Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign Exploitation Wave Vulnerability

Akira exploitation of SonicWall SSL VPN flaw CVE-2024-40766

Updated 04.12.2025 00:06
Case score 68
Members 4 First seen 11.09.2025 13:33 Latest activity 04.12.2025 00:06

Overview

**CVE-2024-40766** exploitation against **SonicWall SSL VPN** endpoints has become an Akira-linked intrusion and ransomware story, with attackers using malicious logins on exposed devices and, in some cases, abusing or bypassing OTP MFA. Activity observed from **October 4, 2025** spread across more than **100 accounts** in **16 environments** and in some intrusions quickly moved to scanning and Windows account access attempts. **Marquis Software Solutions** later disclosed a ransomware intrusion through a SonicWall firewall that exposed data tied to **74 banks and credit unions** and affected more than **400,000 customers**. SonicWall customers have been urged to patch, rotate credentials, remove unused accounts, and tighten portal and lockout controls.
Latest development Open development history 4 earlier developments Akira expands SonicWall CVE-2024-40766 exploitation Akira ransomware remains active against SonicWall firewalls, with Arctic Wolf observing dozens of incidents over the past three months tied to CVE-2024-40766 abuse, SSL VPN logins from VPS hosting providers, Impacket SMB activity, and Active Directory discovery. The campaign targets SSL VPN accounts using OTP MFA, and Barracuda separately observed Akira affiliates using Datto RMM, backup agents, and PowerShell to gain control while avoiding security alerts.
  1. Earlier development

    Akira campaign compromises SonicWall accounts despite OTP MFA

    Arctic Wolf observed an ongoing Akira ransomware campaign against SonicWall firewalls and SSL VPN accounts in which attackers successfully logged in even when one-time password (OTP) multi-factor authentication was enabled, with the activity tied to CVE-2024-40766 and likely involving reused credentials or previously stolen OTP seeds. After gaining access, the actors reportedly scanned internal networks within 5 minutes, used Impacket, RDP, dsquery, SharpShares, and BloodHound for reconnaissance, targeted Veeam Backup & Replication servers for credential extraction, and used a Bring-Your-Own-Vulnerable-Driver chain with consent.exe, rwdrv.sys, and churchill_driver.sys to disable endpoint defenses.

  2. Earlier development

    SonicWall SSL VPN exploitation wave (Akira-linked)

    The wave first centered on **SonicWall SSL VPN** access and quickly showed signs of repeated use across multiple intrusions. Early reporting tied the activity to **Akira ransomware** resurgence beginning in **late July 2025**.

  3. Earlier development

    Akira targeting of SonicWall devices for initial access

    Rapid7 and SonicWall described continued Akira-affiliated targeting of SonicWall devices for initial access, with increased intrusions over the past month and renewed activity since late July 2025. SonicWall tied the abuse to CVE-2024-40766, warning that brute-forced credentials, misconfigured LDAP SSL VPN Default User Groups, and exposed Virtual Office Portal access can let compromised accounts inherit sensitive permissions and enable unauthorized network access.

  4. Earlier development

    SonicWall SSL VPN access control flaw actively exploited (CVE-2024-40766)

    SonicWall patched **CVE-2024-40766** in **August 2024** after identifying an **access control** flaw that could enable **unauthorized resource access** and trigger **firewall crashes**. The bug affects exposed **SSLVPN** endpoints across several firewall generations.

Signals

Impact signals
Exploitation
CVEs/products
Geographic context
Remediation
Status
Threat context
Affected surface

Threat actor context

3 listed

Malware & tooling context

9 families · 9 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Campaign Akira ransomware group SonicWall initial-access campaign
Updated 11.09.2025 13:33 Lead Contribution 62
Objective Financial Extortion Campaign Active

The **Akira ransomware group** is associated with a continuing **SonicWall SSL VPN** initial-access campaign that uses **CVE-2024-40766** and related credential abuse to breach victim networks. A newer victim-impact update shows **Marquis Software Solutions** was hit by a **ransomware attack on August 14, 2025** through a **SonicWall firewall**, exposing files with personal information for customers of **74 banks and credit unions** and affecting **over 400,000 customers**. Marquis says there is **no evidence** the data has been misused or published, while the breach details reinforce the campaign’s focus on **SonicWall VPN** access and post-compromise theft.

Campaign Akira SonicWall SSL VPN MFA-bypass campaign
Updated 28.09.2025 21:49 Scoring Support Contribution 2
Objective Financial Extortion Campaign Active Patch Patch Available

In late September, **Arctic Wolf** reported an ongoing **Akira** campaign against **SonicWall** firewalls and **SSL VPN** accounts that could log in even when **OTP MFA** was enabled, with activity tied to **CVE-2024-40766** and likely involving reused credentials or stolen OTP seeds. After access, the actors reportedly moved quickly into internal reconnaissance, including scans within **5 minutes**, use of **Impacket**, **RDP**, **dsquery**, **SharpShares**, and **BloodHound**, plus attempts to target **Veeam Backup & Replication** and disable defenses with a **BYOVD** chain. On **October 11, 2025**, **Huntress** said the same broad abuse pattern had affected **more than 100 accounts** across **16 customer environments**, with logins from **202.155.8[.]73** and signs of valid-credential use. Huntress also said SonicWall’s separate backup-file exposure in **MySonicWall** had no evidence linking it to the recent compromise spike.

Exploitation Wave SonicWall SSL VPN exploitation wave (Akira-linked)
Updated 11.09.2025 13:33 Scoring Support Contribution 2
Exploitation Active Exploitation CVSS 9.3 Critical Patch Patch Available

An **Akira ransomware**-linked **exploitation wave** is driving a **widespread compromise** of **SonicWall SSL VPN devices** for initial access, with attacks using **CVE-2024-40766** and, in some cases, rapidly moving from login activity to **network scanning** and attempts to access **Windows accounts**. Huntress said the latest activity began on **October 4, 2025** and impacted **more than 100 accounts** across **16 customer environments**, with authentications in its cases originating from **202.155.8[.]73**. SonicWall also disclosed unauthorized exposure of **firewall configuration backup files** in **MySonicWall** accounts, but Huntress said there is **no evidence yet** linking that incident to the spike in compromises.

Vulnerability SonicWall SSL VPN access control flaw actively exploited (CVE-2024-40766)
Updated 11.09.2025 19:32 Scoring Support
Exploitation Active Exploitation Exploit No Known Public Exploit Data Type Passwords CVSS 9.3 Critical 1 more in details
All signals
Exploitation Active Exploitation Exploit No Known Public Exploit Data Type Passwords CVSS 9.3 Critical Patch Patch Available

**CVE-2024-40766** is a **SonicWall SSL VPN** access control flaw that has been **actively exploited** to breach exposed devices, with **Akira ransomware** tied to the campaign. Recent reporting says attackers used **malicious SSL VPN logins** and, in some cases, were able to bypass or abuse **OTP MFA**, then move to **port scanning**, **Impacket SMB activity**, and rapid ransomware deployment. The campaign has been observed across multiple victims and has remained active since **mid-2024**, with new infrastructure and incidents continuing into **2025**.