Qilin Ransomware Attacks Exploit PAN-OS VPN Bypass

Qilin ransomware affiliates are exploiting a patched PAN-OS authentication bypass to establish unauthorized VPN sessions and compromise Windows domains.
Illustration showing a Palo Alto Networks firewall connected to a laptop displaying the Qilin ransomware logo, representing exploitation of a PAN-OS vulnerability to deploy ransomware.

Qilin ransomware affiliates are exploiting a patched Palo Alto Networks authentication bypass vulnerability to enter corporate networks through GlobalProtect VPN services, according to new incident response findings from Arctic Wolf Labs.

The security firm investigated multiple intrusions during June 2026 that began with exploitation of CVE-2026-0257. Attackers reportedly used the flaw to establish unauthorized VPN sessions before stealing credentials, moving across Windows environments and deploying Qilin ransomware.

Palo Alto Networks has confirmed limited exploitation attempts against unpatched devices. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on May 29, requiring affected US federal agencies to remediate it by June 1.

The incidents show how quickly ransomware operators can turn a weakness in an internet-facing security appliance into domain-wide compromise. Firewalls and VPN gateways sit at the edge of enterprise networks, making authentication bypass vulnerabilities especially valuable to attackers seeking an alternative to stolen passwords or phishing.

GlobalProtect flaw opens unauthorized VPN sessions

CVE-2026-0257 affects the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS. The vulnerability becomes exploitable when authentication override cookies are enabled alongside certain certificate configurations.

A remote attacker can abuse the weakness without valid credentials to bypass authentication controls and establish an unauthorized VPN connection. The vendor assigned the flaw a CVSS 4.0 score of 7.8 and a High severity rating, while the National Vulnerability Database currently lists a CVSS 3.1 score of 9.1, or Critical.

Arctic Wolf said the attackers used successful exploitation to gain authenticated access through GlobalProtect. Some of the infrastructure observed across separate incidents overlapped, potentially indicating shared exploitation tooling or infrastructure used by Qilin affiliates.

The vulnerability affects supported releases across the PAN-OS 10.2, 11.1, 11.2 and 12.1 branches, as well as affected versions of Prisma Access. Panorama and Cloud NGFW are not affected. Palo Alto Networks has published the complete fixed-version matrix in its security advisory for CVE-2026-0257.

Attackers turn VPN access into domain compromise

After entering victim networks, the threat actors moved rapidly to preserve access and collect administrative credentials. Arctic Wolf observed attempts to extract credentials from Windows process memory and copy Active Directory database information, potentially giving attackers access to password hashes for accounts across the domain.

The operators then used compromised administrative accounts, Windows administrative shares and PsExec to execute tools and move between systems. They also deployed remote access and tunneling software, including AnyDesk, Ngrok and LogMeIn, in some of the investigated environments.

Before launching the ransomware, the attackers reportedly disabled Microsoft Defender real-time protection in some cases and cleared Windows event logs. These actions can reduce endpoint detection and destroy evidence that defenders need to reconstruct the intrusion.

Arctic Wolf observed the Qilin payload being password protected and staged in consistent locations across multiple victims. Password gating can prevent the malware from executing automatically in security sandboxes, complicating analysis and delaying identification.

Affiliate tactics ranged from encryption to data theft

The activity varied significantly after initial access. Some intrusions progressed quickly to widespread encryption without evidence of data theft. Others involved longer reconnaissance, extensive credential harvesting and exfiltration before the ransomware was deployed.

In double-extortion cases, the attackers reportedly used legitimate file transfer and cloud storage tools, including Rclone, Proton Drive, FileZilla and MEGA, to remove data from compromised environments. They also targeted backup infrastructure before encryption, an action intended to damage recovery options and increase pressure on victims.

Arctic Wolf said the differing attack patterns may reflect multiple affiliates operating through Qilin’s ransomware-as-a-service program. Affiliates can share ransomware tooling and access methods while choosing their own reconnaissance, persistence and data theft techniques.

Qilin, also known as Agenda, has operated since at least 2022 and uses a double-extortion model that combines file encryption with threats to publish stolen information. The group and its affiliates have targeted organizations across healthcare, manufacturing, education, government and professional services.

Organizations urged to patch and investigate

Administrators should update affected PAN-OS and Prisma Access deployments to a fixed version immediately. Palo Alto Networks also recommends upgrading all GlobalProtect portals and gateways that generate or accept authentication override cookies to prevent compatibility problems between patched and unpatched components.

After updating, organizations should terminate active GlobalProtect sessions so unauthorized connections cannot remain active. Where immediate patching is impossible, the vendor recommends disabling authentication override or using a dedicated certificate exclusively for authentication override cookies.

Security teams should review VPN logs for unexpected sessions, unfamiliar source networks, unusual device names and connections that do not match normal user locations. Suspected exploitation should trigger a broader investigation for credential dumping, administrative share access, remote management tools, log clearing and attempts to disable endpoint protection.

Organizations that confirm exploitation should assume attackers may have obtained privileged domain credentials. Response measures may need to include rotating administrative and service account passwords, securing backup systems and preserving logs in a centralized platform that attackers cannot erase from compromised endpoints.

Arctic Wolf assesses with moderate confidence that attacks exploiting CVE-2026-0257 and leading to Qilin ransomware deployment are likely continuing. Its complete technical findings and defensive recommendations are available in the company’s original research report.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site