Qilin (aka Agenda) ransomware deployment after PAN-OS exploitation
Malware Activity
Summary
Hide ▲
Show ▼
Qilin (aka Agenda) ransomware was deployed across multiple June 2026 intrusions after attackers exploited CVE-2026-0257 in Palo Alto Networks PAN-OS to gain initial access. The activity expanded from VPN session abuse into credential harvesting, lateral movement, and ransomware encryption on victim environments. Some intrusions stopped at encryption-only operations, while others added double-extortion and data theft, increasing pressure on affected networks. The consistent tooling and staging patterns indicate a repeatable Qilin RaaS operation rather than isolated malware use.
Related Happenings
IT services firm in South Asia hit by ransomware attack
Incident
H score31
First: 16.07.2026 13:00
Last: 16.07.2026 13:00
Sources 1
About this happening:
The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...
IT services firm in South Asia hit by ransomware attack
IncidentAbout this happening: The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...
GodDamn ransomware PoisonX BYOVD activity
Malware Activity
H score14
First: 09.07.2026 13:43
Last: 09.07.2026 13:43
Sources 1
About this happening:
GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...
GodDamn ransomware PoisonX BYOVD activity
Malware ActivityAbout this happening: GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...
Qilin consolidates into dominant RaaS position as ransomware market reconcentrates
Threat Actor Meta
H score39
First: 03.07.2026 16:00
Last: 03.07.2026 16:00
Sources 1
About this happening:
Qilin is consolidating into a dominant RaaS position as the ransomware ecosystem shifts back from fragmentation to concentration, increasing affiliate scale and victim vol...
Qilin consolidates into dominant RaaS position as ransomware market reconcentrates
Threat Actor MetaAbout this happening: Qilin is consolidating into a dominant RaaS position as the ransomware ecosystem shifts back from fragmentation to concentration, increasing affiliate scale and victim vol...
Medusa ransomware post-compromise deployment
Malware Activity
H score48
First: 07.04.2026 09:35
Last: 07.04.2026 09:35
Sources 1
About this happening:
Medusa ransomware is being deployed rapidly after initial access, turning intrusions into fast-moving extortion events and shrinking defenders' response time. The malware acti...
Medusa ransomware post-compromise deployment
Malware ActivityAbout this happening: Medusa ransomware is being deployed rapidly after initial access, turning intrusions into fast-moving extortion events and shrinking defenders' response time. The malware acti...
The Gentlemen RaaS split exposed by hastalamuerte
Threat Actor Meta
H score25
First: 19.03.2026 18:00
Last: 19.03.2026 18:00
Sources 1
About this happening:
hastalamuerte exposed the internal workings of The Gentlemen ransomware group, revealing a Qilin-related RaaS split that shows how affiliate-driven ecosystems can rapi...
The Gentlemen RaaS split exposed by hastalamuerte
Threat Actor MetaAbout this happening: hastalamuerte exposed the internal workings of The Gentlemen ransomware group, revealing a Qilin-related RaaS split that shows how affiliate-driven ecosystems can rapi...
Latest development: 17.07.2026 12:00
ReliaQuest reported that The Gentlemen ransomware gang became the most active ransomware group over a three-month period, with 300 incidents and 1,368 victim claims tracked across 11 ransomware groups. The analysis said The Gentlemen overtook Qilin, which had 289 incidents, and linked the rise to aggressive affiliate recruitment, a pre-packaged intrusion kit, and AI-accelerated development.
Timeline
-
21.07.2026 17:04 2 articles · 3h ago
Arctic Wolf Labs details June 2026 PAN-OS exploitation leading to Qilin ransomware
Initial DisclosureArctic Wolf Labs describes multiple June 2026 intrusions against victim environments that began with exploitation of CVE-2026-0257 in Palo Alto Networks PAN-OS, allowing attackers to establish SSL VPN sessions without valid credentials and then harvest credentials, move laterally with PsExec via administrative shares, clear event logs, disable Microsoft Defender Real-Time Protection, and deploy Qilin (aka Agenda) ransomware; follow-on activity varied from encryption-only operations to double-extortion and data exfiltration.
Show sources
- Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access — thehackernews.com — 21.07.2026 17:04
- Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access — thehackernews.com — 21.07.2026 17:04