Threat reportRansomwareTL-2026-3004

Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany; Qilin Affiliate Exploited Check Point VPN Zero-Day CVE-2026-50751

highACTIVE

Qilin Ransomware Suspect Arrested in Japan, Extradited to (TL-2026-3004), also tracked as Qilin ransomware affiliate arrest, is a high-severity ransomware operation, first published 2026-10-07 and last reviewed 2026-10-09. It is attributed to Qilin with medium confidence, affects Check Point Security Gateway Remote Access VPN / Mobile Access (IKEv1), references 7 CVEs (CVE-2026-50751, CVE-2026-50752, CVE-2026-0257), maps to 23 MITRE ATT&CK techniques (T1003.001, T1003.003, T1021.002), and is covered by 9 detection rules and 56 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
7Referenced vulnerabilities
Techniques
23MITRE ATT&CK
Actors
1Qilin
Detection rules
9SPL · KQL · Sigma
IOCs
56Indicators of compromise

Key facts for TL-2026-3004

Threat ID
TL-2026-3004
Also known as
Qilin ransomware affiliate arrest, Osaka arrest Germany extradition
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution
Qilin
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
logistics, health, manufacturing, food-and-beverage, news - media, pharmacy, government administration, political-parties
Target regions
Europe, japan, North America, united kingdom
Detection rules
9
Indicators of compromise
56
Updates
2026-10-09 · 2 updates · revalidated 2× · latest source

Malware and tooling in Qilin Ransomware Suspect Arrested in Japan, Extradited to

Malware and tooling: AgendaCrypt, Bumblebee - S1039, EDR killer (300+ drivers), SystemBC - S9001, Rclone - S1040, Sliver - S0633, Tox

How Qilin Ransomware Suspect Arrested in Japan, Extradited to works

A 28-year-old Russian national suspected of being a core Qilin (Agenda) ransomware member was arrested in Osaka in May 2026 and handed to German authorities on 2026-10-02. He is accused of breaching a German logistics company in September 2024, encrypting its systems and extorting roughly $160,000-165,000 in cryptocurrency. Qilin remains one of the most active RaaS operations, and an affiliate was tied to exploitation of the Check Point IKEv1 VPN authentication bypass CVE-2026-50751 in May-June 2026.

Law-enforcement development. Per SecurityWeek, heise and Tokyo Reporter, a 28-year-old Russian citizen was arrested in Osaka, Japan in May 2026 and transferred to German authorities on 2 October 2026 after the Tokyo High Court approved extradition on the basis of a German arrest warrant. Japan and Germany have no bilateral extradition treaty; heise reports the transfer was possible under Japanese law on a reciprocity assurance and calls it exceptionally rare. The suspect is charged with hacking a German logistics company in September 2024, stealing and encrypting its data and extorting cryptocurrency worth over $160,000 (heise and secondary reports cite about $165,000; Tokyo Reporter cites about 26 million yen and a different year, 2022, which conflicts with the other sources and is treated as an error). Reports differ on role: SecurityWeek describes a suspected core member/affiliate; heise says he is suspected of writing Qilin's malware code and of personally operating inside the victim network. Germany's North Rhine-Westphalia cybercrime unit ZAC NRW is reported to have been involved in Qilin investigations. German agencies and prosecutors are not named in the primary article.

Qilin (also Agenda) is a ransomware-as-a-service operation active since August 2022. Encryptor variants exist in Golang and Rust, including Linux/ESXi builds, and the group runs a Tor leak site on which about 400 victims were listed in 2025. Affiliates reportedly keep 80-85% of ransom. Named victims in reporting include Synnovis (2024, pathology services for London NHS hospitals), Asahi Group (September 2025), Lee Enterprises and Inotiv (2025), Die Linke (March 2026) and the US ATF (August 2026). Resecurity ties Qilin leak-site and data-transfer infrastructure to a Hong Kong/Cyprus/Russia bulletproof-hosting network (Cat Technologies AS57678, Chang Way, Red Bytes).

Initial access: Talos reports Qilin relies mainly on stolen credentials bought or sourced from Telegram and Breach Forums, with roughly six days between compromise and encryption, an EDR-killer that targets 300+ drivers, geofencing that skips post-Soviet locales, SystemBC and Bumblebee before detonation, and local account creation. Resecurity adds spear phishing and RMM tooling. In 2026 a Qilin affiliate was also linked to exploitation of CVE-2026-50751 (CVSS 9.3), a logic flaw in Check Point Remote Access VPN and Mobile Access certificate validation that lets an unauthenticated attacker bypass user authentication over deprecated IKEv1. Exploitation began about 7 May 2026, Check Point noticed it on 4 June, and hotfixes shipped 8 June 2026 alongside CVE-2026-50752 (CVSS 7.4, adversary-in-the-middle on site-to-site VPN, no in-the-wild exploitation reported). Post-compromise, the actor pulled Linux ELF binaries, deployed Sliver C2, used Rclone for exfiltration to country-matched VPS hosts, used the Tox protocol, and targeted Linux, ESXi and Nutanix. Exploitation was limited to a few dozen organizations.

Defender takeaway: the arrest of one suspect does not confirm disruption of Qilin's RaaS; the group's affiliates, infrastructure and leak site remain active. The link between the arrested individual and CVE-2026-50751 is not established by any source. Prioritize disabling IKEv1, applying the Check Point hotfixes, reviewing VPN logs from 2026-05-07, hunting for Rclone/Sliver/SystemBC and EDR-killer drivers, and protecting hypervisors and backups.

MITRE ATT&CK techniques used in TL-2026-3004

Credential Access

T1003.001 LSASS Memory; T1003.003 NTDS; T1555.003 Credentials from Web Browsers

Lateral Movement

T1021.002 SMB/Windows Admin Shares

Exfiltration

T1048 Exfiltration Over Alternative Protocol; T1567.002 Exfiltration to Cloud Storage

Execution

T1059.001 PowerShell; T1072 Software Deployment Tools

Defense Evasion

T1070.001 Clear Windows Event Logs; T1218.011 Rundll32

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566 Phishing

Command and Control

T1105 Ingress Tool Transfer; T1219 Remote Access Tools

Persistence

T1136.001 Local Account; T1547.001 Registry Run Keys / Startup Folder

Impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1657 Financial Theft

Resource Development

T1583.003 Virtual Private Server

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Qilin Ransomware Suspect Arrested in Japan, Extradited to

  • Check Point — Security Gateway Remote Access VPN / Mobile Access (IKEv1)
    Vulnerable versions: R80.40; R81; R81.10; R81.20; R82; R82.10
    Fixed in: R82.10 Jumbo Take 19/6; R82 Jumbo Take 103/91; R81.20 Jumbo Take 141/127/120/113
  • Check Point — Spark firewalls
    Vulnerable versions: R80.20.X; R81.10.X; R82.00.X
    Fixed in: Check Point hotfix per sk185033/sk185035

Remediation for Qilin Ransomware Suspect Arrested in Japan, Extradited to

Patches

  • Check Point hotfixes for CVE-2026-50751 and CVE-2026-50752 released 2026-06-08

Immediate actions

  • Apply Check Point Jumbo Hotfix Accumulators: R82.10 Takes 19/6, R82 Takes 103/91, R81.20 Takes 141/127/120/113 (sk185033, sk185035)
  • Disable IKEv1 for Remote Access and Mobile Access VPN and enforce IKEv2 with machine-certificate authentication
  • Review VPN authentication logs from 2026-05-07 onward for logins without valid credentials
  • Block and hunt for the published attacker IPs at the perimeter and in VPN/firewall logs

Workarounds

  • Disable deprecated IKEv1 where hotfix cannot yet be applied
  • Enable Check Point IPS protections with latest signatures

Longer-term hardening

  • Deploy EDR with tamper protection and block vulnerable-driver loads used by EDR killers
  • Enforce MFA and rotate credentials exposed in infostealer or breach-forum dumps
  • Segment VPN user networks from hypervisors (ESXi, Nutanix) and keep immutable offline backups
  • Restrict and alert on outbound transfers (Rclone, SFTP) to unfamiliar VPS hosts

CVEs associated with Qilin Ransomware Suspect Arrested in Japan, Extradited to

CVE-2026-50751, CVE-2026-50752, CVE-2026-0257, CVE-2024-21762, CVE-2024-55591, CVE-2024-27198, CVE-2023-27532

Timeline of Qilin Ransomware Suspect Arrested in Japan, Extradited to

Showing the 20 most recent tracked events.

  • Qilin (Agenda) ransomware-as-a-service operation becomes active
  • Qilin attack on Synnovis (NHS pathology provider) causes widespread appointment cancellations.
  • German logistics company network breached, data stolen and encrypted; cryptocurrency worth about $160,000-165,000 extorted (month per heise/SecurityWeek)
  • Qilin reaches a reported peak of about 100 victims in June 2025, after averaging 40+ per month in 2025.
  • Asahi Group (Japan) hit by Qilin; roughly 27 GB reportedly stolen
  • Reports describe an alliance of Qilin, DragonForce and LockBit to share tools, techniques and infrastructure (sources differ on timing; ReliaQuest traced links to Q3 2025).
  • Resecurity publishes research linking Qilin to a bulletproof hosting conglomerate spanning Russia, Hong Kong, Cyprus and the UAE.
  • German party Die Linke attacked by Qilin (per heise)
  • 28-year-old Russian national suspected of Qilin involvement arrested in Osaka, Japan (May 2026; exact day not reported)
  • Earliest confirmed exploitation of Check Point VPN IKEv1 authentication bypass CVE-2026-50751, later tied to a Qilin affiliate
  • Palo Alto Networks ships fixes for GlobalProtect authentication bypass CVE-2026-0257 and notes exploit attempts.
  • CISA adds CVE-2026-0257 to the Known Exploited Vulnerabilities catalog.
  • Check Point detects suspicious VPN activity
  • Check Point discloses CVE-2026-50751 and CVE-2026-50752 and releases hotfixes after about a month of unpatched exploitation
  • Arctic Wolf reports June 2026 intrusions via CVE-2026-0257 ending in domain-wide Qilin encryption.
  • US ATF named as a Qilin victim (August 2026, per SecurityWeek)
  • Japanese authorities hand the suspect to German authorities following Tokyo High Court approval
  • SecurityWeek publishes the arrest and extradition report
  • Japanese authorities officially confirm the arrest and extradition (Japanese media first reported on 6 October).
  • BleepingComputer reports Germany arrested the alleged core Qilin member (alias 'Snake'); Qilin has listed 450+ victims since June 2026 and remains active.

Update history for TL-2026-3004

Sources cited for Qilin Ransomware Suspect Arrested in Japan, Extradited to

Detection coverage for TL-2026-3004

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3004 across Splunk SPL, Microsoft KQL and Sigma, covering 56 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
56 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats