including the FBI, CISA, and the UK’s NCSC have disrupted ransomware infrastructure and seized leak sites. These efforts increase operational risks for attackers engaging in data theft.
Despite these challenges, ransomware remains highly profitable. Coveware reports that the average ransom payment surged to $600,000 in Q4 2025, nearly doubling from $325,000 in the previous year’s Q3. While tactics evolve, the financial and operational threats posed by ransomware persist.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
232
MAY 2025
725
Ransomware
01 May 2025 • QILIN
Qilin: Ransomware criminals paying $9k to make malware harder to detect on Windows
Microsoft Disrupts Major Malware-Signing Network, Crippling Ransomware Operations
175
CRITICAL-550
QIL1779265598
Microsoft Disrupts Major Malware-Signing Network, Crippling Ransomware Operations
Cybercriminals are increasingly outsourcing malware distribution to specialized underground services, spending between $5,000 and $9,000 to keep ransomware and other malicious software undetected on Windows systems. This shift reflects the growing professionalization of cybercrime, with hackers relying on "malware signing as a service" (MSaaS) providers to bypass security measures rather than developing their own evasion techniques.
A key player in this ecosystem, Fox Tempest, was recently dismantled by Microsoft’s threat intelligence teams in a significant crackdown. The group had been supplying digitally signed malware to multiple ransomware gangs, including INC Ransom, Qilin, Akira, and Rhysida, allowing their payloads to evade antivirus detection by appearing as trusted software. Microsoft’s operation revoked fraudulently obtained digital certificates and shut down a network of Azure-hosted virtual machines that formed the backbone of the malware-signing infrastructure.
Investigations revealed that Fox Tempest operatives had been exploiting stolen identities and compromised tenant credentials since May 2025 to create hundreds of Azure accounts, which were used to anonymously host malicious infrastructure. The takedown is expected to disrupt the operations of several ransomware groups that relied on the service.
The incident underscores the business-like evolution of cybercrime, with underground markets offering specialized services to streamline attacks. The rise of MSaaS in Europe and beyond signals a dangerous new phase in ransomware campaigns, where criminals leverage third-party providers to scale their operations efficiently.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2025
426
Ransomware
01 Jan 2025 • QILIN
Qilin and Keymous+: Check Point: Which Cyber Risks Rule the Financial Sector?
Surge in Cyberattacks on Financial Sector in 2025
270
CRITICAL-156
NETQIL1770303663
Cyberattacks on Financial Sector Double in 2025, Driven by AI-Powered Threats and Hacktivism
The financial sector faced an unprecedented surge in cyberattacks in 2025, with incidents more than doubling rising from 864 in 2024 to 1,858 according to Check Point Software’s 2025 Finance Sector Landscape Report. The escalation reflects a shift toward more sophisticated, AI-driven tactics, geopolitical hacktivism, and the exploitation of persistent vulnerabilities in cloud security, identity governance, and third-party ecosystems.
Key Threats and Trends
Ransomware, DDoS attacks, and data breaches dominated the threat landscape, with ransomware incidents alone reaching 451 cases nearly half (43.5%) targeting U.S. institutions. The ransomware-as-a-service (RaaS) ecosystem has matured, enabling even moderately skilled actors to launch large-scale campaigns. Leading groups included Qilin (83 attacks), Akira (37), and Clop (19), which leveraged stolen credentials, VPN vulnerabilities, and third-party service providers to infiltrate networks.
DDoS attacks saw a 105% increase, evolving from one-time disruptions to short-burst, high-frequency strikes designed to overwhelm mitigation systems. Hacktivist groups played a major role, with Keymous+ (121 attacks) and NoName057 (98 attacks) linked to North African and pro-Russian motivations, respectively targeting financial platforms in regions of high geopolitical tension. Israel (16.6%), the U.S. (5.9%), and the UAE (5.6%) were the most affected, though not all attacks were financially motivated; many served broader ideological or state-aligned objectives.
Exploitation of Weaknesses
Threat actors capitalized on misconfigurations such as open storage buckets, permissive access controls, and unmonitored APIs to gain initial access. Organized groups like Breach Laboratory exploited these gaps, alongside leaked credentials and dark web marketplaces, to fuel extortion campaigns. Advanced persistent threats (APTs) also surged, with attackers maintaining long-term, covert access to exfiltrate data before disclosure.
The U.S. remained the most targeted country (40% of global incidents), followed by India, Indonesia, South Korea, the UK, and Canada regions with expansive digital banking infrastructure. The report highlights the growing use of AI and deepfake technologies to enhance phishing, impersonation, and social engineering attacks, introducing new risks for financial institutions.
Evolving Attacker Tactics
Elusive threat actors, responsible for 33% of attacks, demonstrated improved operational security, using short-lived infrastructure, decentralized identities, and burner accounts to evade detection. The rise of stealthy data breach operations characterized by delayed disclosure further complicates defense efforts. Check Point’s researchers emphasize the need for always-on detection, multi-CDN routing, and layered defenses to counter these adaptive threats.
The report underscores the financial sector’s vulnerability due to its zero-tolerance for downtime, interconnected systems, and high-value data making it a prime target for both criminal and state-aligned actors. As attacks grow in scale and sophistication, traditional security measures are proving insufficient against the evolving threat landscape.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2024
795
Ransomware
16 Jun 2024 • QILIN
Qilin, Akira, LockBit, DragonForce and Safepay: Ransomware activity never dies, it multiplies
Ransomware Attacks Hit Record Highs in 2025 Despite Major Disruptions
351
CRITICAL-444
QILAKILOCDRASAF1768585619
Ransomware Attacks Hit Record Highs in 2025 Despite Major Disruptions
A new study by Symantec and the Carbon Black Threat Hunter Team reveals that ransomware attacks surged to unprecedented levels in 2025, with threat actors adapting rapidly to law enforcement crackdowns and evolving their extortion tactics.
The report documented 4,737 claimed ransomware attacks the highest annual total on record despite the collapse of two major operations. RansomHub, the most active group at the time, abruptly shut down in April 2025, causing a brief dip in activity. However, former affiliates quickly migrated to other groups, restoring attack volumes within weeks. LockBit (tracked as Syrphid) also failed to recover after late-2024 law enforcement actions.
New leaders emerged to fill the void. Akira and Qilin each accounted for 16% of attacks, while Inc, Safepay, and the newly identified DragonForce contributed smaller but significant shares. The fluid movement of affiliates, access brokers, and tooling between groups sustained overall activity levels.
Beyond traditional encryption-based ransomware, extortion campaigns without encryption surged in 2025. These attacks focused on data theft and public leaks pushed total extortion incidents to 6,182, a 23% increase from 2024. Snakefly’s Cl0p operation played a key role, exploiting vulnerabilities in enterprise software to target government and industrial sectors at scale.
Social engineering also became a dominant attack vector, with groups like ShinyHunters and Scattered Spider using phone-based impersonation, credential harvesting, and OAuth abuse to breach cloud environments. Attackers tricked employees into authorizing malicious apps or sharing authentication codes, reducing reliance on malware.
A new ransomware strain, Warlock, drew attention for its ties to older espionage tooling. Exploiting a zero-day in Microsoft SharePoint and using DLL sideloading, Warlock incorporated components linked to Chinese state-sponsored activity, blending ransomware with broader intrusion campaigns.
Despite these shifts, attack chains remained consistent. Threat actors relied on "living off the land" techniques, leveraging PowerShell, remote management tools, and credential dumping to evade detection. Malware often appeared late in the intrusion, just before encryption or data theft.
The findings underscore how ransomware operations continue to thrive, even as law enforcement disrupts key players, by diversifying extortion methods and exploiting shared infrastructure.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Ransomware
16 Jun 2024 • QILIN
Qilin: Ransomware payments hit record low: only 23% Pay in Q3 2025
Ransomware Payments Hit Record Low in Q3 2025
351
CRITICAL-444
QIL1768636703
Ransomware Payments Hit Record Low in Q3 2025, Coveware Reports
In Q3 2025, only 23% of ransomware victims paid attackers the lowest rate ever recorded continuing a six-year decline in payment rates, according to cybersecurity firm Coveware. This follows a brief uptick in early 2024, when 28% of victims paid, before rates resumed their downward trend.
The average ransom payment dropped to $376,941 (a 66% decrease from Q2), while the median fell to $140,000 (down 65%). Large enterprises are increasingly refusing to pay, recognizing that ransoms rarely prevent data leaks. Meanwhile, ransomware groups like Akira and Qilin are targeting mid-sized firms with smaller, more frequent demands, exploiting their lower resilience with a high-volume, low-demand strategy.
Coveware’s report highlights that payment rates for all ransomware scenarios including encryption, data exfiltration, and extortion fell to 23%, with data exfiltration-only attacks seeing an even lower rate of 19%. The decline reflects growing maturity among enterprises, cyber response teams, and privacy attorneys, who now discourage payments as they sustain the extortion economy.
Attackers continue to exploit common entry points, including remote access compromise (accounting for over half of incidents), phishing, and unpatched software vulnerabilities. Weak credentials, poor configuration hygiene, and social engineering remain key vectors. Despite the shift in payment trends, ransomware groups remain opportunistic, targeting organizations with weak security rather than specific industries.
The median size of impacted companies rose to 362 employees in Q3 (up 27% from Q2), challenging the assumption that larger targets guarantee bigger payouts. While attackers may invest more to breach larger organizations, the return on investment is no longer assured.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Ransomware
16 Jun 2024 • QILIN
Qilin, CL0P, Salesforce, Sinobi and Play: Ransomware and Supply Chain Attacks Set Records in 2025
Ransomware and Supply Chain Attacks Surge in 2025
351
CRITICAL-444
QILCYBSALHALPLA1768955694
Ransomware and Supply Chain Attacks Hit Record Highs in 2025, Signaling Escalating Threats
2025 marked a sharp escalation in cyber threats, with ransomware and supply chain attacks reaching unprecedented levels, according to a new report from threat intelligence firm Cyble. The year saw 6,604 ransomware attacks a 52% increase over 2024 with December alone recording 731 incidents, the second-highest monthly total of the year. Meanwhile, supply chain attacks surged by 93%, rising from 154 in 2024 to 297 in 2025, as threat actors increasingly exploited third-party vulnerabilities to maximize impact.
### Ransomware Groups Adapt and Expand
Ransomware operations remained decentralized and resilient, with affiliates quickly regrouping under new leaders following law enforcement disruptions. Qilin emerged as the dominant group in 2025, claiming 17% of all ransomware victims after RansomHub’s decline likely due to sabotage by rival group Dragonforce. Other top players included Akira, CL0P, Play, and the newcomer Sinobi, with only Akira and Play maintaining their positions from 2024.
Cyble documented 57 new ransomware groups, 27 extortion groups, and over 350 new ransomware strains in 2025, many derived from MedusaLocker, Chaos, and Makop families. Among the most aggressive new groups, Devman, Sinobi, Warlock, and Gunra disproportionately targeted critical infrastructure, particularly in government, law enforcement, energy, and utilities.
### Supply Chain Attacks Evolve in Sophistication
Supply chain attacks not only doubled but also grew in complexity, moving beyond traditional software package poisoning to exploit cloud integrations, SaaS trust relationships, and vendor distribution pipelines. Attackers increasingly abused upstream services such as identity providers and package registries to compromise downstream environments at scale.
A notable example involved attacks on Salesforce via third-party integrations, where threat actors weaponized OAuth-based trust relationships after compromising third-party tokens. Every industry tracked by Cyble was affected, but IT and technology sectors bore the brunt, given their potential to amplify attacks across customer networks.
### Geographic and Industry Targeting
The U.S. remained the most targeted nation, accounting for 55% of all ransomware attacks, followed by Canada, Germany, the UK, Italy, and France. By industry, construction, professional services, and manufacturing were the hardest hit, with healthcare and IT also facing significant threats.
As 2026 begins, the trends suggest no immediate slowdown, with ransomware and supply chain attacks continuing to evolve in both scale and sophistication.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for QILIN ??
What was QILIN's A.I Rankiteo Cyber Score in July 2026 ??
What was QILIN's A.I Rankiteo Cyber Score in June 2026 ??
What was QILIN's A.I Rankiteo Cyber Score in May 2026 ??
What was QILIN's A.I Rankiteo Cyber Score in April 2026 ??
What was QILIN's A.I Rankiteo Cyber Score in March 2026 ??
What was QILIN's A.I Rankiteo Cyber Score in February 2026 ??
What was QILIN's A.I Rankiteo Cyber Score in January 2026 ??
What was QILIN's A.I Rankiteo Cyber Score in December 2025 ??
What was QILIN's A.I Rankiteo Cyber Score in November 2025 ??
What was QILIN's A.I Rankiteo Cyber Score in October 2025 ??
What was QILIN's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on QILIN's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with QILIN ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view QILIN's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?