SUBJECT PROFILE
Qilin (aka Agenda) is a highly active RaaS operation that dominated the ransomware landscape in 2025 and remains a top-tier threat in 2026, ranking #1 by total victim count over the past 12 months with an estimated 1,448 attacks. In a major escalation disclosed June 8, 2026, a Qilin affiliate was confirmed to have exploited CVE-2026-50751 — a critical CVSS 9.3 authentication bypass zero-day in Check Point Remote Access VPN — since May 7, 2026, a full month before a patch was available. CISA added the vulnerability to its KEV catalog on June 9, 2026 with a three-day federal patch deadline, underscoring the severity of active exploitation.
Financial extortion; double-extortion RaaS with aggressive affiliate recruitment and zero-day exploitation capability
OPERATIONAL HISTORY
Zero-day VPN exploitation (CVE-2026-50751 Check Point IKEv1 auth bypass; prior: SonicWall SSL VPN, WatchGuard, Fortinet, F5 VPNs); Sliver C2 framework; Linux/ESXi/Nutanix ransomware payloads (ELF binaries); Rclone for data exfiltration; Tox protocol for C2 communications; double-extortion; open recruitment affiliate model
KNOWN INFRASTRUCTURE
Dark web leak site (DLS); VPS infrastructure (Kaupo Cloud HK, Shock Hosting, Vultr Holdings); geo-matched attacker VPS to victim geography; Check Point CVE-2026-50751 exploitation chain; attacker-controlled ELF payload delivery servers