Threat actors are actively exploiting a critical authentication bypass flaw in Palo Alto Networks firewalls to breach corporate networks and deploy Qilin ransomware, according to new research from Arctic Wolf Labs.
The security firm investigated multiple intrusions throughout June 2026, all tracing back to the same vulnerability as the initial point of entry.
The flaw, tracked as CVE-2026-0257 (CVSS 7.8), affects the GlobalProtect portal and gateway in PAN-OS. It becomes exploitable when authentication override cookies are enabled alongside specific certificate configurations, allowing unauthenticated attackers to bypass login controls entirely and establish legitimate-looking VPN sessions.
Affected versions include PAN-OS 12.1, 11.2, 11.1, and 10.2 (prior to specific patched builds), along with certain Prisma Access releases. Palo Alto Networks has confirmed limited active exploitation in the wild.
In the intrusions Arctic Wolf reviewed, attackers used compromised VPN sessions to gain direct, interactive access to victim networks — completely skipping perimeter authentication.
PAN-OS Vulnerability Exploited
Once inside, attackers followed a fast-moving playbook:
Established persistence using registry Run keys with a distinctive naming pattern (an asterisk plus six random lowercase letters)
Deployed remote access tools like AnyDesk, Ngrok, and LogMeIn for redundant connectivity
Dumped credentials from LSASS memory using rundll32.exe and comsvcs.dll, disguising output as a “.odt” file to evade detection
Extracted the entire Active Directory database via ntdsutil.exe, gaining domain-wide credential access
Used PsExec and administrative shares (C$) for lateral movement across the network
Notably, several attacks originated from systems self-identifying with the hostname “kali,” and overlapping IP addresses appeared in both the initial exploitation and later VPN sessions, suggesting shared infrastructure or tooling among Qilin affiliates.
While the entry point and core techniques remained stable, post-exploitation behavior varied significantly. Some intrusions moved straight to encryption with minimal dwell time, while others involved extensive reconnaissance, credential harvesting at scale, and data theft via Rclone to MEGA cloud storage before ransomware deployment.
This variation is typical of ransomware-as-a-service (RaaS) operations, where different affiliates use shared tools but apply their own strategies.
Before triggering encryption, attackers routinely disabled Microsoft Defender’s real-time protection and wiped Windows Event Logs using a PowerShell script that clears every log channel on the system, not just Security or System logs, making forensic recovery far harder.
The ransomware payload itself, consistently named win.exe, was staged in C:\PerfLogs\, a default Windows directory rarely monitored by security tools. Execution required a password parameter, complicating sandbox analysis.
Tactical Security Recommendations
Arctic Wolf recommends immediate action:
Patch CVE-2026-0257 across all internet-facing PAN-OS and Prisma Access deployments
Terminate all active GlobalProtect sessions after patching
Rotate all domain credentials, including the KRBTGT account, if exploitation is suspected
Monitor and restrict execution from C:\PerfLogs
Forward Windows Event Logs to a centralized SIEM to preserve evidence even if local logs are cleared
Arctic Wolf assesses with moderate confidence that exploitation of this vulnerability leading to Qilin ransomware deployment is ongoing, driven by widespread scanning activity and the RaaS model’s tendency to distribute working exploits across multiple affiliates.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware appeared first on Cyber Security News.



