logo

Arctic Wolf Observes Akira Ransomware Campaign Targeting SonicWall SSLVPN Accounts

ID: 7770cb1a-6d5f-517e-b1e2-775fc6d60212

STIX ID: report--7770cb1a-6d5f-517e-b1e2-775fc6d60212

Feed Name: Arctic Wolf

Threat Score
78/100

Date Published: 2024-09-06

Date Updated: 2026-07-25

Author: Stefan Hostetler

...
...

A remote code execution vulnerability (CVE-2024-40766) in SonicOS was disclosed and later advisory updates indicated potential active exploitation; Arctic Wolf observed Akira ransomware affiliates gaining initial access by compromising locally-managed SSLVPN accounts on vulnerable SonicWall devices (with MFA disabled). The report lists affected device families and fixed firmware versions and strongly recommends immediate SonicOS updates, resetting local SSLVPN passwords, enabling MFA, and restricting WAN/SSLVPN access as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.