Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware
ID: 94fe1299-806f-5332-b61e-23cb65deb12e
STIX ID: report--94fe1299-806f-5332-b61e-23cb65deb12e
Feed Name: Arctic Wolf
Threat Score
**Executive summary:** In June 2026 Arctic Wolf Labs investigated multiple intrusions that leveraged CVE-2026-0257 in Palo Alto GlobalProtect to establish authenticated VPN sessions, perform LSASS dumps and NTDS extraction for domain-wide credential compromise, stage Qilin ransomware at C:\PerfLogs\win.exe, move laterally via PsExec/admin shares, and in some cases exfiltrate data to cloud services (MEGA) prior to double-extortion ransomware deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
