Threat actors have launched a widespread campaign targeting SonicWall SSL VPN devices, resulting in the compromise of over 100 accounts across at least 16 customer environments. Security firm Huntress reported that attackers are rapidly authenticating into multiple accounts on compromised devices, indicating possession of valid credentials rather than relying on brute-force methods. The campaign began in earnest around October 4, 2025, with authentication attempts traced to a specific IP address, 202.155.8[.]73. In some cases, attackers disconnected after brief access, but in others, they conducted network scanning and attempted to access local Windows accounts, suggesting a range of post-compromise activities. The incident follows SonicWall’s disclosure of a security breach involving unauthorized exposure of firewall configuration backup files stored in MySonicWall accounts, which could provide attackers with sensitive information such as user and group settings, DNS configurations, and certificates. Although there is no direct evidence linking the configuration file breach to the VPN compromises, the risk of credential exposure remains high, prompting advisories for organizations to reset credentials on live firewall devices. Concurrently, security teams observed a surge in Akira ransomware incidents exploiting SonicWall SSL VPN devices, initially suspected to be due to a zero-day but later attributed to the known vulnerability CVE-2024-40766. This vulnerability, an improper access control flaw in SonicOS, affects multiple generations of SonicWall devices and was first disclosed and patched in August 2024. Despite the availability of a patch, unpatched devices remain vulnerable and have been actively targeted by Akira ransomware affiliates. In one documented case, Darktrace detected suspicious activity including network scanning, lateral movement, privilege escalation, and data exfiltration on a customer’s network, with approximately 2 GiB of data exfiltrated before the attack was contained. The attackers’ tactics included leveraging both the CVE-2024-40766 vulnerability and misconfigurations to gain access. The campaign underscores the importance of timely patching and credential hygiene, as attackers are exploiting both technical vulnerabilities and exposed credentials to infiltrate networks. Organizations using SonicWall’s cloud backup service are particularly at risk if they have not reset credentials following the configuration file exposure. Security advisories recommend immediate credential resets and patching of all affected SonicWall devices to mitigate ongoing threats. The incidents highlight the persistent threat posed by ransomware groups like Akira, who continue to exploit both new and previously disclosed vulnerabilities in widely deployed network infrastructure. The rapid detection and response by managed security services, such as those provided by Darktrace, have proven effective in limiting the impact of these attacks. However, the scale and speed of the current campaign demonstrate the attackers’ ability to coordinate and execute widespread compromises across multiple organizations. The situation remains dynamic, with ongoing investigations into the full extent of the compromise and the potential links between credential exposure and active exploitation. Organizations are urged to review their SonicWall device configurations, monitor for suspicious authentication activity, and ensure all security patches are applied without delay.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
In October 2025, Huntress reported widespread SSL VPN account authentications affecting more than 100 accounts, indicating broad compromise activity against SonicWall environments. The activity was linked in public reporting to ongoing post-exploitation and ransomware risk.
In September 2025, SonicWall disclosed unauthorized access to cloud-stored firewall configuration backups in MySonicWall. This increased concern that exposed configuration data could create follow-on risk for VPN and firewall customers.
Darktrace reported at least three other U.S. incidents showing similar 'vmwaretools' downloads and SSH exfiltration to the same ASN, indicating a broader campaign. The overlap suggested repeated Akira-linked tradecraft, potentially with variation across affiliates.
Darktrace's autonomous response and MDR teams blocked key endpoints and ports and quarantined suspected devices during the August 20 incident. The response reportedly limited observed exfiltration to about 2 GiB and prevented further escalation.
During the August 20 intrusion, the attackers abused Kerberos and AD CS in a manner consistent with the UnPAC the Hash technique to extract NTLM hashes via PKINIT and U2U. They also used WinRM and RDP for movement, downloaded a 'vmwaretools' payload from rare external IPs, and exfiltrated data over SSH to infrastructure associated in OSINT with Akira.
On August 20, 2025, Darktrace observed an intrusion at a U.S. customer in which a compromised SonicWall VPN server was the likely initial access point. The attackers conducted scanning, lateral movement, privilege escalation, and limited data exfiltration consistent with Akira tradecraft.
In an August 19, 2025 update, SonicWall said earlier activity thought to reflect a zero-day was instead linked to password reuse and CVE-2024-40766 exploitation. This changed the public understanding of how attackers were obtaining access.
Defenders observed a surge of Akira ransomware incidents involving SonicWall SSL VPN devices across July and August 2025. The campaign affected multiple U.S. organizations and was initially thought to involve a new zero-day before later reassessment.
On August 4, 2025, SonicWall issued mitigation guidance in response to the ongoing SSL VPN compromise activity. Security vendors including Huntress, Arctic Wolf, GuidePoint Security, and FieldEffect also shared related observations and indicators.
By early August 2025, public reporting described active exploitation of SonicWall Gen 7 SSL VPN functionality to bypass MFA and gain unauthorized access, with Akira frequently following. At the time, the initial access method was described as a suspected zero-day with no confirmed CVE.
On 2024-09-06, SonicWall updated its advisory for CVE-2024-40766 to warn of possible active exploitation and expanded the affected exposure from management interfaces to include local SSLVPN user accounts. The same day, Arctic Wolf reported Akira intrusions using compromised local SSL VPN accounts on unpatched devices without MFA as an initial access vector.
SonicWall later said activity in 2024 that had initially been considered possible zero-day exploitation was actually associated with password reuse and exploitation of CVE-2024-40766 during some Gen 6 to Gen 7 migrations where passwords were not reset. This revised the attribution of the initial access vector for earlier incidents.
SonicWall had previously disclosed CVE-2024-40766, a vulnerability later linked to Akira-related SonicWall SSL VPN intrusions. Subsequent reporting said incidents first suspected as a zero-day were instead tied in part to this flaw.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 31 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
8 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcesecurityonline.info
Open sourcecentripetal.ai
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourcedarktrace.com
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.