Ransomware reports usually describe an attack after the damage is done. A newer analysis from Secuinfra GmbH offers something rarer: a look at the attacker's own working files. Recovered from a compromised Qilin affiliate server, the material traces an intrusion from Exchange mailbox collection to backup destruction, wiper deployment, and the first reported executions of the ransomware. This is the Qilin ransomware attack chain explained through the operator's own leftovers, and it carries practical lessons for defenders.

What the exposed Qilin server revealed

According to Secuinfra, the files recovered from the server let researchers reconstruct the order in which an affiliate worked through a victim environment. That matters because most public write-ups rely on forensic traces left on victim machines, which are often incomplete or wiped. Material from the attacker's side can show intent and sequence, not just the aftermath.

Qilin runs as a ransomware-as-a-service operation, meaning core developers supply the tooling while independent affiliates carry out the intrusions. Our profile of Qilin's double-extortion model explains that partnership structure in more detail. An exposed affiliate server is a useful window into the affiliate side of that arrangement, where the day-to-day work of an intrusion actually happens.

From mailbox theft to backup destruction: the attack stages

The summary of Secuinfra's findings describes a progression with distinct phases:

  1. Exchange mailbox collection. The intrusion begins with the collection of mailboxes from Exchange. Email holds credentials, internal contacts, invoices, and sensitive conversations, which makes it valuable both for further access and for pressure during extortion.
  2. Backup destruction. Before encryption, the affiliate goes after the victim's backups, removing the most obvious path to recovery.
  3. Wiper deployment. The files also point to a wiper being used as part of the operation, not only encryption.
  4. Ransomware execution. Only after those steps do the first reported executions of the ransomware itself appear.

The order is the key takeaway. Encryption is the last visible act, not the first. By the time ransom notes appear, the attacker has typically already read mail, taken data, and removed safety nets.

Why wipers and backup deletion raise the stakes

A standard ransomware incident gives the victim a choice: restore from backups or negotiate. Destroying backups first removes the first option. Adding a wiper pushes things further, since wiped data cannot be recovered even if a ransom is paid, which changes the calculus of any negotiation.

The mailbox theft compounds this. Qilin's model combines encryption with data theft and public leak threats, so even an organization with perfect restores still faces exposure of stolen messages. Backups solve availability, not confidentiality. For a sense of how often this plays out, see our 2026 guide to Qilin's attack pace.

How defenders can detect and interrupt this pattern

Because the stages are sequential, each one is a chance to interrupt the attack before encryption. Based on the sequence Secuinfra describes, these areas deserve attention:

  • Exchange hardening. Keep servers fully patched, restrict administrative access, and monitor for bulk or unusual mailbox exports.
  • Backup isolation. Keep at least one copy offline or immutable, with separate credentials that are not tied to the primary domain.
  • Early-stage monitoring. Alerts on mass mailbox access and on deletion of backup jobs or snapshots can fire well before ransomware runs.
  • Patching of edge systems. Attackers often enter through exposed infrastructure. Our coverage of a critical Cisco FMC flaw tied to Qilin activity shows why edge management tools need quick updates.
  • Incident rehearsal. Practice restoring from backups and deciding in advance who handles data-exposure notifications.

What This Means For You

If you run IT for a business, treat the early signs of an intrusion, such as unusual mailbox access or backup changes, as potential ransomware precursors rather than minor anomalies. If you are an individual, the lesson is about email: it is often the richest target in any compromise. Use strong, unique passwords, enable multi-factor authentication, and be cautious about what sensitive material sits in old mailboxes.

For organizations that handle other people's private data, the stolen-mail angle matters most. Even a fast recovery does not undo a leak.

Key takeaways

  • Ransomware is the final stage; mailbox theft and backup destruction come first.
  • Offline or immutable backups with separate credentials are essential, and wipers make them even more important.
  • Patch Exchange and edge systems promptly, and monitor for early-stage behavior.
  • Review the Qilin affiliate model and activity levels to understand the scale of the threat, then audit your own backup isolation, Exchange hardening, and patching routines this week.

The Qilin ransomware attack chain explained by Secuinfra's recovered files is a reminder that defenders have more time than it seems: the attacker's steps are visible before encryption, if you are watching for them.