Find notable cyber news and cases, enriched with sources, timelines, and signals.

Qilin (aka Agenda) ransomware deployment after PAN-OS exploitation

Malware Activity
First reported
Last updated
Happening score
H score 40
1 unique sources, 1 articles

Summary

Hide ▲

Qilin (aka Agenda) ransomware was deployed across multiple June 2026 intrusions after attackers exploited CVE-2026-0257 in Palo Alto Networks PAN-OS to gain initial access. The activity expanded from VPN session abuse into credential harvesting, lateral movement, and ransomware encryption on victim environments. Some intrusions stopped at encryption-only operations, while others added double-extortion and data theft, increasing pressure on affected networks. The consistent tooling and staging patterns indicate a repeatable Qilin RaaS operation rather than isolated malware use.

Related Happenings

IT services firm in South Asia hit by ransomware attack

Incident
H score31 First: 16.07.2026 13:00 Last: 16.07.2026 13:00 Sources 1

About this happening: The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...

GodDamn ransomware PoisonX BYOVD activity

Malware Activity
H score14 First: 09.07.2026 13:43 Last: 09.07.2026 13:43 Sources 1

About this happening: GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...

Qilin consolidates into dominant RaaS position as ransomware market reconcentrates

Threat Actor Meta
H score39 First: 03.07.2026 16:00 Last: 03.07.2026 16:00 Sources 1

About this happening: Qilin is consolidating into a dominant RaaS position as the ransomware ecosystem shifts back from fragmentation to concentration, increasing affiliate scale and victim vol...

Medusa ransomware post-compromise deployment

Malware Activity
H score48 First: 07.04.2026 09:35 Last: 07.04.2026 09:35 Sources 1

About this happening: Medusa ransomware is being deployed rapidly after initial access, turning intrusions into fast-moving extortion events and shrinking defenders' response time. The malware acti...

The Gentlemen RaaS split exposed by hastalamuerte

Threat Actor Meta
H score25 First: 19.03.2026 18:00 Last: 19.03.2026 18:00 Sources 1

About this happening: hastalamuerte exposed the internal workings of The Gentlemen ransomware group, revealing a Qilin-related RaaS split that shows how affiliate-driven ecosystems can rapi...

Latest development: 17.07.2026 12:00

ReliaQuest reported that The Gentlemen ransomware gang became the most active ransomware group over a three-month period, with 300 incidents and 1,368 victim claims tracked across 11 ransomware groups. The analysis said The Gentlemen overtook Qilin, which had 289 incidents, and linked the rise to aggressive affiliate recruitment, a pre-packaged intrusion kit, and AI-accelerated development.

Timeline

  1. 21.07.2026 17:04 2 articles · 3h ago

    Arctic Wolf Labs details June 2026 PAN-OS exploitation leading to Qilin ransomware

    Initial Disclosure

    Arctic Wolf Labs describes multiple June 2026 intrusions against victim environments that began with exploitation of CVE-2026-0257 in Palo Alto Networks PAN-OS, allowing attackers to establish SSL VPN sessions without valid credentials and then harvest credentials, move laterally with PsExec via administrative shares, clear event logs, disable Microsoft Defender Real-Time Protection, and deploy Qilin (aka Agenda) ransomware; follow-on activity varied from encryption-only operations to double-extortion and data exfiltration.

    Show sources