INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Qilin Ransomware Exploits CVE-2026-0257 for VPN Access
| 2026-07-21 16:08 CRITICAL HIGH RANSOMWARE & EXTORTION EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The Qilin ransomware gang has been targeting multiple sectors worldwide, including healthcare, manufacturing, and finance, exploiting the critical PAN-OS GlobalProtect vulnerability CVE-2026-0257 to compromise corporate networks. Arctic Wolf researchers warn that this group is using a common initial pattern but diversifying tactics after compromise, with some attacks encrypting entire environments without stealing data while others involve extensive reconnaissance and credential theft before ransomware execution.
Technical Mitigations AI-generated
* Implement a patch management strategy to ensure all devices and systems have the latest security patches, including Palo Alto Networks PAN-OS GlobalProtect updates.
* Conduct regular vulnerability scans and penetration testing to identify potential entry points for attackers exploiting CVE-2026-0257.
* Use secure authentication mechanisms, such as multi-factor authentication (MFA), to prevent unauthorized access to corporate networks.
* Implement a robust incident response plan that includes procedures for responding to ransomware attacks, including Qilin Ransomware exploitation of PAN-OS Authentication Bypass Vulnerability.
* Educate users and administrators about the importance of keeping software up-to-date, using secure protocols (e.g., PsExec), and implementing data loss prevention (DLP) solutions to prevent lateral movement in case of a ransomware attack.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
wi•••••.exe
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
AgendaAgendaQilinQilin
CVE-2026-0257CVE-2026-0257
Target & Sectors
FIVE_EYES
FIVE_EYES
Incident Timeline
August 2022
Threat actors used a previously unknown vulnerability in CVE-2026-0257 to gain unauthorized VPN access for the Qilin ransomware operation.
Click on any entity below to view its context and source!
organisation
Ransomware
Qilin is a Ransomware-as-a-Service (RaaS) operation that surfaced in August 2022 under the "Agenda" name and has since claimed responsibility for more than 2,000 victims on its dark web leak site.
malware
Qilin
Qilin is a Ransomware-as-a-Service (RaaS) operation that surfaced in August 2022 under the "Agenda" name and has since claimed responsibility for more than 2,000 victims on its dark web leak site.
malware
Agenda
Qilin is a Ransomware-as-a-Service (RaaS) operation that surfaced in August 2022 under the "Agenda" name and has since claimed responsibility for more than 2,000 victims on its dark web leak site.
victims
2,000 victims
Qilin is a Ransomware-as-a-Service (RaaS) operation that surfaced in August 2022 under the "Agenda" name and has since claimed responsibility for more than 2,000 victims on its dark web leak site.
October 2025
Qilin Ransomware affiliates used a previously unknown vulnerability in CVE-2026-0257 to gain unauthorized VPN access.
Click on any entity below to view its context and source!
malware
Qilin
In October 2025, Resecurity’s researchers
detailed
how the Qilin RaaS group relies on global bulletproof hosting networks to support its extortion operations.
tactic
Extortion
In October 2025, Resecurity’s researchers
detailed
how the Qilin RaaS group relies on global bulletproof hosting networks to support its extortion operations.
organisation
Resecurity
In October 2025, Resecurity’s researchers
detailed
how the Qilin RaaS group relies on global bulletproof hosting networks to support its extortion operations.
organisation
LockBit
In early October,
DragonForce
,
LockBit
, and
Qilin
formed a ransomware alliance
to boost attack effectiveness, marking a major shift in the cyber threat landscape.
organisation
Ransomware
Ransomware groups DragonForce, LockBit, and Qilin formed a strategic alliance to enhance their attack capabilities, signaling an evolving cyber threat landscape.
May 13
Palo Alto Networks released patches on May 13 and confirmed exploitation attempts against systems that had not applied updates or mitigations.
Click on any entity below to view its context and source!
organisation
Palo Alto Networks
Palo Alto Networks
addressed the vulnerability
on May 13.
Palo Alto Networks addressed the vulnerability (
CVE-2026-0257
) on
May 13
and warned that attackers had begun abusing it to breach corporate networks after Rapid7 reported observing it being exploited against numerous customers starting on May 17.
vulnerability
CVE-2026-0257
Palo Alto Networks addressed the vulnerability (
CVE-2026-0257
) on
May 13
and warned that attackers had begun abusing it to breach corporate networks after Rapid7 reported observing it being exploited against numerous customers starting on May 17.
May 17
Palo Alto Networks addressed the CVE-2026-0257 vulnerability on May 13 and warned that attackers began abusing it to breach corporate networks starting on May 17.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-0257
Palo Alto Networks addressed the vulnerability (
CVE-2026-0257
) on
May 13
and warned that attackers had begun abusing it to breach corporate networks after Rapid7 reported observing it being exploited against numerous customers starting on May 17.
organisation
Palo Alto Networks
Palo Alto Networks addressed the vulnerability (
CVE-2026-0257
) on
May 13
and warned that attackers had begun abusing it to breach corporate networks after Rapid7 reported observing it being exploited against numerous customers starting on May 17.
May 29
Threat actors used CVE-2026-0257 to target GlobalProtect VPN instances.
Click on any entity below to view its context and source!
attribution
Known Exploited Vulnerability
"
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added the flaw to its Known Exploited Vulnerability catalog on May 29,
ordering federal agencies
to secure their GlobalProtect VPN instances within three days.
attribution
GlobalProtect
"
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added the flaw to its Known Exploited Vulnerability catalog on May 29,
ordering federal agencies
to secure their GlobalProtect VPN instances within three days.
June 2026
Threat actors used CVE-2026-0257 to target Palo Alto Networks firewall appliances, exploiting the vulnerability and establishing VPN sessions from compromised systems.
Click on any entity below to view its context and source!
tactic
Ransomware
“Arctic Wolf investigated multiple distinct intrusions during June 2026 that resulted in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances.”
"Arctic Wolf investigated multiple distinct intrusions during June 2026 that resulted in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances,"
it said
.
vulnerability
CVE-2026-0257
“Arctic Wolf investigated multiple distinct intrusions during June 2026 that resulted in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances.”
Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of
CVE-2026-0257
(CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software.
"Arctic Wolf investigated multiple distinct intrusions during June 2026 that resulted in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances,"
it said
.
malware
Qilin
“Arctic Wolf investigated multiple distinct intrusions during June 2026 that resulted in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances.”
"Arctic Wolf investigated multiple distinct intrusions during June 2026 that resulted in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances,"
it said
.
infrastructure
7.8
Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of
CVE-2026-0257
(CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software.
general_metric
7.8 score
Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of
CVE-2026-0257
(CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software.
organisation
PsExec
Threat actors consistently used the same entry point, ransomware staging paths, PsExec execution, and registry persistence.
infrastructure
Windows
The operators scanned networks with SoftPerfect Network Scanner and NetExec, cleared Windows event logs, and in some cases disabled Microsoft Defender before deploying ransomware.
organisation
SoftPerfect Network Scanner
The operators scanned networks with SoftPerfect Network Scanner and NetExec, cleared Windows event logs, and in some cases disabled Microsoft Defender before deploying ransomware.
organisation
NetExec
The operators scanned networks with SoftPerfect Network Scanner and NetExec, cleared Windows event logs, and in some cases disabled Microsoft Defender before deploying ransomware.
organisation
Microsoft Defender
The operators scanned networks with SoftPerfect Network Scanner and NetExec, cleared Windows event logs, and in some cases disabled Microsoft Defender before deploying ransomware.
victims
40 victims
Qilin ransomware
operation has been active since 2022, it has become one of the most active RaaS groups in 2025, claiming over 40 victims monthly and peaking at 100 in June.
infrastructure
Linux
After exploiting CVE-2026-0257, the attackers established VPN sessions from Kali Linux systems, then quickly secured persistent access using registry Run keys, scheduled tasks, and remote administration tools such as AnyDesk, Ngrok, LogMeIn, and MeshAgent.
organisation
MeshAgent
After exploiting CVE-2026-0257, the attackers established VPN sessions from Kali Linux systems, then quickly secured persistent access using registry Run keys, scheduled tasks, and remote administration tools such as AnyDesk, Ngrok, LogMeIn, and MeshAgent.
organisation
Tor
Qilin uses double-extortion tactics, encrypting data while threatening to leak it via Tor-based portals.
organisation
the Active Directory
They harvested credentials by dumping LSASS memory and extracting the Active Directory database (NTDS), enabling lateral movement with PsExec, RDP, and compromised administrator accounts.
organisation
RDP
They harvested credentials by dumping LSASS memory and extracting the Active Directory database (NTDS), enabling lateral movement with PsExec, RDP, and compromised administrator accounts.
organisation
Rclone
Several intrusions also involved data theft using Rclone, ProtonDrive, FileZilla, and MEGA cloud storage, while others focused solely on rapid encryption.
organisation
ProtonDrive
Several intrusions also involved data theft using Rclone, ProtonDrive, FileZilla, and MEGA cloud storage, while others focused solely on rapid encryption.
organisation
FileZilla
Several intrusions also involved data theft using Rclone, ProtonDrive, FileZilla, and MEGA cloud storage, while others focused solely on rapid encryption.
Jul 21, 2026
Threat actors used a previously unknown vulnerability in CVE-2026-0257 to compromise affected VPN services and gain unauthorized access.
2026/07/21
Threat actors used PsExec to exploit the PAN-OS GlobalProtect flaw CVE-2026-0257 to gain unauthorized VPN access.
Click on any entity below to view its context and source!
organisation
CVE-2026-0257
Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access
Qilin ransomware exploits the PAN-OS GlobalProtect flaw CVE-2026-0257 to gain unauthorized VPN access to unpatched networks.
organisation
PAN
Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access
Qilin ransomware exploits the PAN-OS GlobalProtect flaw CVE-2026-0257 to gain unauthorized VPN access to unpatched networks.
Ravie Lakshmanan
Jul 21, 2026
Vulnerability / Network Security
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy
Qilin
(aka Agenda) ransomware on victim environments.
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf.
infrastructure
Windows
Arctic Wolf Labs has observed several attacks in which threat actors exploited CVE-2026-0257 to gain initial access and deploy Qilin ransomware across entire Windows domains.
Despite similarities in ransomware staging paths, PsExec-based execution, and an unusual Windows Registry persistence pattern (i.e., an asterisk followed by six randomized lowercase alphabetic characters), follow-on attacks varied across victims.
"
The threat actors have been found to weaponize the flaw to gain authenticated access to victim networks by establishing SSL VPN sessions, followed by escalating their attacks to facilitate credential harvesting and lateral movement through Windows administrative shares via compromised administrative accounts.
organisation
PAN-OS GlobalProtect
Investigators found evidence that multiple Qilin affiliates are actively abusing the flaw to compromise organizations, making unpatched PAN-OS GlobalProtect devices a high-priority target for ransomware operations.
organisation
Initial Access
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access.
organisation
Vulnerability / Network Security
Ravie Lakshmanan
Jul 21, 2026
Vulnerability / Network Security
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy
Qilin
(aka Agenda) ransomware on victim environments.
organisation
PsExec
"Attackers demonstrated consistent operational patterns despite tradecraft variation: staging ransomware at C:\PerfLogs\, using PsExec for lateral execution via administrative shares, deploying password-protected ransomware payloads, and implementing comprehensive log-clearing routines.
organisation
C:\PerfLogs\
"Attackers demonstrated consistent operational patterns despite tradecraft variation: staging ransomware at C:\PerfLogs\, using PsExec for lateral execution via administrative shares, deploying password-protected ransomware payloads, and implementing comprehensive log-clearing routines.
organisation
Microsoft
The activity is also characterized by the attackers taking deliberate steps to clear event logs and disable Microsoft Defender Real-Time Protection prior to running the ransomware payload so as to minimize the likelihood of detection and avoid leaving forensic evidence.
organisation
Windows Registry
Despite similarities in ransomware staging paths, PsExec-based execution, and an unusual Windows Registry persistence pattern (i.e., an asterisk followed by six randomized lowercase alphabetic characters), follow-on attacks varied across victims.
organisation
Rclone
This ranged from enterprise-wide encryption with no data exfiltration and extensive reconnaissance via remote access tools like AnyDesk, Ngrok, or LogMeIn to large-scale credential theft and instances of data exfiltration to the MEGA cloud service before ransomware deployment using Rclone, Proton Drive, and FileZilla.
organisation
FileZilla
This ranged from enterprise-wide encryption with no data exfiltration and extensive reconnaissance via remote access tools like AnyDesk, Ngrok, or LogMeIn to large-scale credential theft and instances of data exfiltration to the MEGA cloud service before ransomware deployment using Rclone, Proton Drive, and FileZilla.
organisation
GlobalProtect
CVE-2026-0257
is a PAN-OS authentication bypass vulnerability affecting GlobalProtect portals and gateways.
Internet threat watchdog Shadowserver now tracks
over 167,000 GlobalProtect VPN instances exposed online
, while Shodan
found over 172,000 IPs
with a GlobalProtect fingerprint.
organisation
CVE-2026
However, there is no information on how many of them are honeypots or have already been patched against CVE-2026-0257 attacks.
organisation
SSL
"
The threat actors have been found to weaponize the flaw to gain authenticated access to victim networks by establishing SSL VPN sessions, followed by escalating their attacks to facilitate credential harvesting and lateral movement through Windows administrative shares via compromised administrative accounts.
infrastructure
172,000 IPs
Internet threat watchdog Shadowserver now tracks
over 167,000 GlobalProtect VPN instances exposed online
, while Shodan
found over 172,000 IPs
with a GlobalProtect fingerprint.
organisation
Panorama
The vulnerabilities do not affect Panorama or Cloud NGFW deployments.
organisation
Court
The list of victims includes many high-profile organizations such as automotive giants
Nissan
and
Yangfeng
, Japanese beer giant
Asahi
,
pathology services provider Synnovis
, publishing giant
Lee Enterprises
, and
Australia's Court Services Victoria
.
organisation
Palo Alto Networks'
Palo Alto Networks' products and services are used by over 70,000 customers worldwide, including most of the largest U.S. banks and 90% of Fortune 10 companies.
victims
70,000 customers
Palo Alto Networks' products and services are used by over 70,000 customers worldwide, including most of the largest U.S. banks and 90% of Fortune 10 companies.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Arctic Wolf Labs has observed several attacks in which threat actors exploited CVE-2026-0257 to gain initial access and deploy Qilin ransomware across entire Windows domains.
The operators scanned networks with SoftPerfect Network Scanner and NetExec, cleared Windows event logs, and in some cases disabled Microsoft Defender before deploying ransomware.
…n authenticated access to victim networks by establishing SSL VPN sessions, followed by escalating their attacks to facilitate credential harvesting and lateral movement through Windows administrative shares via compromised administrative accounts.
Despite similarities in ransomware staging paths, PsExec-based execution, and an unusual Windows Registry persistence pattern (i.e., an asterisk followed by six randomized lowercase alphabetic characters), follow-on attacks varied across victims.
Metrics
victims
40
Victims
Qilin ransomware
operation has been active since 2022, it has become one of the most active RaaS groups in 2025, claiming over 40 victims monthly and peaking at 100 in June.
Metrics
infrastructure
Linux
Affected Product
After exploiting CVE-2026-0257, the attackers established VPN sessions from Kali Linux systems, then quickly secured persistent access using registry Run keys, scheduled tasks, and remote administration tools such as AnyDesk, Ngrok, LogMeIn, and Me…
Metrics
infrastructure
7.8
Software Version
Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of
CVE-2026-0257
(CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software.
Metrics
victims
2,000
Victims
Qilin is a Ransomware-as-a-Service (RaaS) operation that surfaced in August 2022 under the "Agenda" name and has since claimed responsibility for more than 2,000 victims on its dark web leak site.
Metrics
infrastructure
172,000
Ips
Internet threat watchdog Shadowserver now tracks
over 167,000 GlobalProtect VPN instances exposed online
, while Shodan
found over 172,000 IPs
with a GlobalProtect fingerprint.
Metrics
victims
70,000
Customers
Palo Alto Networks' products and services are used by over 70,000 customers worldwide, including most of the largest U.S. banks and 90% of Fortune 10 companies.
Intelligence Sources
Security Affairs
2026-07-21
BleepingComputer
2026-07-21
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
BleepingComputer
The Hacker News
2026-07-21
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-22T06:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
30x
organisation
Identified Entity
PAN
entity
10x
timeline
Temporal Reference
June 2026
date
6x
tactic
Cyber Operation Type
Phishing
tactic
6x
attribution
Attributing Entity
the U.S. Cybersecurity and Infrastructure Security Agency
authority
4x
industry
Targeted Sector
Healthcare
sector
3x
general metric
%
90
%
2x
malware
Malware Payload
Qilin
tool
2x
infrastructure
Affected Product
Windows
software
2x
tactic
MITRE ATT&CK Technique
T1003.003 - NTDS
technique
2x
victims
Victims
40
victims
2x
target region
Target Country
Australia
country
Contextual Telemetry
Context Block
8 METRICS
vulnerability
Exploited CVE
CVE-2026-0257
cve
general metric
Jul
21
jul
infrastructure
Software Version
7.8
version
general metric
Score
8
score
general metric
Vpn Instances
167,000
vpn instances
infrastructure
Ips
172,000
ips
victims
Customers
70,000
customers
general metric
Companies
10
companies
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.