Fog ransomware targets SonicWall VPNs to breach corporate networks
ID: 51efe73e-1c93-50e0-8d73-df32d38dbc54
STIX ID: report--51efe73e-1c93-50e0-8d73-df32d38dbc54
Feed Name: Bleeping Computer
Threat Score
Arctic Wolf and other researchers observed at least ~30 intrusions where Akira and Fog ransomware actors exploited SonicWall SSL VPN accounts—likely via CVE-2024-40766—gaining access to unpatched endpoints (often without MFA and on default port 4433) and performing rapid VM/backup encryption and data theft; researchers also report shared infrastructure between groups and a large number of internet-exposed vulnerable SonicWall endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
