Akira ransomware group SonicWall initial-access campaign
Campaign
Summary
Hide ▲
Show ▼
The Akira ransomware group is associated with a continuing SonicWall SSL VPN initial-access campaign that uses CVE-2024-40766 and related credential abuse to breach victim networks. A newer victim-impact update shows Marquis Software Solutions was hit by a ransomware attack on August 14, 2025 through a SonicWall firewall, exposing files with personal information for customers of 74 banks and credit unions and affecting over 400,000 customers. Marquis says there is no evidence the data has been misused or published, while the breach details reinforce the campaign’s focus on SonicWall VPN access and post-compromise theft.
Cases
Related Happenings
TCLBanker self-spreading banking trojan
Malware Activity
First: 08.05.2026 01:06
Last: 08.05.2026 01:06
Sources 1
About this happening:
The **TCLBanker** trojan now combines **trojanized installer** delivery with **self-spreading worm modules**, widening access to **59 banking, fintech, and cryptocurrency platform...
TCLBanker self-spreading banking trojan
Malware ActivityAbout this happening: The **TCLBanker** trojan now combines **trojanized installer** delivery with **self-spreading worm modules**, widening access to **59 banking, fintech, and cryptocurrency platform...
Cisco ASA/FTD code execution and authentication bypass flaws (multiple vulnerabilities)
Vulnerability
First: 24.04.2026 20:06
Last: 24.04.2026 20:06
Sources 1
About this happening:
**Cisco ASA/FTD** vulnerabilities **CVE-2025-20333** and **CVE-2025-20362** are still under **active exploitation** and can be chained for **unauthenticated remote control** of af...
Cisco ASA/FTD code execution and authentication bypass flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: **Cisco ASA/FTD** vulnerabilities **CVE-2025-20333** and **CVE-2025-20362** are still under **active exploitation** and can be chained for **unauthenticated remote control** of af...
Sharp rise in brute-force attempts against SonicWall and Fortinet edge devices
Target Trend
First: 15.04.2026 12:30
Last: 15.04.2026 12:30
Sources 1
About this happening:
A **sharp rise** in brute-force attempts against **SonicWall** and **Fortinet** edge devices is increasing risk of perimeter-device compromise across organizations that rely on VP...
Sharp rise in brute-force attempts against SonicWall and Fortinet edge devices
Target TrendAbout this happening: A **sharp rise** in brute-force attempts against **SonicWall** and **Fortinet** edge devices is increasing risk of perimeter-device compromise across organizations that rely on VP...
UNC6783 BPO compromise campaign targeting downstream companies
Campaign
First: 09.04.2026 00:46
Last: 09.04.2026 00:46
Sources 1
About this happening:
**UNC6783** is an active **BPO compromise campaign** targeting **business process outsourcers** and large enterprises to reach downstream environments for **extortion**. The opera...
UNC6783 BPO compromise campaign targeting downstream companies
CampaignAbout this happening: **UNC6783** is an active **BPO compromise campaign** targeting **business process outsourcers** and large enterprises to reach downstream environments for **extortion**. The opera...
Forest Blizzard DNS hijacking token-theft campaign against older routers
Campaign
First: 07.04.2026 20:02
Last: 07.04.2026 20:02
Sources 1
About this happening:
Russia-backed **Forest Blizzard** is running a **DNS hijacking campaign** against older routers to steal **Microsoft Office** authentication tokens, putting accounts at risk acros...
Forest Blizzard DNS hijacking token-theft campaign against older routers
CampaignAbout this happening: Russia-backed **Forest Blizzard** is running a **DNS hijacking campaign** against older routers to steal **Microsoft Office** authentication tokens, putting accounts at risk acros...
Timeline
-
04.12.2025 00:06 1 articles · 5mo ago
Marquis Software Solutions breach impacts over 400,000 customers
Victim Impact UpdateMarquis Software Solutions says a ransomware attack on August 14, 2025 breached its network through a SonicWall firewall and exposed files containing personal information for customers of 74 banks and credit unions, affecting over 400,000 customers; Marquis says there is no evidence the data has been misused or published anywhere.
Show sources
- Marquis data breach impacts over 74 US banks, credit unions — www.bleepingcomputer.com — 04.12.2025 00:06
-
11.09.2025 13:33 4 articles · 8mo ago
Akira targeting of SonicWall devices for initial access
Campaign Scope UpdateRapid7 and SonicWall described continued Akira-affiliated targeting of SonicWall devices for initial access, with increased intrusions over the past month and renewed activity since late July 2025. SonicWall tied the abuse to CVE-2024-40766, warning that brute-forced credentials, misconfigured LDAP SSL VPN Default User Groups, and exposed Virtual Office Portal access can let compromised accounts inherit sensitive permissions and enable unauthorized network access.
Show sources
- SonicWall SSL VPN Flaw and Misconfigurations Actively Exploited by Akira Ransomware Hackers — thehackernews.com — 11.09.2025 13:33
- SonicWall SSL VPN Flaw and Misconfigurations Actively Exploited by Akira Ransomware Hackers — thehackernews.com — 11.09.2025 13:33
- Akira Ransomware’s Exploitation of SonicWall Vulnerability Continues — www.securityweek.com — 29.09.2025 12:32
- Akira Hits SonicWall VPNs in Broad Ransomware Campaign — www.darkreading.com — 29.09.2025 23:53