logo

Akira ransomware breaching MFA-protected SonicWall VPN accounts

ID: 4554f937-610c-558a-b724-984b4e39ece3

STIX ID: report--4554f937-610c-558a-b724-984b4e39ece3

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-09-28

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Akira ransomware actors are actively exploiting previously stolen credentials and likely OTP seeds to bypass MFA on SonicWall SSL VPN devices (initially linked to CVE-2024-40766). After access, attackers perform rapid internal reconnaissance, harvest credentials (notably from Veeam Backup & Replication, MSSQL/PostgreSQL and DPAPI secrets), sideload vulnerable drivers via legitimate executables to disable endpoint protection, and deploy ransomware; administrators are urged to reset VPN credentials and install recommended SonicOS firmware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.