Bulletins //

Cyber Insights: Hackers Exploit Palo Alto PAN-OS Flaw to Deploy Qilin Ransomware

27 July 2026

Overview

A critical vulnerability affecting Palo Alto Networks PAN-OS GlobalProtect gateways is being actively exploited by ransomware operators to gain unauthorised access to enterprise networks.

Security researchers at Arctic Wolf have linked multiple June 2026 incidents to CVE-2026-0257, a high-severity authentication bypass flaw that allows attackers to establish GlobalProtect VPN sessions before progressing rapidly through the attack lifecycle. In the incidents investigated, compromise quickly escalated into credential theft, Active Directory takeover, data exfiltration and deployment of the Qilin (Agenda) ransomware.

Unlike opportunistic ransomware campaigns, these attacks follow a well-defined intrusion methodology. Attackers use the vulnerable VPN gateway as their initial foothold before leveraging legitimate Windows administration tools to move laterally across the environment, making detection more challenging than attacks relying solely on malware.

With exploitation already confirmed in the wild, organisations running vulnerable PAN-OS versions should prioritise remediation immediately.


What is CVE-2026-0257?

The issue centred on the way Opera GX handled the installation of browser mods.

Normally, browser extensions and modifications require some level of user approval before they can be installed. In this case, however, researchers found that a specially crafted website could silently trigger the installation of a GX Mod without displaying prompts, permission requests or confirmation messages.

The victim simply needed to visit a malicious webpage.

Once installed, the browser modification remained active across future browsing sessions, allowing attacker-controlled CSS (Cascading Style Sheets) to influence how websites were rendered inside the browser.

While CSS is typically used to control the appearance of webpages, researchers demonstrated that it could also be manipulated to infer sensitive information from authenticated websites by exploiting browser behaviour rather than directly reading page content.


How the Attack Unfolds

Incident responders observed a remarkably consistent sequence of activity across multiple compromises.

After exploiting the vulnerability to establish a GlobalProtect VPN session, attackers immediately begin gathering credentials from the Windows environment. LSASS memory is targeted to recover user credentials, while Active Directory databases are extracted using legitimate Windows utilities.

Once administrative credentials have been obtained, the attackers pivot throughout the network using built-in Windows administrative shares and PsExec before deploying ransomware across the domain.

Several victims also experienced data theft prior to encryption, indicating that Qilin affiliates continue to operate a double-extortion model designed to maximise pressure during ransom negotiations.

The ransomware payload itself was frequently executed from:

C:\PerfLogs\win.exe

Before encryption, investigators also observed attempts to disable Microsoft Defender and remove Windows Event Logs in an effort to reduce forensic evidence.


Why This Matters

Remote access infrastructure remains one of the most attractive targets for ransomware operators because it provides direct access into corporate environments.

Unlike phishing attacks, which rely on user interaction, vulnerabilities affecting VPN gateways allow attackers to bypass traditional endpoint defences entirely and establish an initial foothold at the network perimeter.

Once inside, Qilin affiliates rely primarily on legitimate administrative utilities rather than bespoke malware. Tools such as PsExec, ntdsutil.exe, PowerShell and Windows administrative shares are all commonly used by IT administrators, allowing malicious activity to blend into normal operational behaviour.

This “living off the land” approach means behavioural monitoring becomes far more important than signature-based malware detection alone.


Who is Qilin?

Qilin, also known as Agenda, has operated as a Ransomware-as-a-Service (RaaS) platform since at least 2022.

Like many modern ransomware groups, Qilin provides affiliates with ransomware tooling while allowing individual operators to conduct their own intrusion campaigns. This explains why investigators observed slight variations in post-compromise activity despite the same vulnerability being exploited.

The group’s objectives remain consistent:

  • Gain initial access
  • Escalate privileges
  • Steal sensitive data
  • Encrypt enterprise systems
  • Extort victims using both encryption and data leakage

The campaign demonstrates that ransomware groups continue to favour proven attack techniques over sophisticated custom malware.


Detection & Monitoring Recommendations

Organisations that permit Opera GX within corporate environments should first verify that all installations have been Because exploitation begins through GlobalProtect, organisations should closely review VPN authentication activity for signs of compromise.

Security teams should investigate unexpected VPN sessions, particularly those originating from hosting providers, unfamiliar countries or devices identifying themselves with the hostname “kali”.

Within Windows environments, analysts should also monitor for behaviours commonly associated with post-compromise activity, including:

  • Execution from C:\PerfLogs
  • PsExec service creation (PSEXESVC.exe)
  • LSASS memory dumping
  • Execution of ntdsutil.exe
  • Registry Run keys with randomly generated names
  • Remote administration tools such as AnyDesk, Ngrok, MeshAgent or LogMeIn
  • File transfer utilities including Rclone, ProtonDrive, FileZilla and MEGA

Additional attention should be given to Windows Event Log clearing, Microsoft Defender tampering and unusual writes to administrative shares, as these activities frequently occurred immediately before ransomware deployment.


Recommended Actions

The highest priority is applying Palo Alto’s security updates to all affected GlobalProtect gateways and confirming that vulnerable PAN-OS versions are no longer in use.

Following patching, organisations should terminate all active VPN sessions and require users to authenticate again. This helps prevent attackers from maintaining existing sessions established before remediation.

Security teams should then perform retrospective log analysis to identify suspicious VPN activity dating back to June 2026, paying particular attention to authentication anomalies and administrator activity originating from remote connections.

Finally, organisations should validate the integrity of Active Directory backups, ensure security logs are forwarded to a central SIEM platform, and confirm that alerts exist for credential dumping, event log clearing and execution from unusual system directories.


Analyst Assessment

The exploitation of CVE-2026-0257 should be treated as a serious operational threat due to the speed with which attackers can progress from initial access to full ransomware deployment.

Although the vulnerability itself provides only the initial foothold, the observed attack chains show mature operators rapidly leveraging credential dumping, Active Directory extraction and lateral movement to compromise entire environments.

The absence of bespoke malware throughout much of the intrusion makes behavioural detection particularly important. Organisations relying solely on malware signatures or antivirus protections may miss critical stages of the attack before ransomware is deployed.

Given the active exploitation already observed, immediate patching, enhanced VPN monitoring and proactive threat hunting should all be considered high-priority defensive measures.


How NormCyber MDR Helps Detect Ransomware Before Encryption

Campaigns like this highlight why detecting attacker behaviour early is critical. By the time ransomware is deployed, the compromise has often been underway for hours or even days. NormCyber’s Managed Detection and Response (MDR) service provides continuous monitoring across VPN infrastructure, identities, endpoints and Active Directory, enabling our SOC analysts to identify suspicious activity long before encryption begins.

Our detection capabilities focus on the behaviours observed throughout campaigns like Qilin, including anomalous VPN authentication, credential dumping, privilege escalation, lateral movement, remote administration tool usage and attempts to disable security controls. By correlating these signals across the environment, NormCyber MDR helps organisations interrupt attacks during the reconnaissance and post-compromise stages, reducing the likelihood of domain-wide compromise, data theft and ransomware deployment.


Sources

Primary:
https://arcticwolf.com/resources/blog/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware/


Secondary:
https://gbhackers.com/palo-alto-pan-os-flaw-to-deploy-qilin-ransomware/