Akira ransomware operators have been actively targeting organizations by exploiting SonicWall SSL VPN devices to gain unauthorized access to corporate networks. Security researchers observed that the attackers were able to authenticate to SonicWall VPN accounts even when one-time password (OTP) multi-factor authentication (MFA) was enabled, raising concerns about the effectiveness of MFA protections in these scenarios. The initial vector for these breaches was linked to an improper access control vulnerability in SonicWall devices, tracked as CVE-2024-40766, which was disclosed in September 2024 and patched in August 2024. Despite the patch, threat actors continued to leverage credentials that had been previously stolen from devices vulnerable to this flaw, allowing them to maintain access even after organizations applied the security update. Arctic Wolf researchers reported that attackers were able to solve multiple OTP challenges, suggesting that they may have compromised OTP seeds or found alternative methods to generate valid tokens, effectively bypassing MFA protections. The campaign has been described as lightning-fast, with Akira ransomware operators quickly exploiting exposed VPN accounts to move laterally within networks and deploy ransomware payloads. SonicWall responded by urging administrators to reset all SSL VPN credentials and ensure that the latest SonicOS firmware was installed on affected devices. The persistence of the attacks, even after patching, highlights the importance of credential hygiene and the need for organizations to rotate credentials following a security incident. The attackers’ ability to bypass MFA by potentially using previously stolen OTP seeds demonstrates a sophisticated understanding of authentication mechanisms and underscores the evolving tactics of ransomware groups. The Akira ransomware group has been known for its rapid intrusions and effective exploitation of remote access infrastructure, making it a significant threat to organizations relying on SonicWall VPN solutions. Security experts recommend that organizations monitor for unusual login activity, enforce strong password policies, and consider additional layers of authentication beyond OTP-based MFA. The incident serves as a reminder that patching vulnerabilities is only one aspect of a comprehensive security strategy, and that post-compromise credential management is critical to preventing ongoing unauthorized access. The Akira campaign against SonicWall VPNs is part of a broader trend of ransomware groups targeting remote access solutions to gain initial footholds in enterprise environments. Organizations are advised to review their VPN access logs, investigate any suspicious activity, and implement network segmentation to limit the impact of potential breaches. The continued exploitation of previously stolen credentials, even after security updates, demonstrates the long-term risks associated with credential theft and the need for proactive incident response measures. This series of attacks has prompted renewed calls for vendors and customers alike to improve the security of remote access infrastructure and to remain vigilant against evolving ransomware tactics.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Researchers and reporting on the campaign recommended that organizations fully reset SonicWall SSL VPN and related Active Directory credentials, not just patch devices. The guidance reflected that compromised credentials could survive firmware upgrades and continue to enable access.
Reporting described how attackers moved from VPN login to reconnaissance, privilege escalation, remote tool deployment, data exfiltration, and encryption within hours. The campaign also used evasion methods including disabling security tools, living-off-the-land binaries, tunneling utilities, and BYOVD techniques.
Google Threat Intelligence Group attributed some of the SonicWall-related intrusion activity to the financially motivated cluster UNC6148. This added an attribution detail to the broader Akira-linked campaign.
Arctic Wolf and Google Threat Intelligence Group observed Akira intrusions into SonicWall VPN accounts protected by OTP-based MFA. Investigators assessed that attackers were likely using credentials and OTP seeds stolen earlier via exploitation of CVE-2024-40766, allowing access even on patched devices.
Arctic Wolf and SonicWall warned of multiple late-July 2025 pre-ransomware intrusions involving SonicWall Gen 7 firewalls with SSL VPN enabled. Early reporting suggested a possible zero-day because some affected devices were reportedly fully patched, had rotated credentials, and in some cases used TOTP MFA.
By July 2025, Akira ransomware operators were actively targeting SonicWall SSL VPN appliances and authenticating to both local and LDAP-synced accounts. The campaign affected multiple sectors and used stolen credentials to gain initial access.
SonicWall released fixes and hardening updates for CVE-2024-40766, an improper access control flaw in SonicWall devices. Later reporting indicates attackers likely used the vulnerability before patching to steal VPN credentials and possibly OTP seeds.
6 references tracked. Mallory keeps watching after this page renders.
shroudcloud.io
Open sourcesecurityonline.info
Open sourcedarkreading.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourceforbes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.