Qilin Ransomware Exploits Palo Alto GlobalProtect Flaw for Initial Access

Threat actors deploying Qilin ransomware exploited a Palo Alto Networks GlobalProtect authentication bypass flaw, CVE-2026-0257, as the consistent initial access vector across multiple June 2026 intrusions investigated by Arctic Wolf Labs.

The campaign moved rapidly from perimeter compromise to domain-wide encryption, with post-exploitation tactics varying between affiliates operating under Qilin’s ransomware-as-a-service model.

CVE-2026-0257 (CVSS 7.8) is an authentication bypass affecting the GlobalProtect portal and gateway in PAN-OS, exploitable when authentication override cookies are enabled alongside a specific certificate configuration.

Qilin Ransomware Exploits Palo Alto GlobalProtect Flaw

The flaw lies in how the gateway decrypts the cookie using a private key without verifying its signature, letting attackers forge valid cookies and recover the public key when the same certificate also serves the HTTPS interface.

Palo Alto Networks disclosed the issue on May 13, 2026, and Rapid7 observed active exploitation beginning as early as May 17. CISA subsequently added the flaw to its Known Exploited Vulnerabilities catalog, ordering federal agencies to mitigate it by June 1, 2026.

Affected versions span PAN-OS 12.1, 11.2, 11.1, and 10.2, along with Prisma Access, while Cloud NGFW and Panorama remain unaffected.security.

Arctic Wolf identified exploitation activity originating from numerous external IPs, with some sessions established from systems self-identifying with the hostname “kali,” consistent with Kali Linux attack platforms, and overlapping source IPs used for both exploitation and subsequent VPN access.

Once inside, actors established persistence via a distinctive registry Run key pattern and deployed layered remote-access tools including AnyDesk, Ngrok, and LogMeIn.

Qilin attack chain (Source: arcticwolf)
Qilin attack chain (Source: arcticwolf)

Credential harvesting followed through LSASS memory dumping via rundll32.exe and comsvcs.dll, and domain-wide NTDS extraction using ntdsutil’s Install From Media method, giving attackers authentication material for every domain account.

Lateral movement relied primarily on PsExec paired with Windows administrative shares, supplemented by SoftPerfect Network Scanner and NetExec for reconnaissance, with RDP as a secondary path.

Before deploying ransomware, actors executed PowerShell routines to clear Windows event logs enterprise-wide and disabled Microsoft Defender real-time protection to suppress detection.

In intrusions involving data theft, actors used Rclone, ProtonDrive, and FileZilla to exfiltrate data to MEGA cloud storage before encryption, while also targeting Veeam backup infrastructure to eliminate recovery options.

Other intrusions skipped exfiltration entirely, moving straight to encryption a variability consistent with multiple affiliates operating under the same RaaS toolkit but pursuing different objectives.

The Qilin payload, consistently named win.exe, was staged at C:\PerfLogs\ a default, rarely monitored Windows directory and executed with a password gate and a –no-admin flag to avoid triggering UAC prompts.

Encrypted files received a unique alphanumeric extension per intrusion, a hallmark of Qilin’s builder-based operation model, which has been active since 2022 and claimed over 500 victims in 2026 alone.

Mitigation

Organizations should patch CVE-2026-0257 immediately across all affected PAN-OS and Prisma Access versions, terminate active GlobalProtect sessions post-patch, and disable authentication override cookies or use dedicated certificates as an interim mitigation.

Security teams should monitor C:\PerfLogs\ for executable creation, hunt for VPN sessions from hosting-provider IPs or “kali”-named hosts, and forward logs to a centralized SIEM to preserve forensic data against enterprise-wide log clearing.

Rotating all domain credentials, including KRBTGT twice, is critical if exploitation is suspected, given the attackers’ consistent escalation to full domain compromise.

Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories