AI Security AI安全 6h ago Updated 2h ago 更新于 2小时前 48

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access 麒麟勒索软件攻击者利用PAN-OS身份验证绕过实现初始访问

Qilin ransomware affiliates are exploiting the patched CVE-2026-0257 authentication bypass in Palo Alto Networks PAN-OS to gain initial network access. The attack chain involves establishing unauthorized SSL VPN sessions, harvesting credentials, and using PsExec for lateral movement across Windows environments. Post-exploitation tactics vary significantly between affiliates, ranging from pure encryption to double-extortion involving data exfiltration to cloud services like MEGA. Consistent opera Qilin勒索软件攻击者利用已修复的高危PAN-OS漏洞CVE-2026-0257绕过身份验证,获取初始访问权限。 攻击者通过SSL VPN会话建立连接,随后使用PsExec进行横向移动,并清除日志以掩盖踪迹。 攻击模式显示Qilin采用RaaS模式,不同附属机构在凭证窃取和数据外泄策略上存在显著差异。 攻击者在部署勒索软件前会禁用Microsoft Defender实时保护,并使用特定注册表项实现持久化。

75
Hot 热度
70
Quality 质量
60
Impact 影响力

Analysis 深度分析

TL;DR

  • Qilin ransomware affiliates are exploiting the patched CVE-2026-0257 authentication bypass in Palo Alto Networks PAN-OS to gain initial network access.
  • The attack chain involves establishing unauthorized SSL VPN sessions, harvesting credentials, and using PsExec for lateral movement across Windows environments.
  • Post-exploitation tactics vary significantly between affiliates, ranging from pure encryption to double-extortion involving data exfiltration to cloud services like MEGA.
  • Consistent operational indicators include staging payloads in C:\PerfLogs, disabling Microsoft Defender Real-Time Protection, and clearing event logs to evade detection.

Why It Matters

This incident highlights the critical risk of unpatched vulnerabilities in core network infrastructure, specifically firewalls and VPN gateways, serving as a primary entry point for sophisticated ransomware campaigns. It demonstrates how Ransomware-as-a-Service (RaaS) models allow diverse affiliates to leverage shared initial access vectors while maintaining distinct operational tradecraft, complicating attribution and defense strategies. For security teams, it underscores the necessity of immediate patching for high-severity CVEs and the importance of monitoring for anomalous VPN authentication behaviors.

Technical Details

  • Vulnerability Exploited: CVE-2026-0257 (CVSS 7.8), an authentication bypass in PAN-OS portal and gateway components that allows unauthenticated remote attackers to establish VPN sessions when specific certificate configurations and authentication override cookies are enabled.
  • Lateral Movement & Execution: Attackers utilize compromised administrative accounts to execute PsExec via Windows administrative shares, facilitating widespread network penetration and credential harvesting.
  • Evasion Techniques: Prior to payload deployment, threat actors systematically clear event logs and disable Microsoft Defender Real-Time Protection. They also employ a unique registry persistence mechanism consisting of an asterisk followed by six randomized lowercase alphabetic characters.
  • Payload Staging & Exfiltration: Ransomware is staged at C:\PerfLogs\. Data exfiltration, where present, utilizes tools such as Rclone, Proton Drive, and FileZilla to transfer data to MEGA cloud storage, while reconnaissance is conducted using tools like AnyDesk, Ngrok, and LogMeIn.

Industry Insight

Organizations must prioritize the immediate application of patches for PAN-OS vulnerabilities and enforce strict certificate management policies to mitigate authentication bypass risks. Security operations centers should enhance monitoring for unusual VPN login patterns and the specific file staging path (C:\PerfLogs\) combined with PsExec usage, as these serve as strong indicators of compromise for this specific campaign. Furthermore, adopting a zero-trust architecture for internal network segments can limit the impact of lateral movement even if initial perimeter defenses are breached.

TL;DR

  • Qilin勒索软件攻击者利用已修复的高危PAN-OS漏洞CVE-2026-0257绕过身份验证,获取初始访问权限。
  • 攻击者通过SSL VPN会话建立连接,随后使用PsExec进行横向移动,并清除日志以掩盖踪迹。
  • 攻击模式显示Qilin采用RaaS模式,不同附属机构在凭证窃取和数据外泄策略上存在显著差异。
  • 攻击者在部署勒索软件前会禁用Microsoft Defender实时保护,并使用特定注册表项实现持久化。

为什么值得看

本文揭示了高级持续性威胁组织如何利用企业网络基础设施中的关键漏洞作为跳板,展示了从初始访问到横向移动的完整杀伤链。对于安全从业者而言,理解这种基于RaaS模型的多样化后续操作有助于优化检测规则和应急响应策略。

技术解析

  • 初始访问向量:利用Palo Alto Networks PAN-OS中的CVE-2026-0257漏洞(CVSS 7.8),该漏洞允许未认证的攻击者在启用特定证书配置和身份验证覆盖Cookie时,绕过身份验证并建立VPN会话。
  • 横向移动与执行:攻击者将勒索软件暂存于C:\PerfLogs\目录,使用PsExec通过Windows管理共享进行横向执行,并采用密码保护的载荷。
  • 反取证与持久化:攻击者会清除事件日志并禁用Microsoft Defender实时保护;持久化机制表现为一个星号后跟六个随机小写字母字符的异常Windows注册表项。
  • 多样化后续操作:部分攻击仅进行加密,而另一些则涉及大规模凭证窃取和数据外泄至MEGA等云服务,使用了Rclone、Proton Drive和FileZilla等工具。

行业启示

  • 强化边界防御:必须确保所有网络设备固件及时更新,特别是针对身份验证绕过类高危漏洞,需实施严格的补丁管理策略。
  • 监控内部横向移动:鉴于攻击者频繁使用PsExec和管理共享,应加强对内部网络异常进程调用和远程执行行为的监控与告警。
  • 应对RaaS复杂性:由于勒索软件即服务(RaaS)导致攻击手法多样化,企业应制定灵活的应急响应计划,涵盖数据泄露检测和不同加密场景下的恢复预案。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全