2026-09-29HIGHMicrosoft: the same toolkit rides into victims regardless of which ransomware brand signs the note
Qilin
actor · actor:qilin single-sourcesingle-source-victim
Qilin / Agenda, Rust-based ransomware-as-a-service; Q3 2025 German operational tempo tripled (GTIG); 23 Q1 2026 healthcare claims
Aliases: Agenda
Coverage
15
9 about it · 6 mentions · first 2026-05-08 → last 2026-09-29
Latest activity
2026-09-29
Microsoft: the same toolkit rides into victims regardless of which ransomware brand signs the note
Peak priority
critical
1 critical · 4 high · 4 notable
Targets
public-sector
sectors: public-sector, education, finance · regions: europe, us, switzerland
Sources cited
42
32 hosts
2026-05-0815 appearances2026-09-29
Action items (5)
Do-now tasks recorded on the entries about Qilin, newest first. Check the date before acting on an older one.
- Upgrade every Secure FMC to its September 2026 hardening release (7.0 and earlier to 7.0.10, 7.2 to 7.2.12, 7.4 to 7.4.8, 7.6 to 7.6.6, 7.7 to 7.7.13, 10.0 to 10.0.2, 10.1 to 10.1.0). Cisco replaced the earlier per-train hot fixes with these releases on 2026-09-16; there is no workaround, and no configuration makes an FMC non-vulnerable.2026-08-04CVE-2026-20079 +2
- Run Cisco's revised compromise check on every FMC that has been network-reachable since 2026-03-04: in expert mode,2026-08-04CVE-2026-20079 +2
zgrep "package_info.*license" /var/log/messages*, a hit naming /var/tmp/license.tmp means the chain reached the package-install step, and Cisco directs those cases to TAC rather than to self-remediation. - Immediate action: An unauthenticated attacker can forge a Remote Access / Mobile Access VPN session without a valid password on gateways running the deprecated IKEv1 key exchange, and the flaw is being exploited in the wild by a Qilin ransomware affiliate (exploitation observed since 7 May 2026, a month before disclosure). NCSC-CH has issued an Action-Required advisory flagging the CVE as actively exploited. Apply hotfix sk185033 now, disable legacy IKEv1 remote-access client support, and begin forensic lookback from 7 May for VPN sessions established without a matching MFA/password event.2026-06-09CVE-2026-50751 +1
- Patch Check Point IKEv1 VPN gateways now (CVE-2026-50751); pre-auth authentication bypass under active exploitation by a Qilin affiliate since 7 May; apply hotfix sk185033, disable deprecated IKEv1 remote-access support, and start forensic lookback from 7 May for VPN sessions established without a matching MFA event.2026-06-09CVE-2026-50751 +1
- For Check Point gateways, apply the early-June hotfix and prefer machine-certificate auth or disable IKEv1 legacy mode now that a CVE-2026-50751 PoC is public (§ 4).2026-06-09CVE-2026-50751 +1
Defender insights
What each entry about Qilin tells a defender to do, newest first.
Triage
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
collaborates with
- Moonstone SleetSekoia/Kudelski Security (2026-09-07): Moonstone Sleet adopted the Qilin ransomware-as-a-service in 2025
- Storm-2570Microsoft: Storm-2570 operates as an affiliate deploying Qilin ransomware as one of its RaaS-brand payloads.
overlaps with
- UAT-11988Cisco Talos: subsequent actions and TTPs were consistent with those of Qilin ransomware affiliates (a TTP-consistency assessment, not a firm identity claim).
related to
- Microsoft DCU Fox Tempest disruptiondownstream user of the disrupted signing service
attributed activity
- Retelit / Qilin extortion attackRetelit's own right-of-reply attributes the 8 June 2026 attack to Qilin, matching Qilin's leak-site claim of 11 July
Story timeline
Every entry that names Qilin, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.
- 2026-09-29Storm-2570: a ransomware affiliate reuses a consistent commodity RMM/tunnelling/credential-theft toolkit across four separate RaaS brands, with government agencies among its confirmed victims
- 2026-09-21Talos finds AI-generated Python wiper and mass-deployment scripts in a Qilin-affected environment, identified by step-numbered comments and consistent per-step logging
- 2026-09-08Sekoia and Kudelski Security split the 'Lazarus umbrella' into six named DPRK clusters, and document two of them adopting commodity ransomware-as-a-service within two months of each other
- 2026-08-24Rapid7's Q2 2026 quarterly report: high- and critical-severity disclosures doubled year on year to 8,539 while the number newly exploited held flat at 40, and 62% of what was exploited needed no user interaction at all
- 2026-08-10Qilin compromised Italian telecommunications and cloud operator Retelit on 8 June, the company confirmed it only after an investigation forced the question, and one of the three affected data centres was its certified backup site
- 2026-08-04CVE-2026-20079, Cisco Secure Firewall Management Center: unauthenticated authentication bypass to root, unpatched for five months and only exploitable in a post-boot window (CVSS 10.0)
- 2026-07-29Romanian public university UVVG Arad confirms a cyberattack on its IT infrastructure; a Qilin leak-site listing is the only thing linking an actor to it
- 2026-06-25"Mistic" backdoor: signed-Defender DLL sideloading and in-memory tradecraft by access broker Woodgnat/KongTuke
- 2026-06-10Dragos Q1 2026 Industrial Ransomware Analysis: 1,020 industrial incidents, The Gentleman's 4× surge against Romanian energy, and the IT-adjacent intrusion pattern
- 2026-06-09CVE-2026-50751, Check Point Security Gateway: IKEv1 VPN authentication bypass, actively exploited by a Qilin affiliate
- 2026-06-09CVE-2026-42271, BerriAI LiteLLM: low-privilege command injection to host RCE, added to CISA KEV
- 2026-06-09Check Point IKEv1 VPN Authentication Bypass (CVE-2026-50751)
- 2026-05-23Rapid7 Q1 2026 Threat Landscape Report: vulnerability exploitation now top initial-access vector at 38 %; KEV median time to listing collapses to 5 days
- 2026-05-20Microsoft DCU disrupts Fox Tempest malware-signing-as-a-service feeding Rhysida, INC, Qilin and Akira ransomware operations
- 2026-05-08Qilin ransomware hits Die Linke (Germany): 1.5 TB claimed, DPA notified (~April 2026, first coverage)
Hunting pivots
CVEs (exploited first)
Affected products
ATT&CK techniques (22 across 12 tactics)
22 techniques observed across 6 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessValid Accounts · Valid Accounts: Default Accounts · Exploit Public-Facing Application
- ExecutionSystem Services: Service Execution
- PersistenceValid Accounts · Valid Accounts: Default Accounts · Server Software Component: Web Shell
- Privilege EscalationExploitation for Privilege Escalation · Valid Accounts · Valid Accounts: Default Accounts · Domain or Tenant Policy Modification: Group Policy Modification
- StealthValid Accounts · Valid Accounts: Default Accounts
- Defense ImpairmentDomain or Tenant Policy Modification: Group Policy Modification · Disable or Modify Tools
- Credential AccessOS Credential Dumping: LSASS Memory · OS Credential Dumping: NTDS · Credentials from Password Stores
- DiscoveryNetwork Service Discovery
- Lateral MovementRemote Services: Remote Desktop Protocol · Lateral Tool Transfer
- Command and ControlApplication Layer Protocol: DNS · Remote Access Tools · Protocol Tunneling
- ExfiltrationExfiltration Over Web Service: Exfiltration to Cloud Storage
- ImpactData Encrypted for Impact · Service Stop · Inhibit System Recovery · Financial Theft
Initial Access TA0001
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×1
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
Execution TA0002
T1569.002System Services: Service Execution×1
Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (<code>services.exe</code>) is an interface to manage and manipulate services. The service control manager is accessible to users via GUI components as well as system utilities such as <code>sc.exe</code> and Net.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
Persistence TA0003
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×1
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation×1
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×1
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1
Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.
Evidence: 2026-09-21/qilin-ai-generated-wiper-locker-scripts-forensic-markers · ATT&CK page ↗
Stealth TA0005
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×1
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
Defense Impairment TA0112
T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1
Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.
Evidence: 2026-09-21/qilin-ai-generated-wiper-locker-scripts-forensic-markers · ATT&CK page ↗
T1685Disable or Modify Tools×2
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
Credential Access TA0006
T1003.001OS Credential Dumping: LSASS Memory×1
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
T1003.003OS Credential Dumping: NTDS×1
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in <code>%SystemRoot%\NTDS\Ntds.dit</code> of a domain controller.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
T1555Credentials from Password Stores×1
Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
Discovery TA0007
T1046Network Service Discovery×1
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
Lateral Movement TA0008
T1021.001Remote Services: Remote Desktop Protocol×1
Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
T1570Lateral Tool Transfer×1
Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
Command and Control TA0011
T1071.004Application Layer Protocol: DNS×1
Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
T1219Remote Access Tools×1
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
T1572Protocol Tunneling×2
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
Exfiltration TA0010
T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1
Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
Impact TA0040
T1486Data Encrypted for Impact×5
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-09-21/qilin-ai-generated-wiper-locker-scripts-forensic-markers · 2026-09-08/sekoia-kudelski-dprk-lazarus-umbrella-six-cluster-split · 2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector · 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · 2026-07-29/uvvg-arad-romania-university-cyberattack-qilin-claim · ATT&CK page ↗
T1489Service Stop×1
Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services or processes can inhibit or stop response to an incident or aid in the adversary's overall objectives to cause damage to the environment.
Evidence: 2026-09-21/qilin-ai-generated-wiper-locker-scripts-forensic-markers · ATT&CK page ↗
T1490Inhibit System Recovery×1
Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.
Evidence: 2026-09-21/qilin-ai-generated-wiper-locker-scripts-forensic-markers · ATT&CK page ↗
T1657Financial Theft×1
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.
Evidence: 2026-09-08/sekoia-kudelski-dprk-lazarus-umbrella-six-cluster-split · ATT&CK page ↗
Entries about Qilin (9)
Earlier coverage (6)
Sekoia and Kudelski Security split the 'Lazarus umbrella' into six named DPRK clusters, and document two of them adopting commodity ransomware-as-a-service within two months of each otherSekoia and Kudelski Security (a Switzerland-based firm) jointly reassessed DPRK's offensive-cyber organization on 2026-09-07, replacing the historical "Lazarus umbrella" with six tracked sub-clusters and documenting that Andariel and Moonstone Sleet each adopted a commodity ransomware-as-a-service (Play and Qilin respectively) within two months of one another, a single observed timing overlap the authors call notable, consistent with the general possibility that nominally espionage-focused DPRK units rent criminal ransomware infrastructure alongside bespoke tooling.Qilin compromised Italian telecommunications and cloud operator Retelit on 8 June, the company confirmed it only after an investigation forced the question, and one of the three affected data centres was its certified backup siteIrpiMedia reported on 2026-08-04 that Retelit, one of Italy's largest business telecommunications and cloud operators, had been compromised in an extortion attack claimed by Qilin, with roughly 270,000 files listed on the leak site and an estimated 300 GB published across two dumps. Retelit made no announcement through its own channels; after the article ran it sent the outlet a right-of-reply confirming an 8 June 2026 attack attributed to Qilin, notified to Italy's national cybersecurity agency, CSIRT-ITA, the postal police and the data-protection authority, and scoping the damage to virtualisation infrastructure in 3 of its 38 national data centres, around 7% of distributed systems. IrpiMedia names those three as Verona, Rome and Milan (Milan being the site certified for Retelit's own backup and service continuity) and reports customers complaining of backup-recovery failure.Romanian public university UVVG Arad confirms a cyberattack on its IT infrastructure; a Qilin leak-site listing is the only thing linking an actor to itUniversitatea de Vest "Vasile Goldis" din Arad, a Romanian public university, issued a press release on 2026-07-28 confirming that a recently identified cyberattack affected its IT infrastructure and the digital services used in academic and administrative work, that it notified the national cybersecurity directorate DNSC, the data-protection authority ANSPDCP and organised-crime prosecutors DIICOT, and that technical teams are working with external specialists on gradual restoration. The university does not say which systems are unavailable, whether personal data was accessed or exfiltrated, when the attack occurred, or who was responsible. Separately, the Qilin ransomware operation listed the university on its leak site with an estimated attack date of 2026-07-26, a claim carried only by a leak-site mirror, which none of the Romanian reporting mentions at all.CVE-2026-50751, Check Point Security Gateway: IKEv1 VPN authentication bypass, actively exploited by a Qilin affiliateCheck Point IKEv1 VPN auth bypass (CVE-2026-50751, CVSS 9.3) actively exploited by a Qilin affiliate since 7 May, a month before disclosure. Unauthenticated session forgery on Remote Access / Mobile Access gateways; NCSC-CH issued an Action-Required advisory and CISA added it to KEV (Check Point, 2026-06-08).Microsoft DCU disrupts Fox Tempest malware-signing-as-a-service feeding Rhysida, INC, Qilin and Akira ransomware operationsMicrosoft Digital Crimes Unit disrupts Fox Tempest malware-signing-as-a-service. 1,000+ fraudulent short-lived Microsoft Artifact Signing certificates revoked; signspace[.]cloud seized via SDNY court order. Downstream customers include Vanilla Tempest (Rhysida), Storm-0501, Storm-2561, Storm-0249; ransomware families served include Rhysida, INC, Qilin, Akira (Microsoft Threat Intelligence, 2026-05-19). Detection: hunt for Microsoft-signed PE binaries with cert validity ≤72h from Trusted Signing issuers.Qilin ransomware hits Die Linke (Germany): 1.5 TB claimed, DPA notified (~April 2026, first coverage)The German federal party Die Linke confirmed in April 2026 that the Qilin ransomware group (also known as Agenda, a Rust-based RaaS platform known for double extortion) encrypted and exfiltrated its systems, with the gang claiming 1.5 TB of internal data.
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Akira×3
- Check Point Security Gateway IKEv1 Remote Access/Mobile Access certificate-validation authentication bypass (CVSS 9.3), actively exploited by Qilin affiliate since 2026-05-07, CISA KEV×2
- Rhysida×2
- Andariel×1
- Anubis (ransomware-as-a-service)×1
- BerriAI LiteLLM MCP test endpoints command injection to host RCE (CVSS 8.7), CISA KEV, actively exploited; unauthenticated when chained with CVE-2026-48710×1
- BERT (ransomware-as-a-service)×1
- Check Point IKEv1 site-to-site VPN MitM via certificate validation weakness (CVSS 7.4), no observed exploitation×1
Where this entity is cited
Source distribution
- sec.cloudapps.cisco.com5 (12%)
- rapid7.com3 (7%)
- attack.mitre.org2 (5%)
- blog.talosintelligence.com2 (5%)
- helpnetsecurity.com2 (5%)
- microsoft.com2 (5%)
- advisories.ncsc.nl1 (2%)
- aradon.ro1 (2%)
- other24 (57%)
All cited sources (42)
- advisories.ncsc.nlNCSC-NL advisory NCSC-2026-0179, 2026-06-16https://advisories.ncsc.nl/advisory?id=NCSC-2026-0179
- aradon.roAradon.rohttps://www.aradon.ro/aradon-stirile-judetului-arad/atac-cibernetic-la-uvvg-arad-2225370/
- attack.mitre.orgT1078 Valid Accountshttps://attack.mitre.org/techniques/T1078/
- attack.mitre.orgT1190 Exploit Public-Facing Applicationhttps://attack.mitre.org/techniques/T1190/
- bismark.itBismark.ithttps://www.bismark.it/9139/retelit-nel-mirino-del-ransomware-qilin-colpito-uno-dei-principali-operatori-italiani-delle-telecomunicazioni/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang/
- blog.checkpoint.comCheck Point advisoryhttps://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/
- blog.talosintelligence.comCisco Taloshttps://blog.talosintelligence.com/fmc-ongoing-exploitation/
- blog.talosintelligence.comCisco Taloshttps://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/
- blogs.microsoft.comMicrosoft On the Issues, DCU legal action, 2026-05-19https://blogs.microsoft.com/on-the-issues/2026/05/19/disrupting-fox-tempest-a-cybercrime-service/
- broadcom.comBroadcom/Symantec protection bulletinhttps://www.broadcom.com/support/security-center/protection-bulletin/backdoor-mistic-new-backdoor-may-be-linked-to-ransomware-access-broker
- cisa.govCISAhttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- csoonline.comCSO Onlinehttps://www.csoonline.com/article/4189132/be-on-the-lookout-for-mistic-a-new-backdoor-used-by-ransomware-broker.html
- dragos.comDragos, 2026-06-03https://www.dragos.com/dragos-industrial-ransomware-analysis-q1-2026
- github.comGitHub Advisory GHSA-v4p8-mg3p-g94ghttps://github.com/advisories/GHSA-v4p8-mg3p-g94g
- globenewswire.comGlobeNewswire press releasehttps://www.globenewswire.com/news-release/2026/05/21/3299378/36514/en/Rapid7-Q1-2026-Threat-Landscape-Report-Finds-Vulnerability-Exploitation-Overtakes-Social-Engineering-as-the-Top-Initial-Access-Vector.html
- heise.deHeise Online, Ransomware-Angriff auf Die Linkehttps://www.heise.de/news/
- helpnetsecurity.comHelp Net Security, 2026-06-08https://www.helpnetsecurity.com/2026/06/08/check-point-cve-2026-50751-qilin-ransomware/
- helpnetsecurity.comHelp Net Security, 2026-06-12https://www.helpnetsecurity.com/2026/06/12/cve-2026-50751-poc-exploit/
- horizon3.aiHorizon3.ai analysishttps://horizon3.ai/attack-research/vulnerabilities/cve-2026-42271-chained-with-cve-2026-48710/
- irpimedia.irpi.euIrpiMediahttps://irpimedia.irpi.eu/retelit-operatore-cloud-e-telecomunicazioni-attacco-informatico/
- kudelskisecurity.comKudelski Security (Switzerland)https://kudelskisecurity.com/research/beyond-lazarus-organization-of-dprk-cyber-capabilities
- microsoft.comMicrosoft Threat Intelligence, Exposing Fox Tempest, 2026-05-19https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/
- microsoft.comMicrosoft Security Blog / Microsoft Threat Intelligencehttps://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/
- radioromania.roRadio Româniahttps://www.radioromania.ro/stiri-locale/arad-universitatea-de-vest-tinta-unui-atac-cibernetic-id203468.html
- ransomware.liveRansomware.live (Qilin leak-site mirror)https://www.ransomware.live/id/VW5pdmVyc2l0YXRlYSBkZSBWZXN0IOKAnlZhc2lsZSBHb2xkaciZ4oCdIGRpbiBBcmFkQHFpbGlu
- rapid7.comRapid7https://www.rapid7.com/blog/post/etr-critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751/
- rapid7.comRapid7 Labshttps://www.rapid7.com/blog/post/tr-new-report-ai-threats-q2-2026-ends-traditional-patch-cycles
- rapid7.comRapid7 Q1 2026 Threat Landscape Reporthttps://www.rapid7.com/blog/post/tr-q1-2026-threat-landscape-report-geopolitics-ransomware/
- retelit.itRetelithttps://www.retelit.it/it/stampa/comunicati-stampa
- sec.cloudapps.cisco.comCisco PSIRT (CVE-2026-20242 advisory)https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-javarce-y2NypXwk
- sec.cloudapps.cisco.comCisco PSIRT (CVE-2026-20324 advisory)https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sftunn-codex-c3O4Jft2
- sec.cloudapps.cisco.comCisco PSIRThttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
- sec.cloudapps.cisco.comCisco PSIRT (advance notification)https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-jfxK98ZP
- sec.cloudapps.cisco.comCisco PSIRThttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
- security-hub.ncsc.admin.chNCSC-CH Security Hubhttps://security-hub.ncsc.admin.ch/#/posts/12615
- securityweek.comSecurityWeekhttps://www.securityweek.com/new-mistic-rat-opens-door-to-several-ransomware-families/
- sekoia.comSekoiahttps://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities
- sportarad.roSportarad.rohttps://www.sportarad.ro/2026/07/28/universitatea-de-vest-vasile-goldis-din-arad-ofera-informatii-cu-privire-la-incidentul-de-securitate-cibernetica-ce-a-vizat-infrastructura-it-a-institutiei/
- support.checkpoint.comCheck Point sk185033https://support.checkpoint.com/results/sk/sk185033
- therecord.mediaThe Record, 2026-05-19https://therecord.media/microsoft-disrupts-fox-tempest-malware-signing-service
- vulncheck.comVulnCheckhttps://www.vulncheck.com/blog/cisco-fmc-auth-bypass-cve-2026-20079