{"id":14453,"date":"2026-07-21T10:04:27","date_gmt":"2026-07-21T10:04:27","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/07\/21\/hackers-exploiting-palo-altos-pan-os-vulnerability-to-deploy-qilin-ransomware\/"},"modified":"2026-07-21T10:04:27","modified_gmt":"2026-07-21T10:04:27","slug":"hackers-exploiting-palo-altos-pan-os-vulnerability-to-deploy-qilin-ransomware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/07\/21\/hackers-exploiting-palo-altos-pan-os-vulnerability-to-deploy-qilin-ransomware\/","title":{"rendered":"Hackers Exploiting Palo Alto\u2019s PAN-OS Vulnerability to Deploy Qilin Ransomware"},"content":{"rendered":"<p>    Hackers Exploiting Palo Alto\u2019s PAN-OS Vulnerability to Deploy Qilin Ransomware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">Threat actors are actively exploiting a critical authentication bypass flaw in Palo Alto Networks firewalls to breach corporate networks and deploy Qilin ransomware, according to new research from Arctic Wolf Labs.<\/p>\n<p class=\"wp-block-paragraph\">The security firm investigated multiple intrusions throughout June 2026, all tracing back to the same vulnerability as the initial point of entry.<\/p>\n<p class=\"wp-block-paragraph\">The flaw, <a href=\"https:\/\/cybersecuritynews.com\/palo-alto-vpn-vulnerability-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">tracked as CVE-2026-0257 (CVSS 7.8)<\/a>, affects the GlobalProtect portal and gateway in PAN-OS. It becomes exploitable when authentication override cookies are enabled alongside specific certificate configurations, allowing unauthenticated attackers to bypass login controls entirely and establish legitimate-looking VPN sessions.<\/p>\n<p class=\"wp-block-paragraph\">Affected versions include PAN-OS 12.1, 11.2, 11.1, and 10.2 (prior to specific patched builds), along with certain Prisma Access releases. Palo Alto Networks has confirmed limited active exploitation in the wild.<\/p>\n<p class=\"wp-block-paragraph\">In the intrusions Arctic Wolf reviewed, attackers used compromised VPN sessions to gain direct, interactive access to victim networks \u2014 completely skipping perimeter authentication.<\/p>\n<h2 id=\"h-pan-os-vulnerability-exploited\" class=\"wp-block-heading\"><strong>PAN-OS Vulnerability Exploited<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Once inside, attackers followed a fast-moving playbook:<\/p>\n<ul class=\"wp-block-list\">\n<li>Established persistence using registry Run keys with a distinctive naming pattern (an asterisk plus six random lowercase letters)<\/li>\n<li>Deployed remote access tools like <a href=\"https:\/\/cybersecuritynews.com\/anydesk-0-day-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">AnyDesk<\/a>, Ngrok, and LogMeIn for redundant connectivity<\/li>\n<li>Dumped credentials from LSASS memory using rundll32.exe and comsvcs.dll, disguising output as a \u201c.odt\u201d file to evade detection<\/li>\n<li>Extracted the entire Active Directory database via ntdsutil.exe, gaining domain-wide credential access<\/li>\n<li>Used PsExec and administrative shares (C$) for lateral movement across the network<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">Notably, several attacks originated from systems self-identifying with the hostname \u201ckali,\u201d and overlapping IP addresses appeared in both the initial exploitation and later VPN sessions, suggesting shared infrastructure or tooling among Qilin affiliates.<\/p>\n<p class=\"wp-block-paragraph\">While the entry point and core techniques remained stable, post-exploitation behavior varied significantly. Some intrusions moved straight to encryption with minimal dwell time, while others involved extensive reconnaissance, credential harvesting at scale, and data theft via Rclone to MEGA cloud storage before ransomware deployment.<\/p>\n<p class=\"wp-block-paragraph\">This variation is typical of <a href=\"https:\/\/cybersecuritynews.com\/new-shinysp1d3r-ransomware-as-a-service-in-active-development\/\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware-as-a-service (RaaS) operations<\/a>, where different affiliates use shared tools but apply their own strategies.<\/p>\n<p class=\"wp-block-paragraph\">Before triggering encryption, attackers routinely disabled Microsoft Defender\u2019s real-time protection and wiped Windows Event Logs using a PowerShell script that clears every log channel on the system, not just Security or System logs, making forensic recovery far harder.<\/p>\n<p class=\"wp-block-paragraph\">The ransomware payload itself, consistently named <code>win.exe<\/code>, was staged in <code>C:PerfLogs<\/code>, a default Windows directory rarely monitored by security tools. Execution required a password parameter, complicating sandbox analysis.<\/p>\n<h2 id=\"h-tactical-security-recommendations\" class=\"wp-block-heading\"><strong>Tactical Security Recommendations<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Arctic Wolf recommends immediate action:<\/p>\n<ul class=\"wp-block-list\">\n<li>Patch CVE-2026-0257 across all internet-facing PAN-OS and Prisma Access deployments<\/li>\n<li>Terminate all active GlobalProtect sessions after patching<\/li>\n<li>Rotate all domain credentials, including the KRBTGT account, if exploitation is suspected<\/li>\n<li>Monitor and restrict execution from C:PerfLogs<\/li>\n<li>Forward Windows Event Logs to a centralized SIEM to preserve evidence even if local logs are cleared<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/arcticwolf.com\/resources\/blog\/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Arctic Wolf assesses with moderate confidence<\/a> that exploitation of this vulnerability leading to Qilin ransomware deployment is ongoing, driven by widespread scanning activity and the RaaS model\u2019s tendency to distribute working exploits across multiple affiliates.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 87%,rgb(169,184,195) 100%)\"><strong>The Privilege Paths Attackers See, That You Don\u2019t: BeyondTrust Pathfinder Platform do it for You -&gt; <a href=\"https:\/\/www.beyondtrust.com\/products\/identity-security-insights\/assessment?utm_source=cybersecuritynews&amp;utm_medium=web&amp;utm_campaign=prospecting&amp;campid=701Vw00000aN1mhIAC\">Get Free Identity Security Assessment<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cve-2026-0257-qilin-ransomware\/\">Hackers Exploiting Palo Alto\u2019s PAN-OS Vulnerability to Deploy Qilin Ransomware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cve-2026-0257-qilin-ransomware\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Exploiting Palo Alto\u2019s PAN-OS Vulnerability to Deploy Qilin Ransomware Threat actors are actively exploiting a critical authentication bypass flaw in Palo Alto Networks firewalls to breach corporate networks and deploy Qilin ransomware, according to new research from Arctic Wolf Labs. The security firm investigated multiple intrusions throughout June 2026, all tracing back to the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-14453","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/14453"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=14453"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/14453\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=14453"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=14453"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=14453"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}