CiberLATAMbywhalemate

Qilin Posts Argentina’s Vitar Group on Leak Site

Qilin posted Argentina’s Vitar Group on its leak site, while threat intel also tracked recent group activity in Spain.

Whalemate Labs · AI-assisted researchPublished:3 min read

Qilin posted Argentina’s Vitar Group on its leak site, according to dark web monitoring. The entry adds to other recent reports on the group’s activity, including September victims in several countries and a Cisco Talos attribution tied to exploitation of a Cisco Secure Firewall Management Center flaw to gain access and deploy ransomware.

Qilin posted the Argentine company Vitar Group on its leak site, according to dark web monitoring. The entry adds to other recent reports on the group’s activity. In September, Qilin added victims in multiple countries and was linked by Cisco Talos to exploitation of a Cisco Secure Firewall Management Center flaw to gain access to environments, move inside networks, and deploy ransomware on selected systems.

What is known about the Vitar Group case?

The confirmed detail from Pulse (Kalir) is that Qilin posted Vitar Group on its leak site. No other incident details were disclosed in the material, such as the initial access vector, internal scope, or the type of data affected. The available confirmation is limited to the Argentine company’s appearance on the leak site.

What do recent monitoring reports show about Qilin?

Security Arsenal reported that QILIN added four victims between September 7 and 9, 2026, in a batch dominated by targets in the United States, South Korea, and Spain. During that same period, Ransomware.live logged an entry for Taurus Ibérica with a discovery timestamp of September 15, 2026 at 15:01 UTC, and classified it as a Qilin victim.

The available coverage also provides a relevant technical precedent. Security Affairs reported that Cisco Talos attributed a third cluster, identified as UAT-11988, to a campaign that exploited a vulnerability in Cisco Secure Firewall Management Center for initial access, carried out extensive reconnaissance, set up SOCKS and reverse SSH tunnels, collected credentials, and then deployed ransomware.

CyberNewsAI added that the same cluster used static credentials, performed Active Directory reconnaissance, collected service account secrets, and mapped infrastructure before using SOCKS5 proxies and reverse SSH tunnels. Separately, Security Affairs said the CVE-2026-20079 vulnerability was added to CISA’s KEV catalog and received a patch deadline for federal agencies on September 12, 2026.

What TTPs are appearing in other ransomware campaigns?

Security Arsenal described techniques that keep recurring in recent MedusaLocker and PANZER campaigns. In MedusaLocker’s case, the report cited exploitation of exposed remote services, phishing with malicious attachments or links, abuse of RMM tools, and unpatched perimeter devices. In PANZER, it documented exploitation of edge appliances, abuse of valid accounts, and phishing with credentials aimed at IT staff, with victims concentrated in Europe.

The same monitoring also showed Qilin activity beyond Argentina and Spain. Security Arsenal said the group added four victims in a 24-hour span between September 7 and 9, with a presence also in the United States and South Korea, reinforcing the publication pace tracked by threat intelligence teams.

What did the Qilin ATF case show?

Pasquale Pillitteri reported that Qilin published 6.3 GB of ATF investigation files on August 31, 2026, and removed the links about a day later. In that same case, the agency said the affected system operated independently from the corporate network, a detail that narrows the scope of the incident disclosed by the group.

Sources

View all