Skip to content
Blogs

Blogs

Akira Targets SonicWall VPNs in Zero-Day Surge

Posted on September 3, 2025September 26, 2025 By Finstein.ai No Comments on Akira Targets SonicWall VPNs in Zero-Day Surge

In late July 2025, Arctic Wolf identified a surge in ransomware intrusions linked to SonicWall SSL VPNs, with evidence suggesting the exploitation of a likely zero-day vulnerability. Several incidents involved compromised VPN access despite devices being fully patched and protected with TOTP-based MFA. In many cases, accounts were breached shortly after credential rotations, pointing to unauthorized access methods beyond brute force or credential stuffing.

The Akira ransomware group appears to be behind the campaign, with observed activity dating back to October 2024. Attackers are leveraging Virtual Private Server (VPS) infrastructure for VPN authentication, contrasting with typical broadband ISP logins seen in legitimate access.

Arctic Wolf recommends temporarily disabling SonicWall SSL VPN services until official patches are available. Organizations should enable SonicWall log monitoring and deploy Arctic Wolf Agent and Sysmon for enhanced visibility. Customers are also urged to integrate supported Endpoint Detection and Response (EDR) solutions.

Additional hardening measures include enforcing MFA, removing unused accounts, maintaining strong password hygiene, and enabling SonicWall’s security services. Arctic Wolf also advises filtering VPN authentication from specific hosting-related ASNs associated with suspicious activity.

Research is ongoing, and organizations are encouraged to remain alert for further guidance as new intelligence becomes available.

Contact us : Finstein Cyber — Cybersecurity & VAPT Services

Source : : https://arcticwolf.com/resources/blog/arctic-wolf-observes-july-2025-uptick-in-akira-ransomware-activity-targeting-sonicwall-ssl-vpn/

#Cybersecurity #Ransomware #AkiraRansomware #SonicWallVPN #ZeroDay #Infosec #ThreatIntel #MFA #VPNSecurity #EDR #ArcticWolf #CyberDefense #Sysmon #IncidentResponse #DataProtection #NetworkSecurity #CISO #ITSecurity

Security

Post navigation

Previous Post: Akira Targets SonicWall VPNs in Zero-Day Surge
Next Post: Stealthy ‘Plague’ Backdoor Hits Linux Systems

Related Posts

Could a copied File-Fix link be hiding malware? Security
Iranian Cyber Offensive Shows Unprecedented Coordination Cyber
Stealthy ‘Plague’ Backdoor Hits Linux Systems Security
Akira Targets SonicWall VPNs in Zero-Day Surge Security
India-Linked Group Targets Turkish Defense Security
Scattered Spider Hijacks VMware Systems Security

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Categories

  • Ai
  • Captcha
  • Common
  • Cyber
  • Data Privacy
  • ERP Next
  • Hacker
  • Healthcare
  • Hitrust
  • IT
  • RBI
  • Security
  • SOC
  • Uncategorized

Copyright © 2026 Blogs.

Powered by PressBook Masonry Blogs