logo

Akira Ransomware Targeting Critical Vulnerability in SonicWall SSLVPN (Campaign)

ID: 16344e0b-3469-5405-ae2a-3309927b6c8a

STIX ID: report--16344e0b-3469-5405-ae2a-3309927b6c8a

Feed Name: Wiz Cloud Threat Landscape

Threat Score
85/100

Date Published: 2025-08-06

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers observed active exploitation of CVE-2024-40766 in SonicWall TZ and NSa firewalls (firmware ≤ 7.2.0-7015) enabling MFA bypass and use of over-privileged service accounts to gain perimeter access; attackers persist via Cloudflared/OpenSSH/AnyDesk, move laterally with WMI, PowerShell Remoting and brute-forced RDP, exfiltrate credentials (including Veeam and NTDS.dit), disable defenses and delete recovery artifacts before deploying Akira ransomware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.