
Qilin
Ransomware-as-a-service crew; led May 2026 victim tally and exploiting Check Point VPN zero-day for initial access.
Last refreshed: 14 June 2026 · Appears in 1 active topic
How is Qilin using a VPN zero-day to break into organisations before patches exist?
Timeline for Qilin
Held the most-active ransomware brand spot for a second consecutive month
Cybersecurity: Threats and Defences: Qilin leads ransomware a second monthGained post-compromise access to at least one organisation via the Check Point VPN zero-day
Cybersecurity: Threats and Defences: VPN zero-day open a month pre-patchMentioned in: Crews now cross-claim each rival victim
Cybersecurity: Threats and DefencesClaimed 11 victims to lead all ransomware crews in May 2026
Cybersecurity: Threats and Defences: Ransomware tempo holds at 95 in MayBackground
Qilin is a ransomware-as-a-service (RaaS) operation that emerged in 2023 and has become one of the most consistently active crews in the global ransomware ecosystem. Operating on a commercial model in which core developers lease tooling to independent affiliates who Conduct attacks and share ransom proceeds, Qilin targets organisations across healthcare, manufacturing, professional services and education. In May 2026 it led all ransomware crews with 11 claimed victims out of 95 disclosed attacks across 37 active groups, according to BlackFog's monthly tracking, with no sign of consolidation narrowing the ecosystem.
Qilin gained particular notoriety in mid-2024 when it attacked Synnovis, a pathology service provider for NHS Trusts in London, causing widespread blood-test disruption at King's College Hospital, Guy's and St Thomas' and other major NHS sites. The attack forced thousands of appointment and operation cancellations and emergency appeals for O-negative blood, establishing Qilin as a crew willing to strike healthcare critical infrastructure where care-delivery downtime accelerates ransom payment decisions. That targeting posture has continued into 2026. In June 2026, a confirmed Qilin affiliate was identified in post-compromise activity following exploitation of CVE-2026-50751, a CVSS 9.3 authentication bypass in Check Point's Remote Access VPN that had been actively abused for approximately one month before the hotfix shipped. CISA listed the flaw with an unprecedented three-day federal remediation window.
The Check Point VPN exploitation places Qilin squarely in the 2026 edge-device initial-access arc: rather than phishing or credential stuffing, the affiliate used a zero-day authentication bypass in the perimeter gateway itself, a technique that bypasses endpoint detection, MFA, and most zero-trust controls deployed behind the gateway. Bitdefender's June 2026 threat debrief noted that affiliates across RaaS programmes are increasingly cross-claiming victims, driven by a commoditised initial-access broker market and free movement between programmes. Qilin's consistent volume, willingness to attack healthcare, and adoption of VPN zero-days as an entry vector make it a persistent structural threat rather than a cyclical peak operator.