DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // QILIN-PAN-OS-CAMPAIGNFIRST SEEN: JUL 2022

QILIN (AGENDA)

ALSO KNOWN AS: Agenda, Qilin RaaS
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Unknown (assessed Russia-linked)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:JUL 2022
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL77/100
RESOURCES77/100
PERSISTENCE80/100
STEALTH72/100
IMPACT86/100

Qilin (originally launched as 'Agenda' in July 2022, rebranded as a RaaS in February 2023) remains one of the top two most prolific ransomware groups globally in 2026 with 289 victims in Q2 alone. A major campaign update disclosed July 20–22, 2026 by Arctic Wolf Labs revealed Qilin affiliates actively exploiting CVE-2026-0257, a critical PAN-OS GlobalProtect authentication bypass (CVSS 9.1), enabling unauthenticated VPN access to corporate networks and leading directly to domain-wide encryption. Multiple distinct intrusions in June 2026 were traced to this single entry point across unpatched Palo Alto Networks firewall appliances.

Financial — high-volume ransomware via RaaS affiliate model with double extortion

CVE-2026-0257 (PAN-OS GlobalProtect auth bypass) exploitation, credential harvesting (LSASS dump, NTDS extraction), lateral movement via Windows admin shares, PsExec-based ransomware staging and execution, registry persistence, double extortion (encrypt + exfiltrate), Rust-based payload, RaaS affiliate model

ENTERPRISE
HEALTHCARE
FINANCE
CONSTRUCTION
CRITICAL INFRASTRUCTURE
RETAIL
TECHNOLOGY

PAN-OS GlobalProtect VPN exploitation (CVE-2026-0257) for initial access; LSASS memory dumping and AD database extraction post-compromise; PsExec for lateral movement; ransomware staging via consistent file paths; dedicated leak site for victim publication

FILE DATE: MAR 2025
Legal Department Announcement
Qilin announced it was building an internal legal department to file evidence of victims' regulatory violations with tax authorities and law enforcement — a novel extortion escalation tactic.
FILE DATE: JUN 2026
CVE-2026-0257 PAN-OS Exploitation Wave
Arctic Wolf Labs investigated multiple June 2026 intrusions all originating from ██████████████████████ Palo Alto GlobalProtect, leading to rapid domain-wide Qilin ransomware deployment — some with minimal dwell time and no prior data exfiltration.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn