Classification: TLP:CLEAR | Publication Date: 2026-10-03 | Source: ransomware.live leak-site monitoring | Nature of data: Unverified threat-actor claims
QILIN Ransomware Gang: 4 New Leak-Site Listings Spanning Transportation, Manufacturing, Hospitality & Professional Services
Executive Summary
Security Arsenal's dark web monitoring of the QILIN ransomware operation's .onion leak site shows four new victim listings published between 2026-10-01 and 2026-10-02. QILIN claims to have compromised and has listed the following organizations:
- Thai Lion Air (Transportation, TH) — published 2026-10-02
- Inova Semiconductors GmbH (Manufacturing, DE) — published 2026-10-02
- Sports Events365 (Hospitality, GB) — published 2026-10-02
- Dynamic Office Solutions (Professional Services, GB) — published 2026-10-01
These are unverified claims by a criminal actor. A leak-site listing is an accusation, not a confirmed breach. However, the cluster is operationally meaningful: four listings in a 48-hour window across three countries and four sectors indicates an active campaign cadence, and organizations in these sectors — particularly those with internet-facing VPN, RDP, or virtualization infrastructure — should treat this as a trigger for proactive threat hunting against QILIN's known playbook. This briefing provides detection engineering content (Sigma, KQL, and rapid-response scripts), incident response priorities, and hardening guidance mapped to the gang's observed tradecraft.
Sourcing & Verification
- Corroboration: 4 of 4 listings in this dataset were independently observed by a second leak-site crawler; 0 appear on a single source only. Multi-source observation confirms that the gang made the claim — it does not confirm that any breach occurred.
- Inclusion on a leak site reflects the threat actor's claim and is NOT confirmation of a breach. No corroboration tier in our data confirms victimization; only the named organization or its regulator can do that.
- Named organizations may dispute a listing, and a denial is likewise not proof the claim is false. Disclosure obligations vary by jurisdiction and sector, and not every incident is reportable — neither silence nor denial settles the question.
- Corrections: Security Arsenal will publish corrections as warranted and welcomes contact from any named organization at security@securityarsenal.com.
Threat Actor Profile — QILIN
Aliases: Qilin, Agenda (the operation was first observed under the Agenda name in mid-2022 before rebranding).
Operating model: QILIN runs a Ransomware-as-a-Service (RaaS) program, recruiting affiliates through underground forums and providing them with encryptors (historically written in Rust and Go, enabling cross-platform Windows/Linux/ESXi targeting), a negotiation panel, and leak-site infrastructure. Affiliates execute intrusions; the core group takes a percentage of ransom payments. This model means initial access tradecraft can vary between affiliates while post-access tooling (encryptor, exfiltration staging, leak-site workflow) remains consistent.
Ransom demands: Demands are typically calibrated to victim revenue, ranging from the low hundreds of thousands of USD for small professional-services firms to multi-million-dollar demands for large enterprises. The group negotiates via a victim-specific Tor portal and applies double-extortion pressure with staged data releases.
Known initial access methods (group-level tradecraft, not attributed to any specific listing above):
- Spear phishing with malicious attachments or links delivering loaders
- Exploitation of internet-facing remote access services — VPN concentrators, firewall management interfaces, and exposed RDP
- Valid account abuse, including credentials purchased from initial access brokers
- Occasional supply-chain / MSP pivoting
Double extortion: QILIN exfiltrates data before detonating encryption and threatens publication on its dedicated leak site. Staging typically involves archiving tools (7-Zip/WinRAR) and exfiltration via Rclone, MegaSync, or direct transfer to attacker-controlled infrastructure.
Dwell time: Observed dwell time from initial access to encryption commonly ranges from several days to roughly two weeks, with data theft and lateral movement occupying most of that window. This gives defenders a realistic detection opportunity — the pre-encryption phase is noisy.
Current Campaign Analysis
Sectors targeted (per the live listing data): Transportation, Manufacturing, Hospitality, and Professional Services — a deliberately diversified spread rather than single-sector focus, consistent with an affiliate-driven RaaS where multiple operators work in parallel.
Geographic concentration: Thailand (1), Germany (1), United Kingdom (2). The UK weighting in this small sample tracks with QILIN's historical preference for Western European and North American professional-services targets, though four listings is too small a sample to declare a geographic shift.
Victim profile: The set spans a large regional airline carrier, a mid-size German semiconductor manufacturer, a UK-based hospitality/events ticketing business, and a UK professional-services firm. This mix (one large enterprise plus small-to-mid-market organizations with estimated revenues from the low millions to hundreds of millions USD) is characteristic of RaaS affiliate operations: whatever access can be obtained gets monetized. Mid-market manufacturing and professional-services firms remain attractive because they hold monetizable IP and client data but frequently lack 24/7 detection capability.
Posting frequency / escalation pattern: Four listings in ~48 hours (2026-10-01 through 2026-10-02) represents an elevated cadence. Three of the four posted on a single day (2026-10-02), suggesting either a batch publication after parallel intrusions matured or a deliberate pressure tactic. Watch for follow-on activity: QILIN commonly publishes proof-of-theft samples days after the initial listing if negotiations stall.
CVE exposure hypothesis (sector-level, NOT attributed to any named victim): We have no evidence linking any specific listing above to a specific CVE. However, QILIN affiliates are known to exploit internet-facing edge and management infrastructure, and the following CISA KEV entries — all confirmed as exploited in ransomware operations — represent exposure categories defenders in the targeted sectors should treat as urgent:
- CVE-2026-50751 (Check Point Security Gateway improper authentication, IKEv1) — perimeter VPN access vector
- CVE-2026-20316 (Cisco Secure FMC hard-coded password) — firewall management plane compromise
- CVE-2026-59310 (VMware vCenter path traversal) — virtualization control plane, highly relevant given QILIN's ESXi-targeting encryptor variants
- CVE-2026-63077 (JetBrains TeamCity deserialization) — CI/CD pipeline compromise enabling supply-chain-style lateral movement
- CVE-2026-48027 (Nx Console embedded malicious code) — developer-workstation supply chain exposure
If any of these products sit in your environment unpatched, treat patching as a same-day action regardless of whether you are in the listed sectors.
Detection Engineering
The following detections target QILIN's documented playbook: edge/VPN initial access, phishing-driven execution, PsExec/WMI lateral movement, shadow copy destruction, and pre-encryption data staging. Tune thresholds to your environment before production deployment.
---
title: QILIN - Shadow Copy Deletion via vssadmin or wmic
id: 9f1a2c3e-7b41-4e55-9a01-qilin0000001
status: experimental
description: Detects deletion of Volume Shadow Copies, a hallmark pre-encryption action used by QILIN ransomware operators to inhibit recovery.
author: Security Arsenal Threat Intelligence
date: 2026/10/03
references:
- https://securityarsenal.com/darkside
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\vssadmin.exe'
- '\wmic.exe'
- '\bcdedit.exe'
selection_cmd:
CommandLine|contains:
- 'delete shadows'
- 'shadowcopy delete'
- 'resize shadowstorage'
- 'recoveryenabled no'
condition: selection_img and selection_cmd
falsepositives:
- Legitimate backup administration; rare on end-user workstations
level: high
tags:
- attack.impact
- attack.t1490
---
title: QILIN - PsExec-Style Remote Service Creation and Lateral Movement
id: 9f1a2c3e-7b41-4e55-9a01-qilin0000002
status: experimental
description: Detects remote service installation and named-pipe patterns consistent with PsExec-based lateral movement, a technique QILIN affiliates use to distribute encryptors and tooling across hosts.
author: Security Arsenal Threat Intelligence
date: 2026/10/03
references:
- https://securityarsenal.com/darkside
logsource:
product: windows
service: system
detection:
selection_event:
EventID: 7045
selection_svc:
ServiceName|contains:
- 'PSEXESVC'
- 'PAExec'
- 'csexecsvc'
ServiceFileName|contains:
- '\ADMIN$\'
- 'PSEXESVC'
condition: selection_event and 1 of selection_svc*
falsepositives:
- Legitimate administrative tooling; correlate with expected admin activity windows
level: high
tags:
- attack.lateral-movement
- attack.t1569.002
- attack.t1021.002
---
title: QILIN - Data Staging and Exfiltration Tooling Execution
id: 9f1a2c3e-7b41-4e55-9a01-qilin0000003
status: experimental
description: Detects execution of archiving and cloud exfiltration utilities (Rclone, MegaSync, 7-Zip with high-compression flags) frequently used by QILIN operators for data theft prior to encryption.
author: Security Arsenal Threat Intelligence
date: 2026/10/03
references:
- https://securityarsenal.com/darkside
logsource:
category: process_creation
product: windows
detection:
selection_exfil_tools:
Image|endswith:
- '\rclone.exe'
- '\megasync.exe'
- '\FileZilla.exe'
selection_archive:
Image|endswith:
- '\7z.exe'
- '\7za.exe'
- '\rar.exe'
CommandLine|contains:
- ' a '
- ' -p'
condition: selection_exfil_tools or selection_archive
falsepositives:
- IT-managed archiving and sync tools; whitelist known software deployment paths
level: medium
tags:
- attack.collection
- attack.t1560.001
- attack.exfiltration
- attack.t1567.002
The following Sentinel hunt query surfaces the pre-ransomware staging window: new admin-share service installations followed by shadow copy tampering or bulk file access on the same host within a 24-hour correlation window.
// QILIN pre-ransomware staging hunt: lateral movement followed by anti-recovery or staging behavior
let window = 24h;
let SuspiciousServices =
SecurityEvent
| where EventID == 7045
| where ServiceName has_any ("PSEXESVC", "PAExec", "csexecsvc")
or ServiceFileName has_any ("ADMIN$", "PSEXESVC")
| project ServiceInstallTime=TimeGenerated, Computer, ServiceName, ServiceFileName, Account;
let AntiRecovery =
DeviceProcessEvents
| where FileName in~ ("vssadmin.exe", "wmic.exe", "bcdedit.exe")
| where ProcessCommandLine has_any ("delete shadows", "shadowcopy delete", "resize shadowstorage", "recoveryenabled no")
| project AntiRecoveryTime=TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessAccountName;
AntiRecovery
| join kind=inner (SuspiciousServices) on $left.DeviceName == $right.Computer
| where AntiRecoveryTime between (ServiceInstallTime .. (ServiceInstallTime + window))
| extend TimeDeltaMinutes = datetime_diff("minute", AntiRecoveryTime, ServiceInstallTime)
| project Computer, ServiceInstallTime, ServiceName, AntiRecoveryTime, ProcessCommandLine, TimeDeltaMinutes, Account
| order by Computer asc, ServiceInstallTime asc;
The following rapid-response script enumerates scheduled tasks created in the last 7 days (a common QILIN persistence/execution mechanism), checks shadow copy health, and flags hosts with RDP exposed on non-standard listeners — run it from an elevated prompt on suspect hosts or at scale via your RMM/EDR remote shell.
# QILIN Rapid Triage Script - Security Arsenal - 2026-10-03
# Run elevated. Outputs to C:\IRTriage\qilin-triage-<hostname>.txt
$outDir = "C:\IRTriage"
New-Item -ItemType Directory -Path $outDir -Force | Out-Null
$outFile = Join-Path $outDir ("qilin-triage-" + $env:COMPUTERNAME + ".txt")
"=== QILIN RAPID TRIAGE - $(Get-Date -Format o) - $env:COMPUTERNAME ===" | Out-File $outFile
"`n--- [1] Scheduled tasks created in last 7 days ---" | Out-File $outFile -Append
Get-ScheduledTask | ForEach-Object {
$info = $_ | Get-ScheduledTaskInfo -ErrorAction SilentlyContinue
[PSCustomObject]@{
TaskName = $_.TaskName
TaskPath = $_.TaskPath
Author = $_.Author
State = $_.State
LastRun = $info.LastRunTime
Action = ($_.Actions | ForEach-Object { "$($_.Execute) $($_.Arguments)" }) -join '; '
}
} | Where-Object {
$_.TaskPath -notlike "\Microsoft*" -and ($_.LastRun -gt (Get-Date).AddDays(-7))
} | Format-List | Out-File $outFile -Append
"`n--- [2] Volume Shadow Copy status (expect copies present; empty list on a server = red flag) ---" | Out-File $outFile -Append
Get-WmiObject Win32_ShadowCopy -ErrorAction SilentlyContinue |
Select-Object ID, InstallDate, VolumeName | Format-Table -AutoSize | Out-File $outFile -Append
"`n--- [3] RDP exposure check ---" | Out-File $outFile -Append
$rdpEnabled = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections).fDenyTSConnections
$rdpPort = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber).PortNumber
"RDP Disabled flag (0=enabled): $rdpEnabled | RDP Port: $rdpPort" | Out-File $outFile -Append
Get-NetTCPConnection -State Listen -ErrorAction SilentlyContinue |
Where-Object { $_.LocalPort -in @(3389, $rdpPort) } |
Select-Object LocalAddress, LocalPort, OwningProcess | Format-Table -AutoSize | Out-File $outFile -Append
"`n--- [4] Recent vssadmin / bcdedit / wmic shadow operations (process audit, if enabled) ---" | Out-File $outFile -Append
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4688; StartTime=(Get-Date).AddDays(-7)} -ErrorAction SilentlyContinue |
Where-Object { $_.Message -match 'vssadmin|bcdedit|shadowcopy|delete shadows' } |
Select-Object TimeCreated, Message -First 25 | Format-List | Out-File $outFile -Append
"`nTriage complete. Review $outFile for anomalies." | Out-File $outFile -Append
Write-Host "Output written to $outFile"
Incident Response Priorities
T-minus detection checklist (before encryption fires):
- Unexplained
vssadmin delete shadows,bcdedit ... recoveryenabled no, or WMI shadow deletion events - New services installed via ADMIN$ (Event ID 7045) on multiple hosts in a short window
- Rclone, MegaSync, or unfamiliar archiving processes on servers holding sensitive data
- Large outbound transfers to unfamiliar cloud storage or VPS IPs, especially outside business hours
- New local/domain admin accounts or unexpected additions to privileged groups
- GPO modifications pushing scripts or disabling security tooling; EDR agents reporting tamper events
- Authentication anomalies against VPN/firewall management interfaces (new source geographies, impossible travel)
Assets QILIN historically prioritizes for exfiltration:
- File servers and document management systems containing contracts, financial records, and HR/PII data
- Industry-specific IP (relevant here: semiconductor design data for manufacturing targets; passenger/booking data for transportation and hospitality)
- Email archives of executives and legal/finance teams (leverage for negotiation pressure)
- Backup infrastructure — targeted for destruction or encryption first to remove recovery options
Containment actions, ordered by urgency:
- Isolate affected network segments and disable compromised accounts immediately — speed beats completeness in the first hour.
- Block egress to known exfiltration tooling endpoints and flag any large outbound flows for capture before severing.
- Preserve evidence: memory and disk images of patient-zero and any staging host before remediation; capture volatile data from VPN/firewall appliances.
- Protect backups: take backup infrastructure offline or into immutable mode; verify at least one clean restore point predates the earliest indicator of compromise.
- Rotate credentials enterprise-wide for privileged accounts; assume Kerberos tickets and cached credentials are compromised.
- Engage IR support and counsel early — if your organization appears on a leak site, legal, regulatory, and communications workstreams must start in parallel with technical containment.
Hardening Recommendations
Immediate (24 hours):
- Patch or mitigate the CISA KEV entries referenced above where present: CVE-2026-50751 (Check Point), CVE-2026-20316 (Cisco FMC), CVE-2026-59316/CVE-2026-59310 (vCenter), CVE-2026-63077 (TeamCity). Internet-facing instances are same-day priorities.
- Disable IKEv1 on Check Point gateways where operationally feasible; audit VPN appliance logs for anomalous admin sessions.
- Enforce MFA on all remote access (VPN, RDP gateways, firewall management planes) and disable RDP exposure to the internet entirely — front it with VPN + MFA or ZTNA.
- Deploy the Sigma detections and the Sentinel hunt query above; alert on any shadow copy deletion outside approved backup windows.
- Block execution of Rclone/MegaSync via AppLocker or WDAC for users and servers without a documented business need.
Short-term (2 weeks):
- Segment networks so that a single compromised workstation cannot reach backup infrastructure, hypervisor management (vCenter/ESXi), or domain controllers over SMB/RDP/WinRM.
- Implement tiered administration: dedicated privileged access workstations, no domain admin logons to member servers or endpoints.
- Move backups to immutable/object-lock storage with an offline or logically air-gapped copy; test restoration quarterly.
- Enable PowerShell Script Block Logging, process command-line auditing (Event 4688), and forward Windows System + Security logs to a central SIEM with 90+ day retention.
- Establish dark web monitoring for your organization's name, domains, and executive identities so leak-site listings surface to you in hours, not weeks.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.