Qilin
Cybercrime Financial Dormant
- Mentions
- 4
- First seen
- 08 Jun 2026
- Last seen
- 21 Jul 2026
Relevant to you · Relevant
- Threat focus:
- ransomware
- Sector / region:
- Manufacturing
Origin
Unattributed
Sources
inferred Confidence medium
Profile
The Qilin ransomware group actively exploits vulnerabilities in VPN appliances, notably an authentication bypass in PAN-OS and zero-day flaws in Check Point VPNs, to gain initial access for ransomware attacks. Recent reports link these security flaws directly to Qilin and their use in compromising corporate networks. The group focuses on compromising VPN appliances to deploy ransomware in target environments.
Affected vendors
Check PointPalo Alto Networks
Associated malware / tools
QilinQilin ransomware
Linked CVEs
- CVE-2026-0257 KEV CVSS 7.8 EPSS 87%
Activity (8 weeks)
Recent activity
- Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access The Hacker News
- Critical Palo Alto VPN bug now exploited by Qilin ransomware gang BleepingComputer
- Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks SecurityWeek
- Check Point links VPN zero-day attacks to Qilin ransomware gang BleepingComputer