Skip to content
Blogs

Blogs

Akira Targets SonicWall VPNs in Zero-Day Surge

Posted on September 3, 2025March 9, 2026 By Finstein.ai No Comments on Akira Targets SonicWall VPNs in Zero-Day Surge

In late July 2025, Arctic Wolf identified a surge in ransomware intrusions linked to SonicWall SSL VPNs, with evidence suggesting the exploitation of a likely zero-day vulnerability. Several incidents involved compromised VPN access despite devices being fully patched and protected with TOTP-based MFA. In many cases, accounts were breached shortly after credential rotations, pointing to unauthorized access methods beyond brute force or credential stuffing.

The Akira ransomware group appears to be behind the campaign, with observed activity dating back to October 2024. Attackers are leveraging Virtual Private Server (VPS) infrastructure for VPN authentication, contrasting with typical broadband ISP logins seen in legitimate access.

Arctic Wolf recommends temporarily disabling SonicWall SSL VPN services until official patches are available. Organizations should enable SonicWall log monitoring and deploy Arctic Wolf Agent and Sysmon for enhanced visibility. Customers are also urged to integrate supported Endpoint Detection and Response (EDR) solutions.

Additional hardening measures include enforcing MFA, removing unused accounts, maintaining strong password hygiene, and enabling SonicWall’s security services. Arctic Wolf also advises filtering VPN authentication from specific hosting-related ASNs associated with suspicious activity.

Research is ongoing, and organizations are encouraged to remain alert for further guidance as new intelligence becomes available.

Contact us : Finstein Cyber — Cybersecurity & VAPT Services

Source : : https://arcticwolf.com/resources/blog/arctic-wolf-observes-july-2025-uptick-in-akira-ransomware-activity-targeting-sonicwall-ssl-vpn/

#Cybersecurity #Ransomware #AkiraRansomware #SonicWallVPN #ZeroDay #Infosec #ThreatIntel #MFA #VPNSecurity #EDR #ArcticWolf #CyberDefense #Sysmon #IncidentResponse #DataProtection #NetworkSecurity #CISO #ITSecurity

Cyber

Post navigation

Previous Post: Akira Targets SonicWall VPNs in Zero-Day Surge
Next Post: Stealthy ‘Plague’ Backdoor Hits Linux Systems

Related Posts

The Blurred Line Between Corporate Management and Malware Cyber
Is Your Proprietary Code the New Ransomware Target Is Your Proprietary Code the New Ransomware Target? Ai
Your Firewall Will Fail. Is Your Recovery Ready? Your Firewall Will Fail. Is Your Recovery Ready? Cyber
Your Firewalls are Perfect, Your Employees are Not. Your Firewalls are Perfect, Your Employees are Not. Cyber
The Login That Lies The Login That Lies Ai
Why Being a “Good Employee” Makes You Easier to Phish. Why Being a “Good Employee” Makes You Easier to Phish. Cyber

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Categories

  • Ai
  • Cyber
  • Data Sciences
  • ERPNext
  • Technology

Copyright © 2026 Blogs.

Powered by PressBook Masonry Blogs