Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware – Arctic Wolf

Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware – Arctic Wolf
Arctic Wolf Labs found multiple June 2026 intrusions in which attackers used CVE-2026-0257 against Palo Alto Networks firewall appliances to gain VPN access and quickly deploy Qilin ransomware across victim networks. The activity showed shared operational patterns, including PsExec lateral movement, credential theft, log clearing, and in some cases data exfiltration for double-extortion, suggesting overlapping Qilin affiliates or shared exploitation infrastructure. #CVE-2026-0257 #PaloAltoNetworks #Qilin #GlobalProtect #PsExec

Keypoints

  • CVE-2026-0257 was used as the initial access vector in multiple intrusions.
  • Attackers exploited Palo Alto Networks GlobalProtect VPN sessions to bypass authentication.
  • Qilin ransomware was staged in C:PerfLogs and executed with password protection.
  • Threat actors dumped LSASS and extracted NTDS data to steal domain credentials.
  • PsExec, AnyDesk, Ngrok, and LogMeIn were used for lateral movement and persistence.

Read More: https://arcticwolf.com/resources/blog/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware/