Akira ransomware operators are compromising SonicWall Gen 7 SSL VPN accounts protected by OTP-based MFA, using credentials—and potentially OTP seeds—harvested through the previously disclosed improper-access-control flaw CVE-2024-40766. SonicWall assessed the activity as exploitation of that known vulnerability rather than a new zero-day; some incidents were associated with legacy credentials retained during Gen 6-to-Gen 7 migrations. Intrusions have continued against patched appliances, including systems running SonicOS 7.3.0, because firmware updates do not invalidate previously stolen authentication material.
After authenticating to VPN services, affiliates rapidly conduct network reconnaissance, escalate privileges, target backup infrastructure, deploy remote-management and tunneling tools, exfiltrate data, and encrypt systems—often within hours. Researchers observed security-control evasion, including bring-your-own-vulnerable-driver attacks to disable endpoint defenses, and attributed portions of the activity to the financially motivated cluster UNC6148. Organizations operating SonicWall SSL VPNs should update firmware, reset all SSL VPN and Active Directory credentials rather than relying on patching alone, remove legacy accounts and migration artifacts, and investigate anomalous VPN logins and rapid post-login reconnaissance.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
Akira ransomware operators began targeting SonicWall SSL VPN appliances, including accounts protected by one-time-password MFA. The activity was linked to credentials compromised through CVE-2024-40766.
Google Threat Intelligence Group reported similar abuse of SonicWall VPNs. Some activity was attributed to financially motivated UNC6148, which deployed the OVERSTEP rootkit on SMA 100-series appliances.
Arctic Wolf observed multiple late-July intrusions using SonicWall SSL VPN access as an initial-access vector and initially assessed that the evidence could indicate a zero-day. Some affected Gen 7 devices were reportedly patched, had undergone credential rotation, or used TOTP MFA.
SonicWall patched CVE-2024-40766, an improper-access-control vulnerability in its devices. Attackers later used credentials and potentially OTP seeds obtained before the patch to access VPN accounts.
Akira intrusions continued against SonicWall devices including systems running SonicOS 7.3.0, because previously compromised credentials remained usable after firmware upgrades. Researchers recommended resetting all SSL VPN and Active Directory credentials on affected deployments.
Arctic Wolf documented that Akira operators could authenticate to SonicWall VPN accounts protected by OTP MFA, likely with previously stolen credentials and OTP seeds. After access, the operators rapidly scanned networks, targeted backup infrastructure, disabled security tooling, exfiltrated data, and encrypted environments in as little as 55 minutes.
SonicWall notified affected customers and partners, published mitigation guidance, and recommended credential changes and upgrades to SonicOS 7.3.0. It also urged customers to disable SSL VPN where practical and restrict access to trusted source IPs.
SonicWall said with high confidence that the Gen 7 SSL VPN incidents were related to the previously disclosed CVE-2024-40766, not a new zero-day. It reported fewer than 40 confirmed cases and linked them to legacy credentials retained during Gen 6-to-Gen 7 migrations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcesecurityonline.info
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourceforbes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.