Qilin clearnet leak site
During June 2026, Arctic Wolf Labs traced several ransomware intrusions to one entry point. Attackers exploited a Palo Alto Networks firewall flaw to break in. Each case ended in Qilin ransomware encryption. In short, one perimeter bug opened the door to full domain compromise.
At a glance
| Actor / group | Qilin ransomware (also “Agenda”), a ransomware-as-a-service operation. Likely multiple affiliates |
| Activity type | Perimeter exploitation leading to ransomware; some cases with data theft (double extortion) |
| Targets / victims | Multiple distinct victim environments across sectors |
| Scale | Several intrusions in June 2026; broad scanning for vulnerable devices |
| Law-enforcement status | No arrests reported. Vendor confirms limited active exploitation |
| Source | Arctic Wolf Labs; Palo Alto Networks advisory |
TL;DR
Arctic Wolf Labs tied a June 2026 wave of Qilin ransomware to CVE-2026-0257. The flaw is an authentication bypass in Palo Alto GlobalProtect. Attackers used it to gain VPN access, then moved to domain-wide encryption.
What happened
The intrusions all began the same way. Attackers abused CVE-2026-0257 to establish GlobalProtect VPN sessions without valid credentials. From there, they gained interactive access to victim networks.
Next, the actors harvested credentials and spread out. They dumped LSASS memory and extracted the Active Directory database. Then they moved laterally through administrative shares. Finally, they staged and ran the ransomware.
The vulnerability
CVE-2026-0257 carries a CVSS score of 7.8. It affects the GlobalProtect portal and gateway in PAN-OS. Palo Alto Networks has confirmed limited active exploitation on unpatched devices. Affected releases span several PAN-OS 10.2, 11.1, 11.2, and 12.1 branches, plus some Prisma Access versions. Cloud NGFW and Panorama are not affected.
Who is behind it
Qilin is a ransomware-as-a-service brand active since at least 2022. It runs a double-extortion model and recruits affiliates through underground forums. Notably, tradecraft varied between the June cases. Some intrusions rushed straight to encryption. Others involved heavy reconnaissance and data theft first.
That variation points to several affiliates, not one crew. Arctic Wolf notes the pattern is “consistent with RaaS models.” The researchers also saw exploitation from systems self-identifying as Kali hosts, with overlapping source IPs. Therefore, the intrusions may share tooling or infrastructure. Attribution to specific individuals remains open, and no one has been charged.
Impact and scale
The damage reached domain level in each case. Attackers stole domain password hashes and disabled defenses. In double-extortion cases, they exfiltrated data to cloud storage before encryption. They also targeted backup infrastructure to block recovery.
Arctic Wolf assesses “with moderate confidence” that these attacks are likely ongoing. Broad scanning and the RaaS model both support that view.
What comes next and how to stay protected
Patch first, then hunt. The perimeter is the decisive point in this chain.
- Update PAN-OS and Prisma Access to the fixed versions in Palo Alto’s advisory.
- Review GlobalProtect logs for VPN sessions from unfamiliar or Kali-identified hosts.
- Watch for payloads staged in C:\PerfLogs and PsExec activity across admin shares.
- Alert on LSASS dumping, NTDS extraction, and mass event-log clearing.
- Flag large outbound transfers to cloud storage from servers that rarely use it.
Early detection changes the outcome. Teams that catch initial access or credential theft can stop encryption before it starts. Treat indicators as descriptive; attackers rotate paths and tools between operations.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.