logo

Watch Guard! Qilin affiliate exploits network appliances for initial access

ID: b15347a4-352a-5cc4-a542-4eb89703337d

STIX ID: report--b15347a4-352a-5cc4-a542-4eb89703337d

Feed Name: Ctrl-Alt-Int3l

Threat Score
85/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Ctrl-Alt-Intel

...
...

Ctrl-Alt-Intel details a Qilin Ransomware-as-a-Service affiliate whose repeated OPSEC errors (exposed open-directories) revealed Sliver C2 configurations, Chisel/"fos" SOCKS tooling, Python reverse shells, exploit POCs for WatchGuard and Fortinet (multiple CVEs), and multiple Qilin Linux binaries capable of encrypting Linux, ESXi, and Nutanix hosts; the report enumerates C2/IP IOCs, file hashes, victim-linked ransomware samples, and shows heavy targeting of German and US perimeter appliances leading to widespread compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.