logo

Arctic Wolf Observes July 2025 Uptick in Akira Ransomware Activity Targeting SonicWall SSL VPN – Copy

ID: 7f459c76-b38a-51c7-8972-e1a95c38e697

STIX ID: report--7f459c76-b38a-51c7-8972-e1a95c38e697

Feed Name: Arctic Wolf

Threat Score
78/100

Date Published: 2025-08-01

Date Updated: 2026-07-26

Author: Julian Tuin

...
...

Arctic Wolf reports an active campaign involving Akira ransomware that has increased targeting of SonicWall SSLVPNs (observed since July 2025 and instances back to October 2024), possibly tied to exploitation of CVE-2024-40766; the bulletin includes numerous IoCs (IP addresses and ASNs), recommends disabling SSLVPN where possible, rotating credentials, applying SonicOS updates (7.3.0), enabling MFA and security services, and deploying log/agent monitoring to detect and mitigate intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.