Qilin, also known as Agenda and Qilin Locker, is a ransomware-as-a-service operation that emerged in 2022 and became one of the most active global extortion threats by 2025–2026. It uses a double-extortion model in which affiliates encrypt victim systems and steal data, then pressure organizations by threatening public disclosure. Victimology has been concentrated in manufacturing, business services, technology, healthcare, and financial organizations, with activity reported across high-GDP Western countries and a stated prohibition on targeting CIS member states. Public reporting has linked the operation to hundreds of victims in 2026 alone and to sustained activity across North America and Europe.
Qilin intrusions have been associated with multiple initial access paths. High-confidence reporting ties affiliates to exploitation of internet-facing VPN and edge infrastructure, including Palo Alto Networks GlobalProtect authentication-bypass flaws and Check Point VPN vulnerabilities. Other observed access patterns include use of stolen VPN or RDP administrator credentials. Once inside, operators conduct broad post-exploitation activity that can vary by affiliate, ranging from rapid encryption-only attacks to longer dwell-time intrusions involving reconnaissance, credential theft, lateral movement, backup targeting, data exfiltration, and enterprise-wide ransomware deployment.
Observed tradecraft includes persistence through scheduled tasks and Windows registry modifications; credential theft through LSASS dumping and Active Directory database extraction; reconnaissance with network scanning and administrative tooling; lateral movement via PsExec, RDP, and administrative shares; and defense evasion through log clearing, Microsoft Defender tampering, AMSI bypass, obfuscated PowerShell, termination of security tools, and bring-your-own-vulnerable-driver techniques. Data theft has been conducted with common transfer and remote administration utilities and cloud-storage services prior to encryption. Reporting also notes targeting of backup infrastructure to hinder recovery.
Qilin is widely assessed as a mature affiliate ecosystem rather than a single intrusion crew. Variations in tempo and tooling across incidents are consistent with multiple affiliates operating under shared ransomware infrastructure and extortion branding. The group has been linked to campaigns affecting government entities, public administration, energy, healthcare, finance, and industrial organizations, and has become a prominent actor in the broader ransomware and extortion landscape.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-50751 (CVSS skóre 9,3) Spoločnosť Check Point vydala bezpečnostné aktualizácie pre kritickú zraniteľnosť ovplyvňujúcu produkty Remote Access VPN, Mobile Access/SSL VPN a Spark Firewall, ktorú útočníci aktívne zneužívali v útokoch minimálne od 7. mája 2026. V jednom prípade bol útok spojený s ransomvérovou skupinou Qilin. CVE-2026-50751 súvisí s logickou chybou v procese validácie certifikátov pri výmene šifrovacích kľúčov v rámci protokolu IKEv1. Vzdialeným neautentifikovaným útočníkom umožňuje obísť prihlasovanie a vytvoriť VPN reláciu.
A flaw in the popular VPN service, tracked as CVE-2026-0257, could allow attackers to bypass authentication and establish an unauthorized connection. The vulnerability primarily affects the GlobalProtect portal and gateway for Palo Alto Networks’ PAN-OS software. | Analysis by Arctic Wolf Labs suggests attacks on GlobalProtect customers could be the work of the Qilin ransomware group or affiliates. Indeed, researchers detected Qilin ransomware during several instances across June.
Recently, the group have been observed exploiting CVE-2025-31324, (SAP NetWeaver Visual Composer vulnerability) and have previously exploited CVE-2023-27532 (Veeam Backup and Replication vulnerability). | Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.
Recently, the group have been observed exploiting CVE-2025-31324, (SAP NetWeaver Visual Composer vulnerability) and have previously exploited CVE-2023-27532 (Veeam Backup and Replication vulnerability). | Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.
CVE-2024–21762 and CVE-2024–55591: Critical vulnerabilities in Fortinet’s FortiGate and FortiProxy devices, enabling authentication bypass and remote code execution. CVE-2024–21762, patched in February 2025, remains a major concern with tens of thousands of exposed systems. | Qilin ransomware, also known as Agenda, has emerged as one of the most significant and evolving cyber threats globally, rapidly ascending to become a top-tier ransomware-as-a-service (RaaS) operation.
CVE-2024–21762 and CVE-2024–55591: Critical vulnerabilities in Fortinet’s FortiGate and FortiProxy devices, enabling authentication bypass and remote code execution. | Qilin ransomware, also known as Agenda, has emerged as one of the most significant and evolving cyber threats globally, rapidly ascending to become a top-tier ransomware-as-a-service (RaaS) operation.
On June 8th 2026, Check Point Research identified two CVEs (CVE-2026-50751, CVE-2026-50752) which can be abused to bypass Checkpoint VPN Authentication services, allowing threat actors to access network devices and traffic behind the VPN. | Check Point Research has medium confidence that the attacker is affiliated with Qilin as they use the Qilin ransomware toolkit.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
18 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In June, CISA ordered federal agencies to secure their Check Point Remote Access VPN and Mobile Access deployments against another authentication bypass vulnerability (CVE-2026-50751) that was exploited in zero-day attacks by the Qilin ransomware gang.
Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS, which Unit 42 tracks as Spikey Scorpius.
Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.
Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.
According to VX-Underground, DragonForce proposed establishing communication channels with the LockBit and the Qilin group.
Our Threat Hunter Team has separately observed ModeloRAT used in attacks that deployed Qilin ransomware, linking this tool to ransomware deployment.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
A flaw in the popular VPN service, tracked as CVE-2026-0257, could allow attackers to bypass authentication and establish an unauthorized connection.
Rapid7 noted that customers compromised in this wave of attacks had Cloud Authentication Service (CAS) disabled. Others, meanwhile, had GlobalProtect portal or gateway authentication override cookies enabled.
After exploiting CVE-2026-0257, the attackers established VPN sessions from Kali Linux systems, then quickly secured persistent access using registry Run keys, scheduled tasks, and remote administration tools such as AnyDesk, Ngrok, LogMeIn, and MeshAgent.
After exploiting CVE-2026-0257, the attackers established VPN sessions from Kali Linux systems, then quickly secured persistent access using registry Run keys, scheduled tasks, and remote administration tools such as AnyDesk, Ngrok, LogMeIn, and MeshAgent.
payload win.exe stagé dans C:\PerfLogs\ , exécuté avec --password et --no-admin
some of these intrusions went from VPN authentication bypass to full encryption with minimal dwell time, while others involved weeks of credential harvesting... From there, credential dumping and lateral movement through administrative shares follow a well-documented playbook
From there, credential dumping and lateral movement through administrative shares follow a well-documented playbook
Qilin was observed leveraging Palo Alto Networks GlobalProtect VPN firewalls to drop ransomware and conduct data exfiltration against unspecified victims.
231 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named ransomware operation that DevMan reportedly worked as an affiliate for before launching its own RaaS scheme.
A newer dominant ransomware family/group in the fragmented post-takedown RaaS landscape.
Ransomware family operated by the Qilin ransomware gang; mentioned here as exploiting a separate Check Point authentication bypass vulnerability in zero-day attacks.
Qilin is a ransomware family operated under a ransomware-as-a-service model. In the reported intrusions, it was observed after exploitation of the GlobalProtect authentication bypass vulnerability, with post-exploitation ranging from rapid encryption-only operations to full double extortion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.