The Akira ransomware group has been exploiting vulnerabilities in SonicWall SSL VPN appliances, particularly those inherited by large enterprises through mergers and acquisitions (M&A) of small- and medium-sized businesses. Attackers have leveraged legacy admin credentials, weak hostnames, and inadequate endpoint defenses to gain rapid access to sensitive systems, with lateral movement to domain controllers occurring in under 10 hours on average. Security researchers note that these attacks are not necessarily targeting M&A activity directly, but the inherited, often misconfigured SonicWall devices present a lucrative entry point for ransomware operations.
Experts warn that the integration of overlooked or poorly secured network devices during M&A processes significantly increases the risk of compromise for acquiring organizations. The Akira campaign highlights the broader challenge of managing legacy security appliances, as attackers continue to exploit such devices for initial access and rapid ransomware deployment. Organizations are urged to conduct thorough asset inventories and strengthen security controls around inherited IT infrastructure, especially network edge devices like SSL VPNs.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On November 26, 2025, reporting based on ReliaQuest research highlighted that Akira had been compromising inherited SonicWall SSL VPN appliances in post-acquisition environments. The findings emphasized that many acquiring companies were unaware the devices still existed and that stale admin credentials were enabling ransomware deployment.
SonicWall released updated firmware and additional security guidance to address exploitation of SSL VPN devices, including issues tied to CVE-2024-40766. Despite the availability of patches, many organizations remained exposed because of end-of-life devices and poor credential hygiene.
During the 2025 intrusion wave, investigators found Akira could move laterally from compromised SonicWall SSL VPN access to domain controller compromise in as little as five to 10 hours. The activity affected multiple industries and was assessed as opportunistic rather than specifically aimed at M&A targets.
Between June and October 2025, ReliaQuest observed a series of Akira ransomware intrusions targeting organizations running SonicWall SSL VPN appliances. Initial access commonly involved legacy SonicWall devices and inherited administrator credentials left behind after mergers and acquisitions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcecsoonline.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.