QILIN

RANSOMWARE

Confirmed CVEs (12)

Exploited by this group as confirmed by threat intelligence sources.

CVE-2025-14733 CRITICAL WatchGuard Fireware OS 9.8 CVE-2026-24423 CRITICAL SmarterTools SmarterMail 9.8 CVE-2025-40554 CRITICAL SolarWinds Web Help Desk 9.8 CVE-2026-24061 CRITICAL GNU Inetutils 9.8 CVE-2025-9242 CRITICAL WatchGuard Fireware OS 9.8 CVE-2025-59718 CRITICAL Fortinet FortiSwitchManager 9.8 CVE-2024-21762 CRITICAL Fortinet FortiProxy 9.8 CVE-2024-55591 CRITICAL Fortinet FortiOS 9.8 CVE-2026-50751 CRITICAL checkpoint Quantum Security Gateway 9.3 CVE-2026-0257 CRITICAL Palo Alto Networks Cloud NGFW 9.1 CVE-2023-27532 HIGH Veeam Backup & Replication 7.5 CVE-2026-20316 MEDIUM Cisco Secure Firewall Management Center (FMC) 5.3

Predicted CVEs (51) CORRELATION

How does prediction work?

Predicted CVEs are identified through automated correlation using multiple sources: vendor/product profiles historically targeted by the group (MITRE ATT&CK), attack chain patterns (KEV + TTPs), threat intelligence (MISP, STIX), and AI analysis. These CVEs have not been confirmed as exploited by this specific group, but have a high probability of being targets based on the actor's operational profile.

CVE-2024-3400 CRITICAL Palo Alto Networks PAN-OS predicted 10.0 CVE-2021-44228 CRITICAL Apache Software Foundation Apache Log4j2 predicted 10.0 CVE-2026-20131 CRITICAL Cisco Secure Firewall Management Center (FMC) predicted 10.0 CVE-2025-32433 CRITICAL erlang otp low 10.0 CVE-2025-55182 CRITICAL Meta react-server-dom-webpack predicted 10.0 CVE-2025-55182 CRITICAL Meta react-server-dom-webpack low 10.0 CVE-2026-20079 CRITICAL Cisco Secure Firewall Management Center (FMC) low 10.0 CVE-2021-44228 CRITICAL Apache Software Foundation Apache Log4j2 low 10.0 CVE-2026-20079 CRITICAL Cisco Secure Firewall Management Center (FMC) high 10.0 CVE-2020-2021 CRITICAL Palo Alto Networks PAN-OS predicted 10.0 CVE-2025-52691 CRITICAL SmarterTools SmarterMail predicted 10.0 CVE-2026-24423 CRITICAL SmarterTools SmarterMail predicted 9.8 CVE-2020-12812 CRITICAL Fortinet FortiOS predicted 9.8 CVE-2024-21762 CRITICAL Fortinet FortiProxy predicted 9.8 CVE-2026-23760 CRITICAL SmarterTools SmarterMail predicted 9.8 CVE-2026-1731 CRITICAL BeyondTrust Remote Support(RS) & Privileged Remote Access(PRA) low 9.8 CVE-2024-0012 CRITICAL Palo Alto Networks Cloud NGFW predicted 9.8 CVE-2022-26501 CRITICAL Veeam Backup & Replication predicted 9.8 CVE-2024-40711 CRITICAL Veeam Backup and Recovery predicted 9.8 CVE-2026-104286 CRITICAL Fortinet FortiMail predicted 9.8 CVE-2024-55591 CRITICAL Fortinet FortiOS predicted 9.8 CVE-2025-14733 CRITICAL WatchGuard Fireware OS predicted 9.8 CVE-2022-26318 CRITICAL WatchGuard Firebox and XTM Appliances predicted 9.8 CVE-2022-42475 CRITICAL Fortinet FortiProxy predicted 9.8 CVE-2026-1731 CRITICAL BeyondTrust Remote Support(RS) & Privileged Remote Access(PRA) predicted 9.8 CVE-2026-50751 CRITICAL checkpoint Quantum Security Gateway predicted 9.3 CVE-2026-0257 CRITICAL Palo Alto Networks Cloud NGFW predicted 9.1 CVE-2021-45046 CRITICAL Apache Software Foundation Apache Log4j low 9.0 CVE-2021-45046 CRITICAL Apache Software Foundation Apache Log4j predicted 9.0 CVE-2026-73570 HIGH Zimbra Collaboration low 8.9 CVE-2022-26500 HIGH Veeam Backup & Replication predicted 8.8 CVE-2021-34527 HIGH Microsoft Windows 10 Version 1809 predicted 8.8 CVE-2025-33073 HIGH Microsoft Windows 10 Version 1507 low 8.8 CVE-2024-21412 HIGH Microsoft Windows 11 version 21H2 predicted 8.1 CVE-2025-24472 HIGH Fortinet FortiProxy predicted 8.1 CVE-2023-28252 HIGH Microsoft Windows 10 Version 1809 predicted 7.8 CVE-2022-30190 HIGH Microsoft Windows 10 Version 1809 low 7.8 CVE-2021-1675 HIGH Microsoft Windows 10 Version 1809 predicted 7.8 CVE-2022-30190 HIGH Microsoft Windows 10 Version 1809 predicted 7.8 CVE-2020-0787 HIGH Microsoft Windows predicted 7.8 CVE-2024-26169 HIGH Microsoft Windows 10 Version 1809 predicted 7.8 CVE-2021-36942 HIGH Microsoft Windows Server 2019 predicted 7.5 CVE-2023-27532 HIGH Veeam Backup & Replication predicted 7.5 CVE-2023-36884 HIGH Microsoft Windows 10 Version 1809 predicted 7.5 CVE-2025-58034 HIGH Fortinet FortiWeb predicted 7.2 CVE-2024-9474 HIGH Palo Alto Networks Cloud NGFW predicted 7.2 CVE-2021-43890 HIGH Microsoft App Installer predicted 7.1 CVE-2025-68686 MEDIUM Fortinet FortiOS predicted 5.9 CVE-2022-41091 MEDIUM Microsoft Windows 10 Version 1809 predicted 5.4 CVE-2026-20316 MEDIUM Cisco Secure Firewall Management Center (FMC) high 5.3 CVE-2026-20316 MEDIUM Cisco Secure Firewall Management Center (FMC) predicted 5.3

ATT&CK Techniques (55)

T1078 Valid Accounts Initial Access T1190 Exploit Public-Facing Application Initial Access T1566 Phishing Initial Access T1566.003 Phishing: Spearphishing via Service Initial Access T1059.001 Command and Scripting Interpreter: PowerShell Execution T1059.004 Command and Scripting Interpreter: Unix Shell Execution T1569 System Services Execution T1569.002 System Services: Service Execution Execution T1037 Boot or Logon Initialization Scripts Persistence T1053 Scheduled Task/Job Persistence T1053.005 Scheduled Task/Job: Scheduled Task Persistence T1098.004 Account Manipulation: SSH Authorized Keys Persistence T1136 Create Account Persistence T1547 Boot or Logon Autostart Execution Persistence T1068 Exploitation for Privilege Escalation Privilege Escalation T1027 Obfuscated Files or Information Defense Evasion T1036.001 Masquerading: Invalid Code Signature Defense Evasion T1134.004 Access Token Manipulation: Parent PID Spoofing Defense Evasion T1211 Exploitation for Defense Evasion Defense Evasion T1480 Execution Guardrails Defense Evasion T1497.001 Virtualization/Sandbox Evasion: System Checks Defense Evasion T1553.002 Subvert Trust Controls: Code Signing Defense Evasion T1562.001 Disable or Modify Tools Defense Evasion T1562.004 Impair Defenses: Disable or Modify System Firewall Defense Evasion T1564 Hidden Artifacts Defense Evasion T1564.003 Hidden Artifacts: Hidden Window Defense Evasion T1003.001 OS Credential Dumping: LSASS Memory Credential Access T1040 Network Sniffing Credential Access T1110.002 Brute Force: Password Cracking Credential Access T1555.003 Credentials from Web Browsers Credential Access T1012 Query Registry Discovery T1046 Network Service Discovery Discovery T1082 System Information Discovery Discovery T1614 System Location Discovery Discovery T1021 Remote Services Lateral Movement T1021.001 Remote Services: Remote Desktop Protocol Lateral Movement T1021.002 Remote Services: SMB/Windows Admin Shares Lateral Movement T1021.004 Remote Services: SSH Lateral Movement T1570 Lateral Tool Transfer Lateral Movement T1560.001 Archive Collected Data: Archive via Utility Collection T1602.002 Network Device Configuration Dump Collection T1011 Exfiltration Over Other Network Medium Exfiltration T1011.001 Exfiltration Over Other Network Medium: Exfiltration Over Bluetooth Exfiltration T1048.003 Exfiltration Over Alternative Protocol: Unencrypted Non-C2 Protocol Exfiltration T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage Exfiltration T1001 Data Obfuscation Command and Control T1001.001 Data Obfuscation: Junk Data Command and Control T1071.001 Application Layer Protocol: Web Protocols Command and Control T1572 Protocol Tunneling Command and Control T1486 Data Encrypted for Impact Impact T1490 Inhibit System Recovery Impact T1561 Disk Wipe Impact T1561.001 Disk Wipe: Disk Content Wipe Impact T1587.001 Develop Capabilities: Malware Resource Development T1590.004 Gather Victim Network Information: Network Topology Reconnaissance