Qilin Ransomware Abuses DCSync (MS-DRSR) to Harvest AD Domain Credentials Including KRBTGT
Qilin Ransomware Abuses DCSync (MS-DRSR) to Harvest AD (TL-2026-1310), also tracked as Agenda ransomware, is a high-severity ransomware operation, first published 2026-07-14. It is attributed to Qilin (Russia) with medium confidence, affects Microsoft Active Directory Domain Services (MS-DRSR / Directory, maps to 20 MITRE ATT&CK techniques (T1003, T1020, T1021), and is covered by 9 detection rules and 23 indicators of compromise.
Key facts for TL-2026-1310
- Threat ID
- TL-2026-1310
- Also known as
- Agenda ransomware, Qilin RaaS
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-07-14
- Last reviewed
- 2026-07-14
- Attribution
- Qilin
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- manufacturing, professional-services, retail, hospitality, technology, construction, engineering, health, education, pharmacy
- Target regions
- North America, 155 - Western Europe, united kingdom, japan, united states of america
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in Qilin Ransomware Abuses DCSync (MS-DRSR) to Harvest AD
Malware and tooling: Agenda Ransomware, Qilin Rust-based variant, Qilin ransomware, Cobalt Strike, CyberDuck, Mimikatz, Mimikatz NetSync module, PSEXEC, Qilin RaaS affiliate panel
A Qilin ransomware intrusion abused the DCSync technique against the Directory Replication Service Remote Protocol (MS-DRSR) to impersonate a domain controller, harvesting the KRBTGT hash and NTLM password hashes for every account in the domain — enabling Golden Ticket forgery and domain-wide compromise ahead of encryption.
How Qilin Ransomware Abuses DCSync (MS-DRSR) to Harvest AD works
Security researcher Maurice Fielenbach identified a Qilin ransomware intrusion in which the attackers, after escalating to the built-in Administrator account, performed a DCSync operation against a target domain controller. DCSync abuses the Microsoft Directory Replication Service Remote Protocol (MS-DRSR) to simulate a domain controller requesting a normal Active Directory replication cycle; a caller holding the 'Replicating Directory Changes' and 'Replicating Directory Changes All' extended rights (commonly held by Domain Admins/Enterprise Admins, or granted via ACL misconfiguration) can retrieve the full NTDS.dit-equivalent credential material remotely, without ever touching disk on the DC, making the technique attractive because it evades traditional file-based credential-dumping detections (e.g. LSASS memory access alerts).
Windows Security Event ID 4662 ("An operation was performed on an object") logged the abuse: legitimate Azure AD Connect / Entra Connect synchronization activity from an MSOL_* service account produced a baseline of 4662 events with ObjectServer=DS and AccessMask=0x100 at 01:19, 01:21, and 01:23. At 01:25 the same event signature spiked into the hundreds, but this time the Subject account was the built-in Administrator — not a domain controller computer account and not an approved MSOL_* sync account — a clear anomaly signaling an unauthorized DCSync replication request. The abused extended rights map to the Active-Directory control-access GUIDs DS-Replication-Get-Changes-All (1131f6ad-9c07-11d1-f79f-00c04fc2dcd2) and DS-Replication-Get-Changes (1131f6aa-9c07-11d1-f79f-00c04fc2dcd2).
The operation harvested the KRBTGT account's current and historical password hashes as well as NTLM password hashes for every account in the domain. KRBTGT hash possession lets an adversary forge Kerberos Ticket Granting Tickets (Golden Tickets) that grant domain-wide, persistent, and difficult-to-revoke authentication as any user including Domain Admins — independent of subsequent password resets for ordinary accounts. Mimikatz's lsadump::dcsync module (and its NetSync companion for legacy replication) is the tool most commonly associated with weaponizing this technique, and is called out in the source reporting as the tool that popularized DCSync abuse.
Qilin (also tracked under the earlier Agenda ransomware lineage) is a Russian-speaking-attributed ransomware-as-a-service (RaaS) operation, active since August 2022, that recruits affiliates for up to 80-85% of ransom proceeds and has become the most active ransomware operation tracked in 2026 by MOXFIVE, with over 1,500 claimed victims since launch and more than 500 in 2026 alone, across Manufacturing, Professional Services, Retail/Hospitality, Technology, Construction/Engineering, Healthcare, Education, and Pharmaceutical sectors, concentrated in North America and Western Europe (notable victims include NHS-affiliated London hospitals in 2024, automotive supplier Yanfeng, UK's Big Issue, Japan's Asahi brewery in October 2025, and US-based Inotiv). Qilin's original ransomware payload (Agenda) was written in Go; the operation introduced a Rust-based variant in late 2022 explicitly to make static and dynamic analysis harder for defenders.
Across its broader campaign history (beyond this specific intrusion), Qilin affiliates gain initial access via phishing with user-executed malicious attachments, exploitation of public-facing applications (FortiGate and SAP NetWeaver vulnerabilities have been observed), exposed RDP and unprotected VPN portals, and dark-web-purchased stolen credentials. Once inside, credential-based access is the highest-frequency vector, achieved via brute forcing, Mimikatz memory-resident credential dumping, and Group Policy scripts that harvest saved Google Chrome credentials. Defense evasion includes BYOVD (Bring Your Own Vulnerable Driver) techniques for access-token manipulation, masquerading via legitimate system administration/RMM tooling to blend in, and Linux ransomware encryptors executed inside the Windows Subsystem for Linux (WSL) specifically to bypass Windows-native detections. Lateral movement to domain controllers is achieved with PsExec and RDP, with CobaltStrike deployed as a lateral tool-transfer and C2 support platform. Data staging and exfiltration is performed via CyberDuck prior to double-extortion. Ahead of and during encryption, Qilin operators delete Volume Shadow Copies and target Veeam backup infrastructure to inhibit system recovery, and clear Windows Event Logs to remove forensic evidence — then follows through with the double-extortion encryption/exfiltration for which Qilin is broadly known (the group has also added DDoS capability and a 'Call Lawyer' negotiation-panel feature as additional extortion levers in 2025-2026). The DCSync-based domain credential harvest documented in this specific intrusion sits squarely in that broader Qilin credential-access and privilege-escalation tradecraft, performed after escalation to Administrator-equivalent privilege and ahead of the encryption phase.
MITRE ATT&CK techniques used in TL-2026-1310
Credential Access
T1003 OS Credential Dumping; T1110 Brute Force; T1555 Credentials from Password Stores; T1558 Steal or Forge Kerberos Tickets
Exfiltration
T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service
Lateral Movement
T1021 Remote Services; T1550 Use Alternate Authentication Material; T1570 Lateral Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal
Privilege Escalation
Discovery
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566 Phishing
Execution
Impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery
Affected products and versions in Qilin Ransomware Abuses DCSync (MS-DRSR) to Harvest AD
- Microsoft — Active Directory Domain Services (MS-DRSR / Directory Replication Service Remote Protocol)
Vulnerable versions: all supported Active Directory Domain Services versions with misconfigured or over-broad replication ACLs
Fixed in: not a software vulnerability — mitigated via ACL hardening and credential rotation, not a patch
Remediation for Qilin Ransomware Abuses DCSync (MS-DRSR) to Harvest AD
Immediate actions
- Alert on Event ID 4662 with ObjectServer=DS and AccessMask=0x100 where the Subject account is neither a domain controller computer account nor an approved directory-sync account (e.g. MSOL_*, ADSync)
- Investigate and rotate credentials for any account observed invoking DS-Replication-Get-Changes-All (GUID 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2) or DS-Replication-Get-Changes (GUID 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2) outside expected sync windows
- Force a KRBTGT password reset (twice, per Microsoft guidance, spaced to allow ticket lifetime expiry) if unauthorized DCSync activity is confirmed to invalidate any forged Golden Tickets
- Reset NTLM/Kerberos credentials domain-wide following confirmed DCSync compromise
- Preserve and forensically review Windows Security Event Logs before any Qilin-affiliated actor can clear them (T1070.001), since log clearing is part of the group's standard pre-encryption playbook
Workarounds
- Deploy a SIEM correlation rule flagging any 4662/DS/0x100 event where Subject.Account NOT IN (domain controller computer accounts, approved sync service accounts)
Longer-term hardening
- Restrict and audit the Active Directory ACL entries granting 'Replicating Directory Changes' and 'Replicating Directory Changes All' extended rights to the minimum required set of accounts
- Remove administrative accounts from being nested in local Administrators groups across endpoints to limit lateral escalation paths to DCSync-capable privilege
- Deploy tiered administration (e.g. Microsoft ESAE / tiered AD model) so day-to-day Administrator accounts cannot reach domain-controller-equivalent replication rights
- Enable and centrally monitor Directory Service auditing (Event ID 4662) with a baseline allow-list of approved replication-capable accounts
- Patch internet-facing FortiGate and SAP NetWeaver appliances and disable/VPN-gate exposed RDP, consistent with Qilin's observed initial-access vectors
- Harden and immutably back up Veeam and other backup infrastructure against shadow-copy deletion and backup-targeted destruction
Timeline of Qilin Ransomware Abuses DCSync (MS-DRSR) to Harvest AD
- Qilin ransomware operation emerges (August 2022), tracked as the successor lineage to the Go-based Agenda ransomware.
- Qilin introduces a Rust-based ransomware variant in late 2022, explicitly to make static and dynamic malware analysis harder for defenders.
- Qilin claims a major attack on NHS-affiliated London hospitals, causing a declared critical incident in UK healthcare services.
- Qilin claims an attack on Japan's Asahi brewery, among the group's notable 2025 victims.
- The DCSync abuse technique, detection fingerprint, and Qilin ransomware attribution are publicly disclosed by cybersecuritynews.com.
- Security researcher Maurice Fielenbach identifies the anomalous Event ID 4662 pattern through Windows Security log analysis, distinguishing it from the legitimate MSOL_* sync baseline.
- NTLM password hashes for every account in the domain are harvested in the same DCSync replication request.
- The KRBTGT account's current and historical password hashes are extracted via the DCSync operation, enabling potential Golden Ticket forgery for persistent, domain-wide authentication.
- At 01:25, hundreds of Event ID 4662 DS-Replication-Get-Changes-All events fire under the built-in Administrator account rather than a domain controller or approved sync account, indicating an unauthorized DCSync replication request against MS-DRSR.
- Legitimate Azure AD Connect / Entra Connect MSOL_* synchronization activity logs a normal baseline of Event ID 4662 (ObjectServer=DS, AccessMask=0x100) replication requests at 01:19, 01:21, and 01:23.
Sources cited for Qilin Ransomware Abuses DCSync (MS-DRSR) to Harvest AD
Threats related to Qilin Ransomware Abuses DCSync (MS-DRSR) to Harvest AD
- FortiBleed Credential Theft Campaign Linked to INC and Lynx Ransomware Operations
- FortiBleed Credential-Theft Campaign Linked to INC and Lynx Ransomware Operations
- FortiBleed Credential Theft Campaign: FortigateSniffer Tool Deployed Against 430,000+ FortiGate Firewalls, Linked to INC Ransom and Lynx Ransomware
- ELECTRUM (Russian state-linked) PathWiper destructive wiper campaign targets Ukrainian ISPs and Polish CHP/energy facilities
- Black Basta Ransomware: Internal Chat Leaks Expose $100M+ RaaS Operation — Conti Successor Unmasked
- INC Ransom Affiliate Network Targeting Pacific Critical Infrastructure (AU/NZ/Tonga Joint Advisory)
Detection coverage for TL-2026-1310
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1310 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.