Classification: TLP:CLEAR | Publication Date: 2026-10-08 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims
QILIN Ransomware Gang: 14 New Leak-Site Claims Posted — Sector Targeting Analysis & Detection Rules
Executive Summary
Between 2026-10-04 and 2026-10-07, the QILIN ransomware operation published 14 new victim listings on its dark web leak site, based on monitoring of the group's .onion infrastructure via ransomware.live. The claims span manufacturing (5 listings), professional services (2), financial services (2), agriculture and food production (1), transportation (1), technology (1), and other/unclassified sectors, with claimed victims across QA, ES, TR, IE, FI, US, TH, AU, and CL.
Every listing in this briefing is an unverified claim made by a criminal organization. Inclusion here does not mean any named organization was breached. Manufacturing remains the most heavily represented sector in this batch — consistent with QILIN's long-standing preference for mid-market industrial and production firms with low tolerance for operational downtime.
Security teams in manufacturing, financial services, and professional services should treat this as an elevation in ambient threat from one of the most persistent RaaS operations currently active, and apply the detection content and hardening guidance below.
Sourcing & Verification
- Of the 14 listings covered in this briefing, 5 were independently observed by a second leak-site crawler (multi-source), and 9 appear on ransomware.live only (single-source). Single-source listings carry additional uncertainty — we cannot independently confirm the posting itself exists.
- Multi-source corroboration means two independent crawlers observed the gang publish the claim. It does not confirm a breach occurred. No tier in our data confirms a breach — only the named organization or its regulator can do that.
- Inclusion in this briefing reflects the threat actor's claim only. A named organization may dispute a listing; a denial is likewise not proof the claim is false. Disclosure obligations vary by jurisdiction and not every incident is reportable, so neither silence nor denial settles the question.
- Security Arsenal will publish corrections as warranted and welcomes contact from any named organization at security@securityarsenal.com.
Threat Actor Profile — QILIN
QILIN (also tracked as Agenda, and historically overlapping with the Water Galura cluster) is one of the longest-running ransomware-as-a-service (RaaS) operations, active since mid-2022. Key characteristics:
- Operating model: Classic RaaS. A core team maintains the Rust/Go-based encryptor, leak site, and negotiation infrastructure; affiliates conduct intrusions and share ransom proceeds (typically 80–85% to the affiliate). Affiliate recruitment occurs on Russian-language criminal forums.
- Ransom demands: Typically range from $50,000 to $5M+ USD depending on victim revenue, with healthcare and public-sector-adjacent victims historically seeing the highest demands. QILIN negotiators are known to be aggressive and quick to publish proof-of-theft data.
- Initial access: Phishing with malicious attachments/links is the most commonly observed vector, followed by exploitation of internet-facing VPN and firewall appliances, exposed RDP, and — increasingly — vulnerable virtualized infrastructure (vCenter/ESXi) and remote management tooling. Affiliates also purchase access from initial access brokers (IABs).
- Double extortion: Standard. Data is exfiltrated (commonly via Rclone, MEGA, or custom tooling) before encryption. Non-paying victims are listed on the leak site with escalating data dumps.
- Dwell time: Observed dwell time is typically 3 to 14 days from initial access to detonation, though affiliate quality varies widely. The pre-encryption window is where defenders win or lose.
- Tooling: PsExec, WMI/WinRM for lateral movement; Cobalt Strike and SystemBC beacons; AnyDesk/Splashtop for persistence; built-in capability to delete Volume Shadow Copies, kill security tooling, and target ESXi datastores.
Current Campaign Analysis
Sector Targeting
Manufacturing dominates this batch with 5 of 14 claims — Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi (TR), CORBY ROCK MILL (IE), Chadwick Switchboards (AU), Emser (ES), and Cotesma (CL). Financial services accounts for 2 (BNYH and J&D Financial, both with unconfirmed jurisdictions), professional services for 2 (EPTISA, ES; Global Security Concepts, US), with single listings in agriculture/food production (Matadero Frigorífico Avinyó, ES), transportation (Delta Marine, FI), and technology (Onsemi, US). Qatar National Import & Export (QA) and Asia Era One (TH) round out the set with unclassified sectors.
Geographic Concentration
The batch is notably distributed: Spain (3 listings) is the most represented single country, followed by the United States (2) and single claims across Qatar, Türkiye, Ireland, Finland, Thailand, Australia, and Chile. This is consistent with a multi-affiliate RaaS model rather than a geographically coordinated campaign — affiliates pursue whatever access they can obtain or purchase.
Victim Profile
The claimed organizations skew toward mid-market enterprises — regional manufacturers, professional services firms, and specialty financial companies — a classic QILIN pattern: large enough to pay meaningful ransoms, small enough to lack 24/7 SOC coverage. Estimated revenues for this profile typically fall in the $10M–$500M range.
Posting Cadence
14 listings in 4 days is a moderately elevated cadence for QILIN, which has historically averaged 2–5 postings per day during active periods. The clustering of 6 postings on 2026-10-05/06 suggests batch publication following a coordinated negotiation-failure window — a common tactic to maximize pressure and leak-site visibility.
CVE Exposure (Hypothesis — Not Attribution)
We have no evidence linking any specific CVE to any specific named listing above. However, the following CISA KEV entries — all confirmed as exploited by ransomware actors — map directly to QILIN's documented initial-access playbook and represent the exposure surface affiliates are most likely monetizing right now:
- CVE-2026-59310 (VMware vCenter path traversal) — direct path to the virtualization layer QILIN encryptors target.
- CVE-2026-50751 (Check Point Security Gateway improper authentication) — edge-VPN compromise, a top QILIN entry vector.
- CVE-2026-20316 (Cisco FMC hard-coded password) — management-plane takeover of firewall infrastructure.
- CVE-2026-63077 (JetBrains TeamCity deserialization) — build-server compromise enabling supply-chain-style internal spread.
- CVE-2026-48027 (Nx Console embedded malicious code) — developer-tooling supply chain exposure.
Treat unpatched instances of any of the above as priority-zero remediation this week.
Detection Engineering
The following detections target QILIN's documented TTPs: VPN/edge exploitation follow-on activity, phishing-driven macro and script execution, RDP brute force, PsExec/WMI lateral movement, Cobalt Strike-style beaconing, and pre-encryption data staging.
---
title: QILIN - Ransomware Pre-Encryption Staging and Shadow Copy Deletion
id: 9f2a1c44-7b31-4c5e-9a11-qilin000001
status: production
description: Detects deletion or resizing of Volume Shadow Copies and backup catalog tampering consistent with QILIN pre-encryption staging behavior
references:
- https://securityarsenal.com/darkside
author: Security Arsenal Threat Intelligence
date: 2026/10/08
modified: 2026/10/08
tags:
- attack.impact
- attack.t1490
logsource:
category: process_creation
product: windows
detection:
selection_vssadmin:
Image|endswith: '\vssadmin.exe'
CommandLine|contains:
- 'delete shadows'
- 'resize shadowstorage'
selection_wmic:
Image|endswith: '\wmic.exe'
CommandLine|contains: 'shadowcopy'
selection_bcdedit:
Image|endswith: '\bcdedit.exe'
CommandLine|contains:
- 'recoveryenabled no'
- 'ignoreallfailures'
selection_wbadmin:
Image|endswith: '\wbadmin.exe'
CommandLine|contains: 'delete catalog'
condition: 1 of selection_*
falsepositives:
- Legitimate backup administration (rare; verify against change windows)
level: high
---
title: QILIN - PsExec or WMI Remote Execution for Lateral Movement
id: 9f2a1c44-7b31-4c5e-9a11-qilin000002
status: production
description: Detects PsExec service execution and WMI-spawned remote processes consistent with QILIN affiliate lateral movement tooling
references:
- https://securityarsenal.com/darkside
author: Security Arsenal Threat Intelligence
date: 2026/10/08
modified: 2026/10/08
tags:
- attack.lateral-movement
- attack.t1569.002
- attack.t1047
logsource:
category: process_creation
product: windows
detection:
selection_psexec:
Image|endswith:
- '\psexec.exe'
- '\psexesvc.exe'
- '\paexec.exe'
selection_psexec_renamed:
OriginalFileName: 'psexec.c'
selection_wmi_child:
ParentImage|endswith: '\wmiprvse.exe'
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\rundll32.exe'
- '\mshta.exe'
condition: 1 of selection_*
falsepositives:
- Enterprise software deployment tools; baseline admin PsExec usage by source account
level: high
---
title: QILIN - Data Staging and Exfiltration Tool Execution
id: 9f2a1c44-7b31-4c5e-9a11-qilin000003
status: production
description: Detects execution of Rclone and archive staging utilities commonly used by QILIN affiliates for pre-encryption data theft
references:
- https://securityarsenal.com/darkside
author: Security Arsenal Threat Intelligence
date: 2026/10/08
modified: 2026/10/08
tags:
- attack.exfiltration
- attack.t1567.002
- attack.collection
- attack.t1560.001
logsource:
category: process_creation
product: windows
detection:
selection_rclone:
Image|endswith: '\rclone.exe'
selection_rclone_cl:
CommandLine|contains:
- 'rclone copy'
- 'rclone sync'
- 'rclone move'
- 'mega.nz'
selection_archive:
Image|endswith:
- '\7z.exe'
- '\rar.exe'
- '\winrar.exe'
CommandLine|contains:
- ' a '
- ' -p'
condition: selection_rclone or selection_rclone_cl or selection_archive
falsepositives:
- Legitimate backup scripts using rclone; allowlist known service accounts and paths
level: medium
The following Sentinel hunt query surfaces the lateral-movement and staging chain — anomalous admin authentications followed by remote execution and shadow copy tampering within a compressed window:
// QILIN pre-ransomware hunt: anomalous logons -> remote exec -> shadow tampering within 6h
let Lookback = 7d;
let SuspiciousLogons =
SecurityEvent
| where TimeGenerated > ago(Lookback)
| where EventID == 4624 and LogonType in (3, 10)
| where Account !endswith "$" and Account !in~ ("ANONYMOUS LOGON", "SYSTEM")
| summarize FirstLogon=min(TimeGenerated), Sources=dcount(IpAddress), SourceIPs=make_set(IpAddress)
by Account, Computer
| where Sources > 2 // same account hitting a host from multiple sources
| project Account, Computer, FirstLogon, SourceIPs;
SuspiciousLogons
| join kind=inner (
SecurityEvent
| where TimeGenerated > ago(Lookback)
| where EventID == 4688
| where NewProcessName has_any ("psexec", "wmic", "vssadmin", "bcdedit", "rclone", "wbadmin")
or CommandLine has_any ("delete shadows", "shadowcopy delete", "recoveryenabled no", "rclone copy")
| project ExecTime=TimeGenerated, Account=SubjectAccount, Computer, NewProcessName, CommandLine, ParentProcessName
) on Account, Computer
| where ExecTime between (FirstLogon .. FirstLogon + 6h)
| summarize Actions=make_set(strcat(NewProcessName, " | ", CommandLine)), ActionCount=count(),
FirstAction=min(ExecTime), LastAction=max(ExecTime)
by Account, Computer, FirstLogon, SourceIPs
| project Account, Computer, FirstLogon, FirstAction, LastAction, ActionCount, Actions, SourceIPs
| order by FirstAction asc
The following rapid-response script checks the three most urgent host-level indicators: exposed RDP, recently created scheduled tasks, and shadow copy health:
# QILIN Rapid Triage - run as Administrator on suspect hosts or fleet-wide via your RMM
# Checks: exposed RDP, scheduled tasks created in last 7 days, shadow copy tampering
Write-Host "=== QILIN Rapid Triage $(Get-Date -Format 'yyyy-MM-dd HH:mm') on $env:COMPUTERNAME ===" -ForegroundColor Cyan
# 1) RDP exposure check
$rdpEnabled = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server').fDenyTSConnections -eq 0
if ($rdpEnabled) {
$nla = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp').UserAuthentication
Write-Host "[ALERT] RDP ENABLED. NLA: $(if($nla -eq 1){'On'}else{'OFF - CRITICAL'})" -ForegroundColor Red
Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue |
Select-Object LocalAddress, LocalPort, OwningProcess | Format-Table
} else { Write-Host "[OK] RDP disabled." -ForegroundColor Green }
# 2) Scheduled tasks created in the last 7 days
Write-Host "`n--- Scheduled tasks created/modified in last 7 days ---"
Get-ScheduledTask | ForEach-Object {
$info = $_ | Get-ScheduledTaskInfo -ErrorAction SilentlyContinue
$task = $_
$xml = Export-ScheduledTask -TaskName $task.TaskName -TaskPath $task.TaskPath -ErrorAction SilentlyContinue
if ($xml -and ([xml]$xml).Task.RegistrationInfo.Date) {
$created = [datetime]([xml]$xml).Task.RegistrationInfo.Date
if ($created -gt (Get-Date).AddDays(-7)) {
[PSCustomObject]@{ Name=$task.TaskName; Path=$task.TaskPath; Created=$created;
Action=(([xml]$xml).Task.Actions.Exec.Command -join '; ') }
}
}
} | Format-List
# 3) Shadow copy inventory - ransomware staging often deletes these
Write-Host "`n--- Volume Shadow Copies ---"
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
if ($shadows) {
$shadows | Select-Object VolumeName, InstallDate, @{n='SizeGB';e={[math]::Round((Get-CimInstance Win32_ShadowStorage -ErrorAction SilentlyContinue | Select-Object -First 1).UsedSpace/1GB,2)}} | Format-Table
} else { Write-Host "[ALERT] NO shadow copies present - investigate for vssadmin deletion (Event ID 8222 or Sysmon ID 1)." -ForegroundColor Red }
# 4) Suspicious staging artifacts in common exfil paths
Write-Host "`n--- Large archives modified in last 7 days (potential staging) ---"
Get-ChildItem C:\Users\, C:\ProgramData\ -Recurse -Include *.zip,*.7z,*.rar -ErrorAction SilentlyContinue |
Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-7) -and $_.Length -gt 100MB } |
Select-Object FullName, LastWriteTime, @{n='SizeMB';e={[math]::Round($_.Length/1MB,1)}} | Format-Table
Write-Host "=== Triage complete ===" -ForegroundColor Cyan
Incident Response Priorities
T-Minus Detection Checklist (Before Encryption Fires)
QILIN's pre-detonation window is your best — often only — opportunity. Hunt for, in order of signal value:
- vssadmin / bcdedit / wbadmin execution outside change windows (shadow copy deletion almost always immediately precedes detonation).
- New or renamed remote access tooling: AnyDesk, Splashtop, ScreenConnect installs on servers where they were never present.
- Rclone, MEGA, or large outbound transfers to consumer cloud storage — especially from file servers or database hosts.
- PsExec/WMIC spawning processes on multiple hosts from a single source workstation or server.
- EDR/AV tampering: service stops, uninstall attempts, or Safe Mode boot configuration changes (
bcdedit /set safeboot). - Mass file reads on a single share or host over a short window (staging behavior).
- Authentication anomalies: a single account touching many hosts, impossible travel on VPN, or logons from newly registered devices.
Assets QILIN Historically Prioritizes for Exfiltration
- Finance and accounting data (invoices, banking details, payroll)
- HR records and PII (used as secondary extortion leverage)
- Legal documents, contracts, and M&A material
- Engineering/IP: CAD files, schematics, source code — particularly relevant given this batch's manufacturing skew
- Email archives from executive mailboxes
Containment Actions — Ordered by Urgency
- Isolate affected network segments at the switch/VLAN level — do NOT power off hosts (preserve memory artifacts).
- Disable compromised or suspect accounts and force enterprise-wide credential resets, prioritizing privileged and service accounts.
- Block egress to consumer cloud storage and known exfil infrastructure at the proxy/firewall.
- Kill persistence: revoke active VPN sessions, disable newly created accounts and scheduled tasks, remove unauthorized RMM tools.
- Verify backup integrity — confirm offline/immutable copies exist and shadow copies were not destroyed on backup infrastructure.
- Engage IR support and legal counsel before any threat actor communication; preserve logs (VPN, EDR, authentication) for forensic scoping.
Hardening Recommendations
Immediate (24 Hours)
- Patch or mitigate the KEV set above — CVE-2026-59310 (vCenter), CVE-2026-50751 (Check Point), CVE-2026-20316 (Cisco FMC) are directly aligned with QILIN's entry playbook. If patching isn't possible, isolate management interfaces from all untrusted networks.
- Enforce MFA on all remote access — VPN, RDP gateways, and any RMM tooling. QILIN affiliates rely heavily on valid accounts; MFA breaks the cheapest path.
- Disable internet-exposed RDP entirely; require VPN + MFA for any remote administration.
- Block or alert on shadow copy deletion commands using the Sigma rules above.
- Restrict Rclone/7-Zip/WinRAR execution to approved service accounts via AppLocker or WDAC.
Short-Term (2 Weeks)
- Segment the network: isolate OT/production environments from IT, and restrict workstation-to-workstation SMB/RPC — QILIN lateral movement depends on flat networks.
- Implement tiered administration with dedicated privileged access workstations; eliminate standing domain admin usage.
- Deploy immutable, offline backups with tested restore runbooks; verify backup credentials are separate from AD.
- Centralize and retain logs (VPN, authentication, process creation, DNS) for a minimum of 90 days in a platform attackers cannot reach.
- Harden email controls: block macro-enabled Office attachments, enable attack surface reduction rules for Office child processes and script execution.
- Monitor for data staging baselines: establish normal outbound volume per host and alert on anomalies — exfiltration is the extortion leverage; stop it and you defang the double-extortion model.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.