Target Industry

Indiscriminate targeting; heightened risk to organisations with SonicWall Gen 7/Gen 8 firewalls and SSL VPN enabled.

Overview

SonicWall has concluded its investigation into recent Akira ransomware activity against Gen 7 firewalls, confirming no evidence of a zero-day exploit. Instead, intrusions have been linked to CVE-2024-40766 (a critical improper access control flaw (CVSS 9.3) disclosed in 2024) in combination with credential reuse and poor password hygiene following platform migrations.

Most incidents involved organisations upgrading from Gen 6 to Gen 7 or Gen 8 appliances without resetting local user credentials, allowing attackers to reuse previously compromised accounts.

Affected Products

  • Latitude series 
  • Precision series 
  • Rugged series 
  • Pro Plus and Pro Max lines 

Impact

Exploitation enables full domain compromise, data exfiltration, and ransomware deployment through valid account access. Notably:

  • UNC6148 threat actors have deployed Overstep, a persistent rootkit/backdoor enabling credential theft, session hijacking, and lateral movement.
  • At least one Gen 8 compromise has been observed, likely due to inherited credentials from earlier configurations.

Exploitation

  • CVE-2024-40766: Improper access control in SonicOS, previously exploited in ransomware campaigns.
  • Post-patch exploitation continues where admins failed to reset compromised credentials.
  • EPSS: 22.08% – indicating a moderate likelihood of further exploitation in the next 30 days.
  • Public exploitation techniques are known to multiple ransomware groups.

Containment, Mitigations & Remediations

SonicWall recommends:

  1. Upgrade firmware to SonicOS 7.3.0 or later for enhanced brute-force/MFA protections.
  2. Reset all local user account passwords – especially those retained during Gen 6→Gen 7/8 migrations.
  3. Enforce MFA and strong password policies.
  4. Remove unused or inactive accounts.
  5. Enable Botnet Protection and Geo-IP Filtering.
  6. Audit VPN and authentication logs for unusual activity.
  7. Consider disabling SSL VPN where operationally feasible.

Threat Landscape

This campaign underlines that patching alone is insufficient if password resets and account audits are not enforced. The combination of historic credential compromise and sophisticated persistence tooling allows actors like UNC6148 to breach even fully updated systems. Continued opportunistic targeting is expected, especially among organisations that migrated without full credential hygiene.

Further Information

Intelligence Terminology Yardstick

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content