Hackers Exploit Palo Alto PAN-OS Flaw to Deploy Qilin Ransomware
ID: d68dff60-afc9-5c64-a939-23e531472c96
STIX ID: report--d68dff60-afc9-5c64-a939-23e531472c96
Feed Name: GBHackers
Multiple June 2026 intrusions exploited PAN-OS authentication-bypass CVE-2026-0257 to establish GlobalProtect sessions and deliver Qilin (Agenda) ransomware. Operators used LSASS memory dumps, PsExec and administrative shares for lateral movement, staged payloads in C:\PerfLogs, deployed remote access tools, cleared event logs, and in some cases exfiltrated data to cloud services (MEGA, ProtonDrive) for double-extortion; affected PAN-OS branches and mitigations (apply vendor fixes, terminate sessions, review VPN logs, and monitor specific TTPs) are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
