Qilin ransomware operator extradited from Japan to Germany: what the record shows, and what it does not
By Sethu Satheesh · 9 Oct 2026 · 15 min read
Source: www.heise.de
Threat Actor: Qilin (a.k.a. Agenda) · Target: An unnamed German logistics company (September 2024 intrusion); charged suspect is an unnamed 28-year-old Russian national
Executive Summary
A 28-year-old Russian national described in reporting as a core member of the Qilin (Agenda) ransomware operation was arrested in Osaka in late May 2026 while travelling in Japan, found extraditable by the Tokyo High Court, and handed to German authorities on 2 October 2026 to face prosecution.123 His name has not been made public in any reviewed source, and he is a charged suspect who has not been convicted.4 The German arrest warrant rests on a single alleged offence: that in September 2024 he broke into the network of a German logistics company, encrypted its data, and extorted a Bitcoin ransom of about ¥26 million — rendered by English-language outlets as roughly $160,000 to $165,000.135
The handover is itself the story. Japan has extradition treaties with only two countries, South Korea and the United States, and in some years carries out no treaty-less extraditions at all; the transfer went through Japan's Act on Extradition (逃亡犯罪人引渡法), which permits surrender to a non-treaty state on a reciprocity assurance once a court confirms the conditions are met.14 According to the Japanese newspaper Asahi Shimbun, whose reporting German-language outlet heise relayed, German special investigators knew in advance that the wanted man intended to travel to Japan and pre-positioned the case so that the Tokyo High Court could confirm the German warrant, allowing the arrest in Osaka in May.1 How investigators gained that foreknowledge of his travel is not disclosed in any public record.
His alleged role is what distinguishes the case from an affiliate arrest. Investigative sources say he was responsible for building the attack systems inside the Qilin criminal network and took a proportional cut of ransoms collected by the affiliate teams that carried out individual intrusions — an infrastructure-and-tooling role at the operator end of a ransomware-as-a-service business, rather than a front-line intruder.5 Asahi Shimbun additionally reports he is accused not only of programming but of acting as a direct perpetrator who manipulated the German company's systems himself.1 Qilin has, separately, become one of the most active ransomware brands in the world and claimed the October 2025 attack that halted beer production at Japan's Asahi Group Holdings — a different "Asahi" entirely from the newspaper, and an incident that current reporting does not tie to this suspect.16
Why this matters: the public evidentiary record is unusually thin for a case this widely reported. No German prosecutor's office, the Bundeskriminalamt, Europol or Eurojust has published a statement that could be located as of 8 October 2026; the entire account traces to Asahi Shimbun and unnamed Japanese investigative sources carried by the Jiji Press wire. The figures that readers are repeating — the $165,000 ransom, the September 2024 date, the "core member" label — each sit at a different level of confirmation, and at least one outlet has already published the attack year as September 2022.7 This paper separates what a court actually found (extradition eligibility) from what investigators have asserted (role, seniority, direct perpetration) from what nobody has published (the tracing method, the prosecuting office, the charges' statute numbers).
Weekly Digest
Get the next investigation in your inbox
New research, once a week. No vendor pitches.
Verification of Claims
-
Claim: A 28-year-old Russian national was handed from Japan to Germany on 2 October 2026 over a Qilin-linked case. → Verified → The age and 2 October handover appear in ChainCatcher and News On Japan; the Russian nationality and the German destination are in the Jiji Press wire report and heise.1235 The nippon.com/Jiji relay itself gives only "a Russian national" without the age.2
-
Claim: The German warrant is based on a September 2024 intrusion into a German logistics company, with a Bitcoin ransom of about ¥26 million. → Partially verified → The logistics company, the September 2024 date, the encryption and the ¥26 million (~$160,000–$165,000) Bitcoin ransom are consistently reported by heise (citing Asahi Shimbun), ChainCatcher and News On Japan.135 They are investigative-source claims, not a published charging document; no German prosecutor statement confirming them could be located.
-
Claim: The suspect was a "core member" who built Qilin's attack infrastructure and took a cut of affiliate ransoms. → Partially verified → This is the characterisation attributed to Japanese investigative sources and carried by ChainCatcher and the Jiji wire.25 The Tokyo High Court ruling that was actually made concerned extradition eligibility for the logistics-company offence, not a judicial finding that he is a Qilin principal.4 It is an allegation, reported as such.
-
Claim: German investigators knew in advance he would travel to Japan and pre-positioned the arrest. → Partially verified → heise, relaying Asahi Shimbun, states that "special investigators reportedly knew in advance that the wanted person would travel to Japan" and therefore obtained confirmation of the German warrant from the Tokyo High Court before the May arrest.1 The underlying intelligence — how that foreknowledge was obtained — is not in any reviewed source.
-
Claim: This suspect was behind Qilin's 2025 attack on Asahi Group Holdings. → Unverified → No reviewed source states this. Coverage juxtaposes the arrest with Qilin's Asahi Group claim because both touch Japan, but the warrant concerns the German logistics company, and the May access to Qilin's dark-web site described by News On Japan relates to Asahi Group data, not to this man's identification.36
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| Aug 2022 | Trend Micro | First version of the ransomware documented under the name "Agenda", later rebranded Qilin | 8 |
| September 2024 | Qilin (alleged) | Intrusion into a German logistics company's network; data encrypted; Bitcoin ransom (~¥26M) extorted — the basis of the German warrant | 15 |
| March 27, 2026 | Die Linke (The Left) | German party reports a Qilin ransomware attack on its IT infrastructure and files a criminal complaint | 9 |
| Late May 2026 | Osaka Prefectural Police / Japanese authorities | Russian suspect arrested in Osaka while travelling, on the pre-confirmed German warrant | 135 |
| May 2026 | Japanese investigators + cybersecurity specialists | Access Qilin's dark-web leak site, which held data believed stolen from Asahi Group | 3 |
| 2026 (mid-year) | Tokyo High Court | Rules the conditions for extradition to Germany are met | 45 |
| October 2, 2026 | German authorities | Take custody of the suspect; he faces prosecution in Germany | 15 |
| October 6, 2026 | Jiji Press | Reports the extradition, citing investigative sources | 2 |
Operation Anatomy
The record describes two distinct mechanisms that must be kept apart: the alleged intrusion that produced the German warrant, and the law-enforcement operation that ended in the Osaka arrest. For the intrusion itself, almost no forensic detail has been published; what follows for the intrusion is Qilin's documented mode of operation, flagged where it is the group's general tradecraft rather than established for this victim.
The charged offence
German investigators allege that in September 2024 the suspect gained unauthorised access to a German logistics company's network, encrypted its corporate data, and demanded a Bitcoin ransom of about ¥26 million; the company paid in Bitcoin to prevent publication of the stolen data, and part of that payment allegedly flowed to the suspect.15 Asahi Shimbun reports he is accused of being a direct perpetrator who manipulated the company's systems himself, in addition to his alleged infrastructure role.1 The specific initial-access vector, the ransomware variant deployed, the exfiltration channel and the on-chain path of the ransom have not been disclosed in any reviewed source and are marked unknown.
Qilin's documented mode of operation (group tradecraft, not confirmed for this victim)
Qilin runs a ransomware-as-a-service platform: affiliates conduct the intrusions while the operators provide payload generation, the data-leak infrastructure and ransom negotiation.8 Group-IB, which infiltrated the affiliate programme in March 2023, reported affiliates receive up to 80% of ransoms at or below $3 million and up to 85% above it, with the operators taking the remainder — the "cut" structure this suspect is alleged to have sat on the operator side of.85 Documented affiliate access methods include valid stolen credentials against public-facing services such as a Citrix server, and at least one affiliate's claim of phishing; internal reconnaissance with Nmap/Nping; lateral movement over RDP and PsExec; defence evasion through bring-your-own-vulnerable-driver tooling (e.g. Terminator.exe) and intermittent encryption; and cross-platform lockers written in Go and Rust, including a Linux build targeting VMware ESXi.8
The law-enforcement operation
The operation that led to the arrest is better documented than the intrusion. German special investigators had foreknowledge that the wanted man would travel to Japan and used it to pre-position the case: they obtained the Tokyo High Court's confirmation of the German arrest warrant so that Japanese authorities could detain him on arrival, which they did in Osaka in late May 2026.1 Because Japan and Germany have no bilateral extradition treaty, the surrender proceeded under Japan's Act on Extradition, which allows extradition to a non-treaty state on a reciprocity assurance once a court finds the statutory conditions met — the finding the Tokyo High Court made before the 2 October handover.14 The intelligence behind the travel foreknowledge is the single most important unanswered question in the case and is not in the public record; assertions elsewhere that it came from infrastructure or endpoint compromise could not be confirmed and are not repeated here.
Loading diagram...
Accused
Identity: A 28-year-old Russian national. His name has not been published in any reviewed source and is not stated here.45 Alleged role: Building the attack systems within the Qilin network and taking a proportional cut of affiliate ransoms; additionally accused by Asahi Shimbun of being a direct perpetrator in the German intrusion.15 Status: Charged suspect, extradited to Germany on 2 October 2026; not convicted. No plea, trial date or charging document has been reported.4 Charging authority and statutes: Not identified in any reviewed source. No German prosecutor's office, the Bundeskriminalamt, Europol or Eurojust has published a statement locatable as of 8 October 2026; the account traces to Asahi Shimbun and Japanese investigative sources via Jiji Press.12 Presumption of innocence: The allegations are untested in court. He is presumed innocent unless and until convicted.
Attribution and naming basis: The "core member" characterisation and the infrastructure role come from unnamed investigative sources relayed by Japanese media, not from a court finding or a named charging document; the Tokyo High Court addressed only extradition eligibility.45 Because no reviewed source names him and he is charged rather than convicted, no name is published here.
The Qilin (Agenda) operation: Aliases: Qilin; Agenda (the original name under which Trend Micro documented it in August 2022).8 Attribution: Believed to originate in Russia, on the basis of Russian-language artefacts and a documented avoidance of CIS-country targets; no formal government attribution has been issued.8 Model: Ransomware-as-a-service with a double-extortion leak site (Tor, plus a clearnet "WikiLeaksV2" site from May 2024); active since at least May 2022.8 Prior operations: Claimed the October 2025 ransomware attack that disrupted Asahi Group Holdings in Japan,6 and the March 2026 attack on the German party Die Linke.9
MITRE ATT&CK techniques (Qilin's documented tradecraft; IDs verified live on attack.mitre.org):
| ID | Technique |
|---|---|
| T1078 | Valid Accounts |
| T1566 | Phishing |
| T1046 | Network Service Discovery |
| T1021.001 | Remote Services: Remote Desktop Protocol |
| T1021.002 | Remote Services: SMB/Windows Admin Shares |
| T1685 | Disable or Modify Tools |
| T1490 | Inhibit System Recovery |
| T1486 | Data Encrypted for Impact |
| T1567 | Exfiltration Over Web Service |
| T1657 | Financial Theft |
OPSEC: The one disclosed failure is behavioural, not technical: the suspect travelled to a jurisdiction where he could be detained, and investigators had advance knowledge of the trip.1 No reused handle, KYC-exchange record, leaked IP or seized server has been described in any reviewed source.
Technical Indicators
indicators: none disclosed
note: >
No file hashes, C2 domains, IP addresses, ransom-wallet addresses or
malware samples specific to the German logistics-company intrusion have
been published in any reviewed source. The German logistics company has
not been named. Qilin's general tooling (Go and Rust lockers, a Linux/ESXi
variant, BYOVD defence evasion via Terminator.exe, PsExec, Nmap/Nping) is
documented by Trend Micro, Group-IB, Secureworks and SentinelOne as relayed
by BushidoToken, but is group tradecraft, not indicators tied to this case.
leak_sites:
- 'Tor data-leak site (double extortion)'
- 'WikiLeaksV2 (clearnet, in use from May 2024)'Legal and Regulatory Response
The case is a criminal prosecution in Germany. The suspect was extradited from Japan on 2 October 2026 under Japan's Act on Extradition (逃亡犯罪人引渡法) after the Tokyo High Court confirmed the conditions for surrender to a non-treaty state were met; Japan has bilateral extradition treaties only with South Korea and the United States, making this a rare treaty-less extradition.14 Japanese extradition law bars surrender of a person who is to be prosecuted in Japan or who has not finished serving a Japanese sentence, which heise notes leaves open why Japan did not itself pursue a case arising from Qilin's Asahi Group attack.1
As of 8 October 2026, no German prosecutor's office, the Bundeskriminalamt, Europol or Eurojust has published a statement on this extradition that could be located, and no charging document, statute numbers, plea or trial date has been reported.12 Separately, Die Linke filed a criminal complaint in Germany over the March 2026 Qilin attack on the party.9
Impact Assessment
- Confirmed: A Russian national was extradited from Japan to Germany on 2 October 2026 in a Qilin-linked case, following a Tokyo High Court extradition ruling.15
- Reported, not independently confirmed: A German logistics company was breached in September 2024, its data encrypted, and a Bitcoin ransom of about ¥26 million ($160,000–$165,000) paid; the suspect allegedly built Qilin's attack systems and took a cut of affiliate ransoms.15
- Reported, not independently confirmed: Qilin's October 2025 attack disrupted order processing, shipping and production at Asahi Group Holdings in Japan; the group claimed it and posted alleged documents to its leak site. The Record could not verify the data claims and Asahi did not comment on them.6
- Estimated: The dollar value of the ransom varies across outlets ($160,000 to $165,000) because it is a conversion of the ¥26 million figure at different rates.35
- Unknown: The identity of the German logistics company; the intrusion's technical specifics; the on-chain path of the ransom; the method by which investigators learned of the suspect's travel; the German charging office and statutes.
Lessons and Defensive Recommendations
For SOC/defenders:
- Qilin affiliates have entered through valid stolen credentials against public-facing services (e.g. Citrix) and through phishing; enforce phishing-resistant MFA on all external access and monitor for anomalous RDP and PsExec use consistent with the group's lateral-movement pattern.8
- Watch for bring-your-own-vulnerable-driver activity (
Terminator.exeand similar) that disables EDR, and for intermittent-encryption behaviour that can slip under volume-based ransomware detection.8 - Protect VMware ESXi and vCenter specifically: Qilin ships a Linux/ESXi locker and spreads to hypervisors, where a single detonation can encrypt many guests at once.8
For leadership and incident responders:
- Paying a ransom does not close the matter. In this case the payment itself became evidence: the alleged flow of part of the Bitcoin ransom to the suspect underpins the German warrant.1 Preserve payment and negotiation records for law enforcement.
- Treat the leak site as live intelligence. Japanese investigators accessed Qilin's dark-web site with cybersecurity specialists to examine stolen data — defenders and victims can monitor the same surface for exposure.3
For investigators and journalists:
- Separate what a court found from what investigators asserted. The Tokyo High Court ruled only on extradition eligibility; the "core member" and "built the infrastructure" claims are investigative-source characterisations.45
- Check the attack year and the actor link before repeating them: one outlet dated the intrusion to September 2022 against a September 2024 consensus, and the Asahi Group attack is not established as this suspect's work.76
Sources
Footnotes
-
heise online — Rare occurrence: Japan extradites ransomware suspect to Germany — October 6, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25
-
nippon.com (Jiji Press) — "Qilin" Hacker Group Member Held in Japan, Sent to Germany — October 6, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
News On Japan — Russian "Qilin" Member Extradited to Germany After Osaka Arrest — October 6, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9
-
shattered.io — Qilin Ransomware Member, 28, Extradited to Germany — October 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10
-
ChainCatcher — 28-year-old Qilin core member extradited from Japan to Germany — October 6, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18
-
The Record — Cybercrime crew claims attack on Japanese brewer as it restarts operations — October 8, 2025 ↩ ↩2 ↩3 ↩4 ↩5
-
The Tokyo Reporter — Russian hacker nabbed in Osaka, extradited to Germany — October 6, 2026 ↩ ↩2
-
BushidoToken — Tracking Adversaries: The Qilin RaaS — June 2024 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10
-
heise online — Qilin: Left Party reports Russian ransomware attack — March 27, 2026 ↩ ↩2 ↩3
Related Research
Operation KillSwitch seized KillSec's leak site and five servers on 30 September 2026, securing 110 TB of stolen data. A 16-year-old is the alleged main operator; a Dutch national is indicted in Puerto Rico. What the primary sources say, and where the numbers diverge.
A Conti affiliate who coded a loader and intruded on twelve victims got 48 months in Nashville on 10 September 2026. The judgment credits custody since his July 2023 arrest in Cork, leaving about ten months. Plea agreement and docket analysed.
South Africa's air navigation provider ATNS found ransomware-linked malware in an OT network supporting aviation weather services, with suspected data exfiltration to China-based IPs. No flights were disrupted; the actor is unknown and a forensic probe is under way.