CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Qilin

actor · actor:qilin single-sourcesingle-source-victim

Qilin / Agenda, Rust-based ransomware-as-a-service; Q3 2025 German operational tempo tripled (GTIG); 23 Q1 2026 healthcare claims

Aliases: Agenda

Coverage
15
9 about it · 6 mentions · first 2026-05-08 → last 2026-09-29
Latest activity
2026-09-29
Microsoft: the same toolkit rides into victims regardless of which ransomware brand signs the note
Peak priority
critical
1 critical · 4 high · 4 notable
Targets
public-sector
sectors: public-sector, education, finance · regions: europe, us, switzerland
Sources cited
42
32 hosts
2026-05-0815 appearances2026-09-29

Action items (5)

Do-now tasks recorded on the entries about Qilin, newest first. Check the date before acting on an older one.

  • Upgrade every Secure FMC to its September 2026 hardening release (7.0 and earlier to 7.0.10, 7.2 to 7.2.12, 7.4 to 7.4.8, 7.6 to 7.6.6, 7.7 to 7.7.13, 10.0 to 10.0.2, 10.1 to 10.1.0). Cisco replaced the earlier per-train hot fixes with these releases on 2026-09-16; there is no workaround, and no configuration makes an FMC non-vulnerable.
    2026-08-04CVE-2026-20079 +2
  • Run Cisco's revised compromise check on every FMC that has been network-reachable since 2026-03-04: in expert mode, zgrep "package_info.*license" /var/log/messages*, a hit naming /var/tmp/license.tmp means the chain reached the package-install step, and Cisco directs those cases to TAC rather than to self-remediation.
    2026-08-04CVE-2026-20079 +2
  • Immediate action: An unauthenticated attacker can forge a Remote Access / Mobile Access VPN session without a valid password on gateways running the deprecated IKEv1 key exchange, and the flaw is being exploited in the wild by a Qilin ransomware affiliate (exploitation observed since 7 May 2026, a month before disclosure). NCSC-CH has issued an Action-Required advisory flagging the CVE as actively exploited. Apply hotfix sk185033 now, disable legacy IKEv1 remote-access client support, and begin forensic lookback from 7 May for VPN sessions established without a matching MFA/password event.
    2026-06-09CVE-2026-50751 +1
  • Patch Check Point IKEv1 VPN gateways now (CVE-2026-50751); pre-auth authentication bypass under active exploitation by a Qilin affiliate since 7 May; apply hotfix sk185033, disable deprecated IKEv1 remote-access support, and start forensic lookback from 7 May for VPN sessions established without a matching MFA event.
    2026-06-09CVE-2026-50751 +1
  • For Check Point gateways, apply the early-June hotfix and prefer machine-certificate auth or disable IKEv1 legacy mode now that a CVE-2026-50751 PoC is public (§ 4).
    2026-06-09CVE-2026-50751 +1

Defender insights

What each entry about Qilin tells a defender to do, newest first.

2026-09-29HIGHMicrosoft: the same toolkit rides into victims regardless of which ransomware brand signs the note

Triage

2026-09-21NOTABLECisco Talos: a Qilin intrusion's own staging directory held ransomware deployment scripts the investigators assess were probably written by an AI model

2026-09-08NOTABLEA Swiss research lab co-publishes the DPRK actor-tracking update: two nominally-espionage clusters rented commodity ransomware in the same window

2026-08-10HIGHA European carrier serving 193 public administrations disclosed a two-month-old Qilin intrusion in a right-of-reply, not a press release

Triage

2026-07-29NOTABLEWest University Vasile Goldis Arad notifies DNSC, the data-protection authority and prosecutors after an attack on academic and administrative systems

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

collaborates with

overlaps with

related to

attributed activity

Story timeline

Every entry that names Qilin, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.

  1. 2026-09-29Storm-2570: a ransomware affiliate reuses a consistent commodity RMM/tunnelling/credential-theft toolkit across four separate RaaS brands, with government agencies among its confirmed victims
    active-threatsMicrosoft: the same toolkit rides into victims regardless of which ransomware brand signs the note
  2. 2026-09-21Talos finds AI-generated Python wiper and mass-deployment scripts in a Qilin-affected environment, identified by step-numbered comments and consistent per-step logging
    active-threatsCisco Talos: a Qilin intrusion's own staging directory held ransomware deployment scripts the investigators assess were probably written by an AI model
  3. 2026-09-08Sekoia and Kudelski Security split the 'Lazarus umbrella' into six named DPRK clusters, and document two of them adopting commodity ransomware-as-a-service within two months of each other
    researchA Swiss research lab co-publishes the DPRK actor-tracking update: two nominally-espionage clusters rented commodity ransomware in the same window
  4. 2026-08-24Rapid7's Q2 2026 quarterly report: high- and critical-severity disclosures doubled year on year to 8,539 while the number newly exploited held flat at 40, and 62% of what was exploited needed no user interaction at all
    mentionresearchRapid7 Q2 2026: disclosure volume doubled, exploitation did not, and missing-authentication disclosures rose 247%
  5. 2026-08-10Qilin compromised Italian telecommunications and cloud operator Retelit on 8 June, the company confirmed it only after an investigation forced the question, and one of the three affected data centres was its certified backup site
    active-threatsA European carrier serving 193 public administrations disclosed a two-month-old Qilin intrusion in a right-of-reply, not a press release
  6. 2026-08-04CVE-2026-20079, Cisco Secure Firewall Management Center: unauthenticated authentication bypass to root, unpatched for five months and only exploitable in a post-boot window (CVSS 10.0)
    trending-vulnerabilitiesCisco has replaced the hot fixes for its CVSS 10.0 Secure FMC authentication bypass with the September hardening releases
  7. 2026-07-29Romanian public university UVVG Arad confirms a cyberattack on its IT infrastructure; a Qilin leak-site listing is the only thing linking an actor to it
    active-threatsWest University Vasile Goldis Arad notifies DNSC, the data-protection authority and prosecutors after an attack on academic and administrative systems
  8. 2026-06-25"Mistic" backdoor: signed-Defender DLL sideloading and in-memory tradecraft by access broker Woodgnat/KongTuke
    mentionactive-threats
  9. 2026-06-10Dragos Q1 2026 Industrial Ransomware Analysis: 1,020 industrial incidents, The Gentleman's 4× surge against Romanian energy, and the IT-adjacent intrusion pattern
    mentiondeep-diveDragos Q1 2026 Industrial Ransomware Analysis: 1,020 industrial incidents, The Gentleman's 4× surge against Romanian energy, and the IT-adjacent intrusion
  10. 2026-06-09CVE-2026-50751, Check Point Security Gateway: IKEv1 VPN authentication bypass, actively exploited by a Qilin affiliate
    trending-vulnerabilities
  11. 2026-06-09CVE-2026-42271, BerriAI LiteLLM: low-privilege command injection to host RCE, added to CISA KEV
    mentiontrending-vulnerabilities
  12. 2026-06-09Check Point IKEv1 VPN Authentication Bypass (CVE-2026-50751)
    mentiondeep-dive
  13. 2026-05-23Rapid7 Q1 2026 Threat Landscape Report: vulnerability exploitation now top initial-access vector at 38 %; KEV median time to listing collapses to 5 days
    mentionresearch
  14. 2026-05-20Microsoft DCU disrupts Fox Tempest malware-signing-as-a-service feeding Rhysida, INC, Qilin and Akira ransomware operations
    active-threats
  15. 2026-05-08Qilin ransomware hits Die Linke (Germany): 1.5 TB claimed, DPA notified (~April 2026, first coverage)
    active-threats
ATT&CK techniques (22 across 12 tactics)

22 techniques observed across 6 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessValid Accounts · Valid Accounts: Default Accounts · Exploit Public-Facing Application
  • ExecutionSystem Services: Service Execution
  • PersistenceValid Accounts · Valid Accounts: Default Accounts · Server Software Component: Web Shell
  • Privilege EscalationExploitation for Privilege Escalation · Valid Accounts · Valid Accounts: Default Accounts · Domain or Tenant Policy Modification: Group Policy Modification
  • StealthValid Accounts · Valid Accounts: Default Accounts
  • Defense ImpairmentDomain or Tenant Policy Modification: Group Policy Modification · Disable or Modify Tools
  • Credential AccessOS Credential Dumping: LSASS Memory · OS Credential Dumping: NTDS · Credentials from Password Stores
  • DiscoveryNetwork Service Discovery
  • Lateral MovementRemote Services: Remote Desktop Protocol · Lateral Tool Transfer
  • Command and ControlApplication Layer Protocol: DNS · Remote Access Tools · Protocol Tunneling
  • ExfiltrationExfiltration Over Web Service: Exfiltration to Cloud Storage
  • ImpactData Encrypted for Impact · Service Stop · Inhibit System Recovery · Financial Theft

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗

Execution TA0002

T1569.002System Services: Service Execution×1

Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (<code>services.exe</code>) is an interface to manage and manipulate services. The service control manager is accessible to users via GUI components as well as system utilities such as <code>sc.exe</code> and Net.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗

T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1

Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.

Evidence: 2026-09-21/qilin-ai-generated-wiper-locker-scripts-forensic-markers · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗

Defense Impairment TA0112

T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1

Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.

Evidence: 2026-09-21/qilin-ai-generated-wiper-locker-scripts-forensic-markers · ATT&CK page ↗

T1685Disable or Modify Tools×2

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗

Credential Access TA0006

T1003.001OS Credential Dumping: LSASS Memory×1

Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

T1003.003OS Credential Dumping: NTDS×1

Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in <code>%SystemRoot%\NTDS\Ntds.dit</code> of a domain controller.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

T1555Credentials from Password Stores×1

Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

Discovery TA0007

T1046Network Service Discovery×1

Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

Lateral Movement TA0008

T1021.001Remote Services: Remote Desktop Protocol×1

Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

T1570Lateral Tool Transfer×1

Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

Command and Control TA0011

T1071.004Application Layer Protocol: DNS×1

Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗

T1219Remote Access Tools×1

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

T1572Protocol Tunneling×2

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗

Exfiltration TA0010

T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×5

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-09-21/qilin-ai-generated-wiper-locker-scripts-forensic-markers · 2026-09-08/sekoia-kudelski-dprk-lazarus-umbrella-six-cluster-split · 2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector · 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · 2026-07-29/uvvg-arad-romania-university-cyberattack-qilin-claim · ATT&CK page ↗

T1489Service Stop×1

Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services or processes can inhibit or stop response to an incident or aid in the adversary's overall objectives to cause damage to the environment.

Evidence: 2026-09-21/qilin-ai-generated-wiper-locker-scripts-forensic-markers · ATT&CK page ↗

T1490Inhibit System Recovery×1

Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.

Evidence: 2026-09-21/qilin-ai-generated-wiper-locker-scripts-forensic-markers · ATT&CK page ↗

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-09-08/sekoia-kudelski-dprk-lazarus-umbrella-six-cluster-split · ATT&CK page ↗

Entries about Qilin (9)

2026-09-29 · view entry permalink →

HIGHNATOB2

Storm-2570: a ransomware affiliate reuses a consistent commodity RMM/tunnelling/credential-theft toolkit across four separate RaaS brands, with government agencies among its confirmed victims

Microsoft Threat Intelligence profiles Storm-2570, a ransomware affiliate it has tracked since April 2025 that operates across multiple ransomware-as-a-service ecosystems rather than committing to one brand, deploying Qilin, DragonForce, Anubis and BERT payloads interchangeably against victims in healthcare, education, government agencies and services, financial services, energy, retail, IT and food/agriculture across the US, Canada, UK, Spain, the Netherlands and Puerto Rico (Microsoft Security Blog, 2026-09-24). Post-compromise, the affiliate routinely conducts internal network discovery using NetScan, SoftPerfect Network Scanner Portable and Nmap alongside native discovery commands and file-searching activity, to identify reachable hosts and services, map internal networks and locate systems, shares and files of interest ahead of credential access or encryption. Regardless of the final ransomware brand, Microsoft describes a recurring commodity toolchain across deployments: MeshAgent/MeshCentral, frequently renamed per-victim (for example meshagent64-[org].exe) and one of the affiliate's most frequently observed tools, as the operational bridge from initial access into account manipulation and credential access; Atera plus Splashtop, ScreenConnect, NinjaRMM, and, in one intrusion, a persistent LocalSystem-service Cloudflared.exe tunnel, and ngrok exposing RDP for redundant remote access; ntdsutil-driven Install-From-Media dumps of ntds.dit for offline domain-credential extraction; Mimikatz, LaZagne and pypykatz for credential harvesting; systematic Windows Defender tampering (disabling real-time monitoring, adding C:\PerfLogs exclusions, direct WinDefend registry edits) ahead of deployment; PsExec-driven lateral movement using @ip.txt host lists, including an rdp.bat script that force-enables RDP, alongside Impacket and NetExec over SMB; and s5cmd- or Rclone-based exfiltration to attacker-controlled S3 buckets ahead of double-extortion.

Because the toolkit, not the ransomware brand, is what recurs, defenders who alert only on a known ransomware binary or a specific RaaS brand's indicators will miss the affiliate entirely on its next engagement under a different payload. The consistent tradecraft gives a detection surface that survives a brand switch: a renamed MeshAgent binary establishing outbound C2, an ntdsutil IFM snapshot followed by offline credential extraction, a persistent-service Cloudflared.exe process, discovery-scanner activity (NetScan/Nmap) ahead of lateral movement, and s5cmd/Rclone processes initiating outbound transfers to cloud object storage are the behaviors Microsoft's reporting keys on across Storm-2570 engagements, independent of which ransomware note appears at the end. Microsoft's own post closes with a Defender XDR detection and mitigation mapping tied to each of these behaviors.

Triage: MeshAgent, Atera, ScreenConnect and NinjaRMM are legitimate tools many organizations already run for IT support; the discriminator is not the tool's presence but its provenance and configuration: a renamed executable (meshagent64-[org].exe rather than the vendor's own binary name), an RMM agent installed outside a change-managed deployment window, or a Cloudflared.exe process registered as a persistent LocalSystem service rather than invoked interactively are the signals Microsoft's own telemetry keys on.

Microsoft Threat Intelligence has observed Storm-2570 in multiple investigated intrusions affecting organizations in United States, Canada, United Kingdom, Spain, Netherlands, and Puerto Rico, including healthcare and public health, education, government agencies and services, financial services, energy, consumer retail, Information technology (IT), food and agriculture, consumer services, commercial facilities, non-government organization (NGO), chemicals, critical manufacturing, and transportation.

Microsoft Security Blog / Microsoft Threat Intelligence 2026-09-24

Builds on: Cisco Talos: a Qilin intrusion's own staging directory held ransomware deployment scripts the…

threat29 Sep 04:55Zsingle-sourceOpen finding →

2026-09-21 · view entry permalink →

NOTABLENATOB2

Talos finds AI-generated Python wiper and mass-deployment scripts in a Qilin-affected environment, identified by step-numbered comments and consistent per-step logging

Investigating a separate, Qilin-affected environment, Cisco Talos found three Python post-exploitation scripts in the operator's own staging directory that it assesses with medium-to-high confidence were generated with AI assistance rather than hand-written: deadman.py, a time-triggered wiper deployed via Group Policy Object; veeam_kill.py, which stops, disables and destroys Veeam backup infrastructure; and deploy_locker.py, a mass-deployment launcher for the ransomware payload itself (Cisco Talos, 2026-09-17). Talos's basis for the AI-generation call is stylistic rather than a direct admission or watermark: veeam_kill.py's main() function divides execution into four numbered stages, each carrying a comment and a progress-log line held to a uniform level of detail, and deadman.py's do_gpo function shows the same evenly-commented, staged structure, a pattern Talos found consistent across the scripts and consistent with specification-style docstrings rather than typical hand-written incident-response or red-team tooling. The operator's own bash history additionally references a local tool named llm_chatbot, which Talos cites as corroborating evidence for AI involvement in the scripting workflow.

Talos identified several characteristics in Python scripts found in an open directory used by Qilin that suggest, with medium-to-high confidence, that scripts may have been generated using AI

Figure 17 shows an excerpt from "veeam_kill.py", a Python script designed to stop, disable, and destroy Veeam backups. As shown in Figures 17 and 18, the main() function clearly divides the overall process into four stages, labeled "Step 1" through "Step 4," with comments and progress logs provided at a consistent level of detail for each step.

Cisco Talos 2026-09-17

Builds on: A Swiss research lab co-publishes the DPRK actor-tracking update: two nominally-espionage…

threat21 Sep 04:41Zsingle-sourceOpen finding →
Sources: Cisco Talos

2026-08-04 · view entry permalink →

HIGHCVE-2026-20079 +2exploitedupdatedNATOA1

CVE-2026-20079, Cisco Secure Firewall Management Center: unauthenticated authentication bypass to root, unpatched for five months and only exploitable in a post-boot window (CVSS 10.0)

Cisco Secure Firewall Management Center is the box that holds the policy, the rules and the credentials for a firewall fleet, and CVE-2026-20079 gives an unauthenticated caller root on it. Cisco describes the flaw as "due to an improper system process that is created at boot time", reachable by sending crafted HTTP requests, and scores it CVSS 3.1 10.0 (CWE-288) against Secure FMC Software and Cisco Security Cloud Control Firewall Management "regardless of device configuration" (Cisco PSIRT, 2026-08-03). What makes this worth acting on now rather than in March is the timeline: the advisory went out on 2026-03-04 with no fix and no workaround, and the per-train hot fixes plus the first compromise-check guidance only arrived with advisory version 2.0 on 2026-07-31, and Cisco has revised that check three times since, v2.1 and v2.2 the same day and v2.3 on 2026-08-03. For roughly five months the only available response was exposure reduction. Those hot fixes are no longer the remediation: revision 2.6 of 2026-09-16 replaced them with the September hardening releases (see the correction below).

The mechanics explain why exposure is narrower than a CVSS 10.0 suggests, and why the detection guidance matters more than usual. VulnCheck built a working exploit and published the chain on 2026-03-26: a startup process leaves a partial csm_processes session in the sfsnort.sessions database, and if nobody authenticates after boot that session persists and can be upgraded using the hardcoded machine-user credential report:snortrules, yielding the sf_action_id request token; an arbitrary file write through the validateLicense bulk AJAX endpoint on sajaxintf.cgi drops a Cisco-format Makeself script to /var/tmp/license.tmp, and calling pjb.cgi with SF::UI::DataObjectLibrary::upgradeReadinessCall makes the appliance process that file as an upgrade package, executing it as root (VulnCheck, 2026-03-26). VulnCheck also found the precondition is fragile (dashboard interaction by a real administrator, cloud-managed session activity, or a periodic cleanup all clear the injected session) so in its assessment the realistic exploitation window is shortly after a reboot, or on appliances nobody logs into. That same source counts roughly 300 internet-facing FMC instances on Censys and between 600 and 700 on FOFA.

Cisco's advisory, as first published on 2026-08-03, said it had seen no public announcements or malicious use of this CVE (Cisco PSIRT, 2026-08-03); CISA's KEV addition on 2026-09-09 (see the update below) now confirms active exploitation Cisco itself had not observed, and Cisco's own advisory has since been revised to say the same thing. The reason to treat it as out-of-band even before that KEV listing sat on the same web interface: the separate static low-privilege credential flaw CVE-2026-20316 is CISA KEV-listed with exploitation Cisco says has been ongoing since July 2026 (covered here on 2026-07-30), and in that advisory Cisco raises the Security Impact Rating to High specifically because "this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges" (Cisco PSIRT, 2026-08-03). An attacker already using the exploited flaw for low-privilege read access is one documented step from the root path this CVE opens.

Detection, and the discriminator: both advisories key compromise assessment on the same artifact, a package_info.pl invocation against /var/tmp/license.tmp in /var/log/messages*, run as root via sudo from the www account. Legitimate FMC upgrades and licensing operations do run package_info.pl, so the file path is the signal rather than the command: a genuine upgrade references a package under Cisco's own upgrade directories, not a temporary file in /var/tmp. Because the injected session only survives while no administrator has authenticated, correlate any unauthenticated web-UI activity against appliance boot and uptime records, a request sequence reaching CGI endpoints with no preceding interactive login, minutes after a reboot, is the shape here. Hardening beyond the fixed release is exposure reduction; Cisco notes that "If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced", and low-touch appliances that nobody logs into are precisely the ones that stay exploitable longest.

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

Cisco PSIRT 2026-08-03

In August 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.

Cisco PSIRT (advisory revision 2.5, 2026-09-09)

A registered sftunnel peer has incorrect permissions to write an arbitrary file to any location on the device.

A successful exploit could allow the attacker to write a file to the device that is executed with root privileges. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.

Cisco PSIRT (cisco-sa-fmc-sftunn-codex-c3O4Jft2)

The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.

Cisco PSIRT (cisco-sa-fmc-sftunn-codex-c3O4Jft2 / cisco-sa-fmc-javarce-y2NypXwk)
Updaterun 2026-09-10T0410Z-intelcvestagssummarybody

CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog on 2026-09-09, with a remediation due date of 2026-09-12 for federal civilian agencies. This confirms active exploitation that Cisco's own advisory had not reported as of its last revision, and reverses the no-known-malicious-use framing this entry's main analysis carried. The compromise check and hot-fix guidance above are unchanged; any FMC that has been network-reachable since 2026-03-04 and has not yet had the compromise check run should be treated as a priority, not a precaution.

Updaterun 2026-09-13T0409Z-intelentitiestechniquestagsevidencesourcesbody

Cisco Talos confirmed active exploitation by three distinct post-compromise clusters (Cisco Talos, 2026-09-09). UAT-12197 exploited this CVE alone, planting a JSP web shell in the CSM Tomcat webroot and a JAR-based command executor used to query the FMC's internal user database for credentials (Cisco Talos, 2026-09-09). UAT-11823 exploited both this CVE and CVE-2026-20316 together; Talos states the cluster "overlaps in tooling with the Sandworm APT actor" (Cisco Talos, 2026-09-09), replacing the appliance's license.tmp file with a malicious root-executed package before deploying a variant of Cyclops Blink, the modular implant the US and UK previously attributed to Sandworm. UAT-11988 entered via CVE-2026-20316's static credential alone and, after AD/MySQL credential harvesting, tunnel-based lateral movement and disabling security tooling, deployed ransomware whose subsequent actions Talos found "were consistent with those of Qilin ransomware affiliates" (Cisco Talos, 2026-09-09). Cisco's own advisory was separately revised (v2.5, 2026-09-09) to confirm it became aware of active exploitation of this vulnerability in August 2026 (Cisco PSIRT, 2026-09-09), and Cisco has scheduled a further comprehensive Secure FMC/ASA/FTD hardening release for 2026-09-16 (Cisco PSIRT advance notification, 2026-09-09).

A JSP file appearing in the CSM Tomcat webroot, or a JAR-based executor querying the FMC's own user database, is UAT-12197's signature; a Cyclops Blink deployment resolves its command-and-control address over DNS-over-HTTPS rather than a hardcoded address, so DoH lookups from the FMC management-plane process are a discriminator; and a SOCKS5 proxy or reverse-SSH tunnel originating from the FMC and forwarding LDAP, LDAPS, Kerberos, SMB or NetBIOS/WinRM traffic toward the internal directory is UAT-11988's lateral-movement signature, worth treating as an active-compromise indicator whether or not ransomware has yet deployed.

Updaterun 2026-09-18T0410Z-intelcvessourcesevidencebody

Cisco's promised 2026-09-16 hardening release shipped on schedule, adding two more critical, unauthenticated-adjacent root-RCE flaws to the same Secure FMC product line: CVE-2026-20324 (CVSS 9.9), a flaw in the sftunnel inter-device communication protocol where a registered peer has incorrect file-write permissions, letting an attacker who already holds valid low-privilege device credentials write an arbitrary file that executes as root (Cisco PSIRT, 2026-09-16); and CVE-2026-20242 (CVSS 9.8), an insecure Java deserialization bug in the FMC External Database Access feature reachable by a host already present in that feature's allowlist, needing no credentials of its own (Cisco PSIRT, 2026-09-16). Cisco confirms ASA and FTD Software are not affected by either flaw; there is no workaround for CVE-2026-20324, while CVE-2026-20242 can be mitigated by disabling External Database Access entirely until patched. Cisco states it is not aware of any public announcements or malicious use of either flaw.

Correctionrun 2026-09-20T1308Z-auditheadlinecvesactionsbody

The per-train hot fixes are no longer Cisco's remediation for CVE-2026-20079. Revision 2.6 of the advisory, dated 2026-09-16, records "Replaced hot fixes with the security hardening releases", and the Fixed Releases table now reads 7.0 and earlier to 7.0.10, 7.2 to 7.2.12, 7.4 to 7.4.8, 7.6 to 7.6.6, 7.7 to 7.7.13, 10.0 to 10.0.2 and 10.1 to 10.1.0 (Cisco PSIRT, 2026-09-16). Cisco adds that the hardening releases carry this fix "as well as multiple other internally discovered vulnerabilities" and recommends upgrading to them, directing anyone who still needs hot-fix detail to its support centre. An appliance patched with the earlier hot fix is fixed for this flaw but not for the rest of the hardening release.

Builds on: Cisco patches an actively exploited hardcoded credential in Secure FMC, CVSS 5.3, but Cisco…

vulnerability04 Aug 04:45Zmulti-sourceOpen finding →

Earlier coverage (6)

2026-09-08NOTABLENATOB2Sekoia and Kudelski Security split the 'Lazarus umbrella' into six named DPRK clusters, and document two of them adopting commodity ransomware-as-a-service within two months of each otherSekoia and Kudelski Security (a Switzerland-based firm) jointly reassessed DPRK's offensive-cyber organization on 2026-09-07, replacing the historical "Lazarus umbrella" with six tracked sub-clusters and documenting that Andariel and Moonstone Sleet each adopted a commodity ransomware-as-a-service (Play and Qilin respectively) within two months of one another, a single observed timing overlap the authors call notable, consistent with the general possibility that nominally espionage-focused DPRK units rent criminal ransomware infrastructure alongside bespoke tooling.2026-08-10HIGHNATOB1Qilin compromised Italian telecommunications and cloud operator Retelit on 8 June, the company confirmed it only after an investigation forced the question, and one of the three affected data centres was its certified backup siteIrpiMedia reported on 2026-08-04 that Retelit, one of Italy's largest business telecommunications and cloud operators, had been compromised in an extortion attack claimed by Qilin, with roughly 270,000 files listed on the leak site and an estimated 300 GB published across two dumps. Retelit made no announcement through its own channels; after the article ran it sent the outlet a right-of-reply confirming an 8 June 2026 attack attributed to Qilin, notified to Italy's national cybersecurity agency, CSIRT-ITA, the postal police and the data-protection authority, and scoping the damage to virtualisation infrastructure in 3 of its 38 national data centres, around 7% of distributed systems. IrpiMedia names those three as Verona, Rome and Milan (Milan being the site certified for Retelit's own backup and service continuity) and reports customers complaining of backup-recovery failure.2026-07-29NOTABLENATOB2Romanian public university UVVG Arad confirms a cyberattack on its IT infrastructure; a Qilin leak-site listing is the only thing linking an actor to itUniversitatea de Vest "Vasile Goldis" din Arad, a Romanian public university, issued a press release on 2026-07-28 confirming that a recently identified cyberattack affected its IT infrastructure and the digital services used in academic and administrative work, that it notified the national cybersecurity directorate DNSC, the data-protection authority ANSPDCP and organised-crime prosecutors DIICOT, and that technical teams are working with external specialists on gradual restoration. The university does not say which systems are unavailable, whether personal data was accessed or exfiltrated, when the attack occurred, or who was responsible. Separately, the Qilin ransomware operation listed the university on its leak site with an estimated attack date of 2026-07-26, a claim carried only by a leak-site mirror, which none of the Romanian reporting mentions at all.2026-06-09CRITICALexploitedupdatedCVE-2026-50751, Check Point Security Gateway: IKEv1 VPN authentication bypass, actively exploited by a Qilin affiliateCheck Point IKEv1 VPN auth bypass (CVE-2026-50751, CVSS 9.3) actively exploited by a Qilin affiliate since 7 May, a month before disclosure. Unauthenticated session forgery on Remote Access / Mobile Access gateways; NCSC-CH issued an Action-Required advisory and CISA added it to KEV (Check Point, 2026-06-08).2026-05-20HIGHMicrosoft DCU disrupts Fox Tempest malware-signing-as-a-service feeding Rhysida, INC, Qilin and Akira ransomware operationsMicrosoft Digital Crimes Unit disrupts Fox Tempest malware-signing-as-a-service. 1,000+ fraudulent short-lived Microsoft Artifact Signing certificates revoked; signspace[.]cloud seized via SDNY court order. Downstream customers include Vanilla Tempest (Rhysida), Storm-0501, Storm-2561, Storm-0249; ransomware families served include Rhysida, INC, Qilin, Akira (Microsoft Threat Intelligence, 2026-05-19). Detection: hunt for Microsoft-signed PE binaries with cert validity ≤72h from Trusted Signing issuers.2026-05-08NOTABLEQilin ransomware hits Die Linke (Germany): 1.5 TB claimed, DPA notified (~April 2026, first coverage)The German federal party Die Linke confirmed in April 2026 that the Qilin ransomware group (also known as Agenda, a Rust-based RaaS platform known for double extortion) encrypted and exfiltrated its systems, with the gang claiming 1.5 TB of internal data.

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats7
  • Research3
  • Vulns3
  • Deep dive2

Source distribution

  • sec.cloudapps.cisco.com5 (12%)
  • rapid7.com3 (7%)
  • attack.mitre.org2 (5%)
  • blog.talosintelligence.com2 (5%)
  • helpnetsecurity.com2 (5%)
  • microsoft.com2 (5%)
  • advisories.ncsc.nl1 (2%)
  • aradon.ro1 (2%)
  • other24 (57%)
All cited sources (42)