September 20, 2026

#3 Qilin Ransomware Group

qilin

Qilin ransomware continues to pose a significant threat to Australian organisations, with recent claimed victims spanning retail, non-profit services, technology, finance, construction and healthcare.

Qilin operates a ransomware-as-a-service (RaaS) model. MITRE ATT&CK identifies Qilin as an active ransomware family associated with Agenda and notes its ability to target Windows, Linux and VMware ESXi environments.

Recent Australian claims include Reddrop Group and Thorndale Foundation, both listed by Qilin in September. The Thorndale listing reportedly included samples such as passport photographs and invoices, while the Reddrop Group claim had no published evidence at the time of reporting. These remain threat-actor claims and should not automatically be treated as independently confirmed breaches.

The continued Australian activity is consistent with wider regional reporting. Group-IB identified Qilin as one of the most active ransomware operators in the ANZ region during Q2 2026, recording 11 attacks, while its August report again placed Qilin among the region’s most active operators.

Broad Targeting

Qilin’s victim profile is notably diverse. Its activity has affected organisations across healthcare, manufacturing, technology, financial services, retail, transportation, utilities and professional services. This makes the group relevant not only to large enterprises but also to Australian and New Zealand mid-market organisations.

Recent claims involving Australian organisations illustrate this breadth:

Company Domain Date Industry Country
Reddrop Group reddrop.com.au 16 Sep 2026 Retail AU
Thorndale Foundation thorndale.com.au 15 Sep 2026 Non-Profit AU
DigiGround digiground.com.au 29 Aug 2026 Software & IT Services AU
The Frame Group framegroup.com.au 29 Aug 2026 Software & IT Services AU
Professional prms.com 21 Aug 2026 Finance AU
Asset Flooring Group Australia assetflooring.com.au 3 Aug 2026 Construction AU
Seed Outsourcing seedoutsourcing.com 3 Aug 2026 Finance AU
Pennant Hills Golf Club pennanthillsgolfclub.com.au 2 Jul 2026 Sports / Hospitality AU
The Banyans thebanyans.com.au 8 Jun 2026 Healthcare AU
Kinetic Education kineticeducation.com.au 8 Jun 2026 Education AU
Alpha Group NZ alphagroup.nz 24 May 2026 Biotechnology / Healthcare / Manufacturing NZ
Branded Products brandedproducts.com.au 24 May 2026 Advertising AU
Generation Life genlife.com.au 15 May 2026 Finance / Investment AU
Australian College of Business Intelligence acbi.edu.au 15 May 2026 Education AU
Menzies Group menziesgroup.com.au 15 May 2026 Facilities / Cleaning Services AU
Australian College acbi.edu.au 15 May 2026 Education AU
Bluize bluize.com.au 13 May 2026 Hospitality / Gaming AU
Construction Sciences constructionsciences.net 28 Apr 2026 Construction / Engineering AU
Tripod Farmers tripodfarmers.com.au 17 Apr 2026 Food & Beverage / Agriculture AU
Peuker & Alexander peuker.com.au 10 Apr 2026 Construction / Manufacturing AU
Seeing Machines seeingmachines.com 31 Mar 2026 IT-Enabled Services AU
Kennedy McLaughlin kennedymclaughlin.com.au 23 Mar 2026 Accounting AU
Fortress Resistors fortressresistors.com 10 Mar 2026 Industrial Equipment AU
Maintenance & Project Engineering mpe.com.au 22 Feb 2026 Consulting / Asset Management AU
Esperance Metaland espmetaland.com.au 21 Feb 2026 Metals & Mining / Construction / Manufacturing AU
Mt Barker Co-op mtbarkercoop.com.au 11 Feb 2026 Retail AU
Esperance Communications ec.com.au 30 Jan 2026 Electronics / Software & IT Services AU

Dates and victim status reflect the supplied dataset. Leak-site listings are allegations by the threat actor unless independently confirmed.

Qilin Tradecraft

Qilin combines conventional ransomware deployment with extensive use of legitimate administration and remote-access functionality.

Reported techniques include:

  • Valid accounts and credential theft for initial access and privilege escalation.
  • Exploitation of public-facing applications and remote services.
  • Phishing, including malicious attachments and links.
  • PowerShell and command-line execution.
  • RDP, SMB, SSH and WinRM for lateral movement.
  • Cobalt Strike and other remote-access tooling.
  • Chisel, Ngrok and other tunnelling mechanisms to maintain connectivity.
  • Archive-based collection before data exfiltration.
  • Defense impairment, including termination or modification of security tooling.
  • Data exfiltration followed by encryption, supporting a double-extortion model.

MITRE ATT&CK documents Qilin’s use of PowerShell, exploitation of public-facing applications, SMB and SSH, remote-access software, process discovery and data encryption.

Qilin activity has also been associated with Agenda Ransomware, Qilin.B, NETXLOADER and SmokeLoader. Reported vulnerabilities associated with Qilin activity include CVE-2023-27532 and CVE-2024-1853, while separate 2026 reporting has linked Qilin activity to exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center.

MITRE ATT&CK Techniques

Technique ID Description / Qilin association
Exploit Public-Facing Application T1190 Exploitation of externally accessible applications and interfaces
Exploitation for Client Execution T1203 Exploitation of vulnerabilities for execution
Phishing: Spearphishing Attachment T1566.001 Malicious attachments used for initial access
Phishing: Spearphishing Link T1566.002 Malicious links used for initial access
External Remote Services T1133 Use of externally accessible remote services
Remote Services T1021 Lateral movement through remote services
RDP T1021.004 Remote Desktop Protocol
PowerShell T1059.001 PowerShell-based execution and discovery
Valid Accounts T1078 Abuse of legitimate credentials
Network Service Scanning T1046 Discovery of network services
Remote Access Software T1219 Remote-management and access tooling
Brute Force T1110 Credential attacks
System Network Configuration Discovery T1016 Network discovery
Data Encrypted for Impact T1486 Encryption of victim systems and data
Application Layer Protocol: Web Protocols T1071.001