UAT-11988 is a financially motivated ransomware activity cluster assessed with high confidence to be a ransomware operator and linked to Qilin ransomware affiliates. The actor gained access to Cisco Secure Firewall Management Center appliances by abusing CVE-2026-20316 and associated static credentials, then executed attacker-controlled content with root privileges. UAT-11988 performed reconnaissance, harvested Active Directory service-account and database credentials, enumerated domain systems, and identified high-value systems including domain controllers, federation infrastructure, messaging servers, file servers, and database servers. It staged and exfiltrated collected data, used SOCKS5 proxying and reverse-SSH tunneling to reach internal enterprise services, employed Impacket and pass-the-hash tooling for lateral movement, and used tools intended to disable antivirus protections. The operation ultimately deployed Qilin ransomware against selected endpoints.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cluster believed connected to Qilin that exploited Cisco Secure FMC CVE-2026-20316 for access, reconnaissance, credential theft, and identification of endpoints for potential encryption.
A ransomware operator that accessed Cisco FMC through static credentials associated with CVE-2026-20316, conducted enterprise reconnaissance and credential theft, established SOCKS and reverse-SSH tunneling, deployed AV-killing tools, and deployed Qilin ransomware to selected endpoints.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.