Qilin (Agenda) Ransomware Hits Romanian Oil Pipeline Operator Conpet — 4,000km Critical Infrastructure, ~1TB Exfiltrated, Chrome Credential Harvesting via GPO

Qilin (Agenda) Ransomware Hits Romanian Oil Pipeline (TL-2026-0096) is a critical-severity ransomware operation, first published 2026-02-05. It is attributed to Qilin (Russia) with high confidence, maps to 26 MITRE ATT&CK techniques (T1003, T1003.001, T1005), and is covered by 9 detection rules and 28 indicators of compromise.

Key facts for TL-2026-0096

Threat ID
TL-2026-0096
Severity
CRITICAL
Status
ACTIVE
Category
RANSOMWARE
First published
2026-02-05
Last reviewed
2026-02-05
Attribution
Qilin
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
Energy, Oil and Gas, Critical Infrastructure, Healthcare, Water and Wastewater, Government
Target regions
Romania, Europe, United Kingdom, Global
Detection rules
9
Indicators of compromise
28

Malware and tooling in Qilin (Agenda) Ransomware Hits Romanian Oil Pipeline

Malware and tooling: Qilin, Cobalt Strike, Rclone - S1040

Qilin (Agenda) ransomware group claimed attack on Conpet S.A., Romania's state-owned national oil pipeline operator managing 4,000km of crude oil and petroleum product pipelines. Nearly 1TB of data exfiltrated in double-extortion campaign. Part of broader Qilin campaign targeting Romanian critical infrastructure including water utilities, energy, and hospitals. Qilin operates as a Ransomware-as-a-Service (RaaS) platform written in Rust and Go, known for cross-platform capabilities (Windows + Linux/ESXi), Cobalt Strike deployment, Chrome credential harvesting via GPO-deployed scripts, and systematic targeting of healthcare and critical infrastructure globally.

How Qilin (Agenda) Ransomware Hits Romanian Oil Pipeline works

Qilin ransomware (also tracked as Agenda) claimed responsibility for a cyberattack against Conpet S.A., Romania's national crude oil pipeline transport company headquartered in Ploiești. Conpet operates approximately 4,000km of pipeline infrastructure transporting crude oil from domestic production fields and the Constanța Black Sea port to refineries across Romania. The company is majority state-owned (58.7% by the Romanian Ministry of Energy) and listed on the Bucharest Stock Exchange (COTE). The attack resulted in nearly 1TB of data exfiltration before encryption, following Qilin's standard double-extortion model — encrypt systems and threaten to publish stolen data on their dark web leak site. This attack is part of a broader campaign targeting Romanian critical infrastructure, with Qilin and affiliated groups also targeting Romanian water utilities, energy providers, and healthcare facilities. Qilin has been active since mid-2022, initially as 'Agenda' ransomware written in Go before rebranding to Qilin and rewriting their encryptor in Rust for cross-platform targeting of Windows, Linux, and VMware ESXi. The group operates a sophisticated RaaS program offering affiliates 80-85% revenue share. Notable Qilin TTPs include: Cobalt Strike for C2 and lateral movement, GPO-deployed PowerShell scripts to harvest Chrome browser credentials across entire domains (discovered by Sophos X-Ops in August 2024), exploitation of Citrix and VPN vulnerabilities for initial access, systematic targeting of healthcare (NHS Synnovis pathology services attack in June 2024 disrupted London hospitals for weeks), and cross-platform ESXi encryption capability. Conpet's role as Romania's sole crude oil pipeline operator makes this attack a direct threat to national energy security and EU energy supply chain.

MITRE ATT&CK techniques used in TL-2026-0096

credential-access

T1003 OS Credential Dumping; T1003.001 LSASS Memory; T1555.003 Credentials from Web Browsers

collection

T1005 Data from Local System; T1074.001 Local Data Staging

lateral-movement

T1021.001 Remote Desktop Protocol; T1021.002 SMB/Windows Admin Shares; T1570 Lateral Tool Transfer

defense-evasion

T1027 Obfuscated Files or Information; T1070.004 File Deletion; T1078.002 Domain Accounts; T1484.001 Group Policy Modification

discovery

T1046 Network Service Discovery; T1082 System Information Discovery

execution

T1053 Scheduled Task/Job; T1059.001 PowerShell

command-and-control

T1071.001 Web Protocols

persistence

T1133 External Remote Services; T1547.001 Registry Run Keys / Startup Folder

initial-access

T1190 Exploit Public-Facing Application

impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1529 System Shutdown/Reboot

exfiltration

T1567.002 Exfiltration to Cloud Storage

defense-impairment

T1685 Disable or Modify Tools

Remediation for Qilin (Agenda) Ransomware Hits Romanian Oil Pipeline

Patches

  • Apply all pending Citrix/NetScaler patches (Qilin initial access vector)
  • Apply VPN gateway patches for known exploited vulnerabilities
  • Update VMware ESXi to address CVE-2024-37085 (Qilin ESXi targeting)

Immediate actions

  • Isolate affected systems and segment OT networks from IT networks to protect pipeline SCADA/ICS systems
  • Engage national CERT (CERT-RO) and Romanian National Cyber Security Directorate (DNSC) for incident response
  • Activate offline backups for critical business systems and pipeline operations control
  • Block known Qilin C2 infrastructure at perimeter firewalls
  • Force password reset for all domain accounts — Qilin harvests Chrome credentials via GPO scripts

Workarounds

  • Disable Chrome credential sync on domain-joined machines via GPO
  • Restrict PowerShell execution policy on endpoints
  • Block Cobalt Strike beacon C2 patterns at network perimeter

Longer-term hardening

  • Implement network segmentation isolating pipeline SCADA/OT from corporate IT
  • Deploy EDR with ransomware-specific detection (Cobalt Strike, credential harvesting, lateral movement)
  • Disable Chrome password saving via GPO and enforce enterprise password manager
  • Implement MFA on all VPN, Citrix, and remote access entry points — Qilin exploits these for initial access
  • Review and restrict GPO deployment capabilities to prevent attacker-deployed scripts
  • Establish dark web monitoring for exfiltrated Conpet data on Qilin leak site
  • Conduct tabletop exercise for pipeline disruption scenarios

Timeline of Qilin (Agenda) Ransomware Hits Romanian Oil Pipeline

  • Agenda ransomware first observed by Group-IB and Trend Micro. Written in Go, targeting healthcare and education sectors in Asia and Africa. Source: Group-IB, Trend Micro
  • Agenda ransomware rebrands to Qilin. Encryptor rewritten in Rust for cross-platform capability (Windows, Linux, VMware ESXi). RaaS program launched with 80-85% affiliate revenue share. Source: Trend Micro
  • Qilin attacks Synnovis, a pathology services provider for NHS hospitals in London. Attack disrupts blood testing and pathology services at King's College Hospital, Guy's and St Thomas', and other NHS trusts for weeks. Over 800 planned operations and 700 outpatient appointments cancelled. Source: NHS England
  • Sophos X-Ops discovers Qilin deploys GPO-pushed PowerShell scripts to harvest Chrome browser credentials across entire Active Directory domains before encryption. Novel technique: IPM.Note script dumps Chrome Login Data SQLite database from all domain-joined machines. Source: Sophos X-Ops
  • Qilin begins campaign targeting Romanian critical infrastructure. Multiple Romanian entities targeted including water utilities, energy providers, and hospitals. Source: Romanian cybersecurity reporting
  • Conpet activates incident response procedures. CERT-RO and Romanian National Cyber Security Directorate (DNSC) engaged. Pipeline operations continue via manual controls and OT isolation. Source: Romanian government reporting
  • Qilin claims attack on Conpet S.A., Romania's national oil pipeline operator. Nearly 1TB of data exfiltrated. 4,000km pipeline network's IT systems affected. Data posted to Qilin dark web leak site. Source: Qilin leak site, cybersecurity media
  • As of 2026-05-29, this Qilin (Agenda) RaaS threat remains ACTIVE: the actor is undisrupted and posting fresh victims (ransomware.live shows 1,882 total, latest discovered 2026-05-28, +8% MoM), ranking among 2026's top groups. The Feb 2026 Conpet pipeline incident (infostealer→WSUS→~1TB exfil; OT/SCADA spared) is contained, but no CVE/patch applies and the campaign continues.

Sources cited for Qilin (Agenda) Ransomware Hits Romanian Oil Pipeline

Threats related to Qilin (Agenda) Ransomware Hits Romanian Oil Pipeline

Detection coverage for TL-2026-0096

As of 2026-02-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0096 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats