DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // QILIN-VPN-CAMPAIGN-2026FIRST SEEN: AUG 2022

QILIN

ALSO KNOWN AS: Agenda, AgendaCrypt
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Unknown (RaaS operation; suspected Eastern European affiliation)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:AUG 2022
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL73/100
RESOURCES73/100
PERSISTENCE76/100
STEALTH68/100
IMPACT82/100

Qilin (aka Agenda) is a highly active RaaS operation that dominated the ransomware landscape in 2025 and remains a top-tier threat in 2026, ranking #1 by total victim count over the past 12 months with an estimated 1,448 attacks. In a major escalation disclosed June 8, 2026, a Qilin affiliate was confirmed to have exploited CVE-2026-50751 — a critical CVSS 9.3 authentication bypass zero-day in Check Point Remote Access VPN — since May 7, 2026, a full month before a patch was available. CISA added the vulnerability to its KEV catalog on June 9, 2026 with a three-day federal patch deadline, underscoring the severity of active exploitation.

Financial extortion; double-extortion RaaS with aggressive affiliate recruitment and zero-day exploitation capability

Zero-day VPN exploitation (CVE-2026-50751 Check Point IKEv1 auth bypass; prior: SonicWall SSL VPN, WatchGuard, Fortinet, F5 VPNs); Sliver C2 framework; Linux/ESXi/Nutanix ransomware payloads (ELF binaries); Rclone for data exfiltration; Tox protocol for C2 communications; double-extortion; open recruitment affiliate model

HEALTHCARE
MANUFACTURING
TECHNOLOGY
FINANCIAL SERVICES
GOVERNMENT
LEGAL SERVICES

Dark web leak site (DLS); VPS infrastructure (Kaupo Cloud HK, Shock Hosting, Vultr Holdings); geo-matched attacker VPS to victim geography; Check Point CVE-2026-50751 exploitation chain; attacker-controlled ELF payload delivery servers

FILE DATE: MAY 2026
Check Point VPN Zero-Day Campaign (CVE-2026-50751)
A Qilin affiliate began silently exploiting CVE-2026-50751, a zero-day authentication bypass in Check Point Remote Access VPN (CVSS 9.3), beginning May 7, 2026 — targeting dozens of organizations globally before the vendor detected activity on June 4 and issued emergency hotfixes on June 8.
FILE DATE: JUN 2026
Healthcare Blitz
Qilin claimed 9 healthcare victims in a single 24-hour window on █████████████ continuing a pattern of aggressive healthcare sector targeting documented throughout Q2 2026.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn