Fog Ransomware greift SonicWall VPNs an, um in Unternehmensnetzwerke einzudringen

Teilen:

Fog and Akira ransomware operators are increasingly breaching corporate networks through SonicWall VPN accounts, with the threat actors believed to be exploiting CVE-2024-40766, a critical SSL VPN access control flaw.

SonicWall fixed the SonicOS flaw in late August 2024, and roughly a week later, it warned that it was already under active exploitation.

At the same time, Arctic Wolf security researchers reported seeing Akira ransomware affiliates leveraging the flaw to gain initial access to victim networks.

A new report by Arctic Wolf warns that Akira and the Fog ransomware operation have conducted at least 30 intrusions that all started with remote access to a network through SonicWall VPN accounts.

Of these cases, 75% are linked to Akira, with the rest attributed to Fog ransomware operations.

Interestingly, the two threat groups appear to share infrastructure, which shows the continuation of an unofficial collaboration between the two, as previously documented by Sophos.

While the researchers aren’t 100% positive the flaw was used in all cases, all of the breached endpoints were vulnerable to it, running an older, unpatched version.

In most cases, the time from intrusion to data encryption was short, at about ten hours, even reaching 1.5-2 hours on the quickest occasions.

In many of these attacks, the threat actors accessed the endpoint via VPN/VPS, obfuscating their real IP addresses.

Arctic Wolf notes that apart from operating unpatched endpoints, compromised organizations did not appear to have enabled multi-factor authentication on the compromised SSL VPN accounts and run their services on the default port 4433.

“In intrusions where firewall logs were captured, message event ID 238 (WAN zone remote user login allowed) or message event ID 1080 (SSL VPN zone remote user login allowed) were observed,” explains Artic Wolf.

“Following one of these messages, there were several SSL VPN INFO log messages (event ID 1079) indicating that login and IP assignment had completed successfully.”

In the subsequent stages, the threat actors engaged in rapid encryption attacks targeting mainly virtual machines and their backups.

Data theft from breached systems involved documents and proprietary software, but the threat actors didn’t bother with files that were older than six months, or 30 months old for more sensitive files.

Launched in May 2024, Fog ransomware is a growing operation whose affiliates tend to use compromised VPN credentials for initial access.

Akira, a far more established player in the ransomware space, has recently had Tor website access problems, as observed by BleepingComputer, but those are gradually returning online now.

Update 10/28: Japanese researcher Yutaka Sejiyama reports that ther are approximately 168,000 SonicWall endpoints vulnerable to CVE-2024-40766 right now, exposed to the internet.

Sejiyama also told BleepingComputer he has indications that Black Basta ransomware may also be leveraging the same flaw in attacks.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
9:00 pm, Juni 22, 2025
Wetter-Symbol 20°C
L: 19° | H: 21°
wenige Wolken
Luftfeuchtigkeit: 67 %
Druck: 1011 mb
Wind: 17 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 20%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
19° | 21°°C 0 mm 0% 10 mph 67 % 1012 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 23°°C 0.66 mm 66% 14 mph 77 % 1016 mb 0 mm/h
Di. Juni 24 10:00 pm
Wetter-Symbol
13° | 24°°C 0.2 mm 20% 14 mph 81 % 1016 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 28°°C 0 mm 0% 11 mph 88 % 1014 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
17° | 25°°C 1 mm 100% 15 mph 84 % 1018 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
18° | 20°°C 0 mm 0% 10 mph 67 % 1012 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
19° | 20°°C 0 mm 0% 13 mph 70 % 1012 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
17° | 18°°C 0.66 mm 66% 14 mph 77 % 1011 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
15° | 15°°C 0.2 mm 20% 13 mph 64 % 1013 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 13 mph 45 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 13 mph 32 % 1014 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 14 mph 30 % 1014 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 14 mph 40 % 1015 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€85,886.63
-3.32%
Ethereum(ETH)
€1,894.29
-8.63%
Fesseln(USDT)
€0.87
0.01%
XRP(XRP)
€1.70
-5.43%
Solana(SOL)
€111.98
-6.25%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.128178
-6.43%
Shiba Inu(SHIB)
€0.000009
-6.03%
Pepe(PEPE)
€0.000008
-9.86%
Peanut das Eichhörnchen(PNUT)
€0.218233
13.10%
Nach oben scrollen