Skip to content
Qilin Ransomware Claims New Australian Victims Amid Ongoing Exploitation

Qilin Ransomware Claims New Australian Victims Amid Ongoing Exploitation

First seen 28 Sep 2026, 06:32 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 07:36 UTC

The Qilin ransomware group has claimed two new victims in Australia: the Reddrop Group and the Zig Inge Group. The Reddrop Group was listed in a leak post on September 16, 2026, while the Zig Inge Group was mentioned on September 24, 2026. Details about the breaches remain unclear, and no evidence has been provided by the hackers. Qilin operates under a ransomware-as-a-service model, with affiliates receiving a share of ransom payments. Cisco recently warned of Qilin exploiting CVE-2026-20316, a vulnerability in its Secure Firewall Management Center software, to gain unauthorized access. This vulnerability was added to the CISA KEV list on July 29, 2026. Qilin has been highly active, averaging 100 victim listings each month in 2026, totaling 2,323 victims since its emergence in 2022. The group has targeted various sectors, raising concerns about its impact on critical infrastructure.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-29
CVE-2026-20316 added to CISA KEV
CISA listed CVE-2026-20316 for active exploitation, affecting Cisco's Secure Firewall Management Center.
Cyberdaily.Au
2026-09-16
Reddrop Group listed as Qilin victim
Qilin claimed the Reddrop Group as a victim in a leak post, but provided no further details.
Cyberdaily.Au
2026-09-24
Zig Inge Group listed as Qilin victim
The Zig Inge Group was claimed as a victim by Qilin in a subsequent leak post.
Cyberdaily.Au

More articles in this cluster (2)

Following this threat?

Track Nova, RAlord and Reddrop Group in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed