Published on July 21, 2026

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access


Severity

Medium

Detail

Threat actors have been exploiting the recently patched CVE-2026-0257 vulnerability in Palo Alto Networks PAN-OS as an initial access vector to deploy Qilin (Agenda) ransomware. The authentication bypass flaw affects the PAN-OS portal and gateway components, allowing attackers to establish SSL VPN sessions without valid credentials when authentication override cookies are enabled alongside specific certificate configurations.

Investigations by Arctic Wolf Labs identified multiple incidents in June 2026 where attackers leveraged this vulnerability to infiltrate enterprise networks. The attacks displayed varying objectives, ranging from rapid encryption-only campaigns to full double-extortion operations involving data theft before encryption, indicating activity from different affiliates operating under the Qilin ransomware-as-a-service (RaaS) model.

How?

After successfully exploiting the PAN-OS vulnerability, attackers established authenticated VPN access to victim environments and moved laterally using compromised administrative accounts. They harvested credentials, accessed Windows administrative shares, and used PsExec to distribute the ransomware across the network.

Before deploying the ransomware, the threat actors attempted to evade detection by clearing Windows event logs and disabling Microsoft Defender Real-Time Protection. The ransomware payload was commonly staged in the C:\PerfLogs\ directory, with some attacks also creating persistence through an unusual Windows Registry key consisting of an asterisk followed by six random lowercase letters.

While post-compromise activity differed between victims, attackers frequently performed reconnaissance using remote access tools such as AnyDesk, Ngrok, and LogMeIn. In more advanced intrusions, they exfiltrated sensitive data to cloud storage services including MEGA, Proton Drive, and Rclone, sometimes using FileZilla, before launching the ransomware.

Recommendations

Organizations should immediately apply the latest PAN-OS security updates to remediate CVE-2026-0257 and review SSL VPN configurations, particularly environments using authentication override cookies. VPN authentication logs should be monitored for suspicious or unexpected login activity, especially from unfamiliar IP addresses.

Network defenders should restrict administrative privileges, monitor the execution of tools such as PsExec, and detect attempts to disable security controls or clear Windows event logs. Implementing network segmentation, enabling multi-factor authentication for remote access, and maintaining offline, regularly tested backups can significantly reduce the impact of ransomware attacks. Additionally, monitor for unusual outbound connections and large data transfers to cloud storage services that may indicate data exfiltration prior to ransomware deployment.

Source

https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html