Executive Summary
In mid-2025, Akira ransomware operators launched a widespread campaign targeting organizations using SonicWall VPN appliances, exploiting a critical vulnerability (CVE-2024-40766) in SonicOS firmware. Attackers achieved initial access through malicious SSL VPN logins, sometimes even bypassing one-time password (OTP) multi-factor authentication controls. Following a successful breach, the attackers conducted rapid port scanning and lateral movement via Impacket SMB activity before deploying Akira ransomware, impacting organizations across various sectors. Despite firmware updates and password resets, compromised credentials persisted, leaving several devices exposed, and the campaign has continued to escalate into late September 2025.
This incident illustrates the ongoing evolution and sophistication of ransomware campaigns exploiting network infrastructure vulnerabilities and underscores the urgency of proactive credential management, privileged access monitoring, and swift patch adoption. It exemplifies growing attacks abusing VPNs and MFA, requiring organizations to revisit zero trust and layered defense measures.
Why This Matters Now
The Akira campaign shows that VPN and multi-factor authentication controls can be undermined by credential theft and unpatched vulnerabilities, enabling rapid ransomware deployment. With attackers continuously refining their tactics, organizations must urgently address exposure pathways in remote access systems and enforce strict security hygiene to prevent similar breaches.
Attack Path Analysis
Attackers initially compromised organizations by exploiting CVE-2024-40766 in SonicWall SSL VPNs, bypassing even OTP MFA controls. After gaining valid credentials, they escalated access to penetrate internal network resources. Rapid lateral movement was observed through internal port scanning and SMB (Impacket) activity. Attackers established command channels for remote control and deployment. Exfiltration likely occurred via outbound channels, and finally, Akira ransomware was rapidly deployed, encrypting data and disrupting business operations.
Kill Chain Progression
Initial Compromise
Description
Threat actors exploited the CVE-2024-40766 vulnerability in SonicWall VPNs, enabling malicious logins and bypass of OTP MFA to gain initial foothold.
Related CVEs
CVE-2024-40766
CVSS 9.8An improper access control vulnerability in SonicWall SonicOS management access allows unauthorized resource access and can cause firewall crashes under specific conditions.
Affected Products:
SonicWall SonicOS – < 5.9.2.14-13o, < 6.5.2.8-2n, < 6.5.4.15-116n, <= 7.0.1-5035
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts: Default Accounts
Brute Force: Password Guessing
Modify Authentication Process: Multi-Factor Authentication Interception
Remote Services: SMB/Windows Admin Shares
Network Service Scanning
Obfuscated Files or Information
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-Factor Authentication for All Access
Control ID: 8.4.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art. 9(2)
CISA Zero Trust Maturity Model 2.0 – Continuous Authentication and Credential Protection
Control ID: Identity Pillar
NIS2 Directive – Incident Prevention, Detection, and Response
Control ID: Art. 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
SonicWall VPN vulnerabilities expose financial institutions to Akira ransomware through compromised SSL connections, bypassing MFA protections and enabling rapid deployment.
Health Care / Life Sciences
Healthcare organizations using SonicWall firewalls face critical ransomware exposure via CVE-2024-40766, with HIPAA compliance violations from compromised encrypted traffic and data.
Government Administration
Government agencies with SonicWall VPN infrastructure vulnerable to opportunistic mass exploitation, risking sensitive data through compromised SSL connections and lateral movement.
Information Technology/IT
IT service providers managing SonicWall devices across multiple clients face widespread Akira ransomware exposure through exploited VPN vulnerabilities and credential harvesting.
Sources
- Akira Hits SonicWall VPNs in Broad Ransomware Campaignhttps://www.darkreading.com/application-security/akira-sonicwall-vpns-broad-ransomware-campaignVerified
- SonicWall VPN accounts breached by Akira ransomware - and even those using MFA are at riskhttps://www.techradar.com/pro/security/sonicwall-vpn-accounts-breached-by-akira-ransomware-even-those-using-mfaVerified
- CVE-2024-40766 | INCIBE-CERT | INCIBEhttps://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2024-40766Verified
- Ongoing active exploitation of SonicWall SSL VPNs in Australia (CVE-2024-40766) | Cyber.gov.auhttps://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/ongoing-active-exploitation-of-sonicwall-ssl-vpns-in-australiaVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Effective Zero Trust segmentation, lateral movement controls, and robust egress policy enforcement—as supported by CNSF and associated capabilities—would have detected abnormal VPN logins, limited internal propagation, and contained ransomware impact, reducing or preventing attack success at multiple stages.
Control: Multicloud Visibility & Control
Mitigation: Unusual VPN logins and anomalous ingress activity are detected in real time.
Control: Zero Trust Segmentation
Mitigation: Even with valid credentials, lateral access is constrained by identity-based segmentation boundaries.
Control: East-West Traffic Security
Mitigation: East-west network movement and port scanning are blocked or heavily monitored.
Control: Threat Detection & Anomaly Response
Mitigation: Anomalous remote access and command & control patterns are detected and alerted upon.
Control: Egress Security & Policy Enforcement
Mitigation: Unauthorized outbound data transfers to external destinations are prevented or logged.
Automated distributed policy can isolate impacted segments and reduce blast radius.
Impact at a Glance
Affected Business Functions
- Network Security
- Remote Access Services
- Data Protection
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive corporate data due to unauthorized access through compromised VPNs.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust segmentation to limit lateral movement and restrict access between network segments.
- • Deploy centralized multicloud visibility tools to monitor and rapidly detect anomalous VPN/authentication activity.
- • Implement strict egress controls to detect and block unauthorized outbound data transfers from workloads and services.
- • Use real-time threat detection and automated anomaly response capabilities to quickly identify and disrupt attacker C2 and ransomware deployment.
- • Regularly update, patch, and audit access controls across all perimeter devices, including VPNs, and reset compromised credentials across the environment.



