~/f4n6 $ grep -r "Ransomware: qilin named Geieg (ES)" ./investigations/ --include="*.md"

Ransomware: qilin named Geieg (ES)

Jeff Davies 15 Sep 2026 5 min read

1. Executive summary

On 2026-09-15, the ransomware brand "qilin" listed a Spanish victim, Geieg (www.geieg.cat), on its leak site; the listing was indexed by ransomware.live at 05:02 UTC. The indexed record contains no technical detail — no initial-access vector, no CVE, no malware artefacts, no ransom demand or exfiltration volume — and the accompanying victim page reports 45 compromised users, 3 third-party employee credentials and an external attack surface of 11, figures that are single-sourced to ransomware.live and unverified. The verified reference data contains no CVSS score, no EPSS value and no CISA KEV entry for this item, and no MITRE ATT&CK profile exists for "qilin", so the attribution to that brand is unconfirmed. Bottom line for EMEA financial services: this is a low-specificity, indirect-risk item — the actionable exposure is credential hygiene and third-party/supply-chain visibility, not a patchable vulnerability. Clients with Geieg in their ICT third-party register, or with staff credentials surfacing in infostealer corpora, should treat it as a prompt for verification rather than a confirmed incident.

2. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item.

The item is a leak-site listing about a third-party organisation, not a report of an incident at a client, and it carries no technical facts (no exploited component, no outage, no confirmed data category) that would change a client's obligations under any article in the regulatory reference. The only conditional consideration: if a client has Geieg in its ICT third-party register, the general principles in DORA Art. 28 (ICT third-party risk) and the concentration assessment in DORA Art. 29 become relevant to that register entry — but that depends on facts not present in this item, and no reporting clock is triggered by a leak-site post alone.

3. Technical analysis & attack chain

Confirmed steps (from the indexed record only)

  1. qilin operators posted Geieg (country: ES; website: www.geieg.cat) to their leak site. ransomware.live indexed the post on 2026-09-15 at 05:02:27 UTC.
  2. No ransom demand, negotiation deadline, data-volume figure, sample-file listing, or proof-of-exfiltration artefact is present in the indexed record.
  3. The ransomware.live victim page for Geieg presents the following counts: compromised employees 0, compromised users 45, third-party employee credentials 3, external attack surface 11. The DNS records section and the leak-screenshot section are both empty in the fetched content.

What is not established. The source material does not state the initial access vector, the exploited component or CVE, the malware family or payload capabilities, persistence mechanism, privilege escalation path, command-and-control infrastructure, lateral movement, exfiltration method, or whether encryption was actually deployed. Nothing in the source indicates double-extortion, data theft, or a ransom payment. Do not infer any of these from the brand name alone.

Confidence caveats. This is a single-source item. ransomware.live indexes operator claims and open-web sources without accessing the underlying stolen data (per its own legal disclaimer), so the listing itself is an unverified claim by the operator, and the victim-page counts are unverified third-party telemetry. The counts appear alongside a Hudson Rock sponsorship banner referencing infostealer infections as a ransomware precursor, which suggests the credential figures derive from infostealer-corpus data — but the source does not state this explicitly, so treat the derivation as unconfirmed. The "external attack surface: 11" figure has no stated methodology.

Attribution. The verified reference data contains no MITRE ATT&CK profile for "qilin". The attribution of this listing to that brand is therefore unconfirmed and rests solely on the leak-site post as indexed by ransomware.live.

Cluster context (corpus, single-source). The related ransomware.live records show qilin listings against a set of Iberian and UK organisations in the same index: Aletex Group (ES, www.aletex.net), Semana (ES, www.semana.es), Jbc (ES, www.jbctools.com), Sisint (PT, www.sisint.pt), LGG Advisors (GB, www.lggadvisors.com) and TQ Financial Services (country field blank, www.tqfinancials.com). Publication dates for those records are not supplied, so no temporal clustering can be asserted. The presence of an entity whose name suggests financial services (TQ Financial Services) is noted but is not confirmation of sector targeting — the source gives no sector classification for any victim.

4. Mitigation & containment

There is no patchable component, CVE, or vendor fix in this item, so the actions below are exposure-verification and credential-hygiene controls, not technical containment of a known artefact.

P1 — within 24 hours

  • Check whether Geieg (www.geieg.cat) appears in your ICT third-party / vendor register. If it does, contact the relationship owner to establish whether any service you consume is affected; do not rely on the leak-site post as evidence of impact.
  • Query your identity provider and EDR telemetry for authentication activity from your own staff or contractors to any Geieg-hosted service, and for credential-stuffing or anomalous sign-in patterns against those accounts.
  • If any of your own workforce credentials surface in infostealer telemetry, force password reset and revoke active sessions and refresh tokens for the affected identities — do not rely on password change alone.

P2 — within 72 hours

  • Enforce phishing-resistant MFA (FIDO2/WebAuthn) on all externally reachable identity providers, remote-access gateways and third-party portals. This is the control that most directly breaks the infostealer-credential-to-ransomware path implied by the victim-page counts.
  • Review third-party accounts for standing privileged access; remove dormant accounts and downgrade service accounts that do not require write or administrative rights.
  • Confirm that third-party/contractor identities are covered by the same conditional-access and impossible-travel/sign-in-risk policies as employees — the "third-party employee credentials" figure in this item is the specific reason to check this.

P3 — within 7 days

  • Re-baseline your external attack surface for internet-exposed services belonging to critical suppliers, and reconcile against the supplier's declared inventory.
  • Tabletop the scenario "critical supplier listed on a ransomware leak site, no technical detail available" against your DORA Art. 17 incident-management process, so the decision to escalate or not is pre-agreed rather than improvised.
  • Where contracts permit, verify that key ICT third-party agreements contain the audit, access and cooperation provisions you would need to obtain incident information from a supplier in this situation.

5. Indicators of compromise

No indicators of compromise available in the source material.

The source contains no hashes, domains, IP addresses, URLs, file paths, registry keys, mutexes, or ransom-note text. The only network-identifiable value present is the victim's own legitimate website (www.geieg.cat), which is not a malicious indicator and is therefore not listed. No behavioural indicators are described in the source either — the victim-page counts are aggregate statistics, not observable behaviours.

6. Detection

Insufficient indicators to author detection rules.

7. Sources

  • Ransomware.live, "Ransomware: qilin named Geieg (ES)", https://www.ransomware.live/id/R2VpZWdAcWlsaW4=, published 2026-09-15T05:02:27 UTC (primary item)
  • Ransomware.live, "Victim: Geieg – qilin" (victim detail page with compromised-user and attack-surface counts), https://www.ransomware.live/id/R2VpZWdAcWlsaW4= (external-1)
  • Ransomware.live, "Ransomware: qilin named Aletex Group (ES)", https://www.ransomware.live/id/QWxldGV4IEdyb3VwQHFpbGlu (corpus-1)
  • Ransomware.live, "Ransomware: qilin named Semana (ES)", https://www.ransomware.live/id/U2VtYW5hQHFpbGlu (corpus-2)
  • Ransomware.live, "Ransomware: qilin named LGG Advisors (GB)", https://www.ransomware.live/id/TEdHIEFkdmlzb3JzQHFpbGlu (corpus-3)
  • Ransomware.live, "Ransomware: qilin named TQ Financial Services", https://www.ransomware.live/id/VFEgRmluYW5jaWFsIFNlcnZpY2VzQHFpbGlu (corpus-4)
  • Ransomware.live, "Ransomware: qilin named Jbc (ES)", https://www.ransomware.live/id/SmJjQHFpbGlu (corpus-5)
  • Ransomware.live, "Ransomware: qilin named Sisint (PT)", https://www.ransomware.live/id/U2lzaW50QHFpbGlu (corpus-6)

8. Adverse Trace position

We assess this as a low-specificity, single-sourced leak-site listing with no technical substance: no CVE, no CVSS score, no EPSS value, no CISA KEV entry and no MITRE ATT&CK profile for the named brand, so the qilin attribution is unconfirmed and we do not treat the victim-page counts as verified. Client impact is indirect — the realistic exposure for an EMEA financial services client is credential reuse or third-party dependency on the named victim, not exploitation of a flaw in your own estate — and we are not raising a severity rating on this item alone. We will monitor for a corroborating source (victim statement, national CERT notice, or a second leak-site index) and for any technical detail that would let us author detection content; until then, clients should action the P1 credential checks in §4 and confirm whether Geieg sits in their third-party register.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies