Qilin Affiliates Exploit PAN-OS CVE-2026-0257 GlobalProtect Bypass

Arctic Wolf documented Qilin affiliates exploiting CVE-2026-0257, a PAN-OS GlobalProtect auth bypass, to gain trusted VPN access for double-extortion attacks.
Table of Contents
    Add a header to begin generating the table of contents

    Arctic Wolf published the first public technical analysis documenting Qilin ransomware affiliates actively exploiting CVE-2026-0257 — an unauthenticated authentication bypass in Palo Alto Networks’ GlobalProtect portal and gateway — to gain initial VPN access to target organizations. The Arctic Wolf research describes intrusions that occurred during June 2026 and details a systematic post-exploitation playbook applied after affiliates entered victim networks through the trusted GlobalProtect tunnel.

    CVE-2026-0257 GlobalProtect Bypass Gives Qilin Affiliates a Trusted VPN Tunnel

    CVE-2026-0257 is an unauthenticated authentication bypass vulnerability in the GlobalProtect portal and gateway components of PAN-OS, Palo Alto Networks’ operating system for its NGFW and security platforms. An unauthenticated remote attacker can exploit the flaw to bypass the authentication controls that govern GlobalProtect VPN access, establishing a VPN session that the network treats as a legitimate authenticated user connection — including routing through all associated network trust policies.

    Palo Alto Networks patched CVE-2026-0257 on May 13, 2026. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog in early June 2026, confirming active exploitation at that time. The Arctic Wolf documentation of Qilin affiliates using CVE-2026-0257 during June 2026 intrusions confirms that ransomware operators incorporated the exploit into active attack chains during the window between patch release and broad deployment across enterprise environments.

    Organizations running PAN-OS GlobalProtect as a perimeter VPN gateway that had not applied the May 13 patch by June 2026 were exposed to initial access through a trusted VPN channel — an entry point indistinguishable at the network level from a legitimate employee VPN session.

    Qilin’s Post-Exploitation Playbook: Kali Linux Sessions, RATs, and LSASS Dumps

    After gaining initial access through CVE-2026-0257, Qilin affiliates followed a consistent post-exploitation sequence documented by Arctic Wolf across the June 2026 intrusions. The affiliates established Kali Linux-based VPN sessions through the compromised GlobalProtect infrastructure, providing a persistent attacker-controlled VPN presence within the target network.

    Persistence was established through Windows Registry modifications and scheduled task creation. The affiliates deployed multiple remote access tools — AnyDesk, Ngrok, LogMeIn, and MeshAgent — to maintain redundant access channels across the intrusion period. Credential harvesting targeted the Windows Local Security Authority Subsystem Service through LSASS memory dumps and Active Directory database extraction, providing the affiliates with authentication credentials for lateral movement to additional systems and network segments.

    Reconnaissance activity included SoftPerfect network scanning and NetExec credential validation. Affiliates cleared Windows event logs to reduce forensic visibility and disabled Windows Defender to remove endpoint detection coverage before moving to the extortion phase of the operation.

    Encryption-Only vs. Double-Extortion: Qilin’s Two Observed Attack Modes

    Arctic Wolf documented two distinct operational modes across the June 2026 intrusions, reflecting different affiliate strategies or different operational decisions based on the assessed value of the victim environment.

    In the encryption-only mode, affiliates moved rapidly to domain-wide encryption after establishing initial access and minimal reconnaissance — prioritizing speed over data theft and executing ransomware deployment across the target environment without an extended dwell period.

    In the double-extortion mode, affiliates extended the dwell period to conduct systematic data exfiltration before deploying ransomware. Data was staged and transferred using Rclone, ProtonDrive, FileZilla, and MEGA — a mix of cloud storage synchronization tools and file transfer utilities that tunnel through encrypted channels and blend with legitimate administrative traffic. After exfiltration was complete, affiliates then deployed ransomware for encryption. The double-extortion model allows affiliates to sustain extortion pressure if the victim can recover from backups: the threat of publishing exfiltrated data remains even if encryption is reversed.

    Patching CVE-2026-0257 and Investigating GlobalProtect Exposure

    Organizations running PAN-OS GlobalProtect that have not applied the May 13, 2026 patch should prioritize remediation immediately. CVE-2026-0257 grants attackers the equivalent of authenticated VPN user access to a network — without requiring any valid credentials — from any internet-accessible GlobalProtect endpoint.

    Organizations that patched after June 2026 — or that cannot confirm their patch deployment timeline — should assess whether CVE-2026-0257 was exploited during any unpatched window. The indicators Arctic Wolf documented — Kali Linux VPN sessions, unexpected AnyDesk or MeshAgent installation, LSASS dump artifacts, scheduled task modifications, event log clearing events, and anomalous Rclone or cloud storage activity — are the primary forensic signals to review in GlobalProtect access logs, endpoint detection telemetry, and network traffic records for the period before patch application. The presence of the Ngrok or LogMeIn remote access tools, which are not standard enterprise administration utilities, is a particularly reliable indicator of affiliate activity in environments where those tools had no legitimate deployment.

    Related Posts