Arctic Wolf Labs Observes Increased Fog and Akira Ransomware Activity Linked to SonicWall SSL VPN
ID: 5e41f866-dd69-5aba-b6ef-5050d4bf9631
STIX ID: report--5e41f866-dd69-5aba-b6ef-5050d4bf9631
Feed Name: Arctic Wolf Blog
Threat Score
Arctic Wolf Labs observed an influx of at least 30 Akira and Fog ransomware intrusions since early August 2024 that involved SonicWall SSL VPN account compromise (potentially related to CVE-2024-40766), characterized by rapid encryption of VM/backups, data exfiltration, shared hosting-related IP infrastructure, and a set of IoCs, TTPs, and detection/remediation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
