Skip to main content
Emerging ThreatsMalware & Ransomware

Qilin Ransomware Exploits Palo Alto Networks Flaw for Initial Access

Network equipment on a rack in a mid-tone lit IT room with blurred background.
"Post-exploitation tradecraft varied across intrusions, from rapid encryption-only operations to full double-extortion, possibly suggesting multiple affiliates operating under the Qilin ransomware-as-a-service (RaaS) umbrella," Arctic Wolf Labs said.

CVE-2026-0257: an authentication bypass in PAN-OS

Arctic Wolf Labs investigated multiple intrusions in June 2026 that all began with exploitation of CVE-2026-0257, a high-severity authentication bypass affecting the portal and gateway components of Palo Alto Networks PAN-OS software. The vulnerability, assigned a CVSS score of 7.8, allowed unauthenticated remote attackers to sidestep authentication and establish VPN sessions without valid credentials when authentication override cookies were enabled with specific certificate configurations.

From VPN bypass to authenticated network access

Attackers weaponized the PAN-OS flaw to create SSL VPN sessions that gave them authenticated access into victim networks. Arctic Wolf described a consistent pattern: after establishing VPN access, adversaries escalated activity to harvest credentials and move laterally through Windows administrative shares by using compromised administrative accounts.

Ransomware staging, execution and persistence patterns

Across the intrusions, the Qilin (aka Agenda) ransomware was typically staged to C:\PerfLogs\, and execution commonly used PsExec to run payloads across administrative shares. Attackers deployed password-protected ransomware binaries and implemented broad log-clearing routines before running the payloads. They also disabled Microsoft Defender Real-Time Protection to reduce the chance of detection and to limit forensic evidence.

Arctic Wolf noted an unusual Windows Registry persistence pattern in these intrusions: an asterisk followed by six randomized lowercase alphabetic characters. While the staging path and PsExec execution recurred across cases, follow-on activity differed from victim to victim.

Varied follow-on tradecraft and data exfiltration tools

Post-access behavior ranged widely. Some intrusions proceeded directly to enterprise-wide encryption without evidence of data exfiltration; others showed extensive reconnaissance via remote access tools such as AnyDesk, Ngrok, or LogMeIn. In several instances, adversaries exfiltrated large volumes of data to the MEGA cloud service prior to deploying ransomware, using tools including Rclone, Proton Drive, and FileZilla to move files.

What this means for technologists, affected enterprises, and adversaries

  • Technologists and security teams: Watch specifically for the indicators Arctic Wolf documented — ransomware staged to C:\PerfLogs\, PsExec use over administrative shares, password-protected payloads, aggressive log-clearing, disabling of Microsoft Defender Real-Time Protection, and the registry persistence pattern (an asterisk followed by six randomized lowercase letters). Those signals together map to the attack sequence described in the intrusions.
  • Affected enterprises and procurement leaders: The chain began with a PAN-OS authentication bypass tied to authentication override cookies and certificate configuration; organizations using PAN-OS should verify whether those settings were in use and ensure any vendor-supplied patches are applied. The diversity of follow-on tools — from remote access services to cloud storage and transfer utilities — underscores the need to inventory allowed software and to monitor outbound data transfers and cloud storage endpoints.
  • Adversaries and affiliates: Arctic Wolf’s observation that post-exploitation approaches ranged from encryption-only to double-extortion and credential theft is consistent with a RaaS model in which multiple affiliates can reuse initial access while applying different post-compromise toolsets and goals.

Arctic Wolf’s reporting ties a specific, now-patched PAN-OS authentication bypass to a clear sequence of attacker behaviors: VPN session establishment without credentials, credential harvesting, lateral movement via administrative shares, and a mix of encryption and exfiltration tactics. The combination of a reproducible staging location, PsExec-based lateral execution, registry persistence with a distinctive naming pattern, and deliberate log and protection disablement offers defenders concrete artifacts to hunt for — even as the variation in follow-on tradecraft suggests multiple operators may be at work under the Qilin RaaS umbrella.

Original story: https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html