Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Qilin Ransomware Exploits Palo Alto VPN Flaw to Breach Corporate Networks

Qilin Ransomware Exploits Palo Alto VPN Flaw to Breach Corporate Networks

By: Jordan Vector Cybersecurity Expert

Last updated: July 22, 2026

Human Written
Qilin Ransomware Exploits Palo Alto VPN Flaw to Breach Corporate Networks
  • Qilin ransomware is now exploiting the CVE-2026-0257 vulnerability to gain access to company systems.

  • Various Qilin affiliates adopt different methods after gaining access to the system, some use quick encryption of files, while some stick to double extortion.

  • Palo Alto Networks rolled out fixes to the vulnerability in May. CISA KEV already added the bug to its KEV catalogue and gave federal agencies three days to secure their systems.

Cybersecurity company Arctic Wolf has reported a fresh VPN vulnerability that the Qilin hacker organization is using to compromise corporate systems.

The flaw in the VPN is essentially a case of authentication bypass in Palo Alto Networks’ firewalls. Cybercriminals do not necessarily have to possess real user login credentials to gain access to the VPN system.

This security flaw affects both the GlobalProtect portal and its gateway. It stems from how PAN-OS handles authentication override cookies. Attackers might exploit the configuration of a specific certificate and produce a fake cookie. Thus, letting them gain access to the system without using the login page. Additionally, they can also create a VPN connection without any authorization.

Additionally, Palo Alto Networks fixed this flaw on May 13, and, immediately, on May 17, Rapid7 experts found concrete evidence of exploiting this flaw by the threat actors. Soon after that, CISA got informed of the vulnerability and added it to its list of Known Exploited Vulnerabilities on May 29. The agency also mandated all federal agencies to apply a patch within three days.

Even with patches being available for months now, Qilin affiliates are still using this exploit. The security researchers at Arctic Wolf reported several instances where attackers exploited the bug in June 2026. They noted that this hacker group is using the flaw as an initial access vector.

Qilins Attack Chain

The initial attack will result in a successful establishment of a VPN connection. The connection tends to emanate from systems that have been designated as “kali” hosts. The attack technique is quite rapid in nature.

They concentrate on credential theft for lateral movements. The use of VPN access as an initial entry point is part of a broader trend of ransomware groups prioritizing VPN infrastructure in their attack strategies.

This involves dumping credentials in LSASS memory. Also involved is extracting the entire Active Directory database through NTDS extraction, which gives them access to the entire domain. Their methods include using PsExec and Windows admin shares.

Attackers always maintain consistency with respect to how they stage the ransomware. They deliver the payload to the C:\PerfLogs\ folder, the name it win.exe. In some of the attacks, the hackers employ remote access software such as AnyDesk and Ngrok. They clear Windows event logs so as to erase their tracks. Real-time protection of the defender is disabled before encryption takes place.

The Scope of the Qilin Threat 

Qilin, or “Agenda,” is a Ransomware-as-a-Service (RaaS) group that appeared for the first time in August 2022. The organization has become one of the largest cybercrime groups. Their total victim list on their dark web leak site is incredibly high.

Currently, there are at least 167,000 instances of GlobalProtect VPN compromise online. The exact number of victims which are still vulnerable to the threat remains unclear. Qilin has attacked more than 2,000 victims.

Arctic Wolf evaluates these attacks with a moderate level of confidence. The RaaS model usually distributes successful attacks among many affiliates. So, more attacks based on the CVE-2026-0257 vulnerability will probably come in the near future.

Share this article

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.