qilin

Ransomware
Sourceransomware.live

Vexday analysis

Qilin é uma operação de ransomware observada pela primeira vez em julho de 2022, desenvolvida em Golang e que suporta múltiplos modos de criptografia, todos controlados pelo operador. O grupo adota a prática de dupla extorsão, exigindo pagamento tanto pelo descriptografador quanto pela não divulgação dos dados roubados. Sete vítimas brasileiras são atribuídas a esse agente de ameaça.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Impact and victims

The group qilin has 10 known ransomware victims. See the most affected sectors and countries and recent victims.

10known victims
10in Brazil
6sectors hit
Activity (12 months)
12
03
05
06
07
Most attacked sectors
Agriculture and Food Production2
Manufacturing2
Retail & E-Commerce2
Government & Defense1
Other1
Transportation1
Most affected countries
🇧🇷 Brasil10
Recent victims
CpcgOther · BR · 2026-07-22
PP+KManufacturing · BR · 2026-07-19
S.J. LouisNot Found · BR · 2026-07-08
Eat SaladAgriculture and Food Production · BR · 2026-06-03
Complastex.comManufacturing · BR · 2026-05-06
Arimex ImportadoraRetail & E-Commerce · BR · 2026-03-11
TupiAgriculture and Food Production · BR · 2025-12-09
Prefeitura do Jaboatão dos GuararapesGovernment & Defense · BR · 2024-07-16
Logimodal Operações LogísticasTransportation · BR · 2024-05-03
Lojas TorraRetail & E-Commerce · BR · 2022-11-09

qilin uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →