Qilin (Agenda) Ransomware

Description Summary

Qilin (also known as Agenda) is a Rust- and Go-based ransomware-as-a-service active since August 2022. Affiliates are offered configurable encryption modes and per-victim builds. Qilin gained notoriety in June 2024 for the attack on Synnovis, a UK pathology services provider, which severely disrupted NHS hospitals in London.

Threat Actor

Russian-speaking RaaS operators. Affiliate cut ~80–85%.

Technical Indicators

Encryption Extension
.<random> / .agenda / .Mortis
Encryption Algorithm
ChaCha20 + RSA-4096 (Rust); previously AES
Ransom Note Name
README-RECOVER-<id>.txt
Targeted Industries
Healthcare, Education, Manufacturing, Financial
First Seen
August 2022
Last Seen
Active — most active operation of 2025 (1,000+ victims)
Geographical Location
Global; high-profile UK healthcare impact

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 3 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop