Target Industry
Indiscriminate targeting; heightened risk to organisations with SonicWall Gen 7/Gen 8 firewalls and SSL VPN enabled.
Overview
SonicWall has concluded its investigation into recent Akira ransomware activity against Gen 7 firewalls, confirming no evidence of a zero-day exploit. Instead, intrusions have been linked to CVE-2024-40766 (a critical improper access control flaw (CVSS 9.3) disclosed in 2024) in combination with credential reuse and poor password hygiene following platform migrations.
Most incidents involved organisations upgrading from Gen 6 to Gen 7 or Gen 8 appliances without resetting local user credentials, allowing attackers to reuse previously compromised accounts.
Affected Products
- Latitude series
- Precision series
- Rugged series
- Pro Plus and Pro Max lines
Impact
Exploitation enables full domain compromise, data exfiltration, and ransomware deployment through valid account access. Notably:
- UNC6148 threat actors have deployed Overstep, a persistent rootkit/backdoor enabling credential theft, session hijacking, and lateral movement.
- At least one Gen 8 compromise has been observed, likely due to inherited credentials from earlier configurations.
Exploitation
- CVE-2024-40766: Improper access control in SonicOS, previously exploited in ransomware campaigns.
- Post-patch exploitation continues where admins failed to reset compromised credentials.
- EPSS: 22.08% – indicating a moderate likelihood of further exploitation in the next 30 days.
- Public exploitation techniques are known to multiple ransomware groups.
Containment, Mitigations & Remediations
SonicWall recommends:
- Upgrade firmware to SonicOS 7.3.0 or later for enhanced brute-force/MFA protections.
- Reset all local user account passwords – especially those retained during Gen 6→Gen 7/8 migrations.
- Enforce MFA and strong password policies.
- Remove unused or inactive accounts.
- Enable Botnet Protection and Geo-IP Filtering.
- Audit VPN and authentication logs for unusual activity.
- Consider disabling SSL VPN where operationally feasible.
Threat Landscape
This campaign underlines that patching alone is insufficient if password resets and account audits are not enforced. The combination of historic credential compromise and sophisticated persistence tooling allows actors like UNC6148 to breach even fully updated systems. Continued opportunistic targeting is expected, especially among organisations that migrated without full credential hygiene.
Further Information
Intelligence Terminology Yardstick













