Executive Summary
In early 2024, the Akira ransomware group escalated its campaign by successfully breaching organizations through SonicWall SSL VPN appliances, even when multi-factor authentication (MFA) was enabled. Security researchers determined that Akira actors appeared to bypass one-time password (OTP) protections, potentially by leveraging previously obtained OTP seed information or exploiting weaknesses in authentication management. Following the VPN compromise, attackers moved laterally, exfiltrated data, and encrypted systems to demand substantial ransom payments. This attack vector enabled access to privileged internal resources, resulting in business disruption, data exposure, and financial losses for affected organizations.
The incident underscores how ransomware operators are adapting to bypass commonly deployed defenses, specifically targeting VPN and MFA solutions. Such tactics highlight the urgent need for organizations to reassess remote access controls, authentication infrastructure, and visibility gaps, as similar techniques are increasingly observed in the wild.
Why This Matters Now
This incident spotlights the inadequacy of relying solely on traditional MFA, as cybercriminals are innovating around authentication safeguards to breach corporate networks. Organizations dependent on remote access need to urgently review VPN security, monitor for credential and OTP seed theft, and implement advanced threat detection and segmentation.
Attack Path Analysis
Akira ransomware actors initially accessed the environment by logging into SonicWall SSL VPNs, bypassing MFA controls likely via stolen OTP seeds. Once inside, they escalated privileges to broader network access through compromised credentials or misconfigurations. The attackers moved laterally within the network to identify assets and spread ransomware payloads to strategic systems. They established command and control through covert outbound connections, maintaining persistence for follow-on actions. Data was exfiltrated across encrypted or unfiltered channels, possibly leveraging standard protocols or covert transfer methods. Finally, the attackers executed ransomware payloads, encrypting data and disrupting operations.
Kill Chain Progression
Initial Compromise
Description
Adversaries logged into SonicWall VPN with valid credentials and bypassed MFA, likely using stolen OTP seeds.
Related CVEs
CVE-2024-40766
CVSS 9.6An improper access control vulnerability in SonicWall SonicOS allows remote attackers to bypass authentication and gain unauthorized access.
Affected Products:
SonicWall SonicOS – 7.1.x (7.1.1-7058 and older), 7.1.2-7019, 8.0.0-8035
Exploit Status:
exploited in the wildCVE-2025-40601
CVSS 7.5A stack-based buffer overflow vulnerability in SonicWall SonicOS SSLVPN service allows unauthenticated remote attackers to cause Denial of Service (DoS) and potentially crash the firewall.
Affected Products:
SonicWall SonicOS – Gen8 and Gen7 firewalls
Exploit Status:
no public exploitCVE-2023-44221
CVSS 7.2A post-authentication OS command injection vulnerability in SonicWall SMA100 SSL-VPN management interface allows remote authenticated attackers with administrative privileges to execute arbitrary commands.
Affected Products:
SonicWall SMA100 – 10.2.1.10-62sv and earlier
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts: Default Accounts
Exploit Public-Facing Application
Brute Force: Password Guessing
Modify Authentication Process: Multi-Factor Authentication Interception
Credentials from Password Managers
Data Encrypted for Impact
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-factor authentication for all access into the CDE
Control ID: 8.4.2
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT risk management framework
Control ID: Article 9(2)
CISA ZTMM 2.0 – Continuous Identity Assurance
Control ID: Identity Pillar: Continuous Identity Assurance
NIS2 Directive – Access control and asset management
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Akira ransomware targeting MFA-protected SonicWall VPNs threatens banking operations, requiring enhanced encrypted traffic monitoring and zero trust segmentation to protect financial data.
Health Care / Life Sciences
Healthcare systems using SonicWall VPNs face critical HIPAA compliance risks from Akira ransomware bypassing MFA, necessitating improved threat detection and network segmentation.
Government Administration
Government agencies with SonicWall SSL VPN infrastructure vulnerable to Akira ransomware despite OTP MFA, requiring immediate egress security and anomaly detection implementation.
Information Technology/IT
IT service providers face heightened ransomware exposure through compromised SonicWall VPNs, demanding robust multicloud visibility and inline intrusion prevention system deployment.
Sources
- Akira ransomware breaching MFA-protected SonicWall VPN accountshttps://www.bleepingcomputer.com/news/security/akira-ransomware-breaching-mfa-protected-sonicwall-vpn-accounts/Verified
- SonicWall SSL-VPN SMA100 version 10.X is affected by multiple vulnerabilitieshttps://www.sonicwall.com/support/knowledge-base/sonicwall-ssl-vpn-sma100-version-10-x-is-affected-by-multiple-vulnerabilities/231127094418307Verified
- SonicWall tells customers to patch SonicOS flaw allowing hackers to crash firewallshttps://www.techradar.com/pro/security/sonicwall-tells-customers-to-patch-sonicos-flaw-allowing-hackers-to-crash-firewallsVerified
- SonicWall SonicOS Flaw Confirmed to be Exploited In-the-Wild After PoC Releasehttps://www.aha.org/system/files/media/file/2025/02/h-isac-tlp-white-threat-bulletin-sonicwall-sonicos-flaw-confirmed-to-be-exploited-in-the-wild-after-poc-release-2-19-2024.pdfVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust segmentation, network egress controls, east-west traffic inspection, and threat detection would have restricted lateral movement, limited exposure from compromised VPN accounts, detected ransomware behaviors, and contained exfiltration, minimizing overall impact.
Control: Multicloud Visibility & Control
Mitigation: Unusual VPN logins and credential use could have triggered alerts and prompted investigation.
Control: Zero Trust Segmentation
Mitigation: Policy-based least privilege could have restricted attacker movement post-compromise.
Control: East-West Traffic Security
Mitigation: Lateral movement would be detected, limited, or blocked at workload and service boundaries.
Control: Inline IPS (Suricata)
Mitigation: Suspicious C2 traffic patterns could be detected and stopped in real time.
Control: Egress Security & Policy Enforcement
Mitigation: Unapproved outbound data flows are blocked and data exfiltration attempts detected.
Rapid anomaly detection would trigger incident response mechanisms on ransomware activity.
Impact at a Glance
Affected Business Functions
- Remote Access
- Network Security
- Data Protection
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive corporate data due to unauthorized access through compromised VPN accounts.
Recommended Actions
Key Takeaways & Next Steps
- • Enhance centralized visibility for VPN and cloud login events to rapidly detect unauthorized access.
- • Enforce Zero Trust Segmentation across all user, workload, and network domains to limit exposure post-compromise.
- • Deploy robust east-west traffic inspection and microsegmentation to prevent and detect lateral movement.
- • Apply strict egress filtering and outbound policy enforcement to block exfiltration routes and C2 communications.
- • Integrate continuous anomaly detection and threat response to quickly spot and contain ransomware behaviors before impact.



