Security1 distinct publisher3 min readPublished
Group-IB puts the Qilin affiliate cut at up to 80 percent, and KELA logged a change that routes victim payments through affiliate wallets first, which says more about the operation's incentives than its thin public tradecraft record does.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
KELA's July 2023 observation is the load-bearing detail. Haise, the RAMP profile that advertises Qilin, told the forum that ransom payments go into affiliate wallets first, and only then is a share transferred to the Qilin RaaS owners [9]. That places the core team downstream of its own affiliate for collection. In a market where the operator normally controls the wallet, that is a concession, and concessions of that kind get made to attract and keep the people who do the intrusions.
The economics behind the concession are documented. Group-IB reported affiliates can take up to 80 percent when the paid ransom is 3 million USD or less, rising to 85 percent above that [8]. KELA logged Qilin demands in the 25,000 to 600,000 USD range in mid-2023 and identified one Thai real estate development company that paid 600,000 USD after 20 days of negotiation [16]. At the 80 percent tier, that single payment leaves 480,000 USD with the affiliate and 120,000 USD with the core team [1]. A RAMP account, the gate to the advertisement, costs up to 500 USD in BTC [6], roughly a thousandth of the affiliate's take on that one deal [2]. At the 3 million USD boundary, the five-point step to 85 percent is worth 150,000 USD [3].
The recruitment timeline runs behind the operational one. Haise joined RAMP on 29 May 2022 and advertised Qilin on 13 February 2023, a gap of 260 days [7][4]. The first victim appeared on the Tor leak site in October 2022, with reports of the same code deployed under the name Agenda as early as June 2022 [10]. The crew was encrypting and leaking about four months before it posted the public advertisement [5].
Counting is where the public record is weakest. From Q2 2023, victim listings ran at around five per month and rose noticeably from the start of 2024 [11], but only victims who do not pay get leaked, and BushidoToken notes that establishing true attack volume is difficult [12]. Leak-site tallies are a floor on attacks and a proxy for refusal rates, not a measure of activity. The only stated targeting rule is exclusion: the operators wrote on RAMP that they do not work in CIS countries [15]. Everything else in the victim set reflects affiliate opportunity, spread across Argentina, Australia, Brazil, Canada, France, Germany, Japan, the UK, the US and others, with large companies targeted indiscriminately [13].
For detection engineering, the honest read is that this record does not carry the weight. Qilin is used for domain-wide encryption of servers and workstations with bulk data theft ahead of it [4], which describes the outcome rather than the technique. Naming conventions exist across vendors, Water Galura at Trend Micro and GOLD FEATHER at Secureworks [5], but only a handful of public resources cover affiliate TTPs, with Trend Micro the primary contributor [17]. A tabletop built on this material can exercise the negotiation clock, the double-extortion sequence and the leak-site publication step [3], because those are documented. Host-level detection content still has to come from somewhere else.
Ranked by verification strength, evidence, and original report placement.
The first Qilin victim was posted to the group's Tor data leak site in October 2022, and there are reports of Qilin, formerly known as Agenda, being deployed as early as June 2022.
From Q2 2023 Qilin victims were listed at a rate of around five per month, and the number has noticeably increased since the start of 2024.
Qilin ransomware has been active since at least May 2022 and is named after a mythical Chinese creature.
The origin of the Qilin threat group is believed to be Russia.
Qilin operates as a Ransomware-as-a-Service: affiliates external to the core team run attacks, while the Qilin RaaS handles payload generation, publication of stolen data, and ransom negotiations.
Qilin ransomware is used for domain-wide encryption of servers and workstations, with operators stealing large quantities of data first and demanding ransom for decryption keys and to prevent publication, a model known as double extortion.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
The Gentlemen affiliates encrypt within a day of logging into a VPN with a stolen password1 distinct publisher
security
Nutex discloses stolen patient data breach to SEC, says it is still assessing what was taken3 distinct publishers
security
ToxicPanda 2.0 Widens From 16 Apps to 140, and From Overlays to ADB Shell6 distinct publishers
security
One transitive import is enough: 14 npm packages that run a Linux backdoor with no install hook1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One analyst, many borrowed sources
The figures that carry this story are all secondhand and all reach us through a single writer. Group-IB supplies the 80/85 percent split, KELA the wallet-first change and the 600,000 USD payment, Trend Micro most of the tradecraft, Ransomware.live the victim curve — BushidoToken credits each of them and adds no telemetry of its own. That chain is transparent, which is worth a lot, but two of its most quoted links trace back to the gang's own recruitment post on RAMP, and no second publisher in our coverage re-derives any number.
Franchise demonstrably in production
This is not a proof-of-concept operation. Listings have run at about five victims a month since Q2 2023 and climbed through 2024, spread across fifteen countries, with Yanfeng, The Big Issue and — most consequentially — the NHS pathology provider Synnovis among the named casualties. The count is also structurally low, since victims who pay never get posted, so the visible curve is a floor on a business whose true throughput nobody in this reporting can size.
Recruitment pitch quoted as fact
The overstatement here is inherited rather than authored. BushidoToken hedges carefully — 'believed to be', 'appear to', an explicit warning that the victim chart counts only non-payers — but an 85 percent payout and a wallet-first payment order are exactly what a service says when it is competing for affiliates, and both are repeated with no way to test them against actual transfers. One 600,000 USD payment is doing a lot of work behind a description of a global enterprise.
Everyone in frame is selling something
Follow the money in three directions. The gang is bidding for labour: up to 85 percent of the take, and from July 2023 the affiliate holds the funds and remits upward, which transfers both cash-flow timing and exit risk to the core team's advantage in recruitment terms. The affiliate's entry cost is a 500 USD forum account against a 480,000 USD share of one payout. And the researchers whose findings anchor the account — Group-IB, KELA, Trend Micro, Secureworks — sell threat intelligence, while the writer relaying them runs a personal blog with no product to move, which is why the credits read as thanks rather than marketing.
Credible, uncorroborated, and dated
Confidence lands mid-scale for structural reasons rather than doubts about the author. The account is internally consistent, dates its claims, and flags what it does not know; but it is one publisher, its economics come from criminal advertising, its victim numbers from one aggregator, and its newest events — the 2023 payout change, a victim curve described as rising 'since the start of 2024' — are no longer current. What it says is believable. What it says is also unchecked.