qilin

Ransomware
Sourceransomware.live

About the group

Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.

Exploited vulnerabilities 1

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Impact and victims

The group qilin has 11 known ransomware victims. See the most affected sectors and countries and recent victims.

11known victims
11in Brazil
6sectors hit
Activity (12 months)
12
03
05
06
07
09
Most attacked sectors
Agriculture and Food Production2
Manufacturing2
Retail & E-Commerce2
Transportation2
Government & Defense1
Other1
Most affected countries
🇧🇷 Brasil11
Recent victims
AlicotransTransportation · BR · 2026-09-14
CpcgOther · BR · 2026-07-22
PP+KManufacturing · BR · 2026-07-19
S.J. LouisNot Found · BR · 2026-07-08
Eat SaladAgriculture and Food Production · BR · 2026-06-03
Complastex.comManufacturing · BR · 2026-05-06
Arimex ImportadoraRetail & E-Commerce · BR · 2026-03-11
TupiAgriculture and Food Production · BR · 2025-12-09
Prefeitura do Jaboatão dos GuararapesGovernment & Defense · BR · 2024-07-16
Logimodal Operações LogísticasTransportation · BR · 2024-05-03
Lojas TorraRetail & E-Commerce · BR · 2022-11-09

qilin uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →