216.73.216.6

Active Exploitation of SonicWall VPNs

· Published 04/08/2025 15:03 · Modified 05/08/2025 15:32

Export JSON

Essential information

Published
04/08/2025 15:03
Modified
05/08/2025 15:32
Tags
2025-08-04 akira credential-theft lateral movement mfa bypass ransomware sonicwall vpn zero-day
Related entities
12 observables, 14 techniques (mitre), 1 malware

Description

A potential vulnerability in VPNs is being actively exploited to bypass MFA and deploy . The attack chain begins with a breach of the appliance, followed by post-exploitation techniques including enumeration, detection evasion, , and credential theft. Attackers quickly gain administrative access, establish command and control, move laterally, disable defenses, and deploy . The threat actors use a mix of automated scripts and manual activity, abusing privileged accounts and utilizing various tools for persistence and data exfiltration. Immediate action is advised, including disabling access or severely restricting it, auditing service accounts, and hunting for malicious activity using provided indicators of compromise.

External references