SUBJECT PROFILE
Qilin (originally launched as 'Agenda' in July 2022, rebranded as a RaaS in February 2023) remains one of the top two most prolific ransomware groups globally in 2026 with 289 victims in Q2 alone. A major campaign update disclosed July 20–22, 2026 by Arctic Wolf Labs revealed Qilin affiliates actively exploiting CVE-2026-0257, a critical PAN-OS GlobalProtect authentication bypass (CVSS 9.1), enabling unauthenticated VPN access to corporate networks and leading directly to domain-wide encryption. Multiple distinct intrusions in June 2026 were traced to this single entry point across unpatched Palo Alto Networks firewall appliances.
Financial — high-volume ransomware via RaaS affiliate model with double extortion
OPERATIONAL HISTORY
CVE-2026-0257 (PAN-OS GlobalProtect auth bypass) exploitation, credential harvesting (LSASS dump, NTDS extraction), lateral movement via Windows admin shares, PsExec-based ransomware staging and execution, registry persistence, double extortion (encrypt + exfiltrate), Rust-based payload, RaaS affiliate model
KNOWN INFRASTRUCTURE
PAN-OS GlobalProtect VPN exploitation (CVE-2026-0257) for initial access; LSASS memory dumping and AD database extraction post-compromise; PsExec for lateral movement; ransomware staging via consistent file paths; dedicated leak site for victim publication