HomeTopics 4Network SecurityCookie Crumbles: How a Palo Alto VPN Flaw Became Qilin’s Golden Ticket

Cookie Crumbles: How a Palo Alto VPN Flaw Became Qilin’s Golden Ticket

Date:

Related stories

spot_imgspot_imgspot_imgspot_img

Less than two months after Palo Alto Networks warned of limited exploitation of a high-severity authentication bypass in its PAN-OS firewalls, researchers have now tied a wave of June 2026 Qilin ransomware intrusions directly to the same flaw .

Arctic Wolf Labs, which investigated multiple distinct incidents last month, found that CVE-2026-0257 served as the consistent entry point across every case. Attackers exploited the GlobalProtect VPN portal to establish authenticated sessions without valid credentials and in some cases, moved to full domain encryption in hours .

The vulnerability, rated 7.8 on the CVSS scale, affects PAN-OS versions 10.2, 11.1, 11.2, and 12.1 prior to specific patched builds, along with certain Prisma Access releases . Cloud NGFW and Panorama are not impacted .

“An authentication bypass in an edge-facing enterprise VPN appliance can have significant impact,” Rapid7 warned in May when it first observed exploitation attempts .

What Happened? Understanding CVE-2026-0257

The entry point for these intrusions is CVE-2026-0257 (CVSS 7.8), a critical flaw affecting Palo Alto Networks’ PAN-OS. The vulnerability stems from how the GlobalProtect portal handles authentication override cookies. When specific certificate configurations are enabled, unauthenticated remote attackers can craft malicious requests to bypass authentication completely gaining direct, interactive VPN access without needing valid credentials.

[Attacker / Kali Linux] 
       │
       ▼ (Exploits CVE-2026-0257 Auth Bypass)
[Palo Alto GlobalProtect Gateway]
       │
       ▼ (Valid SSL VPN Session Established)
[Internal Network / Domain Controller]
       │
       ├──► LSASS & NTDS.dit Credential Theft
       ├──► Selective/Full Event Log Wiping
       └──► Qilin Ransomware Executed (C:\PerfLogs\win.exe)

Forensic analysis revealed that threat actors frequently connected from infrastructure self-identifying with the hostname kali. In multiple cases, the exact same external IP addresses were used for initial vulnerability scanning and subsequent VPN session establishment, indicating automated exploitation toolkits.

Arctic Wolf now confirms that impact is being realized at scale.

The Qilin Playbook: Speed, Redundancy, and Evasion

The intrusions all started the same way: attackers exploited CVE-2026-0257 to gain interactive VPN access, skipping perimeter authentication entirely .

From there, the attackers followed a high-speed playbook that Arctic Wolf observers describe as both methodical and adaptive:

Persistence. The attackers established registry Run keys with a distinctive naming pattern (*[a-z]{6}) and deployed multiple remote access tools – AnyDesk, Ngrok, and LogMeIn – to ensure redundant connectivity .

Credential Harvesting. They dumped LSASS memory using rundll32.exe and comsvcs.dll, disguising the output as .odt files to evade detection . Then they extracted the entire Active Directory database via ntdsutil.exe, gaining domain-wide credential access .

Lateral Movement. Using PsExec and administrative shares (C$), the attackers moved across the network—always credential-driven and always with validation. Shellbag artifacts showed they manually navigated to C:\PerfLogs\ to confirm write access before staging payloads .

Defense Evasion. Before deploying ransomware, the attackers systematically cleared Windows Event Logs using a PowerShell routine that enumerates and wipes every log channel on the system—not just Security or System logs . Microsoft Defender’s real-time protection was also disabled in some cases .

Ransomware Deployment. The Qilin payload, consistently named win.exe, was staged at C:\PerfLogs\—a default Windows directory rarely monitored by security tools . Execution required a password parameter, complicating sandbox analysis .

Same Entry, Different Tradecraft

What makes this campaign particularly notable is the variability in post-exploitation behavior across intrusions a hallmark of the RaaS model .

Some affiliates rushed straight to encryption with minimal dwell time and no data exfiltration. Others conducted extensive reconnaissance, deployed Rclone to exfiltrate data to MEGA cloud storage, and then deployed ransomware .

This divergence, combined with overlapping source IPs and systems self-identifying as kali hosts, suggests shared initial-access infrastructure or tooling powering multiple Qilin affiliates .

“This variability is consistent with RaaS models, in which multiple affiliates may leverage shared initial access infrastructure and ransomware tooling while applying their own preferred post-exploitation methodologies,” Arctic Wolf noted .

MEA & Global Implications

For the Middle East and Africa, Qilin is already a familiar name.

A recent ThreatMon analysis of 170 ransomware incidents across the region in 2026 found that Qilin was among the most active groups, hitting Turkey 9 times and targeting healthcare, food, and holding companies . The group has also been linked to attacks on logistics and energy firms across the Gulf .

Globally, Qilin was the most prominent ransomware group in 2025, with 1,153 publicly disclosed victims . The group’s RaaS model continues to scale, and organizations across healthcare, manufacturing, education, government, and professional services remain in the crosshairs .

Arctic Wolf assesses with moderate confidence that these intrusions are likely ongoing .

Defensive Guidance: 10 Actions for Security Teams

Based on Arctic Wolf’s analysis of the CVE-2026-0257/Qilin attack chain, here are 10 practical steps to detect, prevent, and respond to these intrusions :

– Patch & Harden (Immediate)

1. Patch CVE-2026-0257 immediately. Update all internet-facing Palo Alto PAN-OS and Prisma Access deployments to fixed versions .

2. Terminate all active GlobalProtect sessions after patching to immediately invalidate unauthorized sessions .

3. Rotate all credentials if exploitation is suspected—including domain admin accounts, KRBTGT (twice), service accounts, and cloud storage credentials .

– Hunt & Detect

4. Review VPN logs for anomalies—sessions from hosting providers, kali hostnames, or multiple internal IP assignments from the same source .

5. Monitor C:\PerfLogs\ for executable creation and block execution from this directory .

6. Alert on administrative share access patterns—remote writes to C$\Windows\Temp\ or C$\PerfLogs\, and PSEXESVC.exe creation .

7. Forward Windows Event Logs to a centralized SIEM—attackers clear local logs, so centralized preservation is critical . Alert on Event ID 1102 (audit log cleared) .

8. Block/alert on remote access tools (AnyDesk, Ngrok, LogMeIn) and outbound traffic to MEGA storage from non-business systems .

– Structural

9. Restrict NTDS.dit access—monitor ntdsutil.exe with IFM arguments and alert on VSS access to the NTDS file path .

10. Maintain and test an incident response playbook for ransomware—early detection during credential access or lateral movement can prevent encryption .

Conclusion

The June 2026 wave of Qilin ransomware intrusions linked to CVE-2026-0257 is a sobering reminder that perimeter appliances remain prime targets for initial compromise. While post-exploitation tradecraft varies across affiliates, the entry point is consistent—and once domain credentials are harvested, the outcome is often the same: full domain encryption or double extortion .

Organizations that patch aggressively, monitor log-clearing and credential access, and restrict staging directories will have the best chance of catching these intrusions before the ransomware deploys. As Arctic Wolf puts it: “Organizations that detect and respond during initial access or early credential access can prevent irreversible encryption and data theft” .

For training and certification programs on incident response, threat hunting, and SOC operations, visit Saintynet Cybersecurity.

Keywords: Ransomware, CVE-2026-0257, Qilin Ransomware, Palo Alto Networks, GlobalProtect, Incident Response, Threat Intelligence, Cybersecurity Training, Vulnerability Management, Arctic Wolf Labs.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img