LIVE
LATEST THREAT: Arcus Media: The RaaS Operation Targeting Healthcare and Critical Infrastructure THREAT ALERT ACTIVE
Intelligence DB / Campaign Alert Akira

Akira's SonicWall Campaign: How a VPN Appliance Became a Gateway to 100+ Intrusions

From July 2025, Akira ransomware operators systematically shifted initial access focus to SonicWall SSL-VPN appliances, exploiting CVE-2024-40766 to generate a wave of intrusions across manufacturing, professional services, and healthcare organisations.

By Ransomware Tracker ·
AkiraSonicWallCVE-2024-40766SSL-VPNinitial accesscampaignmanufacturinghealthcarecredential theftESXi20252026
Threat Level
9/10
Sectors Targeted
manufacturing
professional-services
healthcare
education
Ransomware Family
Akira

Campaign Overview

From July 2025 through early 2026, Akira ransomware operators conducted a sustained exploitation campaign targeting SonicWall SSL-VPN and SMA appliances, generating a wave of intrusions across manufacturing, professional services, and healthcare organisations. The campaign was documented by Darktrace incident response teams and independently corroborated by multiple threat intelligence vendors who observed Akira intrusions initiating from SonicWall VPN sessions across different victim environments in compressed timeframes.

The campaign marks a deliberate shift in Akira’s initial access portfolio. As patch deployment for Cisco ASA vulnerabilities (the group’s previous primary vector) reduced the available attack surface through 2024-25, Akira systematically identified SonicWall as an under-patched alternative with a large installed base in Akira’s target market: mid-size organisations in manufacturing, professional services, and education that frequently run SonicWall appliances as cost-effective VPN gateway solutions.

Vulnerability: CVE-2024-40766

CVE-2024-40766 is an improper access control vulnerability in SonicWall SonicOS, first disclosed by SonicWall in August 2024 with a CVSS score of 9.3. The vulnerability affects the management interface and SSL-VPN functionality of SonicOS and allows unauthenticated access to resources, potential unauthorised access to the appliance, and in specific firmware versions, firewall crashes.

CISA added CVE-2024-40766 to the Known Exploited Vulnerabilities catalogue in September 2024, acknowledging active exploitation. SonicWall issued patches for affected firmware versions and issued emergency guidance recommending multi-factor authentication enforcement and management interface access restriction.

Despite the September 2024 KEV addition, substantial portions of the SonicWall installed base remained unpatched through 2025. The mid-market organisations that dominate SonicWall deployments often have quarterly or annual patching cadences for edge appliances, or rely on VARs and MSPs for patching who may not have treated the KEV urgently. This created a persistent attack surface that Akira exploited systematically.

Attack Chain Documentation

Darktrace’s investigation into Akira SonicWall intrusions documented a consistent post-exploitation sequence:

Stage 1 - Initial access (0-5 minutes): Successful authentication to SonicWall SSL-VPN portal, either exploiting CVE-2024-40766 directly or using credentials obtained from infostealer logs that include SonicWall portal credentials. VPN session established, attacker receives internal IP allocation.

Stage 2 - Rapid reconnaissance (5-30 minutes): RDP scanning of internal IP ranges from the VPN connection. Identification of domain controllers, file servers, and hypervisor management interfaces. BloodHound LDAP enumeration against Active Directory to identify privileged accounts and delegation paths.

Stage 3 - Credential theft (30-120 minutes): LSASS memory dumping via ProcDump or comsvcs.dll on an accessible Windows host. SAM database extraction. Credential reuse from any found to authenticate to domain controllers or VMware vCenter.

Stage 4 - Persistence and exfiltration prep (1-8 hours): AnyDesk installation for backup remote access. RClone configuration for data exfiltration to Mega or Wasabi cloud storage. Staging of exfiltration — targeting finance directories, HR records, client files, and any data with compliance or regulatory sensitivity.

Stage 5 - ESXi targeting and encryption (8-24 hours): Access to VMware vCenter or direct ESXi management interface. Deployment of Akira’s Linux encryptor to the ESXi host. Encryption of virtual machine disk files across all datastores. Deployment of Windows encryptor across remaining accessible endpoints.

The 8-24 hour timeline from initial VPN access to encryption completion is characteristic of Akira’s fast-paced operational model, distinguishing it from ransomware groups that maintain weeks of dwell time. The speed compresses the detection and response window significantly.

Victim Profile and Sectors

The SonicWall campaign’s victim profile aligns with the SonicWall customer base rather than any specific industry targeting:

Manufacturing: SonicWall is common in manufacturing environments as a cost-effective VPN gateway for remote access to OT monitoring systems and manufacturing execution systems. ESXi virtualisation of engineering workstations makes these environments high-value encryption targets.

Professional services: Law firms, accounting practices, and consulting firms running SonicWall for remote access represent a consistent target. Client data and privileged communications provide strong extortion leverage.

Healthcare: Regional hospitals, specialty clinics, and healthcare groups with SonicWall deployments in smaller facilities. Healthcare’s operational urgency and sensitivity to data breach disclosure creates payment pressure.

Education: Universities and school districts with SonicWall deployments, often less aggressively patched than enterprise targets.

Ransom demands observed in SonicWall-initiated Akira incidents range from $300,000 to $8 million, with amounts calibrated to visible annual revenue of the victim organisation.

Detection Indicators

Key indicators of Akira SonicWall campaign activity:

Initial Access:

  • Successful SonicWall SSL-VPN authentication from unusual geolocations or IP ranges
  • Authentication to VPN immediately followed by broad internal RDP scanning (detectable in NetFlow/VPC flow logs)
  • Multiple failed authentications preceding a success (credential stuffing pattern from infostealer logs)

Post-Exploitation:

  • ProcDump or comsvcs.dll execution on Windows hosts
  • BloodHound LDAP enumeration patterns (large LDAP query volumes, SAMR pipe access)
  • AnyDesk binary installation from command line or staging directory
  • RClone.exe execution with Mega or Wasabi endpoints in command-line arguments

Pre-Encryption:

  • vssadmin.exe delete shadows (shadow copy deletion)
  • bcdedit.exe /set recoveryenabled no (recovery disabled)
  • ESXi SSH session initiation from non-standard sources
  • vCenter API calls from internal IPs that have not previously accessed vCenter

Remediation and Prevention

Immediate for SonicWall deployments:

  1. Apply all SonicOS firmware patches for CVE-2024-40766 and related vulnerabilities immediately. Check the SonicWall Product Security Notice for your specific model and firmware version.

  2. Enable multi-factor authentication on all SonicWall SSL-VPN portals. This is the most effective single control — Akira’s credential reuse from infostealer markets is blocked by MFA even when credentials are known.

  3. Restrict management interface access to defined admin IP ranges. The management interface should not be accessible from the internet.

  4. Review SSL-VPN authentication logs for the past 90 days for anomalous access patterns.

Broader resilience:

  • ESXi and vCenter management plane should not be accessible from general corporate networks. VLAN segmentation for hypervisor management is the appropriate architecture.
  • Immutable backup copies of VMware datastores and critical data should be maintained offline or in cloud-based immutable storage that the ESXi host cannot reach.
  • AnyDesk and remote access tools should be blocked by application control policies unless explicitly required, or monitored for unexpected installation.

References

// Related Intelligence
Campaign Alert

INC Ransom's Law Firm Campaign: 20 Victims in 48 Hours and What It Means for the Legal Sector

Group Profile

Akira Ransomware: VMware ESXi Targeting, Linux Encryptors, and 300+ Victims in 18 Months

Campaign Alert

Cl0p's Oracle EBS Campaign: Mass Exploitation via CVE-2025-61882