CVE-2026-0257 Qilin Ransomware Hits GlobalProtect
A single vulnerable VPN gateway can lay open an entire corporate network. Affiliates of the Qilin extortion group are already turning a fresh PAN-OS GlobalProtect flaw to precisely that purpose.
Arctic Wolf specialists have linked several June 2026 attacks to the vulnerability. Each one culminated in the encryption of Windows systems.
Understanding the Vulnerability
CVE-2026-0257 permits an attacker to bypass authentication on GlobalProtect portals and gateways. Consequently, an adversary can establish an unauthorised VPN connection without valid credentials.
The flaw affects Palo Alto Networks appliances running PAN-OS. However, it does not touch Panorama or Cloud NGFW deployments.
A Patch That Arrived Before the Storm
Palo Alto Networks released fixes on 13 May. Two weeks later, Rapid7 specialists confirmed attacks against systems that had not been updated.
CISA followed at the end of May by adding the flaw to its catalogue of known exploited vulnerabilities. That designation signalled the urgency plainly enough.
How the Intrusions Unfolded
Entry and Persistence
In every incident examined, the attackers connected over VPN from systems running Kali Linux. Afterwards, they entrenched themselves in the network.
Their footholds relied on autorun keys, scheduled tasks, and remote access utilities. None of these techniques is exotic, yet together they proved durable.
Credentials and Lateral Movement
The operators then harvested credentials from LSASS memory and the Active Directory database. From there, they traversed the estate using PsExec and RDP.
Finally, they distributed Qilin across the entire domain. The path from perimeter compromise to domain-wide encryption proved remarkably short.
Two Distinct Playbooks
Subsequent behaviour diverged sharply between cases. In some intrusions, the attackers encrypted infrastructure swiftly and stole nothing at all.
Elsewhere, the approach grew far more deliberate. Those operators conducted reconnaissance, disabled Microsoft Defender, and purged Windows event logs. Moreover, they installed AnyDesk, Ngrok, and LogMeIn before siphoning data out through cloud storage and launching the ransomware.
Arctic Wolf assesses that these differences may reflect several Qilin affiliates operating under the ransomware-as-a-service model.
The Payload Itself
The malicious file typically bore the name win.exe. Attackers staged it in the C:\PerfLogs directory and launched it with password-protected parameters.
Once running, the program encrypted files and appended distinctive extensions. Those extensions varied from one campaign to the next.
Why the Threat Persists
Arctic Wolf believes attacks through CVE-2026-0257 are probably continuing. Active scanning for vulnerable appliances underpins that judgement.
Palo Alto Networks therefore urges administrators to install the released updates or apply the recommended mitigations. Externally reachable GlobalProtect gateways deserve the most immediate attention.
Practical Defensive Steps
Patching remains the priority, yet it is not the whole answer. Forwarding Windows event logs to a central SIEM preserves evidence even when local logs are wiped.
Likewise, monitor for unexpected remote access tooling and unusual VPN sessions. Those signals often surface long before encryption begins.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.