HomeSecurityFog and Akira ransomware compromise corporate networks via SonicWall VPN

Fog and Akira ransomware compromise corporate networks via SonicWall VPN

The attackers behind Fog and Akira ransomware compromise corporate networks via SonicWall VPN accounts.

Fog ransomware Akira SonicWall VPN

Cybercriminals are believed to be exploiting CVE-2024-40766, a critical vulnerability affecting SSL VPNs. SonicWall patched the SonicOS vulnerability in late August 2024. About a week later, it warned that it was already being used in attacks. At the same time, security researchers at Arctic Wolf reported that affiliates of the Akira ransomware were using the vulnerability to gain initial access to victim networks.

A new report from Arctic Wolf now warns that both Akira and Fog ransomware have carried out at least 30 attacks, which were initiated by remote access to a network via SonicWall VPN accounts. 75% of the attacks are linked to Akira, and the remaining 25% to Fog ransomware.

See also: Russian court sentences four members of REvil Ransomware gang

The two groups appear to share infrastructure, which suggests an informal collaboration, something previously reported by Sophos researchers.

Although researchers are not certain that the above vulnerability was used in all attacks, all compromised endpoints were vulnerable to it, running an older version.

In most cases, data encryption occurred within about ten hours of the initial intrusion, with attacks occurring within 1.5-2 hours. In many of these attacks, the attackers accessed the endpoint via a VPN/VPS, obfuscating their real IP addresses.

Arctic Wolf observed that in addition to using outdated versions, the compromised organizations had not enabled multi-factor authentication on the compromised SSL VPN accounts.

In intrusions where firewall logs were recorded, message event ID 238 (WAN zone remote user login allowed) or message event ID 1080 (SSL VPN zone remote user login allowed) was observed,” explains Arctic Wolf.

After these messages, there were several SSL VPN INFO log messages (event ID 1079) indicating that the connection and IP assignment were completed successfully“.

See also: Qilin.B ransomware: New version of Qilin with stronger encryption

In the next stages, the attackers behind Fog and Akira ransomware performed rapid encryption, primarily targeting virtual machines and backups their

stolen from compromised systems included documents and software, but it appears that the attackers were only interested in new data, as they did not deal with files older than six months or 30 months (for more sensitive files).

Fog and Akira ransomware compromise corporate networks via SonicWall VPN
Fog and Akira ransomware compromise corporate networks via SonicWall VPN

Ransomware protection

Back up your data: One of the most effective ways to protect yourself from a  attack  is to regularly back up your data. This ensures that even if your data is encrypted by ransomware, you will have a safe copy that can be restored without paying the ransom.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Update your operating system and software: Out-of-date operating systems and software are vulnerable to cyberattacks. It is important to regularly update your devices with the latest  security  and software updates to prevent any vulnerabilities that could be exploited by ransomware.

Beware of suspicious emails and links: Ransomware attacks often start with a phishing email or malicious link. It is important to be cautious when opening emails from unknown senders. Also, do not click on suspicious links. These could lead to ransomware being installed on your device.

Use antivirus software:  Installing reputable antivirus software on your devices can help you detect and prevent attacks  . Be sure to update your antivirus software to ensure it is equipped to handle new threats.

See also: Ransomware gangs use LockBit's notoriety to pressure victims

Education: One of the most important steps to protect against ransomware is education. It is important to stay up to date on the latest types of ransomware and how they work. Organizations should also train their employees on how to identify and avoid potential attacks.

Implement strong passwords: Weak or easy passwords can make it easier for hackers to gain access to your devices and install ransomware. It's important to use strong and unique passwords and enable two-factor authentication whenever possible.

Use a VPN: A VPN encrypts your internet connection and provides an extra layer of security against ransomware attacks. This is especially important when using public Wi-Fi networks, which are often unsecured and vulnerable to attacks.

See also: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS