News Room
16
Share
Qilin Ransomware Escalates Global Campaign: Multiple High-Profile Breaches Reported in 48-Hour Surge
criticalThreat Intelligence

Qilin Ransomware Escalates Global Campaign: Multiple High-Profile Breaches Reported in 48-Hour Surge

The Qilin ransomware group has intensified its operations, claiming multiple international victims including AmSpec Group and Akugur Law Firm. The group is utilizing advanced EDR-blinding techniques to bypass modern defenses.

09 August 2026Last updated 18 August 20264 min readUnit 42
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2026-15409
Source:
Unit 42
Read Time:
4 min

Executive Summary

Over the last 48 hours, the Qilin ransomware group has significantly ramped up its extortion activities, listing several high-profile victims across Europe, North America, and the Middle East on its data leak site. As of August 9, 2026, intelligence indicates a coordinated surge targeting the legal, industrial, and testing services sectors. Notable victims identified in this wave include the global testing firm AmSpec Group, the French business services provider ALIZE SUD, and the Turkish legal firm Akugur Law Firm. This escalation occurs amidst a broader competitive landscape where Qilin is vying for dominance against emerging RaaS operators like 'The Gentlemen.'

Threat Analysis

Qilin, a Ransomware-as-a-Service (RaaS) operation formerly known as Agenda, has evolved into one of the most prolific threats of 2026. Recent telemetry suggests the group is shifting its focus from small-to-medium businesses (SMBs) toward large enterprises with revenues exceeding $1 billion. This 'big game hunting' strategy is likely a response to the rising influence of The Gentlemen, who currently account for approximately 17% of global ransomware attacks. The rivalry between these two groups is driving an increase in attack velocity and the adoption of more aggressive double-extortion tactics, where data is exfiltrated and encrypted simultaneously to maximize leverage.

Technical Details

Recent Qilin campaigns have demonstrated a sophisticated use of 'Bring Your Own Vulnerable Driver' (BYOVD) attacks. By embedding vulnerable, signed Windows drivers directly into their ransomware payloads, the actors are able to disable Endpoint Detection and Response (EDR) solutions in a single stage. This represents a significant advancement over 2025 tactics, which typically required multiple stages to achieve EDR blinding. Furthermore, Qilin has been observed exploiting recently disclosed vulnerabilities in VPN infrastructure, including SonicWall SMA 1000 series flaws (CVE-2026-15409) and Check Point VPN zero-days, to gain initial access. Once inside, the group deploys a Rust-based encryptor capable of targeting both Windows and Linux/ESXi environments, utilizing a Behinder-like custom Java web shell for persistent command-and-control.

Attribution Assessment

Encrygma analysts attribute these attacks to the Qilin ransomware collective with high confidence. The group’s signature Rust-based malware and specific negotiation patterns observed in the AmSpec and Akugur incidents align with historical Qilin TTPs. While the group maintains a diverse affiliate base, the recent technical shift toward integrated BYOVD modules suggests a centralized update to their core RaaS toolkit, likely developed by the group's primary operators to maintain a competitive edge in the underground market.

Implications

The targeting of AmSpec Group—a leader in testing, inspection, and certification (TIC)—highlights a growing threat to global supply chain integrity. Compromising TIC firms allows attackers to access sensitive project files, backup databases, and proprietary logs that could facilitate secondary attacks on their clients. Additionally, the breach of legal firms like Akugur underscores the continued risk of highly sensitive data exposure, which Qilin frequently uses to pressure victims into payment through public shaming and regulatory threats.

Recommendations

Organizations are advised to implement strict driver blocklists to mitigate BYOVD attacks, specifically targeting known vulnerable drivers used for EDR blinding. Immediate patching of all VPN appliances, particularly SonicWall and Check Point systems, is critical. Furthermore, defenders should prioritize the implementation of multi-factor authentication (MFA) across all remote access points and maintain immutable, offline backups to ensure recovery in the event of a successful encryption event.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo