Akira exploitation of SonicWall SSL VPN flaw CVE-2024-40766
Case score 68
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 68
- Main story score
- 62
- Related evidence lift
- +6 / 20
- Contributing updates
- 2
- Context updates
- 0
- Campaign Anchors the Akira-linked SonicWall access pattern and the confirmed Marquis ransomware fallout. main
- Campaign Adds the October 2025 widespread authenticated abuse across more than 100 accounts in 16 environments. contributes
- Vulnerability Provides the exact CVE-2024-40766 flaw anchor, patch timing, and product-specific mitigation context. main
- Exploitation Wave Supplies the broader exploitation-wave context, post-login behavior, and immediate response guidance. contributes
-
Old: Akira abuse of SonicWall SSL VPN accessNew: Akira exploitation of SonicWall SSL VPN flaw CVE-2024-40766Why old title changed: The earlier title framed the story as generic access abuse. With the accepted vulnerability record, the activity is more clearly centered on a named, actively exploited SonicWall SSL VPN flaw that anchors both the intrusion pattern and the defensive response.The new title keeps the Akira and SonicWall focus while adding CVE-2024-40766, which better captures the reader-facing framing, the active-exploitation angle, and the remediation urgency without changing the public URL.
Overview
Latest development Open development history Akira expands SonicWall CVE-2024-40766 exploitation Akira ransomware remains active against SonicWall firewalls, with Arctic Wolf observing dozens of incidents over the past three months tied to CVE-2024-40766 abuse, SSL VPN logins from VPS hosting providers, Impacket SMB activity, and Active Directory discovery. The campaign targets SSL VPN accounts using OTP MFA, and Barracuda separately observed Akira affiliates using Datto RMM, backup agents, and PowerShell to gain control while avoiding security alerts.
-
Akira campaign compromises SonicWall accounts despite OTP MFA
Arctic Wolf observed an ongoing Akira ransomware campaign against SonicWall firewalls and SSL VPN accounts in which attackers successfully logged in even when one-time password (OTP) multi-factor authentication was enabled, with the activity tied to CVE-2024-40766 and likely involving reused credentials or previously stolen OTP seeds. After gaining access, the actors reportedly scanned internal networks within 5 minutes, used Impacket, RDP, dsquery, SharpShares, and BloodHound for reconnaissance, targeted Veeam Backup & Replication servers for credential extraction, and used a Bring-Your-Own-Vulnerable-Driver chain with consent.exe, rwdrv.sys, and churchill_driver.sys to disable endpoint defenses.
-
SonicWall SSL VPN exploitation wave (Akira-linked)
The wave first centered on **SonicWall SSL VPN** access and quickly showed signs of repeated use across multiple intrusions. Early reporting tied the activity to **Akira ransomware** resurgence beginning in **late July 2025**.
-
Akira targeting of SonicWall devices for initial access
Rapid7 and SonicWall described continued Akira-affiliated targeting of SonicWall devices for initial access, with increased intrusions over the past month and renewed activity since late July 2025. SonicWall tied the abuse to CVE-2024-40766, warning that brute-forced credentials, misconfigured LDAP SSL VPN Default User Groups, and exposed Virtual Office Portal access can let compromised accounts inherit sensitive permissions and enable unauthorized network access.
-
SonicWall SSL VPN access control flaw actively exploited (CVE-2024-40766)
SonicWall patched **CVE-2024-40766** in **August 2024** after identifying an **access control** flaw that could enable **unauthorized resource access** and trigger **firewall crashes**. The bug affects exposed **SSLVPN** endpoints across several firewall generations.