logo

Arctic Wolf Observes Akira Ransomware Campaign Targeting SonicWall SSLVPN Accounts

ID: c5341177-1b9d-591f-a372-616560dd153f

STIX ID: report--c5341177-1b9d-591f-a372-616560dd153f

Feed Name: Arctic Wolf Blog

Threat Score
75/100

Date Published: 2024-09-06

Date Updated: 2026-04-27

...
...

Arctic Wolf reports CVE-2024-40766, an RCE in SonicOS affecting multiple SonicWall firewall generations; the advisory was later updated indicating potential active exploitation. Arctic Wolf observed Akira ransomware affiliates gaining initial access by compromising locally-managed SSLVPN accounts (with MFA disabled) on vulnerable devices and strongly recommends updating SonicOS to fixed versions, resetting local SSLVPN passwords, enabling MFA, and restricting WAN/SSLVPN management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.