Malware
AgendaCrypt
Also known as: Agenda · Qilin
Ransomware written in Go.
Indicators of Compromise 1
MITRE ATT&CK TTPs 8
T1021.001 T1047 T1059.001 T1070.001 T1082 T1485 T1558 T1566
Remote Desktop Protocol
Lateral Movement
Windows Management Instrumentation
Execution
PowerShell
Execution
Clear Windows Event Logs
Defense Evasion
System Information Discovery
Discovery
Data Destruction
Impact
Steal or Forge Kerberos Tickets
Credential Access
Phishing
Initial Access
Source Articles
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
CISA has added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including critical flaws in SonicWall SMA 1000, Sangoma Switchvox, JFrog Artifactory, Kludex Starlette, Kestra OSS, and Berri LiteLLM. Threat actors are exploiting these vulnerabilities to deploy reverse shells, execute arbitrary code, steal credentials, and deploy cryptocurrency miners. Exploitation of CVE-2026-83548 and CVE-2026-83549 in SonicWall devices has been confirmed, while CVE-2026-9586 and CVE-2026-82329 are being used to gain administrative access and conduct post-exploitation activities. Microsoft and Wiz report active exploitation of CVE-2026-42271 and CVE-2026-48710 in LiteLLM deployments, with attackers achieving remote code execution and stealing API keys, and CVE-2026-49869 in Kestra being used to establish reverse shells and deploy miners.
hacker-news ·1w ago
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Qilin ransomware actors exploited a patched PAN-OS authentication bypass vulnerability (CVE-2026-0257) to gain initial access to victim networks by establishing unauthorized SSL VPN sessions. They then performed credential harvesting, lateral movement using PsExec, and deployed ransomware payloads while clearing logs and disabling Microsoft Defender. Variability in post-exploitation tactics suggests multiple affiliates operating under a ransomware-as-a-service model.
hacker-news ·1mo ago