logo

Arctic Wolf Observes July 2025 Uptick in Akira Ransomware Activity Targeting SonicWall SSL VPN

ID: 0d39ba7b-e3e6-535a-bc4c-7f0066dc9fd6

STIX ID: report--0d39ba7b-e3e6-535a-bc4c-7f0066dc9fd6

Feed Name: Arctic Wolf

Threat Score
75/100

Date Published: 2025-08-01

Date Updated: 2026-07-26

Author: Julian Tuin

...
...

Arctic Wolf reports an active uptick in Akira ransomware activity leveraging SonicWall SSLVPNs (observed since July 2025 and earlier), potentially tied to exploitation of CVE-2024-40766; the bulletin provides a table of IP/ASN IoCs linked to VPN logins and exfiltration, and prescribes mitigations including disabling SSLVPN where possible, rotating credentials, updating SonicOS to 7.3.0, enforcing MFA, enabling security services, blocking hosting-related ASNs for VPN auth, and integrating SonicWall logs with Arctic Wolf MDR for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.