Skip to content
Qilin Ransomware Group Uses Linux Binaries to Target Windows Systems

Qilin Ransomware Group Uses Linux Binaries to Target Windows Systems

First seen 2 Nov 2025, 16:14 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

The Qilin ransomware group, previously known as Agenda, has been executing attacks on Windows hosts using Linux-based binaries, affecting over 700 victims since January 2025. This cross-platform execution leverages Windows Subsystem for Linux (WSL) and legitimate remote management tools, allowing the group to evade traditional Windows-centric security measures. The group has maintained a high level of activity, publishing more than 40 victim listings per month on its leak site.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (6)