216.73.217.22

Update on Ongoing Akira Ransomware Campaign

· Published 27/09/2025 02:35 · Modified 29/09/2025 09:22

Export JSON

Essential information

Published
27/09/2025 02:35
Modified
29/09/2025 09:22
Tags
2025-09-27 CVE-2020-3259 CVE-2023-20269 CVE-2024-40766 akira credential-theft infrastructure rotation ransomware sonicwall ssl vpn
Related entities
1 intrusion sets (apt), 1 malware

Description

The campaign targeting accounts has intensified since July 2025, with new infrastructure observed as recently as September 20. Threat actors are exploiting previously exfiltrated credentials, including those with OTP MFA, likely related to . The attacks are characterized by extremely short dwell times, sometimes as brief as 55 minutes from access to encryption. The campaign is affecting various industries and organization sizes, suggesting opportunistic mass exploitation. Key recommendations include resetting and Active Directory credentials, implementing 's security measures, blocking VPN access from suspicious IPs and ASNs, updating to SonicOS 7.3.0, and deploying additional security monitoring tools.