logo

Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware

ID: 94fe1299-806f-5332-b61e-23cb65deb12e

STIX ID: report--94fe1299-806f-5332-b61e-23cb65deb12e

Feed Name: Arctic Wolf

Threat Score
85/100

Date Published: 2026-07-20

Date Updated: 2026-07-26

Author: Arctic Wolf Labs

...
...

**Executive summary:** In June 2026 Arctic Wolf Labs investigated multiple intrusions that leveraged CVE-2026-0257 in Palo Alto GlobalProtect to establish authenticated VPN sessions, perform LSASS dumps and NTDS extraction for domain-wide credential compromise, stage Qilin ransomware at C:\PerfLogs\win.exe, move laterally via PsExec/admin shares, and in some cases exfiltrate data to cloud services (MEGA) prior to double-extortion ransomware deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.