Quick Summary
AllegedExecutive Summary
On September 23, 2026, the Qilin ransomware group listed Inkript, a technology company specializing in digital services and solutions, on its dark web portal. This listing was identified by SOCRadar’s Dark Web Monitoring service. Inkript operates within the technology sector, which is frequently targeted by ransomware operations, potentially due to the valuable data and critical infrastructure they manage. Qilin has been exceptionally active, claiming 242 other victims within the preceding 60-day period. The group’s operational model appears to be affiliate-driven and indiscriminate, with a primary focus on Manufacturing, Technology, and Professional Services industries, predominantly in the United States, Germany, and the United Kingdom. Inkript’s inclusion aligns with Qilin’s recent pattern of targeting technology companies, forming part of the broader “long tail” of victims.
Technical Analysis
SOCRadar’s Dark Web Monitoring service queried stealer-log data for the domain inkript[.]com, uncovering three records. These records consist of two INTERNAL_AUTH_EMPLOYEE credentials associated with atlas.inkript[.]com, which hosts the Atlas project portal, and a Mattermost instance, both used for internal collaboration. An additional credential was identified at the workstation level, linked to Inkript user credentials for Freshworks CRM, a third-party SaaS platform. The dates of the compromised logs range from March to May 2026, with ingestion extending into May 2026. This suggests a potential harvest window of 4-6 months prior to the listing. While this data is not recent, it could still be valid if the credentials have not been rotated. The identified credential profile aligns with Qilin’s typical initial access vector. This commonly involves acquiring infostealer logs from underground markets, validating these credentials, and then using them to gain authenticated access to corporate portals before proceeding with ransomware deployment. The Category A credentials for atlas.inkript[.]com and the Mattermost instance suggest an attacker may have authenticated directly as an employee into internal systems. The Freshworks CRM record points to a potential concurrent workstation compromise. It is unconfirmed whether these specific exposed credentials were used by Qilin in an actual attack, but their existence predates the leak-site listing by several months. Recommended Actions: Immediate credential rotation for all accounts identified in the compromised records. Enforcement of Multi-Factor Authentication (MFA) on atlas.inkript[.]com, Mattermost, and all other internal portals. Active audit of user sessions on both systems. Review of Freshworks CRM access logs for any anomalous authentication activity within the March–May 2026 timeframe.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.