Skip to content
Auto-CTI
Back to all actors

Qilin

Cybercrime Financial Dormant
Mentions
4
First seen
08 Jun 2026
Last seen
21 Jul 2026

Relevant to you · Relevant

Threat focus:
ransomware
Sector / region:
Manufacturing

Origin

Unattributed

Sources

inferred Confidence medium

Profile

The Qilin ransomware group actively exploits vulnerabilities in VPN appliances, notably an authentication bypass in PAN-OS and zero-day flaws in Check Point VPNs, to gain initial access for ransomware attacks. Recent reports link these security flaws directly to Qilin and their use in compromising corporate networks. The group focuses on compromising VPN appliances to deploy ransomware in target environments.

Affected vendors

Check PointPalo Alto Networks

Associated malware / tools

QilinQilin ransomware

Linked CVEs

Activity (8 weeks)

31
32
33
34
35
36
37
38

Recent activity

ESC