top of page

Hackers exploit Palo Alto flaw to deploy Qilin ransomware

Arctic Wolf Labs investigated multiple June 2026 intrusions in which attackers exploited CVE-2026-0257 in Palo Alto Networks PAN-OS. The flaw allowed unauthorized GlobalProtect VPN access, enabling threat actors to steal credentials, compromise Active Directory, exfiltrate data, and deploy Qilin ransomware across Windows environments.

After gaining initial access, the attackers moved deeper into victim environments, collected credentials, established persistent remote-access channels, compromised Active Directory, stole data, and eventually deployed Qilin ransomware.

What happened to Palo Alto networks PAN-OS systems?

Arctic Wolf Labs investigated several separate intrusions in June 2026 that began with the exploitation of CVE-2026-0257 and ended with Qilin ransomware deployment.

Hackers exploit Palo Alto flaw to deploy Qilin ransomware
Hackers exploit Palo Alto flaw to deploy Qilin ransomware

CVE-2026-0257 is an authentication-bypass vulnerability affecting GlobalProtect Portal and GlobalProtect Gateway components in Palo Alto Networks PAN-OS. Under certain configurations, an unauthenticated remote attacker may bypass security controls and establish an unauthorized VPN connection.

Category

Details

Vulnerability

CVE-2026-0257

Vendor

Palo Alto Networks

Affected platform

PAN-OS and certain Prisma Access deployments

Affected components

GlobalProtect Portal and Gateway

Vulnerability type

Authentication bypass

Immediate impact

Unauthorized VPN access

Exploitation status

Observed by Rapid7 and Arctic Wolf; listed by CISA

Associated malware

Qilin ransomware

Products not affected

Panorama and Cloud NGFW

How did the Qilin ransomware attack chain work?

Once attackers established access through GlobalProtect, they could interact with the internal environment in a manner resembling a legitimate VPN user. This allowed them to move past the perimeter and focus on compromising accounts, endpoints, servers, and Active Directory.

How did the Qilin ransomware attack chain work?
How did the Qilin ransomware attack chain work?

Arctic Wolf Labs observed several recurring post-exploitation activities.

  1. Establishing persistence: The attackers created Registry Run Keys using unusual naming patterns. In several cases, the names began with an asterisk followed by six random lowercase characters.

  2. Deploying additional remote-access channels: Tools such as AnyDesk, Ngrok, and LogMeIn were installed to provide alternative access if the original VPN session was terminated.

  3. Stealing credentials: The attackers used rundll32.exe and comsvcs.dll to dump the memory of the Local Security Authority Subsystem Service, commonly known as LSASS

  4. Extracting Active Directory data: The attackers used ntdsutil.exe to obtain Active Directory database information. This can expose credentials and account data across an entire Windows domain.

  5. Moving laterally: PsExec and administrative shares such as C$ were used to execute commands or distribute files across multiple systems.

  6. Exfiltrating and encrypting data: In some incidents, Rclone was used to transfer data to the MEGA cloud-storage service before Qilin ransomware was deployed.

Why were the attacks difficult to detect?

The initial activity could appear as an authenticated VPN session. Organizations that focus primarily on failed login attempts, brute-force attacks, or visibly malicious traffic may therefore fail to identify the unauthorized access quickly.

The deletion of local event logs can severely limit forensic visibility. Organizations should therefore forward firewall, VPN, Active Directory, endpoint, and Windows logs to a centralized SIEM or protected log-storage platform.

Local administrators and compromised endpoint accounts should not be able to delete or modify the organization’s only copy of security logs.

Which organizations should investigate immediately?

Any organization running affected GlobalProtect components on vulnerable PAN-OS or Prisma Access versions should review Palo Alto Networks’ official advisory and upgrade to a fixed release.

Internet-facing systems should receive the highest priority because they may be directly scanned and targeted by external attackers.

What should organizations do now?

The first priority is to patch affected systems and invalidate any sessions that may have been created before remediation. Organizations should then investigate endpoints, Active Directory, VPN logs, and network activity for evidence of post-exploitation.

First 24-hour response checklist

  • Compare every PAN-OS and Prisma Access deployment against Palo Alto Networks’ CVE-2026-0257 advisory.

  • Upgrade affected systems to a vendor-confirmed fixed version.

  • Terminate all active GlobalProtect sessions after patching.

  • Review unusual VPN sessions dating back to at least May 17, 2026.

  • Identify unauthorized installations of AnyDesk, Ngrok, LogMeIn, PsExec, or Rclone.

  • Investigate LSASS memory access, comsvcs.dll execution, and use of ntdsutil.exe.

  • Confirm whether Microsoft Defender or another endpoint-security product was disabled.

  • Isolate systems showing signs of credential theft or lateral movement.

  • Verify that critical backups are offline, immutable, and recoverable.

What does the IPSIP Vietnam expert perspective show?

Multi-factor authentication should not be treated as the only defense when the vulnerability affects the authentication process itself.

What can organizations implement internally?

  • Maintain an accurate inventory of firewalls, VPN gateways, software versions, and asset owners.

  • Define emergency patching service-level agreements for Internet-facing systems.

  • Restrict VPN users to only the applications and network segments required for their roles.

  • Separate remote-user networks from management interfaces and critical servers.

  • Monitor access to LSASS and changes to Registry Run Keys.

  • Establish an allowlist for remote-access and file-transfer tools.

  • Forward security logs to centralized, tamper-resistant storage.

  • Test offline or immutable backups on a scheduled basis.

  • Run tabletop exercises involving VPN compromise and Active Directory takeover.

Which IPSIP Vietnam's services are relevant?

Organizations that lack continuous monitoring may consider a 24/7 Security Operations Center service. Centralized monitoring can correlate events across firewalls, VPN systems, endpoints, and Active Directory to identify suspicious activity earlier.

IPSIP Vietnam cybersecurity solutions
IPSIP Vietnam cybersecurity solutions

Penetration Testing can also be used to evaluate whether a compromised VPN account could reach sensitive servers, management networks, or Active Directory resources. These services do not replace patching, but they can help validate whether access controls and network segmentation are operating as intended.

References

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page