キリンランサムウェア:攻撃手法と2026年の状況

このガイドでは、Qilinの動作、初期アクセスからデータ漏洩までの攻撃の様相、そしてセキュリティチームが早期に検知するために必要なことについて説明します。.

キリンランサムウェアとは何ですか?

Qilin, also known as Agenda ransomware, is a cybercriminal group that operates under a ransomware-as-a-service model. It launched as Agenda in August 2022 and rebranded to Qilin the following month.

Named after a creature from Chinese mythology (similar to a Chinese unicorn), the group uses double extortion tactics against targets in North America, Europe, and increasingly further afield.

北京との関連を示唆する名称にもかかわらず、Qilinランサムウェアの件は ロシアと関連がある. Researchers base that assessment on Russian-language code artefacts and a documented policy of avoiding targets in Commonwealth of Independent States (CIS) countries, a common self-imposed restriction among Russia-linked groups. No formal government attribution has been issued.

図1:Qilinランサムウェアの身代金要求画面のスクリーンショット。. ソフォス

攻撃のタイムライン

Qilin has become a top ransomware group globally, with a victim list spanning manufacturing, healthcare, education, government, and professional services across more than 60 countries.

  • 2022年6月: The first instance of Qilin ransomware is detected. Attackers successfully accessed a customer’s VPN and compromised the admin account, using RDP to gain access to the customer’s Microsoft System Center Configuration Manager (SCCM) server.
  • 2022年10月 キュウリランサムウェア・アズ・ア・サービスの最初の既知の被害者が、アジェンダという名前で専用リークサイト(DLS)に掲載されています。.
  • 2023年4月APACの被害者から、次のQilin攻撃が報告されました。このグループは進化の兆候を見せており、GoベースのランサムウェアからRustベースの亜種へと移行しています。.
  • 2024年1月オーストラリアの裁判制度が報告しました 二重恐喝攻撃 from Qilin. The attackers worked to extort court files, including the audio-visual archive.
  • June 2024: Qilin gains international notoriety with a $5000万ドルの身代金要求 targeting Synnovis, the pathology provider for several NHS trusts in south-east London. The attack on June 3 halted blood testing across King’s College, Guy’s and St Thomas’, and Lewisham and Greenwich hospitals, cancelling more than 10,000 outpatient appointments and postponing over 1,700 elective operations. When the ransom went unpaid, the group published 400GB of stolen data on June 20. In June 2025, King’s College Hospital NHS Foundation Trust confirmed that delays to blood test results caused by the attack were among the contributing factors in a patient’s death — one of the few ransomware incidents anywhere to be formally linked to a fatality. Synnovis later put its direct costs at more than £32 million and issued breach notifications in February 2026 after an 18-month forensic review.
  • 2025年4月: An attack on SK Inc., a firm that invests heavily in US businesses, was uncovered when files appeared on Qilin’s data leak site. そのグループは1TB以上のファイルを不正に持ち出した サーバーから.
  • 2025年5月: ジョージア州コブ郡 reported an attack conducted by Qilin. The group acquired 150GB of data, including 400,000 files, autopsy photos, Social Security numbers (SSNs), driver’s licenses, and other personal records.
  • 2025年5月: Attackers entered the network of Covenant Health, an Andover, Massachusetts-based system operating hospitals and elder care facilities across New England, on May 18. The intrusion was detected on May 26. Covenant initially reported the breach to regulators as affecting 7,864 people; after extended analysis it revised that figure to 478,188 individuals in a December 31 filing with the Maine Attorney General. Exposed data included names, dates of birth, medical record numbers, SSNs, insurance details, and treatment information. Qilin claimed to have taken 852GB across roughly 1.35 million files, a figure Covenant has never confirmed.
  • September 2025: Qilin compromised Asahi Group Holdings, Japan’s largest brewer, in an attack detected on September 29. There was no zero-day and no novel tooling — the group got in with stolen credentials. Asahi halted production at most of its roughly 30 domestic factories, and its order processing, shipping, and customer service systems went down, causing nationwide product shortages. Its six Japanese beer plants restarted on October 2. Asahi later estimated around ¥5 billion (roughly US$31.4 million) in lost revenue and confirmed in November that personal data belonging to more than 1.5 million people was exposed. Qilin claimed to have stolen about 27GB across 9,300 files; Reuters was unable to verify the authenticity of the documents the group published.
  • September 2025: DragonForce announced a coalition with Qilin and LockBit on a Russian-language underground forum, days after LockBit relaunched with LockBit 5.0. Documented by ReliaQuest, the arrangement is intended to let the three share techniques, infrastructure, and affiliates — a departure from the isolated, often hostile competition that has characterised the ransomware ecosystem.
  • October 2025: Trend Micro and Cisco Talos documented Qilin affiliates running Linux encryptors inside Windows Subsystem for Linux to sidestep Windows-native EDR. The same research counted more than 700 victims across 62 countries since January 2025, with the group publishing over 40 new victims per month in the second half of the year. Attacks on government bodies picked up over the same period, including three US agencies, three French municipalities, and a public utility in Aruba.
  • January 2026: Qilin posted 55 victims to its leak site in roughly the first two weeks of the year, ahead of its own record-setting 2025 pace. Across 2025 the group claimed over 1,000 victims, with manufacturing accounting for around 23% of listings.
  • 2026年3月 キリンは、サイバー攻撃の犯行声明を出した 左派, a German left-wing political party. The party confirmed the incident on March 27, the day after the attack, taking parts of its IT systems offline immediately and filing a criminal complaint with authorities. Qilin threatened to leak stolen data if demands were not met — a textbook example of their double extortion playbook applied to a political target rather than a commercial one.
  • May–June 2026: A Qilin affiliate was linked to exploitation of CVE-2026-50751, a critical authentication bypass in Check Point Remote Access VPN and Mobile Access. Check Point disclosed the flaw on June 8 after tracing exploitation back to May 7. Check Point attributes one confirmed post-compromise case to a Qilin affiliate, with medium confidence.
  • H1 2026: Qilin was the most active ransomware group tracked by Cyble Research and Intelligence Labs, accounting for 370 attacks in North America — close to a fifth of all ransomware incidents recorded in the region — alongside 158 across Europe and the UK, 64 in Asia-Pacific, and 40 in South America.

One counterpoint is worth noting. Halcyon’s Q2 2026 tracking has Qilin still leading by volume but with monthly output down by roughly a third, and TheGentlemen — a former Qilin affiliate that spun off its own brand — taking the monthly lead in June 2026. Softening ransom payment rates appear to be squeezing affiliate economics. Whether that marks a plateau or a temporary dip isn’t yet clear.

Qilin ransomwareは誰を標的にしていますか?

Qilin operates with no self-imposed sector restrictions. Manufacturing consistently ranks as its most-hit vertical across every major tracker, followed by professional services, healthcare, technology, and construction, though the exact ordering varies by source and reporting period.

The assumption that ransomware groups pursue only large enterprises doesn’t hold here. Qilin’s victim lists are full of small and mid-sized organisations: local courts, school districts, water utilities, and independent healthcare practices. What these targets share is not size but pressure — environments where downtime is immediately painful and where security budgets rarely match the exposure.

Compromised organisations tend to share common weak points:

  • Internet-facing VPN and remote access appliances, particularly unpatched or running deprecated protocols
  • Credentials exposed through prior breaches, infostealers, or reuse
  • Legacy systems, flat networks, and backup infrastructure reachable from domain accounts
  • Managed service provider relationships, where compromising one administrator cascades downstream to customers
Figure 2: Industries targeted by Qilin ransomware as of June 7, 2024 — historical snapshot. HSCC

キリンは%の身代金支払いをアフィリエイトに提供し、現在も%で “Call Lawyer” feature 身代金の支払いを増額するよう被害者に圧力をかけるためのツールキットに.

Qilinランサムウェアはどのように機能しますか?

Qilin affiliates gain access through stolen credentials, exposed remote access appliances, and social engineering, then exfiltrate data before encrypting systems and launching double extortion. Written in Go and Rust, it targets Windows, Linux, and VMware ESXi, making it adaptable across varied IT infrastructures — including the virtualisation layer that hosts everything else.

キリンランサムウェアのIOC

  • 組み込みソフトウェアの欠陥の活用 麒麟が〜 Fortinetの脆弱性を悪用していることが確認された, その中には CVE-2024-21762CVE-2024-55591 認証をバイパスして悪意のあるコードを実行するため。.
  • VPN authentication bypass: CVE-2026-50751 (CVSS 9.3) in Check Point Remote Access VPN and Mobile Access allows an unauthenticated remote attacker to establish a VPN session without a valid password. Only deployments using the deprecated IKEv1 key exchange are affected.
  • 認証トークンのハイジャック Attackers exploited a critical flaw (CVE-2024-27198) in JetBrains’ TeamCity On-Premises, allowing remote authentication and unauthorized admin access to servers.
  • Veeamの脆弱性 に発見された脆弱性 Veeam Backup & Replication CVE-2023-27532 攻撃者が設定データベースに保存されている暗号化された認証情報を取得できるようになりました。.
  • Remote management tool abuse: AnyDesk, ScreenConnect, Splashtop, and TeamViewer have all been observed in Qilin intrusions outside legitimate contexts. Unexpected RMM activity is a reliable pre-encryption indicator.
  • Exfiltration tooling: Rclone, Cyberduck, and WinRAR have been used to stage and move data out ahead of encryption.
  • File extensions and ransom notes vary by affiliate. Observed extensions include .麒麟, .議題, .qln, and victim-specific identifiers. Ransom note filenames include README-RECOVER-[会社ID].txt, README.txt, 、そして qilin_Readme.txt. Because Qilin lets affiliates customise these, no single extension or filename should be treated as definitive.
  • コマンド・アンド・コントロール(C2)サーバー ドメインとの通信、例えば bloglake7.cfd 観測されました。.
  • BYOVD(Bring your own Vulnerable Driver) 脆弱なドライバーの活用 like TPwSav.sys to disable Endpoint Detection and Response (EDR) tools. A BYOVD chain delivered via DLL sideloading has been observed terminating hundreds of EDR drivers before encryption.
図3:TeamCityサーバーへのバックドアアクセスにCVE-2024-27198が悪用されました。. ブリーピング・コンピューター.

キリンランサムウェア TTP

初期アクセス

RVToolsのトロイの木馬化されたバージョンをインストールさせるスピアフィッシングメールが従業員を騙した rv-tool.net. In other cases, attackers log in directly using purchased or reused RDP credentials. Increasingly, affiliates skip exploitation entirely and simply authenticate — which is why credential exposure and VPN configuration matter more than patch cadence alone. Targeted campaigns against MSP administrators have also been observed, where compromising a single ScreenConnect admin account cascades to downstream customers.

実行

一度内部に入ると、Qilinはネイティブスクリプトツールを使用してカスタムペイロードをドロップします。PowerShellコマンドはサイレントにダウンロードします ネクストローダー, pulling in the ransomware binary without triggering traditional antivirus. Group Policy has also been used to push scripts across domain-joined machines at scale.

Qilin’s loader disguised itself as a Windows “SystemHealthMonitor” tool and used the Registry Run key to establish persistence. This allowed the malicious script (svchost.js起動時に自動実行する).

New-ItemProperty -Path "HKCU:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

  • システムヘルスモニター"
  • Value "C:\Windows\System32\wscript.exe //B //E:jscript C:\ProgramData\svchost.js"
  • プロパティタイプ文字列-強制

権限昇格

Qilin affiliates bring their own vulnerable drivers (BYOVD), such as Zemana AntiMalware or Toshiba power drivers, to disable security tools and gain system access.

Defense evasion

リネームされたバイナリを使用して upd.exe (a spoof of legitimate AV updaters), Qilin ransomware disables EDR, clears logs, and bypasses detection. Affiliates have also been observed rebooting hosts into Safe Mode to sidestep endpoint defences.

The most significant recent development is the use of Windows Subsystem for Linux. By executing Linux ELF encryptors inside WSL, affiliates run their payload in a space most Windows-focused EDR does not inspect at the same fidelity as native processes. The encryptor can then reach mounted Windows file shares while generating far fewer detection events.

資格情報アクセス

Once elevated, Qilin dumps LSASS memory using tools such as Mimikatz and harvests credentials stored in Google Chrome — in some cases via Group Policy scripts deployed across every domain-joined machine at once, turning a single foothold into organisation-wide credential exposure.

ラテラルムーブメント

認証情報を入手したQilinは、SMB、RDP、WinRM、PsExecを使用してネットワーク上を横断します。ScreenConnectやAnyDeskなどのITツールが、アクセスを拡大するために乗っ取られることもあります。.

影響

When ready, Qilin triggers its payload. Before encryption, affiliates delete shadow copies and backup catalogs — enterprise-wide VSS deletion should be treated as a ransomware precursor in its own right. Backups, if reachable, are targeted first, with Veeam infrastructure a recurring focus.

In 2025 Qilin added a DDoS capability to its toolkit, giving affiliates a third lever of pressure alongside encryption and data leaking. The group also introduced a “Call Lawyer” feature in its negotiation panel, connecting victims to legal consultants to increase settlement pressure by highlighting regulatory exposure. These additions reflect a deliberate shift toward professionalised, multi-vector extortion rather than pure ransomware deployment.

キリンランサムウェア攻撃を防ぐ方法

Protecting yourself against Qilin means adopting a layered defense strategy built around how the group actually gets in: credentials and edge devices, not exotic exploits.

  • Harden remote access first. Patch VPN appliances promptly, disable deprecated protocols such as IKEv1, and require machine certificates for remote access connections. Since affiliates increasingly authenticate rather than exploit, device-based certificates on RDP and VPN close the gap that stolen credentials alone would open.
  • アイデンティティおよびアクセス管理を強化する。. アカウント全体でMFAを実装して認証情報の漏洩リスクを軽減し、ドメインコントローラー、サーバー、ワークステーション、Active Directoryを調査して不審なユーザーアカウントがないか確認してください。.
  • Monitor or disable WSL where it isn’t needed. Most endpoint tooling does not inspect WSL process activity at native fidelity, which is precisely why Qilin uses it. If your estate has no legitimate WSL use case, disabling it removes the technique entirely.
  • Block vulnerable drivers. Maintain an EDR driver blocklist to counter BYOVD chains, and alert on DLL sideloading against security products.
  • Detect exfiltration, not just encryption. Data leaves the environment before the payload fires. Detection built solely around encryption events misses the part of the attack that drives the extortion.
  • Alert on unexpected RMM activity. AnyDesk, ScreenConnect, Splashtop, and TeamViewer appearing outside sanctioned use is a pre-encryption signal worth escalating.
  • Secure off-site, immutable backups. Keep copies that cannot be modified or deleted from the systems they protect, and that are not reachable through domain accounts.
  • ネットワークセグメンテーションを実装する. ネットワークをより小さなセクションに分割し、攻撃者が水平方向に拡散するのをより困難にします。.
  • IoCに注意してください。. QilinのIoC(ファイルハッシュや不審なIPアドレスなど)をネットワーク環境で監視し、潜在的な攻撃を常に把握しておきましょう。.

キリンランサムウェア対策

Be proactive against cyber threats by making sure you’re ready to respond quickly and minimize risk the moment an incident occurs.

二重恐喝ランサムウェアの緩和策

  • 攻撃対象領域を保護してください。. サイベルエンジェル アタックサーフェスマネジメント ソリューションは、インターネット(シャドーITやサードパーティ資産を含む)を継続的にスキャンし、Qilinアフィリエイトによって悪用される一般的な侵入経路である、露出したサービス、認証情報、および誤設定されたシステムを特定します。.
  • データ漏洩検知. Qilin uses double extortion tactics to extract funds from victims. CybelAngel’s データ漏洩防止 Torを含むダークウェブフォーラム、マーケットプレイス、リークサイトを監視し、インシデント対応を迅速化します。.
  • 認証情報漏洩監視. Stolen or reused credentials are the most common vector in Qilin attacks — the Asahi compromise began with nothing more. CybelAngel’s 資格情報インテリジェンス 資格情報がオンラインで収集・漏洩された際に警告し、攻撃者に悪用される前に迅速な削除を促します。.
  • リアルタイムアラートと是正措置. Secure assets and sensitive information with CybelAngel’s 是正 解決策 — 特に攻撃者が企業の情報をダークウェブに流出させた場合。.

よくある質問

Yes. Qilin was the most active ransomware group tracked by Cyble Research and Intelligence Labs in the first half of 2026, with 370 attacks in North America alone. Its leak site has listed more than 2,100 organisations since 2022. Some trackers recorded a decline in monthly output during Q2 2026.

Qilin is assessed as a Russian-speaking operation, based on Russian-language code artefacts and a documented policy of avoiding targets in CIS countries. No government has issued a formal attribution. As a ransomware-as-a-service platform, its attacks are carried out by affiliates rather than the core operators, who take 15–20% of proceeds.


They are the same operation. The group launched as Agenda in August 2022 and rebranded to Qilin the following month. Researchers still use both names. The ransomware was originally written in Go and later rewritten in Rust, which improved its cross-platform reach across Windows, Linux, and VMware ESXi.

By consequence, the June 2024 attack on NHS pathology provider Synnovis: over 10,000 appointments cancelled, more than £32 million in costs, and a patient death formally linked to delayed blood test results. By operational scale, the September 2025 attack on Asahi, which halted production at most of the brewer’s 30 factories and cost roughly $31.4 million in lost revenue.

Most often through stolen or purchased credentials and exposed remote access appliances, rather than sophisticated exploits. Affiliates also use spear-phishing and exploit public-facing applications, including Fortinet and Check Point VPN flaws. The Asahi compromise, one of the most disruptive on record, began with nothing more than compromised passwords.


Yes. In June 2025, King’s College Hospital NHS Foundation Trust confirmed that a patient died unexpectedly during the Synnovis incident, and that a long wait for blood test results caused by the attack was among the contributing factors. It is one of very few ransomware attacks anywhere formally linked to a fatality.

著者について