A New Wave of Cyberattacks: SonicWall Firewalls Under Siege by Akira Ransomware
In the ever-evolving landscape of cybersecurity, organizations using SonicWall firewalls are currently facing a significant threat. Since late July 2025, a surge of attacks deploying Akira ransomware has been detected, alarming security researchers across various sectors.
Rising Threat Levels
Arctic Wolf Labs, a prominent cybersecurity firm, has documented this wave of attacks, which underscores the increasing audacity of threat actors. The initial method of entry for these cybercriminals involves malicious SSL VPN logins. In a troubling twist, these attackers have effectively bypassed multi-factor authentication (MFA) measures, showcasing a disturbing innovation in methods used to exploit vulnerabilities.
The Mechanism of Attack
At the heart of this campaign lies an opportunistic exploitation of vulnerable systems. The entry point for these attacks often traces back to SSL VPNs, specifically those affected by CVE-2024-40766, a vulnerability related to improper access control disclosed in 2024. Rather alarmingly, threat actors have succeeded in authenticating against accounts that are secured with SonicWall’s One-Time Password (OTP) MFA feature, leaving security experts scratching their heads.
The ongoing speculation suggests that these actors might be utilizing harvested credentials from previously compromised devices. This means that even well-patched systems could fall victim to attacks, leading to hard-hitting implications for organizations that believe their defenses are intact.
Attack Timeline and Sequence
Once attackers gain initial access, they act with uncanny speed. The time taken from breaching a system to deploying ransomware is alarmingly short—often mere hours. As reported, some infiltrations have been documented to occur in as little as 55 minutes.
- Initial Access: Cybercriminals log in to SonicWall SSL VPNs using compromised credentials.
- Network Scanning: Within minutes, they execute internal network scans to identify open ports (e.g., SMB, RPC, SQL).
- Privilege Escalation: Attackers elevate privileges, creating new administrator accounts and installing remote management tools such as AnyDesk or TeamViewer to maintain access.
- Security Evasion: To stealthily operate, they disable security measures and employ a “bring-your-own-vulnerable-driver” technique to tamper with endpoint protection.
- Data Exfiltration and Ransomware Deployment: Before encrypting systems, attackers steal sensitive data, packaging it with tools like WinRAR. Akira ransomware is then deployed, encrypting network drives and demanding a ransom.
Recommended Actions for Defense
In light of these recent developments, it’s imperative for organizations using SonicWall devices to adopt proactive security measures. One of the critical recommendations from Arctic Wolf is to reset all SSL VPN credentials, especially for users with accounts that have previously been exposed to the CvE-2024-40766 vulnerability. Simply patching vulnerabilities is insufficient if credentials have already been compromised.
Organizations should also remain vigilant, monitoring for suspicious VPN login attempts originating from Virtual Private Server (VPS) providers. In addition, identifying anomalies in SMB activity may provide early warnings of an impending attack.
The Long-Term Impact
As organizations scramble to bolster their defenses, the ongoing attacks expose a critical need for heightened security awareness and better training programs for employees. The rise of Akira ransomware targeting SonicWall firewalls vividly illustrates the robust adaptability of threat actors, compelling organizations to reassess their cybersecurity strategies in an increasingly hostile digital environment.
With continuous vigilance and a dynamic security approach, businesses can potentially mitigate the risks presented by such advanced threats. Updating protocols, investing in comprehensive training, and fostering a culture of cybersecurity within organizations will prove vital in combating the persistent and evolving challenges of cybercrime.
Stay informed and prepared to adapt.