Skip to main content
Return to TrendAI™ 資安部落格
Cyber crimeRansomware

ATF Reports Breach After Qilin Leak Site Appearance: Insights from TrendAI™

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has reportedly appeared on the Qilin ransomware group’s leak site. Explore how Qilin operates and what organizations can learn from its past tactics.

Cyber crimeRansomware & extortionRansomware as a Service (RaaS)Cyber threatsGovernmentResearch features

Key Takeaways

  • The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has reported a breach affecting a standalone system, following its appearance on the Qilin ransomware group’s leak site.
  • Qilin, also known as Agenda, is a prolific and rapidly evolving ransomware group targeting a wide range of industries across multiple countries.
  • Proactive security measures, particularly isolating critical systems, enforcing multi-factor authentication (MFA), and monitoring for unusual activity, are essential to defend against Qilin and other evolving ransomware threats. TrendAI™ Research has been monitoring this group since its emergence and provides ongoing insights.

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a cybersecurity incident affecting a standalone system that contained sensitive information related to criminal investigations. While the ATF quickly isolated and shut down the affected system, the incident remains under investigation.

This report follows the appearance of ATF on Qilin’s leak site on Wednesday, August 26. While ATF has confirmed a breach, they have not commented on Qilin’s involvement or identified a specific culprit.

In a press release the ATF assured that the system operates independently from their enterprise network, with no signs that the ATF eForms system, or any other ATF system have been affected. The eForms system is used to electronically file various applications and registrations, making a potential breach particularly significant. Despite the agency’s assurances, senior Department of Justice (DOJ) officials have designated the incident a federal “major incident” under applicable guidelines.

What we know about the Qilin RaaS group

TrendAI™ Research has been monitoring the Qilin ransomware-as-a-service (RaaS) group, also tracked as Water Galura and historically known as Agenda, since its emergence in 2022. Qilin has gained notoriety among double-extortion ransomware operators due to its evolving tactics, a broad range of targets, and active collaboration with other ransomware groups.

Technical evolution and tactics

Qilin’s initial activities date back to July 2022, delivering Go-based ransomware with customizable builds for affiliates. The group later introduced Rust-based variants, expanding its reach to Windows, Linux, and ESXi environments. Overtime, Qilin leveraged PowerShell-based tools for lateral movement and deployment in VMware vCenter and ESXi environments, expanding its attack surface.

In 2024 and 2025, affiliates adopted additional malware loaders such as SmokeLoader and NETXLOADER, and utilized the “Bring Your Own Vulnerable Driver” (BYOVD) technique for defense evasion. These developments highlight Qilin’s flexibility and industry-agnostic approach to extortion.

Alliance and recent campaigns

Qilin has continued to demonstrate aggressive operational cadence and a focus on building alliances. On September 15, 2025, Qilin was part of an alliance of ransomware operators, including DragonForce and LockBit.

Heading into 2026, Qilin has continued its activities, with recent purported victims including a German manufacturing company and a tire company, in addition to ATF. This trend reflects Qilin’s focus on the manufacturing sector, though its targeting remains broad.

Extortion tactics and leak site activity

The group operates a Tor-based data leak site to display proof of compromise, pressuring victims to pay. Ransom demands are tailored to the victim’s perceived capacity for payment. If Qilin is indeed behind the attack on ATF, it aligns with their established attack patterns.

By 2025, Qilin had become one of the most prolific ransomware operations, disclosing nearly 1,400 disclosed victims on its leak site, a 538% year-over-year increase from 2024. Data monitored by TrendAI™ OSINT from January to August 2026 highlights the group’s broad impact across industries and geographies.

Figure 1. Top five industries by number of Qilin ransomware victim organizations based on the ransomware group’s leak site
Figure 1. Top five industries by number of Qilin ransomware victim organizations based on the ransomware group’s leak site
Figure 2. Top five countries by number of Qilin ransomware victim organizations based on the ransomware group’s leak site
Figure 2. Top five countries by number of Qilin ransomware victim organizations based on the ransomware group’s leak site

TrendAI Vision One™ Threat Intelligence Hub

TrendAI Vision One™ Threat Intelligence Hub provides the latest insights on emerging threats and threat actors, exclusive strategic reports from TrendAI™ Research, and TrendAI Vision One™ Threat Intelligence Feed in the TrendAI Vision One™ platform.

TrendAI Vision One™ customers can retrieve the indicators associated with Qilin for retrospective sweeping across their environment.

TrendAI Vision One™ XDR Data Explorer App

TrendAI Vision One™ customers can use the XDR Data Explorer App to match or hunt Qilin malicious indicators in their environments.

(malName: *QILIN* OR malName: *AGENDA*) AND eventName: MALWARE_DETECTION AND LogType: detection

More hunting queries are available for TrendAI Vision One™ customers with the Threat Intelligence Hub Entitlement enabled.

Recommendations

Qilin remains one of the most active ransomware operations today. Its ability to deploy customizable Go- and Rust-based variants across multiple platforms, leverage advanced lateral movement and evasion techniques, and form alliances with other major operators underscore the need for a proactive and layered security approach.

TrendAI™ recommends that enterprises maintain heightened vigilance against Qilin ransomware and fully utilize the resources available in the TrendAI Vision One™ platform.

The following best practices can help organizations protect themselves against Qilin and other similar ransomware attacks:

  • Secure remote access and IT management tools: Limit RMM platforms to authorized management hosts, enforce MFA, and monitor for abnormal activity such as logins outside business hours or unusual lateral movement. Restrict which applications and scripts are allowed to run on critical systems.
  • Harden backup infrastructure: Segment backup networks, apply the principle of least privilege, rotate administrative credentials, and monitor for suspicious use of administrative tools (e.g., PowerShell, SQL queries). Implement rapid token or account revocation if credentials are compromised.
  • Detect BYOVD and cross-platform threats: Monitor for unsigned or unexpected driver loads, DLL sideloading, and Linux binary execution on Windows (including via WSL). Expand detection to cover non-native payloads and ensure endpoint protection spans both Windows and Linux.
  • Enhance hybrid environment visibility: Ensure EDR/SOC monitoring includes telemetry from both Windows and Linux systems. Watch for signs of internal lateral movement and early indicators of hybrid ransomware activity.
  • Protect credentials and access tokens: Apply phishing-resistant MFA, strengthen conditional access policies, and closely monitor for abnormal use of privileged accounts or tokens.

Resources

TrendAI™ Research has been monitoring ransomware operators since before the rise of double-extortion schemes in 2020. Ransomware remains a persistent cyberthreat, evolving through resource sharing, personnel movement, and group reformation following takedowns. Among these groups is Qilin (Agenda), detailed in this in-depth report “Ransomware Spotlight: Agenda.”