Arctic Wolf Observes July 2025 Uptick in Akira Ransomware Activity Targeting SonicWall SSL VPN
ID: 0d39ba7b-e3e6-535a-bc4c-7f0066dc9fd6
STIX ID: report--0d39ba7b-e3e6-535a-bc4c-7f0066dc9fd6
Feed Name: Arctic Wolf
Arctic Wolf reports an active uptick in Akira ransomware activity leveraging SonicWall SSLVPNs (observed since July 2025 and earlier), potentially tied to exploitation of CVE-2024-40766; the bulletin provides a table of IP/ASN IoCs linked to VPN logins and exfiltration, and prescribes mitigations including disabling SSLVPN where possible, rotating credentials, updating SonicOS to 7.3.0, enforcing MFA, enabling security services, blocking hosting-related ASNs for VPN auth, and integrating SonicWall logs with Arctic Wolf MDR for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
