
Qilin Ransomware Escalates Global Campaign: Multiple High-Profile Breaches Reported in 48-Hour Surge
The Qilin ransomware group has intensified its operations, claiming multiple international victims including AmSpec Group and Akugur Law Firm. The group is utilizing advanced EDR-blinding techniques to bypass modern defenses.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- High Confidence
- CVE:
- CVE-2026-15409
- Source:
- Unit 42
- Read Time:
- 4 min
Executive Summary
Over the last 48 hours, the Qilin ransomware group has significantly ramped up its extortion activities, listing several high-profile victims across Europe, North America, and the Middle East on its data leak site. As of August 9, 2026, intelligence indicates a coordinated surge targeting the legal, industrial, and testing services sectors. Notable victims identified in this wave include the global testing firm AmSpec Group, the French business services provider ALIZE SUD, and the Turkish legal firm Akugur Law Firm. This escalation occurs amidst a broader competitive landscape where Qilin is vying for dominance against emerging RaaS operators like 'The Gentlemen.'
Threat Analysis
Qilin, a Ransomware-as-a-Service (RaaS) operation formerly known as Agenda, has evolved into one of the most prolific threats of 2026. Recent telemetry suggests the group is shifting its focus from small-to-medium businesses (SMBs) toward large enterprises with revenues exceeding $1 billion. This 'big game hunting' strategy is likely a response to the rising influence of The Gentlemen, who currently account for approximately 17% of global ransomware attacks. The rivalry between these two groups is driving an increase in attack velocity and the adoption of more aggressive double-extortion tactics, where data is exfiltrated and encrypted simultaneously to maximize leverage.
Technical Details
Recent Qilin campaigns have demonstrated a sophisticated use of 'Bring Your Own Vulnerable Driver' (BYOVD) attacks. By embedding vulnerable, signed Windows drivers directly into their ransomware payloads, the actors are able to disable Endpoint Detection and Response (EDR) solutions in a single stage. This represents a significant advancement over 2025 tactics, which typically required multiple stages to achieve EDR blinding. Furthermore, Qilin has been observed exploiting recently disclosed vulnerabilities in VPN infrastructure, including SonicWall SMA 1000 series flaws (CVE-2026-15409) and Check Point VPN zero-days, to gain initial access. Once inside, the group deploys a Rust-based encryptor capable of targeting both Windows and Linux/ESXi environments, utilizing a Behinder-like custom Java web shell for persistent command-and-control.
Attribution Assessment
Encrygma analysts attribute these attacks to the Qilin ransomware collective with high confidence. The group’s signature Rust-based malware and specific negotiation patterns observed in the AmSpec and Akugur incidents align with historical Qilin TTPs. While the group maintains a diverse affiliate base, the recent technical shift toward integrated BYOVD modules suggests a centralized update to their core RaaS toolkit, likely developed by the group's primary operators to maintain a competitive edge in the underground market.
Implications
The targeting of AmSpec Group—a leader in testing, inspection, and certification (TIC)—highlights a growing threat to global supply chain integrity. Compromising TIC firms allows attackers to access sensitive project files, backup databases, and proprietary logs that could facilitate secondary attacks on their clients. Additionally, the breach of legal firms like Akugur underscores the continued risk of highly sensitive data exposure, which Qilin frequently uses to pressure victims into payment through public shaming and regulatory threats.
Recommendations
Organizations are advised to implement strict driver blocklists to mitigate BYOVD attacks, specifically targeting known vulnerable drivers used for EDR blinding. Immediate patching of all VPN appliances, particularly SonicWall and Check Point systems, is critical. Furthermore, defenders should prioritize the implementation of multi-factor authentication (MFA) across all remote access points and maintain immutable, offline backups to ensure recovery in the event of a successful encryption event.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Chaos and M3rx Ransomware Groups Escalate Attacks on US Healthcare and Legal Sectors

Ransomware Surge: Emperador and SafePay Lead Record-Breaking September 2026 Extortion Wave

