Skip to main content
Qilin: Veeam credential abuse to ESXi hypervisor encryption operation cover
COMING SOONAdvancedPRO

Qilin: Veeam credential abuse to ESXi hypervisor encryption

A Qilin operator exploits a manufacturing firm's SSL-VPN edge, recovers stored credentials from an internet-facing backup server, steals a domain-admin token, self-propagates over SMB to vCenter, exfiltrates data over an encrypted tunnel, clears the Windows logs, and encrypts the ESXi datastores after mass-powering-off the guests. Work the FortiGate and Windows logs, the endpoint process tree, the perimeter traffic, and the vCenter/ESXi records to reconstruct the path from the edge to the hypervisor.

1h 35m
7 tasks
150 points
Pro

Launches in 3 days

Aug 18, 2026

Tuesday, August 18, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

SIEMXDRFirewall

What you'll investigate

7 objectives unlock when this operation goes live.

1Find the way in
2Identify the looted server
3Pin the operator's address
4Catch the reach to the hypervisor
5Follow the data out
6Confirm the hypervisor impact
7Classify the recovery sabotage

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Aug 18, 2026, you can jump straight in.

Get Started Free