News Room
16
Share
Qilin Ransomware Targets US Legal and IT Sectors in Latest Double-Extortion Campaign
criticalThreat Intelligence

Qilin Ransomware Targets US Legal and IT Sectors in Latest Double-Extortion Campaign

Qilin ransomware has listed high-profile US targets, including law firm Arnall Golden Gregory LLP and ASCII Group, on its leak site. The group continues to leverage advanced data exfiltration and EDR-bypass techniques.

18 August 2026Last updated 20 August 20264 min readBreachsense
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
North America
Confidence:
High Confidence
CVE:
CVE-2024-55591, CVE-2024-40766
Source:
Breachsense
Read Time:
4 min

Executive Summary

On August 18, 2026, Encrygma intelligence analysts identified a surge in activity from the Qilin ransomware group, targeting high-value professional services in the United States. The group officially listed the Atlanta-based law firm Arnall Golden Gregory LLP and the IT staffing firm ASCII Group on its dedicated leak site (DLS). These incidents follow a broader trend observed throughout August 2026, where ransomware-as-a-service (RaaS) operators have intensified their focus on sectors handling sensitive intellectual property and personally identifiable information (PII). The attacks utilize a double-extortion model, combining file encryption with the threat of public data disclosure to maximize leverage during negotiations.

Threat Analysis

Qilin, also known as Agenda, has evolved into one of the most prolific threat actors of 2026. According to recent telemetry, the group has significantly increased its victim count, contributing to the 6,005 total ransomware victims recorded globally so far this year. Qilin’s strategy involves targeting organizations with low downtime tolerance, such as legal and healthcare entities. The recent breach of Arnall Golden Gregory LLP highlights the group's continued interest in the legal sector, where the theft of attorney-client privileged information provides extreme extortion pressure. Simultaneously, the targeting of ASCII Group suggests a strategic move to acquire data related to IT infrastructure and staffing, potentially facilitating downstream supply chain attacks.

Technical Details

Recent Qilin campaigns have been observed utilizing advanced EDR (Endpoint Detection and Response) evasion techniques. Intelligence reports from Halcyon indicate that Qilin affiliates are increasingly deploying 'EDR-kill' scripts that systematically disable security agents before initiating the encryption phase. The group is also known to exploit vulnerabilities in enterprise edge devices. While Gunra ransomware has recently dominated headlines for exploiting Fortinet FortiOS flaws (CVE-2024-55591), Qilin has been observed using similar initial access vectors, including compromised VPN credentials and unpatched SonicWall SSL VPNs (CVE-2024-40766). Once inside, the actors perform lateral movement using Cobalt Strike and move to exfiltrate data via Rclone to cloud storage providers before deploying the final ransomware payload.

Attribution Assessment

Encrygma attributes these attacks to the Qilin RaaS operation with high confidence. Qilin is a sophisticated cybercriminal collective that operates a sophisticated affiliate program. While the group's core developers are believed to be Russian-speaking, their affiliates are geographically dispersed. The group's shift toward Rust-based ransomware variants allows for easier cross-platform targeting, affecting both Windows and Linux/ESXi environments. The recent activity aligns with Qilin's established tactics, techniques, and procedures (TTPs), specifically their use of customized leak sites and aggressive negotiation tactics.

Implications

The successful breach of a major US law firm and an IT staffing agency underscores the persistent vulnerability of the professional services supply chain. For legal firms, the implication is a total compromise of client confidentiality, which can lead to regulatory fines and irreparable reputational damage. For IT staffing firms, the breach of PII for thousands of contractors and internal employees creates a significant risk of identity theft and targeted phishing campaigns against their client base.

Recommendations

Encrygma recommends that organizations immediately prioritize the following actions: 1. Patch all edge-facing devices, specifically Fortinet and SonicWall appliances, against known RCE vulnerabilities. 2. Implement robust EDR protection with 'tamper protection' enabled to prevent unauthorized service termination. 3. Enforce phishing-resistant Multi-Factor Authentication (MFA) across all remote access points. 4. Conduct regular offline backups and test restoration procedures to ensure operational resilience against encryption-based attacks.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo