Arctic Wolf
Read post

Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware

Arctic Wolf Labs investigated multiple intrusions in June 2026 where threat actors exploited CVE-2026-0257, an authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect, to deploy Qilin ransomware. The vulnerability allowed unauthenticated attackers to establish VPN sessions, after which they performed LSASS dumping and NTDS extraction for credential harvesting, used PsExec and RDP for lateral movement, deployed remote access tools (AnyDesk, Ngrok, LogMeIn), exfiltrated data via Rclone to MEGA in double-extortion cases, and cleared all Windows event logs before encrypting systems. Consistent staging at C:\PerfLogs\, a distinctive registry persistence pattern, and overlapping Kali Linux infrastructure across victims suggest shared tooling or coordinated affiliates under the Qilin RaaS model. Defensive recommendations include immediate patching, credential rotation, centralized log forwarding, monitoring C:\PerfLogs\ for executables, and blocking unsanctioned remote access tools.

    #ransomware
Jul 20•17m read time•From arcticwolf.com
Post cover image
Table of contents
Key TakeawaysSummaryBackgroundTechnical DetailsDefensive GuidanceConclusionAppendix
9.3K Impressions
Arctic Wolf's image
Arctic Wolf

ArcticWolf's platform is a central hub for cybersecurity professionals, offering insights into manag...

77 Followers

•

107 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard