Abyss is a ransomware threat associated with intrusions in which attackers maintain long-term access through compromised edge appliances, particularly SonicWall Secure Mobile Access devices. Documented incidents show initial access obtained by exploiting CVE-2021-20039 on SonicWall SMA systems, followed by installation of a persistent web shell on the appliance. In at least one investigated case, operators later deployed a SOCKS proxy on the compromised device and tunneled RDP traffic into the internal network, allowing them to move from the edge appliance into the victim environment while minimizing the need to place additional malware on internal hosts. This tradecraft reduced opportunities for endpoint detection and enabled the intrusion to remain unnoticed for an extended period before ransomware encryption was executed.
Abyss activity has been observed in incidents involving prolonged dwell time, persistence on internet-facing infrastructure, and post-compromise use of legitimate remote access protocols. Reporting has also noted overlaps between Abyss-related ransomware incidents and later SonicWall SMA compromise activity involving other malware families, indicating recurring attacker interest in vulnerable or poorly monitored remote access appliances as a foothold. Manufacturing and other industrial environments appear in broader ransomware tracking that includes Abyss among less frequently observed groups, but publicly available information in the supplied material is limited regarding a distinct victimology pattern, internal encryption mechanics, or a formal ransomware-as-a-service structure.
High-confidence characteristics supported here are that Abyss is used as ransomware, that it has been deployed after exploitation of vulnerable edge devices, and that associated operators used persistence and post-exploitation access through compromised SMA appliances to facilitate the eventual attack.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...the initial entry point that ultimately led to the deployment of the Abyss ransomware was a compromised SonicWall Secure Mobile Access (SonicWall SMA) device.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Minimal-activity ransomware brand referenced as part of the long-tail of operators.
Ransomware referenced in incidents involving SonicWall SMA appliance compromise; attackers reportedly maintained persistence (e.g., via web shell) and later deployed Abyss.
Ransomware operation referenced as minimal activity in Q2 2025 (no additional detail provided).
Ransomware deployed after attackers compromised a SonicWall SMA device and maintained covert access into the internal network for months before encrypting the environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.