CiberLATAMbywhalemate

Qilin and Securotrop in Q2 2026

Between May and June 2026, multiple trackers and intelligence reports linked Qilin to active ransomware campaigns that escalated around a critical Check

Whalemate Labs · AI-assisted researchPublished:39 min read

As of May 7, 2026, Check Point had detected active exploitation of CVE-2026-50751, a critical authentication bypass in VPN deployments using legacy IKEv1, which allowed unauthenticated attackers to establish remote sessions without valid credentials. Activity intensified in early June and triggered a coordinated emergency response, including vendor patches, CISA warnings, and the addition of the flaw to the KEV catalog. Multiple technical and tracking sources, including Rapid7, SecurityWeek, The Register, and Check Point Research, agreed that at least one incident in the campaign was tied to a Qilin ransomware affiliate.

Executive summary

Cronología Qilin y Check Point Línea de tiempo con hitos entre mayo y julio de 2026 7 MayStartexploitation 4 JunSuspiciousactivity 8 JunHotfix andanalysis 9 JunCISA KEV 15 JunCheck Pointreport 18-24 JunATCOM and Chile 1 JulRegionalcoverage
Timeline of the Qilin campaign and Check Point exposure — Consolidated timeline between May and July 2026, with milestones for exploitation, patch release, attribution to Qilin, and regional claims in Latin America.
By early June 2026, the combination of [a critical Check Point vulnerability](/en/investigations/cve-2024-24919-check-point) and sustained Qilin activity had moved from technical concern to active operations. CVE-2026-50751, an authentication bypass in Check Point Remote Access VPN, Mobile Access, and Spark firewalls that affected only legacy IKEv1 deployments without machine-certificate enforcement, was actively exploited in real-world attacks starting on May 7, according to the timeline reconstructed by Check Point. On June 8 and 9, the situation escalated with vendor notices, publication of indicators of compromise, Rapid7 alerts, specialized media coverage, and CISA's order for FCEB agencies to patch by June 11. The key issue was not simply the bug itself, but that it let an unauthenticated attacker establish a valid VPN session and enter the perimeter without brute force or stolen credentials.

Attribution to Qilin is supported at several confidence levels. Check Point, Rapid7, and SecurityWeek agree that at least one incident observed in the campaign was linked to Qilin ransomware activity, with medium confidence from the vendor and independent technical corroboration of the findings. The Register also offered an operational estimate of limited impact, a few dozen organizations worldwide by early June, although that does not reduce the severity of the flaw for environments with exposed VPNs and legacy settings. In parallel, Check Point observed attempts to download ELF payloads from attacker-controlled servers, a sign that initial VPN access opened the door to Linux payloads and post-compromise stages later used to tie the activity back to Qilin.

Behind that, Red Piranha strengthened the view of Securotrop as an affiliated brand inside the Qilin ecosystem. It does not present it as an independent family, but as a group established in early 2025 that operates within Qilin's affiliate network, keeps its own public identity through a Data Leak Site, and claims to use Qilin software without changing the original code. Red Piranha also noted infrastructure overlap between the two brands, confirmed by multiple independent tracking sources, and said Securotrop's onion address also appears as a Qilin extortion link in a group tracker. That overlap matters when reading public claims in Latin America, because the available material points to a shared extortion and leak ecosystem rather than fully separate campaigns.

Chile has the most visible regional pressure. Between June 18 and 19, multiple posts appeared about ATCOM Outsourcing, a Chilean staffing and outsourcing company, described by some sources as a presumed Qilin victim and by others as a dark web claim, with references to system encryption and operational disruption. No single item confirms the incident, but together they show convergence among trackers, researchers, and specialized users around the same target. In addition, ransomware.live's map for Chile, updated at the end of June, recorded 74 victims and listed Comercial Echave Turri Limitada as attributed to Qilin, while the "Chile under RaaS pressure" analysis added Valbifrut, Ducasse, Conectados Chile, Graneles, and Noi Hotels within a broader double-extortion view.

The regional picture does not stop with Chile. For Argentina, the available material mentions Axionlog in a third-party intelligence report and, at the technical level, the country's inclusion in Check Point Research's report on the CVE-2026-50751 campaign. For Bolivia, Scrutex recorded Qilin victims within a global total of 192 claims between June 8 and 14, with 25 group posts on its leak site. For Peru, Red Piranha spoke of isolated incidents and Qilin's operational footprint through Securotrop, although it did not assign specific groups to those local cases. Colombia appears mainly in alerts from Asobancaria's Financial CSIRT that were discussed by several intelligence actors, and the United States serves as the regulatory center from which CISA pushed urgent remediation. What connects all of this is the same operating pattern, with initial access through legacy VPN, post-exploitation focused on Linux and Windows, and an extortion economy distributed across Qilin and its brands or affiliates.

Context and background

Qilin appears in the material as a ransomware-as-a-service actor with sustained operational presence and an affiliate structure that lets it keep campaign volume without centralizing every intrusion. Red Piranha assigned it 11.03 percent of the ransomware activity observed in its sample from June 2 to 8, 2026, and BleepingComputer, citing the tracking ecosystem, noted that the group maintains a dark web leak site with more than 400 claimed victims since August 2022. That figure should not be read as a universal count, but as an indicator of persistence, affiliate recruitment capacity, and operational continuity.

Flujo de ataque Qilin Secuencia de acceso inicial, post-explotación y extorsión Check Point VPN CVE-2026-50751authentication bypass Remote sessionwithout credentials Post-exploitationELF, Linux, logs Ransomwaredouble extortion Public evidence describes the initial access, part of the post-exploitation, and the link to Qilin, but not a complete forensic case file per victim.
Observed attack chain in the campaign — Synthetic flow from initial access via legacy VPN to post-exploitation and double extortion.
The material also places Securotrop as an affiliate offshoot within the Qilin ecosystem. The importance of that point is not semantic. If Securotrop is in fact a public brand that reuses Qilin software without modifying it, with overlapping infrastructure and a Data Leak Site whose onion address also serves as a Qilin extortion link in trackers, then campaigns attributed to both cannot be treated as separate islands. There is a commercial layer and a technical layer that intersect. The first is ransomware brand management. The second is inherited and shared operational capability.

The CVE-2026-50751 campaign sits inside that context. Check Point describes it as an authentication bypass in VPN and Mobile Access products when IKEv1 is used, an outdated protocol that remained enabled in legacy deployments. The combination of inherited remote clients, no machine-certificate requirement, and a flawed logic check allowed unauthenticated attackers to establish a valid VPN session. That changes the exposure profile for organizations that rely on a single VPN perimeter for remote access, administration, and third-party connectivity. This was not a phishing flaw or credential theft through social engineering, but a direct path into the network.

The coordinated response confirms the sense of systemic risk. CISA not only added the issue to the KEV catalog, it also ordered FCEB agencies to patch within a short window. Check Point recommended disabling IKEv1, requiring machine certificates, and reviewing logs for unauthenticated connections. The emergence of CVE-2026-50752 as a related issue, which enables man-in-the-middle attacks in site-to-site tunnels under IKEv1, reinforces the conclusion that prolonged use of that legacy protocol left a doubly exposed surface, through remote access and through trust between sites.

In Latin America, the material does not show a single mass incident, but rather a series of scattered signals, some corroborated and others only claimed. Chile draws the most attention because of the volume of public mentions, ATCOM's presence, and the overlap with victim lists in ransomware.live and the LinkedIn Pulse analysis on the country. Argentina, Colombia, Bolivia, and Peru appear more as countries touched by Qilin's spillover and by trackers than as scenes with a complete incident dossier. That distinction matters to avoid over-attribution. Working with this material requires separating technical confirmation, leak tracking, and claims from actors or third parties.

Key facts table

Date Fact Source Confidence
2026-05-07 Check Point places the start of CVE-2026-50751 exploitation The Register Confirmed
2026-06-04 Check Point detects suspicious activity and Red Piranha cites ANY.RUN analysis showing shadow copy deletion by Qilin Check Point, Red Piranha Confirmed
2026-06-08 Check Point publishes a hotfix for CVE-2026-50751 and Rapid7 details the flaw Check Point, Rapid7 Confirmed
2026-06-08 CISA adds CVE-2026-50751 to the KEV catalog BleepingComputer, CybersecurityDive Confirmed
2026-06-08 Check Point observes ELF payload retrieval and associates it with medium confidence to Qilin Check Point, Rapid7 Attributed by source as uncertain
2026-06-08 Red Piranha says Qilin represented 11.03 percent of its weekly sample Red Piranha Confirmed
2026-06-08 Red Piranha describes Securotrop as a Qilin affiliate with its own DLS Red Piranha Confirmed
2026-06-09 CISA orders FCEB agencies to patch by June 11 BleepingComputer Confirmed
2026-06-09 SecurityWeek confirms at least one attack tied to a Qilin affiliate SecurityWeek Confirmed
2026-06-11 DeXpose reports a supposed Qilin attack on Axionlog in Argentina DeXpose Attributed by source as uncertain
2026-06-14 Scrutex reports 192 claims and 25 Qilin posts in the week Scrutex Confirmed
2026-06-15 Check Point Research publishes its threat intelligence report Check Point Research Confirmed
2026-06-18 FalconFeeds warns of a supposed Qilin attack on ATCOM Chile FalconFeeds.io Attributed by source as uncertain
2026-06-19 Multiple LinkedIn and X posts amplify the ATCOM case Cyber News Live, Undercode News, Hendry Rahardja, chum1ng0 Attributed by source as uncertain
2026-06-24 LinkedIn Pulse links Qilin to victims in Chile, including Graneles and Noi Hotels Security researcher (LinkedIn Pulse) Confirmed
2026-06-26 Ransomware.live shows 74 victims for Chile and lists Comercial Echave Turri Limitada as a Qilin victim Ransomware.live Confirmed
2026-07-01 CM-Alliance summarizes the global campaign and attributes it to Qilin in the context of vulnerable VPNs CM-Alliance Confirmed

Operation timeline

Date Event Actor/vector Verified source
2026-05-07 Estimated start of active exploitation CVE-2026-50751 in Check Point VPN with IKEv1 The Register
2026-06-04 Suspicious activity is detected and post-exploitation artifacts are observed Qilin-linked actors, ELF retrieval Check Point, Rapid7
2026-06-08 Hotfix, technical alerts, and real-world exploitation reports are published Check Point, Rapid7, SecurityWeek Check Point, Rapid7, SecurityWeek
2026-06-08 CISA adds the flaw to KEV Priority remediation for federal agencies BleepingComputer, CybersecurityDive
2026-06-08 Securotrop is documented as a Qilin affiliate Shared infrastructure, own DLS Red Piranha
2026-06-09 CISA sets a patch deadline for FCEB agencies Exploitation by Qilin affiliates BleepingComputer
2026-06-10 Red Piranha publicly expands its view of Securotrop Affiliate brand inside Qilin Red Piranha
2026-06-11 Reports appear of a supposed case in Argentina Qilin, no public IOC confirmation DeXpose
2026-06-14 Scrutex records a weekly spike in Qilin claims Leak site, 25 posts Scrutex
2026-06-15 Check Point Research publishes a threat report focused on the campaign CVE-2026-50751, multiple organizations and countries Check Point Research
2026-06-18 ATCOM case enters public circulation Qilin, "reportedly" claim FalconFeeds.io
2026-06-19 ATCOM posts multiply on social media Qilin, dark web claims Cyber News Live, Undercode News, Hendry Rahardja, chum1ng0
2026-06-24 LinkedIn Pulse adds Chilean victims linked to Qilin RaaS double extortion Security researcher (LinkedIn Pulse)
2026-06-26 Ransomware.live updates the Chile map Public victim tracking Ransomware.live
2026-07-01 CM-Alliance consolidates the view of the campaign as a June event Qilin, vulnerable VPNs CM-Alliance

Attack chain and TTPs

Matriz TTPs Qilin Tabla visual de técnicas y soporte TTPDescriptionSupport CVE-2026-50751Authentication bypass in Check Point VPNConfirmed ELF post-exploitationLinux binary download after initial accessConfirmed Qilin/Linux linkageOverlap with Qilin binaries for LinuxAttributed by source as uncertain vssadminShadow copy deletion in WindowsConfirmed Securotrop DLSAffiliate brand with shared infrastructureConfirmed
Technical Matrix of TTPs and Support Level — Summary classification of confirmed and attributed techniques based on the consolidated research corpus.
The material supports a partial attack chain, not a complete playbook. The verified starting point is exploitation of CVE-2026-50751 on Check Point devices with legacy IKEv1 configurations. That technical condition matters because it narrows the potential victim set to organizations that kept legacy remote access, did not require machine certificates, and exposed VPN gateways to the internet. Once inside, the remote session was established without valid credentials, avoiding the usual stage of password theft or brute forcing.

After initial access, Check Point observed attempts to download ELF payloads from attacker-controlled infrastructure. That suggests a post-exploitation phase aimed at Linux systems. The reference does not identify the downloaded binary or its exact purpose, but it does support the view that the attacker did not stop at obtaining an interactive session. There was intent to execute or stage additional payloads from owned servers.

Flujo de ataque Qilin Secuencia de acceso inicial, post-explotación y extorsión Check Point VPN CVE-2026-50751authentication bypass Remote sessionno credentials Post-exploitationELF, Linux, logs Ransomwaredouble extortion Public evidence describes the initial access, part of the post-exploitation, and the link to Qilin, but not a complete victim-by-victim forensic record.
Operational chain observed in the campaign — Synthetic flow from initial access via legacy VPN to post-exploitation and double extortion.
Red Piranha adds a useful piece for understanding Qilin behavior. In a sample analyzed in ANY.RUN on June 4, 2026, the ransomware runs `vssadmin delete shadows /all /quiet` to remove shadow copies in Windows and creates logs under `QLOG\ThreadId(1).LOG`. That combination is consistent with classic ransomware goals, where shadow-copy deletion hinders recovery and the internal log helps with execution tracking or operational debugging. The finding does not by itself prove authorship of the incident at ATCOM or in other local victims, but it does fit Qilin's operational profile.
Cronología Qilin y Check Point Línea de tiempo con hitos entre mayo y julio de 2026 7 MayStartexploitation 4 JunSuspiciousactivity 8 JunHotfix andanalysis 9 JunCISA KEV 15 JunCheck Pointreport 18-24 JunATCOM and Chile 1 JulRegionalcoverage
Timeline of the Qilin campaign and Check Point exposure — Consolidated timeline from May through July 2026, with milestones for exploitation, patch releases, attribution to Qilin, and regional claims in Latin America.
Securotrop's attribution deserves its own reading. Red Piranha describes it as a group established in early 2025 that operates within Qilin's affiliate network, maintains its own Data Leak Site, and uses Qilin software without altering the original code. That last line, reported as the group's own public statement, is a sign of an affiliate brand. This is not a different malware family, but an operational label that shares tooling and, likely, extortion infrastructure. The overlap between the onion addresses of Securotrop's DLS and a Qilin extortion link, confirmed by independent trackers, reinforces the relationship.

TTPs observed or attributed

TTP Description Source
CVE-2026-50751 Authentication bypass in Check Point VPN with legacy IKEv1 Check Point, Rapid7
Unauthenticated access Establishment of a valid VPN session without credentials Check Point
Linux post-exploitation Download of ELF payloads from actor-controlled infrastructure Rapid7, Check Point
Shadow copy deletion vssadmin delete shadows /all /quiet to hinder recovery Red Piranha
Internal logging Creation of QLOG\ThreadId(1).LOG during execution Red Piranha
Double extortion Encryption plus threat of data publication LinkedIn Pulse, Red Piranha, public trackers
Shared infrastructure Overlap between Securotrop and Qilin Red Piranha
Own Data Leak Site Securotrop's independent public identity Red Piranha

Regional impact

Regional overview

Mapa regional de Qilin Barras cualitativas por visibilidad pública y confirmación en el corpus Visibility in the corpus ChileHigh United StatesHigh ArgentinaMedium PeruMedium ColombiaMedium BoliviaLow
Regional map of pressure and public visibility — Qualitative distribution of information in the corpus by country and by level of verification available.
The regional material shows distributed and uneven Qilin activity, not a single homogeneous campaign across Latin America. Chile accounts for the largest share of public references, both because of the ATCOM discussion and because of the mapping of other victims attributed to the group. Argentina appears in third-party reports and in coverage of the VPN campaign, but without enough public traceability to reconstruct an individual case with IOCs. Bolivia appears in Scrutex's weekly reporting as one of the countries with claimed Qilin victims during the June 8 to 14 period. Peru shows isolated cases and aggregate statistics, and Colombia is more closely tied to sector alerts from the financial system than to a full intrusion dossier. Brazil and Paraguay do not add further verifiable facts in the material provided.

Argentina

In Argentina, the useful material is brief but consistent on one point. On June 11, DeXpose said Qilin had supposedly attacked Axionlog, described as a leading logistics services provider in the country, and warned about possible exposure of sensitive data. That claim remains source-attributed and not independently confirmed, because the material provides no IOCs, vectors, or technical evidence to support it on its own.

The second relevant element is broader and comes from Check Point Research, which in its June 15 report included references to organizations affected in several countries, including Argentina, within the CVE-2026-50751 campaign. The available material does not name other Argentine victims tied to that exploitation, but the country's inclusion confirms that the campaign had regional reach and was not limited to the United States or Europe.

The CM-Alliance article published on July 1 strengthens that geographic reading by placing Argentina within its coverage of the biggest cyberattacks in June and summarizing the link between the VPN zero-day and Qilin. It adds no new victim or vector details, but it does show the campaign remained relevant at the end of the month.

Chile

Chile is the country with the highest density of facts in the corpus. On June 18, FalconFeeds.io reported that ATCOM Chile, a staffing and outsourcing company based in the country, had allegedly been victimized by Qilin. The next day, Cyber News Live, Undercode News, Hendry Rahardja, and the user chum1ng0 repeated similar versions, some based on the group's own claims and others on dark web references or an alleged leak listing. The pattern is clear, but the evidence remains open-source attribution rather than full technical confirmation.

ATCOM matters because of the type of company it is, not just because of the name. The sources describe it as an outsourcing, staffing, and recruitment player that places workers across the country. In that context, a ransomware incident affects personal data, operational continuity, and third-party services for multiple clients. However, the available material does not include IOCs, malware samples, or a forensic note that would allow anything beyond the public claim. That is why the piece should keep the alleged or presumed label when referring to ATCOM.

Cronología Qilin y Check Point Línea de tiempo con hitos entre mayo y julio de 2026 7 MayStartexploitation 4 JunSuspiciousactivity 8 JunHotfix andanalysis 9 JunCISA KEV 15 JunCheck Pointreport 18-24 JunATCOM and Chile 1 JulRegionalcoverage
Qilin Campaign Timeline and Check Point Exposure — Consolidated timeline between May and July 2026, with milestones for exploitation, patch release, attribution to Qilin, and regional claims in Latin America.
The case becomes more interesting when cross-referenced with ransomware.live's map for Chile and the "Chile under RaaS pressure" analysis. The map, updated at the end of June, recorded 74 victims in the country and listed Comercial Echave Turri Limitada as attributed to Qilin with a discovery date of 2026-05-17. The same page includes other Chilean organizations associated with groups such as Qilin, LockBit5, and Anubis, including Noi Hotels, Graneles de Chile, and Copec S.A., although the public detail is not enough to verify each association.

The LinkedIn Pulse article from June 24 adds another layer by characterizing Qilin as a financially motivated double-extortion ransomware-as-a-service group and, in the Chilean context, listing Valbifrut, Ducasse, Conectados Chile, Graneles, and Noi Hotels as victims linked to Qilin. That piece also says the pressure on the Chilean ecosystem follows the classic double-extortion model, with encryption and threat of data publication. The lack of case-specific TTPs means that relationship has to be treated as a higher-level analytical frame, not as individual confirmation of each attack.

The infrastructure link between Qilin and Securotrop also matters in Chile because it helps explain the reuse of brands and extortion machinery. If Securotrop operates as an affiliate within Qilin, then the fact that different sources mention Qilin or a claim on its leak site does not necessarily contradict the same operating chain. It may be the same criminal economy, presented under different public brands depending on the affiliate or the phase of the extortion cycle.

Paraguay

No additional verifiable facts are available in the supplied material for Paraguay. The absence of records should not be read as the absence of activity, only as a lack of documentary support in the corpus provided.

Bolivia

Scrutex included Bolivia in a group of 30 countries that had between one and three claimed victims during the June 8 to 14, 2026 week. In that same period, Qilin led the activity with 25 posts on its leak site and 45 affected countries, according to the report's tally. The data is useful because it shows regional reach and confirms that Bolivia was not outside the group's weekly claim cycle.

Mapa regional de Qilin Barras cualitativas por visibilidad pública y confirmación en el corpus Visibility in the corpus ChileHigh United StatesHigh ArgentinaMedium PeruMedium ColombiaMedium BoliviaLow
Regional map of pressure and public visibility — Qualitative distribution of information in the corpus by country and by level of verification available.
Scrutex adds a methodological nuance: researchers at PRODAFT and ReliaQuest linked the global rise in Qilin activity to continued exploitation of a vulnerability in VPN devices. The report does not tie that technique to Bolivian victims in particular, nor does it identify specific incidents in the country. The most cautious reading is therefore that Bolivia appeared in Qilin's public claims during the same week the VPN campaign was in full circulation, with no further precision.

Peru

Red Piranha's June 2 to 8 report noted isolated ransomware incidents with victims in Peru, equal to roughly 0.74 percent of global cases in that period. The document does not specify which groups were involved, so the data has to be treated as statistical context rather than a Qilin attribution.

Even so, the same report helps place Securotrop within the Qilin ecosystem and extend the technical reading to the regional environment. Red Piranha describes Securotrop as an affiliated group, with its own DLS and the original Qilin software, and says the onion address of Securotrop's leak site also appears as a Qilin extortion link in a public tracker. In other words, the operational environment affecting Peru is not limited to one name, but to a set of connected brands and leak sites.

Red Piranha also contributes a useful technical piece on Qilin's behavior. In a sample analysis dated June 4, it documented the execution of vssadmin delete shadows /all /quiet and the creation of QLOG\ThreadId(1).LOG log files. That evidence does not point to a specific Peruvian victim, but it does show the kind of execution one can expect in an intrusion attributed to the Qilin family or its affiliate network.

Colombia

Colombia appears in the material from a sector and shared-intelligence angle. Ransomware.live maintains a country page where it tracks alleged victims and discovery dates, including activity attributed to Qilin. The corpus does not provide the detail of each Colombian entry, so the mention functions more as a public tracking signal than as a complete technical case file.

The other information stream comes from the financial sector. Chrysalis Ciberseguridad reported on June 9 that the Financial CSIRT of Asobancaria in Colombia shared information about a "cyber risk" affecting a critical vendor in the country's financial sector. A June 16 post by Alberto Flores Merino reinforced that reference and framed it with hashtags such as #ransomware, #vpn, #checkpoint, #cisa, and #zerotrust. The material does not explicitly say the case is Qilin, but the contextual link to the Check Point campaign and the regulatory urgency is clear.

That pattern matters operationally. Alerts from the Colombian financial ecosystem appeared in the same time window in which CISA and Check Point were publishing warnings about CVE-2026-50751. Although the material does not let us directly tie the Colombian case to a confirmed Qilin incident, it does suggest that exposure of critical vendors to legacy IKEv1 VPNs was a shared regional problem.

Brazil

No additional verifiable facts are available in the supplied material for Brazil. This subsection is left explicit to respect the required structure and avoid unsupported inference.

United States

The United States functions in this corpus as the regulatory and technical observation center. On June 9, CISA ordered FCEB agencies to patch CVE-2026-50751 by June 11, after confirming its exploitation in zero-day attacks by Qilin affiliates. That order was based on the flaw's inclusion in the KEV catalog, which accelerated priority remediation in regulated environments.

The CISA notice cited by BleepingComputer explained that the bug let remote unauthenticated attackers bypass authentication and establish a remote access VPN connection on Check Point Mobile Access/SSL VPN, Remote Access VPN, or Spark devices. Rapid7 added that the flaw was limited to legacy IKEv1 deployments without machine certificates, and that the operational exposure had been limited to a few dozen organizations by early June.

Cronología Qilin y Check Point Línea de tiempo con hitos entre mayo y julio de 2026 7 MayStartexploitation 4 JunSuspiciousactivity 8 JunHotfix andanalysis 9 JunCISA KEV 15 JunCheck Pointreport 18-24 JunATCOM and Chile 1 JulRegionalcoverage
Qilin Campaign Timeline and Check Point Exposure — Consolidated timeline between May and July 2026, with milestones for exploitation, patch release, attribution to Qilin, and regional claims in Latin America.
SecurityWeek complemented that picture by reporting that at least one attack had been confirmed as carried out by a Qilin affiliate and that Check Point assessed the link to that family with medium confidence. BleepingComputer and CybersecurityDive highlighted the coordinated response, which included emergency patches, log review, and disabling IKEv1. The Register, for its part, placed the timeline at an initial stage on May 7 and a visible increase in early June.

The material also mentions Securotrop in an unconfirmed U.S. case. Hendry Rahardja posted about Charisma Media, a U.S.-based organization, as a possible Securotrop victim, with 808 GB of claimed data. That case remains unconfirmed and should not be mixed with the confirmed facts tied to the Check Point campaign.

Technical indicators

Type Value Source
CVE CVE-2026-50751 Rapid7, Check Point, CISA
CVE CVE-2026-50752 BleepingComputer
Detection name Ransom:Win32/QilinCrypt!MSR Red Piranha
MD5 hash 51d39aa39478beeac94f2d12f682ecce Check Point
Command vssadmin delete shadows /all /quiet Red Piranha
Log file QLOG\ThreadId(1).LOG Red Piranha
VPS infrastructure Kaupo Cloud HK Check Point
VPS infrastructure Shock Hosting Check Point
VPS infrastructure Vultr Holdings Check Point

No additional operational domains, full onion addresses, concrete IPs, or binary samples with enough hash data were identified in the supplied material to extend the IOC list beyond what the sources already cited. The corpus does mention that Check Point published IP blocks associated with the campaign, but the consolidated text does not include the full values, so they should not be invented.

Analysis for security teams

The first operational reading is straightforward. If an organization still has Check Point Remote Access VPN or Mobile Access with IKEv1 enabled and no machine-certificate requirement, the exposure is not theoretical. The material shows real-world exploitation, association with ransomware activity, and an emergency response from the defense ecosystem. The priority should be to review whether legacy deployments remain, confirm patching, disable IKEv1, and verify that remote clients do not depend on that protocol.

The second reading is about detection. Check Point recommended reviewing logs for unauthenticated VPN connections. On top of that, teams should look for post-exploitation patterns, especially attempts to download ELF payloads from actor-controlled infrastructure. In Linux or mixed environments, that detail can mark the shift from initial access to remote execution. In Windows environments, shadow-copy deletion through vssadmin delete shadows /all /quiet remains a useful sign of later ransomware activity.

The third reading is about prioritization. The Register and Rapid7 indicate that the campaign affected only a few dozen organizations globally, but that does not reduce the risk for those that fell within the vulnerable surface. The target profile, exposed VPNs and single perimeter controls, is typical of ransomware affiliates. That means the exposure does not just compromise remote access, it also opens a path for exfiltration, lateral movement, and double-extortion pressure.

Flujo de ataque Qilin Secuencia de acceso inicial, post-explotación y extorsión Check Point VPN CVE-2026-50751authentication bypass Remote sessionno credentials Post-exploitationELF, Linux, logs Ransomwaredouble extortion Public evidence describes the initial access, part of post-exploitation, and the link to Qilin, but not a full victim-by-victim forensic record.
Operational chain observed in the campaign — Synthetic flow from initial access via legacy VPN to post-exploitation and double extortion.
For teams monitoring Latin America, the Chile case should be read on two levels. One is the level of publicly claimed victims, where ATCOM appears as a presumed target and other names, such as Graneles de Chile and Noi Hotels, show up in trackers or third-party analyses. The other is the infrastructure and brand layer, where Securotrop operates as a Qilin affiliate with its own Data Leak Site. If an organization sees mentions of Qilin, Securotrop, or leak-site claims, it should assume the phenomenon may be sharing capabilities, not competing with itself.

In regulated sectors, especially financial services and critical infrastructure, the presence of CSIRT alerts and references to VPN, Check Point, and CISA should trigger priority review of perimeter controls. The Colombian signals show that this pressure has already reached critical vendors. The main risk is not only encryption, but persistent initial access before detection, with the possibility of prior exfiltration and later extortion.

Material limitations

The available corpus mixes high-confidence sources with publications explicitly marked as unconfirmed, especially in the ATCOM case and in several claims spread through social media and aggregation sites. That requires distinguishing between a technically supported incident and a public claim repeated by third parties. In particular, ATCOM Chile is cited as a presumed Qilin victim in FalconFeeds.io, Cyber News Live, Undercode News, Hendry Rahardja, and chum1ng0, but the material does not include independent validation that would close attribution.

There is also no uniform package of IOCs, binaries, or forensic telemetry for Chile, Argentina, Bolivia, Peru, or Colombia. The report rests on threat intelligence sources, public trackers, and analyst posts. That is enough to map trends, but not to rebuild a full forensic timeline for each victim. In several cases, the level of detail is reduced to organization names and supposed leak-site claims.

On Securotrop, Red Piranha offers a solid thesis on affiliation and shared infrastructure, but its own report distinguishes between CONFIRMED and ATTRIBUTED techniques. There is not yet an independently documented Securotrop incident with the same level of granularity as the CVE-2026-50751 campaign. For that reason, it would not be appropriate to extend all of Qilin's TTPs to every mention of Securotrop without qualification.

Finally, the consolidated material does not provide verifiable links between any specific local case and exploitation of CVE-2026-50751 across all the countries mentioned. Argentina appears in the Check Point Research report, Colombia in sector alerts, and Bolivia or Peru in weekly statistics, but there is no single line connecting each country to the same technical incident. That fragmentation is a limitation of the corpus, not of the phenomenon.

Sources

View all