Germany Arrests Suspected Qilin Ransomware Core Member After Extradition From Japan
Germany has arrested a Russian national suspected of being a key member of the Qilin ransomware group after the suspect was extradited from Japan earlier this month.
Japan confirmed the extradition to Germany. The country’s National Police Agency said the suspect was detained after arriving in Japan as a tourist.
“When a Russian national for whom Germany had an arrest warrant in connection with a ransomware incident in Germany arrived in Japan, Japan’s Ministry of Justice, the Tokyo High Public Prosecutors Office, and Germany worked together to obtain a provisional detention warrant under the Extradition Act, detain the suspect, and facilitate his extradition.” [machine translated]
Read the Japanese National Police Agency press release.
Qilin ransomware suspect extradited to Germany
Japanese media reported earlier this week that the arrest was based on inside information. Japanese authorities have now officially acknowledged the detention and extradition.
Qilin is a notorious ransomware-as-a-service (RaaS) operation that emerged in August 2022 under the name Agenda. The group uses a classic double-extortion strategy: stealing sensitive data before encrypting victims’ systems and then threatening to publish the stolen information.
Qilin has targeted more than 2,350 organizations
The operation has become one of the most active ransomware threats worldwide. According to the latest statistics, Qilin has targeted more than 2,350 known organizations across 62 countries.
Reported victims include Japanese automaker Nissan, Japanese beer producer Asahi, U.S. newspaper company Lee Enterprises, and Australia’s Court Services Victoria.
The attack on Asahi, Japan’s largest beer producer, was particularly damaging. It disrupted the company’s operations for an extended period and exposed sensitive information belonging to approximately 1.5 million people.
Qilin continues to expand its ransomware activity
More recently, the group attacked the U.S. Bureau of Alcohol, Tobacco, Firearms, and Explosives (ATF). Qilin was also associated with the exploitation of a Check Point VPN zero-day vulnerability and a Palo Alto VPN n-day vulnerability.
Japanese media reported that an alleged Qilin leader was detained at a hotel in Osaka in May. Despite the detention, the ransomware operation has remained a major force in the cybercrime ecosystem, listing more than 450 victims on its data-leak site since June.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



