Hackers Exploit PAN-OS Flaw (CVE-2026-0257) to Deploy Qilin | #ransomware | #cybercrime


Threat actors are actively exploiting a critical authentication bypass flaw in Palo Alto Networks firewalls to breach corporate networks and deploy Qilin ransomware, according to new research from Arctic Wolf Labs.

The security firm investigated multiple intrusions throughout June 2026, all tracing back to the same vulnerability as the initial point of entry.

The flaw, tracked as CVE-2026-0257 (CVSS 7.8), affects the GlobalProtect portal and gateway in PAN-OS. It becomes exploitable when authentication override cookies are enabled alongside specific certificate configurations, allowing unauthenticated attackers to bypass login controls entirely and establish legitimate-looking VPN sessions.

Affected versions include PAN-OS 12.1, 11.2, 11.1, and 10.2 (prior to specific patched builds), along with certain Prisma Access releases. Palo Alto Networks has confirmed limited active exploitation in the wild.

In the intrusions Arctic Wolf reviewed, attackers used compromised VPN sessions to gain direct, interactive access to victim networks — completely skipping perimeter authentication.

PAN-OS Vulnerability Exploited

Once inside, attackers followed a fast-moving playbook:

  • Established persistence using registry Run keys with a distinctive naming pattern (an asterisk plus six random lowercase letters)
  • Deployed remote access tools like AnyDesk, Ngrok, and LogMeIn for redundant connectivity
  • Dumped credentials from LSASS memory using rundll32.exe and comsvcs.dll, disguising output as a “.odt” file to evade detection
  • Extracted the entire Active Directory database via ntdsutil.exe, gaining domain-wide credential access
  • Used PsExec and administrative shares (C$) for lateral movement across the network

Notably, several attacks originated from systems self-identifying with the hostname “kali,” and overlapping IP addresses appeared in both the initial exploitation and later VPN sessions, suggesting shared infrastructure or tooling among Qilin affiliates.

While the entry point and core techniques remained stable, post-exploitation behavior varied significantly. Some intrusions moved straight to encryption with minimal dwell time, while others involved extensive reconnaissance, credential harvesting at scale, and data theft via Rclone to MEGA cloud storage before ransomware deployment.

This variation is typical of ransomware-as-a-service (RaaS) operations, where different affiliates use shared tools but apply their own strategies.

Before triggering encryption, attackers routinely disabled Microsoft Defender’s real-time protection and wiped Windows Event Logs using a PowerShell script that clears every log channel on the system, not just Security or System logs, making forensic recovery far harder.

The ransomware payload itself, consistently named win.exe, was staged in C:\PerfLogs\, a default Windows directory rarely monitored by security tools. Execution required a password parameter, complicating sandbox analysis.

Tactical Security Recommendations

Arctic Wolf recommends immediate action:

  • Patch CVE-2026-0257 across all internet-facing PAN-OS and Prisma Access deployments
  • Terminate all active GlobalProtect sessions after patching
  • Rotate all domain credentials, including the KRBTGT account, if exploitation is suspected
  • Monitor and restrict execution from C:\PerfLogs
  • Forward Windows Event Logs to a centralized SIEM to preserve evidence even if local logs are cleared

Arctic Wolf assesses with moderate confidence that exploitation of this vulnerability leading to Qilin ransomware deployment is ongoing, driven by widespread scanning activity and the RaaS model’s tendency to distribute working exploits across multiple affiliates.

The Privilege Paths Attackers See, That You Don’t: BeyondTrust Pathfinder Platform do it for You -> Get Free Identity Security Assessment



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW