Yaamlabs
Ransomware

Qilin suspect extradited to Germany: what it changes

Japan handed a suspected Qilin ransomware leader to Germany after a months-long police infiltration. What is confirmed, and how to spot a Qilin intrusion.

By Yaali. October 8, 2026, 6 min read, Ransomware, Threat intel.

Cover illustration of open handcuffs beside a closed laptop in front of a glowing globe with an arc between two points, with the Yaamlabs logo and the text: Law enforcement action, Qilin suspect handed from Japan to Germany, $140M paid to the group, per NRW investigators

Japan has handed a 28-year-old Russian national suspected of being one of the leading figures in the Qilin ransomware group to German authorities. He was detained in Japan in May and transferred on Friday, October 2, after the Tokyo High Court approved the request. On October 7 the interior and justice ministers of North Rhine-Westphalia (NRW), Herbert Reul and Benjamin Limbach, announced the case in Düsseldorf and said state investigators had secretly infiltrated the group and watched it for months. His name has not been published, he has not been convicted, and he is presumed innocent.

Qilin, also tracked as Agenda, has run a ransomware-as-a-service (RaaS) operation since 2022: its core team supplies the encryptor, leak site and payment infrastructure, and affiliates break into victims for a share of each ransom. NRW investigators put its toll since 2024 at almost 4,000 organizations worldwide, about 150 of them in Germany. No servers, leak site or affiliate network have been reported seized, so Qilin was not dismantled and its affiliates can keep attacking. If you run VPN access, Windows domains or VMware hosts, its playbook below still applies.

Timeline of the case: a German logistics company attacked in September 2024, months of covert infiltration by LKA NRW and ZAC NRW under Operation Albus, the suspect detained in Japan in May 2026 on a German warrant confirmed by the Tokyo High Court, handed to Germany on October 2 and the case announced in Düsseldorf on October 7, with notes on what the arrest changes and what it does not

What is confirmed about the case

The German case starts with one intrusion. In September 2024 attackers got into the network of a logistics company in NRW, stole data, encrypted its systems and demanded Bitcoin. Japanese reporting puts the demand at about 26 million yen, which outlets convert to roughly $160,000 to $165,000. Heise, citing the Asahi Shimbun, reports the company paid to stop the data being published and that part of the money went to the suspect. TokyoReporter dates the attack to September 2022; every other report we found says 2024.

The investigation ran as "Operation Albus" under the NRW State Criminal Police Office (LKA NRW) and ZAC NRW, the state prosecution service's central cybercrime unit. According to dpa via t-online, LKA specialists got into the group's computers unnoticed, read its communications and followed its cryptocurrency payments. When investigators learned he was travelling to Japan, the Tokyo High Court confirmed the German arrest warrant beforehand so Japanese police could detain him there. Most reports place the arrest in Osaka; one German report says Tokyo.

Japan has extradition treaties only with the United States and South Korea, so this transfer went through its domestic Extradition Act and a court review. Heise calls it a rare step.

What is still unclear

His exact role differs between sources. Japanese reporting, repeated by ZDF, says he built the attack infrastructure and took a percentage of ransoms collected by different operational branches. The Asahi Shimbun, cited by heise, says he wrote code and also worked inside the German company's systems himself. German officials have not published an indictment or the exact charges.

The group-wide figures come from NRW investigators and have not been independently checked: ransom demands of almost $3 billion, of which more than $140 million was actually paid, and several hundred affiliates. Heise also notes it is unclear why Japan did not prosecute him itself, given that Qilin claimed the 2025 attack on Asahi Group Holdings that halted breweries there.

How Qilin affiliates operate

Because affiliates do the break-ins, removing one core member does not change what an intrusion looks like. Cisco Talos documented the following in its October 2025 analysis of several Qilin cases.

  • Talos could not prove a single entry point, but assessed with moderate confidence that administrator credentials leaked on the dark web were used to log in to the VPN, which in one case had no multi-factor authentication (MFA). NTLM (Windows challenge-response) authentication attempts against VPN accounts came first.
  • For discovery they ran commands such as nltest /dclist and net user /domain, then stole credentials with Mimikatz and NirSoft password tools. A batch file set the WDigest UseLogonCredential registry value to 1 so Windows keeps plaintext passwords in memory.
  • Remote access came through AnyDesk, ScreenConnect, Chrome Remote Desktop and Quick Assist. Stolen data was packed with WinRAR and uploaded with Cyberduck to Backblaze storage.
  • To blind endpoint detection and response (EDR) tools, they ran the vendor's own uninstaller, stopped services with sc and loaded a kernel driver that kills security processes.
  • One encryptor spreads across hosts through PsExec with --spread; a second encrypts network shares. Before that, event logs are cleared, shadow copies are removed with vssadmin Delete Shadows /all /quiet, and a PowerShell script turns off HA and DRS in vCenter, changes the ESXi root password and enables SSH.

In an April 2026 report on Japan, Talos found Qilin behind 22 of 134 reported ransomware incidents there in 2025, mostly starting from stolen credentials traded on Telegram and BreachForums, with encryption on average about six days after first access. The US health sector's HC3 threat profile from June 2024 lists spear phishing as an entry route and notes the group's use of remote monitoring and management (RMM) tools.

What to do

Qilin hunt checklist in five rows: VPN logins and MFA, new local admins and WDigest, unapproved remote tools and Cyberduck uploads, EDR tampering and shadow copy deletion, ESXi and vCenter changes, each with the exact log, registry value or command to look for

  1. Close the VPN route first. Require MFA for every VPN account, including service and break-glass accounts. Check whether your domains appear in infostealer or breach data, and reset any VPN credential that does. Review VPN logs for bursts of NTLM authentication attempts against one account.
  2. Watch for the setup steps. Alert on HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest\UseLogonCredential being set to 1, on accounts added to the local Administrators group (Security event 4732), and on repeated net user commands. Talos's Sigma rule fires on three net user runs within 15 minutes.
  3. Block remote tools you do not use. If ScreenConnect, AnyDesk or Cyberduck are not approved, block their installers and hashes and alert on WinRAR archives appearing on servers and on uploads from servers to Backblaze storage.
  4. Protect recovery. Alert on vssadmin delete shadows and on the Volume Shadow Copy service changed to Disabled. Keep at least one backup copy offline or immutable, with credentials that are not in Active Directory.
  5. Harden virtualization. Keep ESXi SSH disabled, restrict vCenter administration to a management network, and alert when HA or DRS is turned off or the ESXi root password changes.
  6. If you were a Qilin victim, report it to the police. In Germany the state police forces run central contact points for cybercrime (ZAC) for businesses. Reul's advice was "Don't pay. Report it." The infiltration means investigators may hold records that match your case, including payment flows.

Talos publishes its Qilin indicators and Sigma and YARA rules on the Cisco-Talos GitHub repositories; load them into your EDR and log monitoring before writing your own.

The wider lesson

Talos measured about six days on average between first access and encryption in its Japanese Qilin cases. Each step above, from a WDigest registry change to a Cyberduck upload, leaves a log entry inside that window. Those alerts only help if someone reviews them the same day, weekends included.

Our security operations team can run these hunts across your endpoints and VPN logs, and safeguarding and hardening covers the MFA, backup and ESXi settings. Open the chat and Yaali, our AI agent, will pass your question to an engineer.


Sources: SecurityWeek, heise online, The Japan Times, Nippon.com (Jiji), TokyoReporter, ZDFheute, t-online (dpa), Cisco Talos, Qilin attack methods, Cisco Talos, ransomware in Japan 2025, HHS HC3 Qilin threat profile, MITRE ATT&CK S1242.

Read next

Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.