🔍 Contexte : Arctic Wolf Labs a publié le 20 juillet 2026 une analyse technique détaillée de plusieurs intrusions observées en juin 2026, toutes initiées via l’exploitation de CVE-2026-0257 ciblant les appliances Palo Alto Networks PAN-OS (GlobalProtect VPN), et aboutissant au déploiement du ransomware Qilin.

🎯 Vecteur d’accès initial : CVE-2026-0257 est une vulnérabilité de contournement d’authentification (CVSS 7.8/High) affectant le portail et la passerelle GlobalProtect de PAN-OS. Elle permet à un attaquant non authentifié d’établir des sessions VPN sans credentials valides. Les versions affectées incluent PAN-OS 10.2, 11.1, 11.2 et 12.1. Des sessions VPN ont été établies depuis des systèmes s’identifiant avec le hostname kali, avec des IP sources incluant 108.61.229.217, 108.61.75.232, 2.188.33.52, 199.247.22.193 et 70.34.205.43.

🛠️ Chaîne d’attaque observée :

  • Persistance : clés Run registry avec pattern *[a-z]{6}, tâche planifiée \MeshUserTask (MeshAgent), déploiement de AnyDesk, Ngrok, LogMeIn
  • Collecte de credentials : dump LSASS via rundll32.exe/comsvcs.dll (sortie en .odt), extraction NTDS via ntdsutil.exe (méthode IFM)
  • Reconnaissance : SoftPerfect Network Scanner (netscan.exe), NetExec (nxc.exe), navigation interactive via shellbags
  • Mouvement latéral : PsExec via partages administratifs (C$), RDP
  • Évasion : effacement enterprise-wide des logs via PowerShell/.NET EventLogSession, désactivation de Microsoft Defender Real-Time Protection
  • Exfiltration : Rclone vers MEGA, ProtonDrive, FileZilla ; ciblage de l’infrastructure Veeam
  • Déploiement ransomware : payload win.exe stagé dans C:\PerfLogs\, exécuté avec --password et --no-admin, via C:\Windows\SysWOW64\cmd.exe

⚙️ Modèle RaaS : La variabilité du post-exploitation (opérations encryption-only vs double extorsion complète) est cohérente avec plusieurs affiliés opérant sous le modèle Qilin RaaS. L’infrastructure d’exploitation partagée et le hostname kali récurrent suggèrent un outillage commun.

📊 Type d’article : Analyse technique et rapport d’incident produit par Arctic Wolf Labs, visant à documenter la chaîne d’attaque, fournir des IOCs et des recommandations défensives à la communauté de sécurité.

🧠 TTPs et IOCs détectés

Acteurs de menace

  • Qilin (cybercriminal) —

TTP

  • T1190 — Exploit Public-Facing Application (Initial Access)
  • T1133 — External Remote Services (Initial Access)
  • T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Persistence)
  • T1053.005 — Scheduled Task/Job: Scheduled Task (Persistence)
  • T1219 — Remote Access Software (Command and Control)
  • T1003.001 — OS Credential Dumping: LSASS Memory (Credential Access)
  • T1003.003 — OS Credential Dumping: NTDS (Credential Access)
  • T1046 — Network Service Discovery (Discovery)
  • T1083 — File and Directory Discovery (Discovery)
  • T1021.001 — Remote Services: Remote Desktop Protocol (Lateral Movement)
  • T1021.002 — Remote Services: SMB/Windows Admin Shares (Lateral Movement)
  • T1570 — Lateral Tool Transfer (Lateral Movement)
  • T1059.001 — Command and Scripting Interpreter: PowerShell (Execution)
  • T1569.002 — System Services: Service Execution (Execution)
  • T1562.001 — Impair Defenses: Disable or Modify Tools (Defense Evasion)
  • T1070.001 — Indicator Removal: Clear Windows Event Logs (Defense Evasion)
  • T1036 — Masquerading (Defense Evasion)
  • T1048 — Exfiltration Over Alternative Protocol (Exfiltration)
  • T1567.002 — Exfiltration Over Web Service: Exfiltration to Cloud Storage (Exfiltration)
  • T1486 — Data Encrypted for Impact (Impact)
  • T1490 — Inhibit System Recovery (Impact)

IOC

  • IPv4 : 108.61.229.217AbuseIPDB · VT · ThreatFox
  • IPv4 : 108.61.75.232AbuseIPDB · VT · ThreatFox
  • IPv4 : 2.188.33.52AbuseIPDB · VT · ThreatFox
  • IPv4 : 199.247.22.193AbuseIPDB · VT · ThreatFox
  • IPv4 : 70.34.205.43AbuseIPDB · VT · ThreatFox
  • CVEs : CVE-2026-0257NVD · CIRCL
  • Fichiers : win.exe
  • Fichiers : netscan.exe
  • Fichiers : nxc.exe
  • Fichiers : rclone.exe
  • Fichiers : ProtonDrive.exe
  • Fichiers : FileZilla.exe
  • Fichiers : ngrok.exe
  • Fichiers : ngrok.yml
  • Fichiers : AnyDesk.exe
  • Fichiers : PSEXESVC.exe
  • Chemins : C:\PerfLogs\win.exe
  • Chemins : C:\Windows\Temp\win.exe
  • Chemins : C:\Windows\Temp\output.odt
  • Chemins : C:\Windows\Temp\NTDS\
  • Chemins : C:\audit\Active Directory\ntds.dit
  • Chemins : C:\ProgramData\AnyDesk\AnyDesk.exe
  • Chemins : C:\PerfLogs\AnyDesk.exe
  • Chemins : C:\Windows\Temp\AnyDesk.exe
  • Chemins : C:\Program Files (x86)\AnyDesk\AnyDesk.exe
  • Chemins : C:\Windows\Temp\rclone.exe
  • Chemins : C:\Windows\Temp\New scan\netscan.exe
  • Chemins : C:\Windows\PSEXESVC.exe

Malware / Outils

  • Qilin (ransomware)
  • PsExec (tool)
  • Rclone (tool)
  • AnyDesk (tool)
  • Ngrok (tool)
  • LogMeIn (tool)
  • MeshAgent (rat)
  • NetExec (tool)
  • SoftPerfect Network Scanner (tool)
  • FileZilla (tool)
  • ProtonDrive (tool)

🟢 Indice de vérification factuelle : 75/100 (haute)

  • ✅ arcticwolf.com — source reconnue (Rösti community) (20pts)
  • ✅ 29012 chars — texte complet (fulltext extrait) (15pts)
  • ✅ 28 IOCs (IPs/domaines/CVEs) (10pts)
  • ⬜ 0/3 IOCs confirmés externellement (0pts)
  • ✅ 21 TTPs MITRE identifiées (15pts)
  • ✅ date extraite du HTML source (10pts)
  • ✅ acteur(s) identifié(s) : Qilin (5pts)
  • ⬜ 0/1 CVE(s) confirmée(s) (0pts)

🔗 Source originale : https://arcticwolf.com/resources/blog/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware/