Financially motivated Qilin ransomware group known for Golang-based encryption and double extortion tactics.
Analyst brief
Qilin is a financially motivated ransomware group first observed in July 2022, primarily targeting entities across the United States, Germany, France, and the UK. It focuses on sectors such as Manufacturing, Healthcare, Technology, and Retail & E-Commerce. The group employs ransomware written in Golang with multiple operator-controlled encryption modes and uses double extortion TTPs, demanding payment for both decryption and non-release of stolen data. Defenders should prioritize multi-factor authentication, network segmentation, regular offline backups, and data loss prevention (DLP) solutions to mitigate data exfiltration risks.
qilin
activecrime
Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.