Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached, Attribution Unconfirmed

Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) (TL-2026-2192) is a high-severity ransomware operation, first published 2026-08-28. It is attributed to Qilin (Russia) with low confidence, affects Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) Standalone, maps to 16 MITRE ATT&CK techniques (T1003.001, T1018, T1021.002), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-2192

Threat ID
TL-2026-2192
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
2026-08-28
Last reviewed
2026-08-28
Attribution
Qilin
Attribution confidence
LOW
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
government administration, police - law enforcement, health, manufacturing, education, financialservices, criticalinfrastructure
Target regions
North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
18

Malware and tooling in Qilin Ransomware Group Claims Cyberattack on ATF (DOJ)

Malware and tooling: Agenda Ransomware, AgendaCrypt, Cobalt Strike, MimiKatz, SystemBC - S9001, AnyDesk, Cobalt Strike, Cyberduck, HRSword, Mimikatz, PSEXEC, ScreenConnect

The Qilin ransomware group added the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), a Department of Justice law enforcement agency, to its Tor leak site, claiming a cyberattack on a standalone system holding information on ATF investigation targets. ATF confirmed the breach, isolated the machine, and designated it a DOJ major incident; the agency's case management, laboratory, and eForms systems were not affected, no ransom is expected to be paid, and independent confirmation of Qilin's involvement is still pending.

How Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) works

On or shortly before August 26, 2026, the Qilin (aka Agenda) ransomware-as-a-service operation listed the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) on its dark-web extortion blog, claiming to have compromised agency data and threatening to publish it absent contact from a company representative. ATF confirmed a cyberattack against a single standalone computer system that held information about targets of ongoing ATF investigations. Per ATF Public Affairs Chief Tanya Roman, the system 'was not connected to any other ATF systems ... and it was quickly shut down when the breach was discovered,' and the incident 'has not impacted ATF's ability to perform its missions.' Senior DOJ officials designated the event a 'major incident' under federal breach-reporting guidance, triggering required incident-response, forensic, and notification processes; ATF states required notifications have been completed. Neither ATF nor Qilin has published sample data, IOCs, or a confirmed initial-access vector for this specific intrusion, and ATF has declined to disclose when the breach occurred or was discovered. Because the target is a federal law-enforcement agency, a ransom payment is considered unlikely, and attribution to Qilin — while consistent with the group's leak-site listing — remains formally unconfirmed pending DOJ's investigation.

Qilin is a Russian-speaking, financially motivated ransomware-as-a-service operation first identified by Trend Micro in August 2022, operating the 'Agenda' ransomware family (originally Go, rewritten in Rust by December 2022) against Windows, Linux, and VMware ESXi targets under a double-extortion model. Group-IB's March 2023 infiltration of the group's affiliate panel found affiliates retain roughly 80-85% of each ransom payment, a structure that has helped the group become one of the most prolific RaaS operations globally — the second most active ransomware brand by reported victim count in July 2026 (127 claimed attacks) — with confirmed intrusions across healthcare (Synnovis/NHS London hospitals, June 2024), manufacturing/beverage (Asahi Breweries, October 2025), education (Académie d'Amiens, 2025), and government/critical-infrastructure targets in 60+ countries. Documented Qilin intrusions typically begin with phishing, brute-forced or credential-stuffed VPN/External Remote Services access (frequently against MFA-less endpoints), or exploitation of internet-facing infrastructure such as CVE-2023-27532 in Veeam Backup & Replication to recover stored backup-infrastructure credentials; affiliates then use Mimikatz-based LSASS credential dumping, Group Policy modification to enable RDP, and legitimate remote-access/RMM tooling (AnyDesk, ScreenConnect, ConnectWise, ngrok, ligolo) alongside Cobalt Strike and SystemBC for command and control, PsExec and SMB admin shares for lateral movement, WinRAR/Cyberduck for staging and cloud exfiltration (observed targeting Backblaze), and vssadmin/backup-job destruction plus multipass AES-256/ChaCha20+RSA-4096 encryption for impact, appending a per-victim company-ID file extension and dropping a 'README-RECOVER-<id>.txt' ransom note. No such technical indicators have been published for the ATF intrusion itself; the TTP detail above reflects the actor's documented playbook from prior, independently investigated Qilin cases and is included as investigative and hunting context, not as confirmed forensic findings for this incident.

MITRE ATT&CK techniques used in TL-2026-2192

Credential Access

T1003.001 OS Credential Dumping: LSASS Memory

Discovery

T1018 Remote System Discovery; T1087.002 Account Discovery: Domain Account

Lateral Movement

T1021.002 Remote Services: SMB/Windows Admin Shares; T1570 Lateral Tool Transfer

Initial Access

T1078.002 Valid Accounts: Domain Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566.002 Phishing: Spearphishing Link

defense-impairment

T1484.001 Domain or Tenant Policy Modification: Group Policy Modification; T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs

Impact

T1489 Service Stop; T1490 Inhibit System Recovery

Collection

T1560.001 Archive Collected Data: Archive via Utility

Exfiltration

T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Affected products and versions in Qilin Ransomware Group Claims Cyberattack on ATF (DOJ)

  • Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) — Standalone investigation-support system (vendor/product not publicly disclosed)
    Vulnerable versions: undisclosed
    Fixed in: N/A - system isolated and shut down

Remediation for Qilin Ransomware Group Claims Cyberattack on ATF (DOJ)

Patches

  • Patch Veeam Backup & Replication to a version beyond 11.0.1.1261 (build P20230227) / 12.0.0.1420 (build P20230223) to remediate CVE-2023-27532 — a documented Qilin initial-access vector industry-wide, not confirmed as used against ATF

Immediate actions

  • Isolate and forensically image any standalone or air-gapped system suspected of compromise before reconnecting it to any network
  • Rotate credentials for any account with access to the affected system and audit for unauthorized account creation or privilege changes
  • Hunt for Qilin-associated tooling (Cobalt Strike, SystemBC, Mimikatz, PsExec, unauthorized AnyDesk/ScreenConnect installs) across the broader environment even if the compromised system was reportedly isolated
  • Review VPN and other externally-facing remote-access logs for brute-force or credential-stuffing patterns and enforce MFA on all external remote services

Workarounds

  • Restrict RDP and Group Policy modification rights to a minimal set of privileged, monitored accounts
  • Disable or tightly restrict SMB admin shares and PsExec usage outside of authorized IT administration windows

Longer-term hardening

  • Segment sensitive investigation-support systems from general enterprise networks with enforced one-way or air-gapped data transfer
  • Deploy EDR with behavioral detection tuned for LSASS access, Windows Event Log clearing, vssadmin/shadow-copy deletion, and mass file encryption patterns
  • Maintain offline, immutable, and regularly tested backups isolated from Active Directory-joined infrastructure
  • Implement application allow-listing to block unauthorized RMM tools (AnyDesk, ScreenConnect, QuickAssist) on sensitive systems

Timeline of Qilin Ransomware Group Claims Cyberattack on ATF (DOJ)

  • Qilin ransomware (as 'Agenda') first identified by Trend Micro, written in Go and offered as ransomware-as-a-service.
  • Qilin operators rewrite the Agenda ransomware payload in Rust to improve cross-platform support and defense evasion.
  • Group-IB infiltrates a Qilin affiliate panel, confirming an 80-85% affiliate revenue share and a structured RaaS operating model.
  • CVE-2023-27532 in Veeam Backup & Replication confirmed under active exploitation; later documented as a Qilin initial-access vector industry-wide.
  • A UK-based pathology and diagnostic services provider is hit by Qilin ransomware, disrupting services at multiple major London hospitals.
  • Qilin claims an attack on Asahi Breweries (Japan), disrupting production systems.
  • Qilin reported as the second most active ransomware group globally in July 2026, with 127 claimed attacks.
  • ATF appears on Qilin's Tor extortion leak site; the gang claims a cyberattack and threatens to publish stolen data absent contact.
  • ATF publicly confirms the breach of a standalone, isolated investigation-support system; DOJ designates the event a 'major incident.'
  • CyberScoop and other outlets publish coverage of the confirmed ATF breach and Qilin's unverified claim of responsibility.

Sources cited for Qilin Ransomware Group Claims Cyberattack on ATF (DOJ)

More in ransomware

Detection coverage for TL-2026-2192

As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2192 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats