Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached, Attribution Unconfirmed
Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) (TL-2026-2192) is a high-severity ransomware operation, first published 2026-08-28. It is attributed to Qilin (Russia) with low confidence, affects Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) Standalone, maps to 16 MITRE ATT&CK techniques (T1003.001, T1018, T1021.002), and is covered by 9 detection rules and 18 indicators of compromise.
Key facts for TL-2026-2192
- Threat ID
- TL-2026-2192
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-08-28
- Last reviewed
- 2026-08-28
- Attribution
- Qilin
- Attribution confidence
- LOW
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- government administration, police - law enforcement, health, manufacturing, education, financialservices, criticalinfrastructure
- Target regions
- North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in Qilin Ransomware Group Claims Cyberattack on ATF (DOJ)
Malware and tooling: Agenda Ransomware, AgendaCrypt, Cobalt Strike, MimiKatz, SystemBC - S9001, AnyDesk, Cobalt Strike, Cyberduck, HRSword, Mimikatz, PSEXEC, ScreenConnect
The Qilin ransomware group added the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), a Department of Justice law enforcement agency, to its Tor leak site, claiming a cyberattack on a standalone system holding information on ATF investigation targets. ATF confirmed the breach, isolated the machine, and designated it a DOJ major incident; the agency's case management, laboratory, and eForms systems were not affected, no ransom is expected to be paid, and independent confirmation of Qilin's involvement is still pending.
How Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) works
On or shortly before August 26, 2026, the Qilin (aka Agenda) ransomware-as-a-service operation listed the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) on its dark-web extortion blog, claiming to have compromised agency data and threatening to publish it absent contact from a company representative. ATF confirmed a cyberattack against a single standalone computer system that held information about targets of ongoing ATF investigations. Per ATF Public Affairs Chief Tanya Roman, the system 'was not connected to any other ATF systems ... and it was quickly shut down when the breach was discovered,' and the incident 'has not impacted ATF's ability to perform its missions.' Senior DOJ officials designated the event a 'major incident' under federal breach-reporting guidance, triggering required incident-response, forensic, and notification processes; ATF states required notifications have been completed. Neither ATF nor Qilin has published sample data, IOCs, or a confirmed initial-access vector for this specific intrusion, and ATF has declined to disclose when the breach occurred or was discovered. Because the target is a federal law-enforcement agency, a ransom payment is considered unlikely, and attribution to Qilin — while consistent with the group's leak-site listing — remains formally unconfirmed pending DOJ's investigation.
Qilin is a Russian-speaking, financially motivated ransomware-as-a-service operation first identified by Trend Micro in August 2022, operating the 'Agenda' ransomware family (originally Go, rewritten in Rust by December 2022) against Windows, Linux, and VMware ESXi targets under a double-extortion model. Group-IB's March 2023 infiltration of the group's affiliate panel found affiliates retain roughly 80-85% of each ransom payment, a structure that has helped the group become one of the most prolific RaaS operations globally — the second most active ransomware brand by reported victim count in July 2026 (127 claimed attacks) — with confirmed intrusions across healthcare (Synnovis/NHS London hospitals, June 2024), manufacturing/beverage (Asahi Breweries, October 2025), education (Académie d'Amiens, 2025), and government/critical-infrastructure targets in 60+ countries. Documented Qilin intrusions typically begin with phishing, brute-forced or credential-stuffed VPN/External Remote Services access (frequently against MFA-less endpoints), or exploitation of internet-facing infrastructure such as CVE-2023-27532 in Veeam Backup & Replication to recover stored backup-infrastructure credentials; affiliates then use Mimikatz-based LSASS credential dumping, Group Policy modification to enable RDP, and legitimate remote-access/RMM tooling (AnyDesk, ScreenConnect, ConnectWise, ngrok, ligolo) alongside Cobalt Strike and SystemBC for command and control, PsExec and SMB admin shares for lateral movement, WinRAR/Cyberduck for staging and cloud exfiltration (observed targeting Backblaze), and vssadmin/backup-job destruction plus multipass AES-256/ChaCha20+RSA-4096 encryption for impact, appending a per-victim company-ID file extension and dropping a 'README-RECOVER-<id>.txt' ransom note. No such technical indicators have been published for the ATF intrusion itself; the TTP detail above reflects the actor's documented playbook from prior, independently investigated Qilin cases and is included as investigative and hunting context, not as confirmed forensic findings for this incident.
MITRE ATT&CK techniques used in TL-2026-2192
Credential Access
T1003.001 OS Credential Dumping: LSASS Memory
Discovery
T1018 Remote System Discovery; T1087.002 Account Discovery: Domain Account
Lateral Movement
T1021.002 Remote Services: SMB/Windows Admin Shares; T1570 Lateral Tool Transfer
Initial Access
T1078.002 Valid Accounts: Domain Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566.002 Phishing: Spearphishing Link
defense-impairment
T1484.001 Domain or Tenant Policy Modification: Group Policy Modification; T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs
Impact
T1489 Service Stop; T1490 Inhibit System Recovery
Collection
T1560.001 Archive Collected Data: Archive via Utility
Exfiltration
T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Affected products and versions in Qilin Ransomware Group Claims Cyberattack on ATF (DOJ)
- Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) — Standalone investigation-support system (vendor/product not publicly disclosed)
Vulnerable versions: undisclosed
Fixed in: N/A - system isolated and shut down
Remediation for Qilin Ransomware Group Claims Cyberattack on ATF (DOJ)
Patches
- Patch Veeam Backup & Replication to a version beyond 11.0.1.1261 (build P20230227) / 12.0.0.1420 (build P20230223) to remediate CVE-2023-27532 — a documented Qilin initial-access vector industry-wide, not confirmed as used against ATF
Immediate actions
- Isolate and forensically image any standalone or air-gapped system suspected of compromise before reconnecting it to any network
- Rotate credentials for any account with access to the affected system and audit for unauthorized account creation or privilege changes
- Hunt for Qilin-associated tooling (Cobalt Strike, SystemBC, Mimikatz, PsExec, unauthorized AnyDesk/ScreenConnect installs) across the broader environment even if the compromised system was reportedly isolated
- Review VPN and other externally-facing remote-access logs for brute-force or credential-stuffing patterns and enforce MFA on all external remote services
Workarounds
- Restrict RDP and Group Policy modification rights to a minimal set of privileged, monitored accounts
- Disable or tightly restrict SMB admin shares and PsExec usage outside of authorized IT administration windows
Longer-term hardening
- Segment sensitive investigation-support systems from general enterprise networks with enforced one-way or air-gapped data transfer
- Deploy EDR with behavioral detection tuned for LSASS access, Windows Event Log clearing, vssadmin/shadow-copy deletion, and mass file encryption patterns
- Maintain offline, immutable, and regularly tested backups isolated from Active Directory-joined infrastructure
- Implement application allow-listing to block unauthorized RMM tools (AnyDesk, ScreenConnect, QuickAssist) on sensitive systems
Timeline of Qilin Ransomware Group Claims Cyberattack on ATF (DOJ)
- Qilin ransomware (as 'Agenda') first identified by Trend Micro, written in Go and offered as ransomware-as-a-service.
- Qilin operators rewrite the Agenda ransomware payload in Rust to improve cross-platform support and defense evasion.
- Group-IB infiltrates a Qilin affiliate panel, confirming an 80-85% affiliate revenue share and a structured RaaS operating model.
- CVE-2023-27532 in Veeam Backup & Replication confirmed under active exploitation; later documented as a Qilin initial-access vector industry-wide.
- A UK-based pathology and diagnostic services provider is hit by Qilin ransomware, disrupting services at multiple major London hospitals.
- Qilin claims an attack on Asahi Breweries (Japan), disrupting production systems.
- Qilin reported as the second most active ransomware group globally in July 2026, with 127 claimed attacks.
- ATF appears on Qilin's Tor extortion leak site; the gang claims a cyberattack and threatens to publish stolen data absent contact.
- ATF publicly confirms the breach of a standalone, isolated investigation-support system; DOJ designates the event a 'major incident.'
- CyberScoop and other outlets publish coverage of the confirmed ATF breach and Qilin's unverified claim of responsibility.
Sources cited for Qilin Ransomware Group Claims Cyberattack on ATF (DOJ)
- ATF cyberattack: Qilin ransomware group claims responsibility
- DOJ firearms agency says hackers breached system containing investigation targets
- US firearms agency ATF confirms cyberattack – Qilin ransomware gang claims it
- ATF Hit By Ransomware Attack, DOJ Says
- Qilin Ransomware Targets U.S. Government Agency ATF
- ATF Confirms Cyberattack Claimed by Qilin Ransomware Gang
- Qilin (cybercrime group)
- Qilin, Software S1242 — MITRE ATT&CK
- Qilin Ransomware Analysis: Critical TTPs and Defense
- Qilin Threat Actor Profile: TTPs, IOCs & Attacks
- Uncovering Qilin attack methods exposed through multiple cases
- HC3 releases threat profile on Qilin ransomware targeting global healthcare, other critical sectors
- Qilin (aka Agenda) Ransomware Threat Profile — HHS HC3
- CVE-2023-27532 — NVD
More in ransomware
- Magniber Ransomware: Rewritten 2022 Variant Uses MSI Installer, AES-NI Encryption, and UAC Bypass
- Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint Defenses
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec References
- Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortion
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)
Detection coverage for TL-2026-2192
As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2192 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.