logo

Fog ransomware targets SonicWall VPNs to breach corporate networks

ID: 51efe73e-1c93-50e0-8d73-df32d38dbc54

STIX ID: report--51efe73e-1c93-50e0-8d73-df32d38dbc54

Feed Name: Bleeping Computer

Threat Score
82/100

Date Published: 2024-10-27

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Arctic Wolf and other researchers observed at least ~30 intrusions where Akira and Fog ransomware actors exploited SonicWall SSL VPN accounts—likely via CVE-2024-40766—gaining access to unpatched endpoints (often without MFA and on default port 4433) and performing rapid VM/backup encryption and data theft; researchers also report shared infrastructure between groups and a large number of internet-exposed vulnerable SonicWall endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.