Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware

Arctic Wolf Labs threat research

Key Takeaways

  • Multiple June 2026 intrusions all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances
  • Ransomware staged at C:\PerfLogs\, using PsExec for lateral execution via administrative shares
  • Overlapping source IP addresses across intrusions suggesting shared exploitation infrastructure
  • Moderate confidence that intrusions leveraging CVE-2026-0257 and leading to Qilin ransomware deployment are likely ongoing

Vulnerability Overview: CVE-2026-0257

CVE-2026-0257 is an authentication bypass vulnerability affecting the GlobalProtect portal and gateway in Palo Alto Networks PAN-OS, with a CVSS score of 7.8 (High). Affected versions include PAN-OS 10.2, 11.1, 11.2, and 12.1 across specific sub-versions.

Post-Exploitation Steps Observed

  1. VPN sessions established from systems with hostname kali
  2. Registry Run key persistence using pattern *[a-z]{6}
  3. Remote tools deployed: AnyDesk, Ngrok, LogMeIn, MeshAgent
  4. LSASS dumped via rundll32.exe/comsvcs.dll; output written to .odt extension to evade .dmp detection
  5. NTDS extracted via ntdsutil.exe IFM method
  6. Network scanning via SoftPerfect Network Scanner and NetExec
  7. Lateral movement via PsExec and RDP
  8. Log clearing via PowerShell routine targeting all Windows event logs — this lets threat actors wipe evidence across the entire forensic surface in one action
  9. Exfiltration tools: Rclone, ProtonDrive, FileZilla — primarily to MEGA cloud storage
  10. Ransomware payload (win.exe) staged at C:\PerfLogs\, executed with password gate and --no-admin flag

Analyst Assessment

Perimeter compromise is the critical point for defenders. After exploitation succeeds, the impact depends on the affiliate's goals. In these intrusions, the threat actors moved methodically from initial access through credential theft to ransomware deployment, following a well-established post-exploitation playbook.

Recommendations

  • Apply available patches for PAN-OS immediately across all affected versions
  • Review VPN session logs for connections from systems named kali or unexpected IP ranges
  • Audit Registry Run keys and scheduled tasks for persistence mechanisms
  • Block or alert on ntdsutil.exe IFM usage outside authorized backup windows
  • Monitor for unauthorized deployment of remote access tools (AnyDesk, Ngrok, MeshAgent)
  • Review and restrict rclone and similar exfiltration tools in your environment

IOCs are available at the Arctic Wolf public GitHub repository.

Experiencing an Incident?

Make Arctic Wolf your first call when you have a breach or cyber incident.