Back to Intelligence

Qilin Ransomware Leader Arrested After Extradition: Detection and Defense Playbook for the Group's Encryptor and Lateral Movement

SA
Security Arsenal Team
October 10, 2026
8 min read

German authorities have arrested a Russian national suspected of being a leading member of the Qilin ransomware-as-a-service (RaaS) operation, following extradition from Japan earlier this month. The arrest is a meaningful law-enforcement win against one of the most prolific ransomware groups currently operating — Qilin consistently ranked among the top ransomware threats through 2025 and into 2026, hitting healthcare, government, manufacturing, and critical infrastructure victims across North America, Europe, and Asia.

But let's be blunt: takedowns and arrests of RaaS personnel rarely degrade operations for long. Qilin is a franchise model. Arresting one core operator doesn't revoke the encryptor builder, the affiliate access, or the leak-site infrastructure. Every affiliate already inside a victim network — or holding purchased access from initial access brokers (IABs) — remains fully operational.

For defenders, the correct response to this news is not celebration — it's a hard audit of your detections against Qilin's documented tradecraft. This post covers exactly that: the group's attack chain, high-fidelity Sigma/KQL/VQL detections for the behaviors affiliates actually execute, and hardening guidance for the platforms Qilin hits hardest, including VMware ESXi.

Technical Analysis

Who is Qilin?

Qilin (also tracked as Agenda) operates a mature RaaS program. Core developers maintain a Rust/Golang encryptor with builds for Windows and Linux — the latter specifically engineered for VMware ESXi hypervisors, allowing affiliates to encrypt entire virtualized estates in a single stroke. Affiliates handle initial access, lateral movement, and extortion; the core team takes a percentage of ransom payments and runs the leak infrastructure.

Typical Qilin Attack Chain (Defender's View)

Observed intrusions follow a repeatable pattern that gives defenders multiple detection opportunities:

  1. Initial access — Exposed RDP/VPN without MFA, phishing, or purchased access from IABs. Compromised valid accounts are the dominant vector.
  2. Persistence & tooling — Deployment of legitimate RMM software (AnyDesk, ScreenConnect, Splashtop) for resilient access that blends into IT noise.
  3. Discovery & credential theft — Kerberoasting, LSASS dumping, and harvesting of backup/Veeam credentials.
  4. Defense evasion — Disabling EDR via vulnerable drivers (BYOVD), clearing event logs, and terminating security services.
  5. Pre-encryption sabotage — Deletion of Volume Shadow Copies (vssadmin delete shadows, wmic shadowcopy delete), disabling recovery (bcdedit ... recoveryenabled no), and stopping backup/database services (net stop on Veeam, SQL, Exchange, and backup agents).
  6. Lateral movement & staging — PsExec-style service execution over SMB/ADMIN$, RDP, and Group Policy abuse to push the encryptor domain-wide. The Linux encryptor is staged against ESXi hosts (often via compromised vCenter credentials) to encrypt datastores.
  7. Double extortion — Data exfiltration before encryption; leak-site publication if payment stalls.

Exploitation Status

Qilin is confirmed, actively exploited in the wild and remains one of the highest-volume ransomware operations of 2025–2026. This is not a theoretical threat — affiliates are encrypting networks weekly. The arrest of one operator does not change the operational risk calculus for any organization.

Detection & Response

The detections below target the behaviors Qilin affiliates reliably execute — particularly the pre-encryption sabotage phase, which is your last, loudest alarm before encryption begins. If you detect step 5 in the chain above, you still have time to isolate hosts.

Sigma Rules

YAML
---
title: Ransomware Shadow Copy Deletion and Recovery Disablement
id: 4f2b8c91-6d3e-4a7b-b5c2-9e1d0f8a3c47
status: experimental
description: Detects deletion of Volume Shadow Copies and disabling of Windows recovery options, a hallmark pre-encryption behavior of Qilin ransomware affiliates.
references:
  - https://attack.mitre.org/techniques/T1490/
  - https://www.bleepingcomputer.com/news/security/germany-arrests-alleged-core-qilin-ransomware-member-after-extradition/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.impact
  - attack.t1490
logsource:
  category: process_creation
  product: windows
detection:
  selection_img_vss:
    Image|endswith:
      - '\vssadmin.exe'
      - '\wmic.exe'
    CommandLine|contains:
      - 'delete shadows'
      - 'shadowcopy delete'
  selection_bcdedit:
    Image|endswith: '\bcdedit.exe'
    CommandLine|contains:
      - 'recoveryenabled no'
      - 'bootstatuspolicy ignoreallfailures'
  condition: selection_img_vss or selection_bcdedit
falsepositives:
  - Legitimate storage administrators resizing shadow storage (resize shadowstorage) uses different command lines
  - Rare backup software maintenance scripts
level: high
---
title: Backup and Database Service Termination Before Encryption
id: 8a1e4d72-3c9f-4b6a-a2d8-7f5e1b9c4d06
status: experimental
description: Detects mass stopping of backup, database, and security services via net.exe or sc.exe, consistent with Qilin pre-encryption sabotage of recovery and detection capabilities.
references:
  - https://attack.mitre.org/techniques/T1489/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.impact
  - attack.t1489
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith:
      - '\net.exe'
      - '\net1.exe'
      - '\sc.exe'
    CommandLine|contains:
      - 'stop veeam'
      - 'stop sql'
      - 'stop mssql'
      - 'stop backup'
      - 'stop vss'
      - 'stop sophos'
      - 'stop mssense'
      - 'stop exchange'
      - 'stop msexchange'
falsepositives:
  - Legitimate maintenance windows stopping individual services (investigate volume and parent process)
  - Software installers during upgrades
level: high
---
title: Unauthorized RMM Tool Installation Consistent with Ransomware Staging
id: c3d7f1a9-5b2e-4e8c-91a4-6d0b3f7e2a58
status: experimental
description: Detects execution of remote monitoring and management tools (AnyDesk, ScreenConnect, Splashtop) from non-standard locations, a common Qilin affiliate persistence and access technique.
references:
  - https://attack.mitre.org/techniques/T1219/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.command_and_control
  - attack.t1219
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|contains:
      - '\anydesk'
      - '\screenconnect'
      - '\splashtop'
  selection_path:
    Image|contains:
      - '\temp\'
      - '\appdata\local\temp\'
      - '\users\public\'
      - '\programdata\'
      - '\downloads\'
  condition: selection_img and selection_path
falsepositives:
  - Organizations that legitimately deploy these RMM tools — baseline approved install paths and filter accordingly
level: medium

KQL — Microsoft Sentinel / Defender Hunt

This query hunts the full pre-encryption sabotage sequence across your estate. Run it as a 7-day retrohunt and convert to an analytic rule with host-level correlation:

KQL — Microsoft Sentinel / Defender
let Lookback = 7d;
DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where (FileName in~ ("vssadmin.exe", "wmic.exe") and ProcessCommandLine has_any ("delete shadows", "shadowcopy delete"))
    or (FileName =~ "bcdedit.exe" and ProcessCommandLine has_any ("recoveryenabled no", "ignoreallfailures"))
    or (FileName in~ ("net.exe", "net1.exe", "sc.exe") and ProcessCommandLine has_any ("stop veeam", "stop sql", "stop mssql", "stop backup", "stop vss", "stop exchange"))
    or (FileName =~ "wevtutil.exe" and ProcessCommandLine has "cl")
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, AccountName
| order by DeviceName asc, TimeGenerated asc

Follow-up hunt for RMM staging on hosts flagged above:

KQL — Microsoft Sentinel / Defender
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where ProcessCommandLine has_any ("anydesk", "screenconnect", "splashtop")
    or FileName has_any ("anydesk", "screenconnect", "splashtop")
| where FolderPath has_any ("\\temp\\", "\\users\\public\\", "\\downloads\\", "\\programdata\\")
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), UserList=make_set(AccountName) by DeviceName, FileName, FolderPath
| order by FirstSeen asc

Velociraptor VQL Hunt

VQL — Velociraptor
-- Hunt for pre-encryption sabotage process execution and Qilin-style ransom notes
SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)(delete shadows|shadowcopy delete|recoveryenabled no|ignoreallfailures|stop veeam|stop sql|stop backup)'
   OR Exe =~ '(?i)(anydesk|screenconnect|splashtop)'
VQL — Velociraptor
-- Sweep user profiles and public directories for ransom note artifacts
SELECT FullPath, Size, Mtime
FROM glob(globs='C:/Users/*/*/RECOVER*', accessor='file')
UNION ALL
SELECT FullPath, Size, Mtime
FROM glob(globs='C:/Users/Public/*/RECOVER*', accessor='file')

Remediation & Hardening Script

Run this on Windows servers to verify recovery resilience and audit for unauthorized RMM tooling:

PowerShell
# Verify VSS protection is intact and shadow copies exist
Write-Host "=== Shadow Copy Status ===" -ForegroundColor Cyan
Get-CimInstance Win32_ShadowCopy | Select-Object DeviceObject, InstallDate, VolumeName
vssadmin list shadows

# Verify recovery boot settings have not been sabotaged
Write-Host "=== Boot Recovery Settings ===" -ForegroundColor Cyan
bcdedit /enum {current} | Select-String -Pattern "recoveryenabled|bootstatuspolicy"

# Audit for RMM tools running from suspicious paths
Write-Host "=== RMM Tool Audit ===" -ForegroundColor Cyan
Get-CimInstance Win32_Process | Where-Object {
    $_.Name -match "anydesk|screenconnect|splashtop" -and
    $_.ExecutablePath -match "Temp|Public|Downloads|ProgramData"
} | Select-Object ProcessId, Name, ExecutablePath, CommandLine

# Audit for recently created suspicious services (PsExec-style staging)
Write-Host "=== Recent Suspicious Services ===" -ForegroundColor Cyan
Get-CimInstance Win32_Service | Where-Object {
    $_.PathName -match "PSEXESVC|ADMIN\$|Temp" -or $_.Name -match "PAExec|RemCom"
} | Select-Object Name, State, PathName, StartName

# Confirm critical backup services are running and monitored
Write-Host "=== Backup Service Health ===" -ForegroundColor Cyan
Get-Service | Where-Object { $_.DisplayName -match "Veeam|Backup|Sophos|Sense" } |
    Select-Object Name, DisplayName, Status, StartType

Remediation

  1. Protect recovery mechanisms. Restrict who can run vssadmin, wmic, and bcdedit via application control (WDAC/AppLocker). Enable tamper protection on your EDR. Test restores monthly — Qilin counts on backups that don't work.
  2. Harden VMware ESXi. Qilin's Linux encryptor is purpose-built for ESXi. Patch hypervisors to current vendor-supported releases, enable lockdown mode, disable ESXi Shell/SSH when not in use, segment the management network, and use dedicated, vaulted credentials for vCenter — never domain admin accounts.
  3. Inventory and block unauthorized RMM. Maintain an allowlist of approved remote access tools and their exact install paths. Alert on anything else.
  4. Enforce MFA on all remote access. VPN, RDP gateways, and vCenter. Compromised credentials remain Qilin affiliates' top entry vector.
  5. Deploy the detections above. Convert the KQL pre-encryption sabotage query into an analytic rule with host correlation — multiple sabotage events on one host within minutes is a near-certain precursor to encryption and warrants automated isolation.
  6. Exercise your ransomware playbook. Arrests don't stop RaaS ecosystems; affiliates migrate between operations constantly. Your IR plan must assume Qilin TTPs survive this takedown intact. If you need support building or validating that capability, Security Arsenal's incident response team runs exactly these engagements.

Related Resources

Security Arsenal Incident Response Services AlertMonitor Platform Book a SOC Assessment incident-response Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.