Connect with us

Security

Exploiting PAN-OS Authentication Bypass: The Qilin Ransomware Attack

Published

on

Exploited Palo Alto Networks Vulnerability Leads to Qilin Ransomware Attacks

Security researchers have reported that threat actors are exploiting a recently patched high-severity vulnerability in Palo Alto Networks PAN-OS to launch Qilin ransomware attacks on unsuspecting victims.

Arctic Wolf Labs conducted investigations into multiple intrusions in June 2026, which were initiated by exploiting CVE-2026-0257, an authentication bypass flaw with a CVSS score of 7.8. This vulnerability affects the portal and gateway components of PAN-OS software.

By successfully exploiting this vulnerability, remote attackers can bypass authentication and establish VPN sessions without valid credentials, particularly when authentication override cookies are enabled with specific certificate configurations.

According to Arctic Wolf Labs, the attackers displayed consistent operational patterns despite variations in their methods. These patterns included staging ransomware at C:PerfLogs, using PsExec for lateral execution via administrative shares, deploying password-protected ransomware payloads, and implementing thorough log-clearing routines.

Further analysis revealed that the threat actors leveraged the vulnerability to gain authenticated access to victim networks by establishing SSL VPN sessions. They then escalated their attacks by harvesting credentials and moving laterally through Windows administrative shares using compromised administrative accounts.

The attackers also took deliberate steps to clear event logs and disable Microsoft Defender Real-Time Protection before executing the ransomware payload. This was done to reduce the chances of detection and avoid leaving behind forensic evidence.

Although there were similarities in ransomware staging paths and execution methods, follow-on attacks varied among victims. These variations ranged from enterprise-wide encryption with no data exfiltration to large-scale credential theft and data exfiltration to cloud services before ransomware deployment.

See also  Europol's Operation AudiA6: Taking Down the Crypto Laundering Network of Ransomware Gangs

Arctic Wolf noted that this variability is in line with Ransomware-as-a-Service (RaaS) models, where multiple affiliates may share initial access infrastructure and ransomware tools while employing their own post-exploitation techniques.

Trending