Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fake Game Apps Deliver Multi-Stage Infostealers, Steal Crypto and Passwords
July 21, 2026
Qilin Ransomware Claims 1,358 Victims, Global Attacks Soar
July 21, 2026
Hackers Hijack Government Websites to Deliver Malware via Trusted Links
July 21, 2026
Home/Threats/Qilin Ransomware Claims 1,358 Victims, Global Attacks Soar
Threats

Qilin Ransomware Claims 1,358 Victims, Global Attacks Soar

Key Takeaways Qilin ransomware has emerged as a significant global threat, claiming 1,358 victims and demonstrating a 443% increase in activity year-over-year. The group leverages common attack...

Marcus Rodriguez
Marcus Rodriguez
July 21, 2026 3 Min Read
3 0

Key Takeaways

  • Qilin ransomware has emerged as a significant global threat, claiming 1,358 victims and demonstrating a 443% increase in activity year-over-year.
  • The group leverages common attack vectors like exposed credentials, unpatched software, and third-party vulnerabilities to compromise systems and exfiltrate data.
  • Qilin’s operations span over 50 countries, contributing to a broader surge in ransomware attacks, with 7,551 publicly disclosed victims between April 2025 and March 2026.
  • Post-incident analysis reveals that many victim organizations remain vulnerable to critical and known exploited flaws even after recovery efforts.

Qilin’s Escalating Global Ransomware Campaign

The Qilin ransomware group has rapidly evolved from an active criminal enterprise into a prominent player in the global cyber extortion landscape. This group employs a dual-threat approach, encrypting targeted systems while simultaneously exfiltrating sensitive data. Victims are then subjected to intense pressure, including the threat of public data leaks, leading to significant operational disruption and reputational damage across various sectors and countries, as detailed in a recent report.

Table Of Content

  • Key Takeaways
  • Qilin’s Escalating Global Ransomware Campaign
  • The Scale of Qilin’s Impact
  • Recovery Does Not End Risk
  • What You Should Do

Ransomware operators, including Qilin, are increasingly exploiting prevalent vulnerabilities such as exposed credentials, unaddressed software flaws, and compromised third-party connections to gain initial access to victim networks. Qilin has notably demonstrated a capacity for swift lateral movement within compromised environments. This includes utilizing techniques like the abuse of RDP history, which allows attackers to efficiently map internal systems and identify valuable accounts within a network.

The Scale of Qilin’s Impact

A report from Black Kite, shared with Cyber Security News (CSN), indicates that Qilin was responsible for 1,358 victim claims during the tracking period. This represents a staggering 443% increase compared to the previous year. Black Kite analysts highlighted that Qilin’s reach extended to over 50 countries, with the group accounting for approximately 15-20% of all publicly disclosed ransomware incidents.

The broader ransomware threat continues to intensify. Black Kite documented 7,551 publicly disclosed ransomware victims between April 2025 and March 2026, marking a 24.9% year-over-year increase. March alone saw a record 861 victims, the highest monthly total observed by the researchers. Qilin’s 1,358 victims position it as a major force in an increasingly competitive and aggressive ransomware market.

By June 2026, the number of active ransomware operations had grown to 146, underscoring a trend where new criminal groups are continually entering the fray even as established ones may cease operations. While the top five ransomware groups collectively claimed 43.6% of disclosed victims, no single entity dominated the year in the manner seen with previous leading groups. Qilin distinguished itself through the sheer volume of its attacks, contrasting with other groups that focused on widespread exploitation, credential theft, or specific geographic targets.

The manufacturing sector remained the most frequently targeted industry, with 1,660 disclosed victims, followed by professional, scientific, and technical services, which recorded 1,389 incidents. Notably, mid-sized organizations with revenues between $50 million and $100 million accounted for a larger proportion of known victims, suggesting an escalating threat to firms beyond major enterprises. Qilin’s expansion also reflects a broader shift in attacker methodologies. Recent reports on the exploitation of PAN-OS flaws illustrate how threat actors can leverage authentication weaknesses in internet-facing systems to gain access and deploy ransomware, making timely patching of exposed infrastructure critically important.

Recovery Does Not End Risk

Post-incident analyses conducted by Black Kite revealed a concerning trend: many organizations remained vulnerable even after their ransomware incidents were officially closed. Approximately 43.5% of victims still harbored critical patch vulnerabilities, while 30.8% continued to possess known exploited vulnerabilities that attackers could readily leverage for subsequent attacks.

These findings underscore that successful recovery from a ransomware attack extends far beyond simply restoring encrypted files. Organizations must implement a robust, ongoing security posture. Structured external reviews at 30, 60, and 90 days following an incident are crucial, with particular attention paid to identifying compromised credentials, critical vulnerabilities, and any systems listed in the Known Exploited Vulnerabilities catalog.

Third-party applications also demand closer scrutiny. The Black Kite report highlighted the misuse of OAuth tokens and connected software as a significant attack vector. Incidents like the Salesloft Drift token theft demonstrate how compromised application access can expose data across interconnected environments.

What You Should Do

  • Prioritize patching based on active exploitation and severity, rather than adhering strictly to routine maintenance schedules.
  • Maintain a comprehensive inventory of all connected applications and regularly review OAuth permissions.
  • Immediately rotate credentials following any suspicious activity or confirmed breach.
  • Enforce multi-factor authentication (MFA) across all internal and vendor accounts to significantly reduce unauthorized access.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitPatchransomwareSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Hackers Hijack Government Websites to Deliver Malware via Trusted Links

Next Post

Fake Game Apps Deliver Multi-Stage Infostealers, Steal Crypto and Passwords

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Trump AI Safety Chief Resigns After Three Months
July 21, 2026
APT42 Targets Officials with AI Phishing, TAMECAT Malware
July 21, 2026
Critical GitHub Actions Flaw Backdoors AsyncAPI npm Packages with Miasma RAT
July 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us