HomeCyber Security
Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware
By Guru Baran
July 21, 2026
Threat actors are actively exploiting a critical authentication bypass flaw in Palo Alto Networks firewalls to breach corporate networks and deploy Qilin ransomware, according to new research from Arctic Wolf Labs.
The security firm investigated multiple intrusions throughout June 2026, all tracing back to the same vulnerability as the initial point of entry.
The flaw, tracked as CVE-2026-0257 (CVSS 7.8), affects the GlobalProtect portal and gateway in PAN-OS. It becomes exploitable when authentication override cookies are enabled alongside specific certificate configurations, allowing unauthenticated attackers to bypass login controls entirely and establish legitimate-looking VPN sessions.
Affected versions include PAN-OS 12.1, 11.2, 11.1, and 10.2 (prior to specific patched builds), along with certain Prisma Access releases. Palo Alto Networks has confirmed limited active exploitation in the wild.
In the intrusions Arctic Wolf reviewed, attackers used compromised VPN sessions to gain direct, interactive access to victim networks — completely skipping perimeter authentication.
PAN-OS Vulnerability Exploited
Once inside, attackers followed a fast-moving playbook:
Established persistence using registry Run keys with a distinctive naming pattern (an asterisk plus six random lowercase letters)
Deployed remote access tools like AnyDesk, Ngrok, and LogMeIn for redundant connectivity
Dumped credentials from LSASS memory using rundll32.exe and comsvcs.dll, disguising output as a “.odt” file to evade detection
Extracted the entire Active Directory database via ntdsutil.exe, gaining domain-wide credential access
Used PsExec and administrative shares (C$) for lateral movement across the network
Notably, several attacks originated from systems self-identifying with the hostname “kali,” and overlapping IP addresses appeared in both the initial exploitation and later VPN sessions, suggesting shared infrastructure or tooling among Qilin affiliates.
While the entry point and core techniques remained stable, post-exploitation behavior varied significantly. Some intrusions moved straight to encryption with minimal dwell time, while others involved extensive reconnaissance, credential harvesting at scale, and data theft via Rclone to MEGA cloud storage before ransomware deployment.
This variation is typical of ransomware-as-a-service (RaaS) operations, where different affiliates use shared tools but apply their own strategies.
Before triggering encryption, attackers routinely disabled Microsoft Defender’s real-time protection and wiped Windows Event Logs using a PowerShell script that clears every log channel on the system, not just Security or System logs, making forensic recovery far harder.
The ransomware payload itself, consistently named win.exe, was staged in C:\PerfLogs\, a default Windows directory rarely monitored by security tools. Execution required a password parameter, complicating sandbox analysis.
Tactical Security Recommendations
Arctic Wolf recommends immediate action:
Patch CVE-2026-0257 across all internet-facing PAN-OS and Prisma Access deployments
Terminate all active GlobalProtect sessions after patching
Rotate all domain credentials, including the KRBTGT account, if exploitation is suspected
Monitor and restrict execution from C:\PerfLogs
Forward Windows Event Logs to a centralized SIEM to preserve evidence even if local logs are cleared
Arctic Wolf assesses with moderate confidence that exploitation of this vulnerability leading to Qilin ransomware deployment is ongoing, driven by widespread scanning activity and the RaaS model’s tendency to distribute working exploits across multiple affiliates.
The Privilege Paths Attackers See, That You Don’t: BeyondTrust Pathfinder Platform do it for You -> Get Free Identity Security Assessment
Tags
cyber security
cyber security news
Copy URL
Linkedin
Twitter
ReddIt
Telegram
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.
Cyber Security Guide
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
How DCSync Attack Helps Hackers Steal Password Hashes Silently from Active Directory
Top 10 Malware Used by Hackers Between July 20-26, 2026, to Launch Cyberattacks
Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate Networks
Latest Cyber News
Cyber Security
DNA Test Software Vulnerability Allows Attackers to Alter Analysis Data
Cyber Security News
Public PoC Released for Critical Rails Active Storage RCE Vulnerability
Cyber Security
Hugging Face Diffusers Vulnerabilities Enable Remote Code Execution Through Malicious AI Models
Cyber Security News
TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks
Cyber Security News
Hackers Exploit VeloCloud Orchestrator Command Injection Vulnerability in the Wild
Expert Talks
Cyber Security News
CMMC Phase II Is Paused, But Contractors’ Data-Security Obligations Are Not
Expert Talks
Security in the AI Era Starts with First Principles
Cyber Security News
Planning Your AI Security – How will You Manage All Your Resources?
Expert Talks
How Pro-Iran Hacktivist Networks Mobilize During Kinetic Conflict
Expert Talks
Why AI-generated identities mean verification can no longer be a one-time check