Qilin Ransomware Abuses DCSync (MS-DRSR) to Harvest AD Domain Credentials Including KRBTGT — Threadlinqs Intelligence
As of 2026-07-14, Qilin Ransomware Abuses DCSync (MS-DRSR) to Harvest AD Domain Credentials Including KRBTGT is a high-severity ransomware threat attributed to Qilin (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-1310 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Qilin · Russia · FINANCIAL
A Qilin ransomware intrusion abused the DCSync technique against the Directory Replication Service Remote Protocol (MS-DRSR) to impersonate a domain controller, harvesting the KRBTGT hash and NTLM
Security researcher Maurice Fielenbach identified a Qilin ransomware intrusion in which the attackers, after escalating to the built-in Administrator account, performed a DCSync operation against a target domain controller. DCSync abuses the Microsoft Directory Replication Service Remote Protocol (MS-DRSR) to simulate a domain controller requesting a normal Active Directory replication cycle; a caller holding the 'Replicating Directory Changes' and 'Replicating Directory Changes All' extended rights (commonly held by Domain Admins/Enterprise Admins, or granted via ACL misconfiguration) can retrieve the full NTDS.dit-equivalent credential material remotely, without ever touching disk on the DC, making the technique attractive because it evades traditional file-based credential-dumping detections (e.g. LSASS memory access alerts).
Windows Security Event ID 4662 ("An operation was performed on an object") logged the abuse: legitimate Azure AD Connect / Entra Connect synchronization activity from an MSOL_* service account produced a baseline of 4662 events with ObjectServer=DS and AccessMask=0x100 at 01:19, 01:21, and 01:23. At 01:25 the same event signature spiked into the hundreds, but this time the Subject account was the built-in Administrator — not a domain controller computer account and not an approved MSOL_* sync account — a clear anomaly signaling an unauthorized DCSync replication request. The abused extended rights map to the Active-Directory control-access GUIDs DS-Replication-Get-Changes-All (1131f6ad-9c07-11d1-f79f-00c04fc2dcd2) and DS-Replication-Get-Changes (1131f6aa-9c07-11d1-f79f-00c04fc2dcd2).
The operation harvested the KRBTGT account's current and historical password hashes as well as NTLM password hashes for every account in the domain. KRBTGT hash possession lets an adversary forge Kerberos Ticket Granting Tickets (Golden Tickets) that grant domain-wide, persistent, and difficult-to-revoke authentication as any user including Domain Admins — independent of subsequent password resets for ordinary accounts. Mimikatz's lsadump::dcsync module (and its NetSync companion for legacy replication) is the tool most commonly associated with weaponizing this technique, and is called out in the source reporting as the tool that popularized DCSync abuse.
Qilin (also tracked under the earlier Agenda ransomware lineage) is a Russian-speaking-attributed ransomware-as-a-service (RaaS) operation, active since August 2022, that recruits affiliates for up to 80-85% of ransom proceeds and has become the most active ransomware operation tracked in 2026 by MOXFIVE, with over 1,500 claimed victims since launch and more than 500 in 2026 alone, across Manufacturing, Professional Services, Retail/Hospitality, Technology, Construction/Engineering, Healthcare, Education, and Pharmaceutical sectors, concentrated in North America and Western Europe (notable victims include NHS-affiliated London hospitals in 2024, automotive supplier Yanfeng, UK's Big Issue, Japan's Asahi brewery in October 2025, and US-based Inotiv). Qilin's original ransomware payload (Agenda) was written in Go; the operation introduced a Rust-based variant in late 2022 explicitly to make static and dynamic analysis harder for defenders.
Across its broader campaign history (beyond this specific intrusion), Qilin affiliates gain initial access via phishing with user-executed malicious attachments, exploitation of public-facing applications (FortiGate and SAP NetWeaver vulnerabilities have been observed), exposed RDP and unprotected VPN portals, and dark-web-purchased stolen credentials. Once inside, credential-based access is the highest-frequency vector, achieved via brute forcing, Mimikatz memory-resident credential dumping, and Group Policy scripts that harvest saved Google Chrome credentials. Defense evasion includes BYOVD (Bring Your Own Vulnerable Driver) techniques for access-token manipulation, masquerading via legitimate system administration/RMM tooling to bl
Target sectors: manufacturing, professional-services, retail, hospitality, technology, construction, engineering, health, education, pharmacy
Target regions: North America, 155 - Western Europe, united kingdom, japan, united states of america
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1566, T1190, T1133, T1204, T1078, T1027, T1036, T1070, T1003, T1558