Akira ransomware SonicWall attacks now bypass multi-factor authentication. Criminals exploit SonicWall SSL VPN accounts even when MFA is enabled.

Researchers observed attackers gaining access despite multiple one-time password prompts. The method remains under investigation, but stolen OTP seeds may play a role.

Vulnerability linked to CVE-2024-40766

SonicWall traced many intrusions to CVE-2024-40766, an improper access control flaw disclosed in September 2024. The company released a patch in August.

Despite the fix, attackers used credentials stolen from devices compromised before the update. These reused credentials allowed them to bypass security controls.

Attack chain and tactics

Once inside, attackers move quickly. They scan networks, identify valuable assets, and pivot laterally using built-in Windows tools. Backup servers often become primary targets.

They also rely on “Bring-Your-Own-Vulnerable-Driver” tactics. By abusing legitimate drivers, criminals disable security tools and clear paths for ransomware deployment.

This combination of speed, stealth, and exploitation makes Akira ransomware SonicWall incidents especially dangerous.

SonicWall’s recommendations

SonicWall urged administrators to reset all VPN credentials and update to the latest SonicOS firmware. Even patched devices remain at risk if credentials were stolen earlier.

Security teams should enforce unique, strong passwords, monitor login attempts, and investigate unusual authentication behavior. Rapid detection remains critical.

Implications for MFA defenses

Akira ransomware SonicWall breaches highlight a serious reality: MFA cannot fully protect accounts if seed material is compromised. Attackers with stolen data can still succeed.

Organizations need layered defenses. Protecting MFA seeds, monitoring endpoints, and ensuring timely patching are essential. Companies should also prepare robust incident response plans.

Conclusion

Akira ransomware SonicWall campaign proves that criminals adapt quickly. By bypassing MFA and exploiting known flaws, they threaten critical infrastructure. SonicWall’s advice underscores the need for constant vigilance, stronger credential management, and layered cybersecurity strategies.


0 responses to “Akira ransomware SonicWall attacks revealed”