The group known as Qilin ransomware (also referred to as Agenda, Gold Feather, and Water Galura) has reported more than 40 victims every month since the beginning of 2025, except for January, with the number of posts on the data leak website reaching a high of 100 cases in June.
See also: Qilin ransomware: Claimed responsibility for the attack on Asahi

This development comes as the ransomware-as-a-service (RaaS) operation has emerged as one of the most active ransomware groups, counting 84 victims each month in August and September 2025. Qilin ransomware has been active since around July 2022.
According to data compiled by Cisco Talos, the U.S., Canada, the U.K., France, and Germany are among the countries most affected by Qilin. Attacks have primarily targeted the manufacturing (23%), professional and scientific services (18%), and wholesale (10%) sectors.
Attacks carried out by Qilin ransomware collaborators likely exploited leaked administrative credentials on the dark web for initial access using a VPN interface, followed by RDP connections to the domain controller and the successfully compromised endpoint.
In the next phase, the attackers performed system reconnaissance and network discovery actions to map the infrastructure, running tools such as Mimikatz, WebBrowserPassView.exe, BypassCredGuard.exe , and SharpDecryptPwd to facilitate the collection of credentials from various applications and export the data to an external SMTP server using a Visual Basic Script.
See also: Qilin ransomware: Breaches 104 organizations in August

Further analysis revealed the threat actor's use of mspaint.exe, notepad.exe , and iexplore.exe to inspect files for sensitive information, as well as a legitimate tool called Cyberduck to transfer files of interest to a remote server while hiding malicious activity.
The stolen credentials enabled privilege escalation and lateral movement, allowing the attackers to install multiple Remote Monitoring and Management (RMM) tools such as AnyDesk, Chrome Remote Desktop, Distant Desktop, GoToDesk, QuickAssist, and ScreenConnect. Talos noted that it could not definitively conclude whether these programs were used for lateral movement.
To evade detection, the attack chain includes running PowerShell commands to disable AMSI, disable TLS certificate validation, and enable Restricted Administrator, in addition to running tools like dark-kill and HRSword to terminate security software. Cobalt Strike and SystemBC are also deployed on the host for persistent remote access.
The infection culminates in the launch of Qilin ransomware, which encrypts files and leaves a ransom note in each encrypted folder, while also deleting event logs and deleting all shadow copies maintained by the Windows Volume Shadow Copy Service (VSS).
The findings coincide with the discovery of a sophisticated Qilin attack that deployed the Linux ransomware variant on Windows systems, combining it with the “bring your own vulnerable driver” (BYOVD) technique and legitimate IT tools to bypass security barriers.
See also: Qilin.B ransomware: New version of Qilin with stronger encryption

In addition to using valid accounts to compromise target networks, select attacks have used spear-phishing techniques.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
