Skip to content

Malware

AgendaCrypt

aka Agenda · Qilin

Qilin ransomware has been active since at least 2022.

AgendaCrypt, also known as Agenda, Qilin, is a Windows malware family.

Background

The Qilin ransomware has been operating since 2022 at the earliest, with samples written in both Golang and Rust seen in the wild. It runs as a Ransomware-as-a-Service (RaaS) operation and has been observed using double-extortion tactics, combining file decryption leverage with the threat of leaking stolen data.


Source: Malpedia (Fraunhofer FKIE).