Qilin (aka Agenda) is a ransomware malware family deployed via RaaS affiliates. It was used in June 2026 attacks exploiting CVE-2026-0257. The malware is staged at C:PerfLogs, executed via PsExec, and often password-protected. It disables Microsoft Defender Real-Time Protection and clears event logs before encryption.