Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

SonicWall SSL VPN Devices Targeted by Threat Actors to Distribute Akira Ransomware

An increase in Akira ransomware attacks has been detected, exploiting unpatched SonicWall SSL VPN devices between July and August 2025.

An increase in Akira ransomware attacks has been detected, exploiting unpatched SonicWall SSL VPN devices between July and August 2025.

Although a patch was released on the same day, many organizations remained vulnerable. This allowed threat actors to gain initial access and deploy Akira's double-extortion scheme.

On Mon, Aug 20, 2025, anomalous network scanning and reconnaissance activity were detected on a U.S. customer’s network. Initially thought to be a potential zero-day, SonicWall later confirmed that all incidents originated from the exploitation of CVE-2024-40766, an improper access control flaw disclosed on Fri, Aug 23, 2024.

The reconnaissance involved repeated Advanced IP Scanner lookups against an internal SonicWall SSL VPN server, followed by lateral movement and data exfiltration.

The SOC team traced the breach to a virtual private network appliance running SonicOS 7.0.1.5035, confirming exploitation of CVE-2024-40766.

Akira targets organizations in various sectors, particularly manufacturing, education, and healthcare.

Attackers used previously stolen credentials and misconfigurations in the Virtual Office Portal to bypass multi-factor protections and escalate privileges. Approximately 2 GiB of sensitive data was exfiltrated before containment actions were implemented.

Technical Analysis of Exploit and Malware

CVE-2024-40766 allows unauthorized access to administrative endpoints, enabling remote control of SSL VPN configurations. A minimal proof-of-concept exploit in Python leverages an HTTP POST to the vulnerable endpoint:

An increase in Akira ransomware attacks has been detected, exploiting unpatched SonicWall SSL VPN devices between July and August 2025.
Harper Fairbanks · Thehackingpost

url = "https://victim-vpn.example.com/cgi-bin/sslvpn_cfg" payload = {"func": "get_user_info", "user": "admin"} response = requests.post(url, data=payload, verify=False) print(response.text)

After gaining access, attackers deployed Akira Windows and Linux variants. The Windows build encrypts file systems, while the ESXi variant targets hypervisor file stores, enabling rapid encryption across cloud infrastructures.

Adversaries moved laterally using WinRM and RDP, extracted NTLM hashes via Kerberos PKINIT and U2U authentication, and deployed ransomware binaries using valid administrative tools.

Command and Control (C2) communications utilized temporary cloud-hosting services and direct downloads from rare IPs.

This campaign emphasizes the critical importance of timely patching and robust configuration management.

CVE-2024-40766 was exploitable over a year after its disclosure, demonstrating that adversaries will continually scan for unpatched systems.

Misconfigurations in Virtual Office Portals enabled initial access even on patched devices, highlighting the need for credential hygiene and periodic configuration audits.

Advertisement

Ransomware operators now favor legitimate administrative protocols to blend malicious activity into normal traffic.

The abuse of the "UnPAC the hash" technique showcases how certificate-based Kerberos authentication can be subverted to extract NTLM hashes for lateral movement.

Monitoring for unusual Kerberos PKINIT requests, DCE-RPC calls, and abnormal external data transfers is essential.

Defenders should adopt a defense-in-depth approach:

Enforce least-privilege access and multi-factor authentication on all VPN portals. Deploy network segmentation to limit lateral movement. Monitor and block rare external endpoints and anomalous administrative tool usage. Leverage AI-driven detection for correlating reconnaissance, credential abuse, and data exfiltration into cohesive incidents.

Rapid triage and containment can drastically reduce impact. Organizations subscribing to managed detection and response services benefit from high-fidelity alerting, expedited investigation, and immediate mitigation, curbing the scope of Akira’s double-extortion tactics. Continuous vigilance, even post-patch, is essential to thwart evolving ransomware threats exploiting legacy vulnerabilities.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories