Qilin, also known as Agenda, has been an active ransomware threat since July 2022. Malware known as SmokeLoader and a previously undocumented .NET compiled loader, also codenamed as NETXLOADER, are being leveraged by threat actors with ties to the Qilin ransomware family.