Malware
Qilin
Qilin ransomware, initially observed in July 2022 under the name “Agenda,” operates on a Ransomware-as-a-Service (RaaS) model.
Qilin is a Linux malware family.
Background
Qilin ransomware, first seen in July 2022 under the name “Agenda,” runs as a Ransomware-as-a-Service (RaaS) operation. Under this model, the core developers supply their malware and infrastructure to affiliates and take a cut of the proceeds from each attack. The name “Qilin” comes from a Chinese mythological creature associated with power and prosperity, an apt symbol for the group's perceived clout and money-driven goals. Despite the Chinese name, the group is tied to Russian-speaking cybercriminals, frequently recruiting affiliates on Russian-language forums and deliberately steering clear of targets in Commonwealth of Independent States (CIS) countries.
Source: Malpedia (Fraunhofer FKIE).