Qilin / Agenda — Rust-based ransomware-as-a-service; Q3 2025 German operational tempo tripled (GTIG); 23 Q1 2026 healthcare claims
actor · actor:Qilin
Coverage timeline
1
first 2026-05-10 → last 2026-05-10
Briefs
1
1 distinct
Sources cited
33
25 hosts
Sections touched
1
weekly_long_running
Co-occurring entities
8
see Related entities below
Story timeline
Where this entity is cited
- weekly_long_running1
Source distribution
- attack.mitre.org4 (12%)
- blog.checkpoint.com2 (6%)
- cloud.google.com2 (6%)
- helpnetsecurity.com2 (6%)
- microsoft.com2 (6%)
- therecord.media2 (6%)
- advisories.ncsc.nl1 (3%)
- blogs.microsoft.com1 (3%)
- other17 (52%)
Related entities
- Check Point: TDS-gated ecosystem impersonating Ghidra/dnSpy/ILSpy delivers SessionGate, RemusStealer, AnimateClipper
- Rust crypto clipboard-hijacker abusing VirusTotal community reputation (Check Point)
- Check Point LangGraph checkpointer SQLi->RCE chain (CVE-2025-67644 + CVE-2026-28277 + CVE-2026-27022)
- Check Point Research March-April 2026 AI Threat Landscape Digest — single operator runs two AI platforms in parallel to breach nine Mexican government agencies; EvilTokens jailbreak-as-a-service
- Die Linke (Germany) — Qilin ransomware, 1.5 TB claimed, DPA notified (April 2026)
- Akira — ransomware operator targeting EU healthcare and SME via edge-device CVE chains and intermittent-encryption EDR evasion
- Check Point IKEv1 VPN authentication bypass (CVE-2026-50751)
- Germany Bundestag first reading of CRA domestic-implementation bill (Drucksache 21/6134)
All cited sources (33)
- cloud.google.comprimaryfooterGTIG — Europe data leak landscapehttps://cloud.google.com/blog/topics/threat-intelligence/europe-data-leak-landscape
- cloud.google.comprimaryinlineGoogle Cloud / Mandiant M-Trends 2026, 2026-03-23https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026
- advisories.ncsc.nlfooterNCSC-NL NCSC-2026-0179https://advisories.ncsc.nl/advisory?id=NCSC-2026-0179
- attack.mitre.orginlineT1021.001 Remote Services: Remote Desktop Protocolhttps://attack.mitre.org/techniques/T1021/001/
- attack.mitre.orginlineT1047 Windows Management Instrumentationhttps://attack.mitre.org/techniques/T1047/
- attack.mitre.orginlineT1078 Valid Accountshttps://attack.mitre.org/techniques/T1078/
- attack.mitre.orginlineT1190 Exploit Public-Facing Applicationhttps://attack.mitre.org/techniques/T1190/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-08https://www.bleepingcomputer.com/news/security/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang/
- blog.checkpoint.comfooterCheck Point Research, 2026-05-08https://blog.checkpoint.com/research/cyber-threats-spike-in-april-2026-as-ransomware-expands-and-attack-volumes-climb-after-short-lived-moderation/
- blog.checkpoint.comfooterCheck Pointhttps://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/
- blogs.microsoft.comfooterMicrosoft On the Issues — DCU legal action, 2026-05-19https://blogs.microsoft.com/on-the-issues/2026/05/19/disrupting-fox-tempest-a-cybercrime-service/
- broadcom.cominlineSymantec, 2026-06-24https://www.broadcom.com/support/security-center/protection-bulletin/backdoor-mistic-new-backdoor-may-be-linked-to-ransomware-access-broker
- comparitech.comfooterComparitech Q1 2026 Healthcare, 2026-04-29https://www.comparitech.com/news/healthcare-ransomware-roundup-q1-2026-stats-on-attacks-ransoms-and-data-breaches/
- csoonline.cominlineCSO Onlinehttps://www.csoonline.com/article/4189132/be-on-the-lookout-for-mistic-a-new-backdoor-used-by-ransomware-broker.html
- cybermaxx.comfooterCyberMaxx Q1 2026https://www.cybermaxx.com/resources/ransomware-research-report-q1-2026-audio-blog-interview/
- dexpose.ioinlineDeXpose.io, 2026-05-07https://www.dexpose.io/qilin-ransomware-strikes-swiss-healthcare-provider-laclinic-montreux/
- dragos.cominlineDragos, 2026-06-03https://www.dragos.com/dragos-industrial-ransomware-analysis-q1-2026
- emsisoft.cominlineEmsisofthttps://www.emsisoft.com/en/blog/47562/the-state-of-ransomware-in-q1-2026/
- github.cominlineGitHub Security Advisory GHSA-c9ph-gxww-7744, 2026-04-29https://github.com/thymeleaf/thymeleaf/security/advisories/GHSA-c9ph-gxww-7744
- heise.defooterHeise Online — Ransomware-Angriff auf Die Linkehttps://www.heise.de/news/
- helpnetsecurity.comfooterHelp Net Securityhttps://www.helpnetsecurity.com/2026/06/12/cve-2026-50751-poc-exploit/
- helpnetsecurity.cominlineHelp Net Security, 2026-06-08https://www.helpnetsecurity.com/2026/06/08/check-point-cve-2026-50751-qilin-ransomware/
- microsoft.comfooterMicrosoft Threat Intelligence, 2026-05-19https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/
- microsoft.cominlineMicrosoft IR, 2026-05-12https://www.microsoft.com/en-us/security/blog/2026/05/12/undermining-the-trust-boundary-investigating-a-stealthy-intrusion-through-third-party-compromise/
- rapid7.comfooterRapid7https://www.rapid7.com/blog/post/etr-critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751/
- research.checkpoint.cominlineCheck Point Researchhttps://research.checkpoint.com/2026/the-state-of-ransomware-q1-2026/
- securelist.cominlineSecurelist (Kaspersky), 2026-05-12https://securelist.com/state-of-ransomware-in-2026/119761/
- security-hub.ncsc.admin.chfooterNCSC-CH Security Hubhttps://security-hub.ncsc.admin.ch/#/posts/12615
- securityweek.cominlineSecurityWeek, 2026-06-24https://www.securityweek.com/new-mistic-rat-opens-door-to-several-ransomware-families/
- techzine.euinlineTechzine, 2026-02-16https://www.techzine.eu/news/security/138806/data-breach-at-odido-responsibility-and-compensation-under-discussion/
- therecord.mediafooterThe Record, 2026-05-19https://therecord.media/microsoft-disrupts-fox-tempest-malware-signing-service
- therecord.mediainlineThe Record, 2026-05-04https://therecord.media/ransomware-group-claims-breach-of-pro-orban-media-firm
- theregister.cominlineThe Register, 2026-02-27https://www.theregister.com/2026/02/27/odido_shinyhunters_leaks/