DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // QILIN-VPN-CAMPAIGN-2026FIRST SEEN: AUG 2022

QILIN

ALSO KNOWN AS: Agenda, AgendaCrypt
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Unknown (RaaS operation; suspected Eastern European affiliation)
ATTRIBUTION:ORGANIZED CRIME
STATUS:● ACTIVE
FIRST OBSERVED:AUG 2022
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL73/100
RESOURCES73/100
PERSISTENCE76/100
STEALTH68/100
IMPACT82/100

Qilin (aka Agenda) is a highly active RaaS operation that dominated the ransomware landscape in 2025 and remains a top-tier threat in 2026, ranking #1 by total victim count over the past 12 months with an estimated 1,448 attacks. In a major escalation disclosed June 8, 2026, a Qilin affiliate was confirmed to have exploited CVE-2026-50751 — a critical CVSS 9.3 authentication bypass zero-day in Check Point Remote Access VPN — since May 7, 2026, a full month before a patch was available. CISA added the vulnerability to its KEV catalog on June 9, 2026 with a three-day federal patch deadline, underscoring the severity of active exploitation.

Financial extortion; double-extortion RaaS with aggressive affiliate recruitment and zero-day exploitation capability

Zero-day VPN exploitation (CVE-2026-50751 Check Point IKEv1 auth bypass; prior: SonicWall SSL VPN, WatchGuard, Fortinet, F5 VPNs); Sliver C2 framework; Linux/ESXi/Nutanix ransomware payloads (ELF binaries); Rclone for data exfiltration; Tox protocol for C2 communications; double-extortion; open recruitment affiliate model

HEALTHCARE
MANUFACTURING
TECHNOLOGY
FINANCIAL SERVICES
GOVERNMENT
LEGAL SERVICES

Dark web leak site (DLS); VPS infrastructure (Kaupo Cloud HK, Shock Hosting, Vultr Holdings); geo-matched attacker VPS to victim geography; Check Point CVE-2026-50751 exploitation chain; attacker-controlled ELF payload delivery servers

FILE DATE: MAY 2026
Check Point VPN Zero-Day Campaign (CVE-2026-50751)
A Qilin affiliate began silently exploiting CVE-2026-50751, a zero-day authentication bypass in Check Point Remote Access VPN (CVSS 9.3), beginning May 7, 2026 — targeting dozens of organizations globally before the vendor detected activity on June 4 and issued emergency hotfixes on June 8.
FILE DATE: JUN 2026
Healthcare Blitz
Qilin claimed 9 healthcare victims in a single 24-hour window on █████████████ continuing a pattern of aggressive healthcare sector targeting documented throughout Q2 2026.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn