Akira Ransomware Actors Target SonicWall SSLVPN
This aggressive approach aligns with Akira's historical tactics of exploiting VPN infrastructure as an initial access vector.
All topics
This aggressive approach aligns with Akira's historical tactics of exploiting VPN infrastructure as an initial access vector.
Cisco’s Talos threat intelligence team said this campaign is the work of an actor it tracks as UAT4356, an APT team that has previously targeted ASA devices.
The incident is a pointed example of how an intrusion at a key point in the software supply chain can have a wide range of downstream effects.
In a new report, ESET researchers have detailed several instances when the two groups’ tools have been found on the same compromised machines in Ukraine.
Microsoft and Cloudflare this week announced that they paired up to disrupt RaccoonO365, a phishing-as-a-service cybercriminal enterprise.
The campaign does not appear to be connected to the previous npm phishing attacks, but it does seem to be related to a rash of GitHub and npm token and secret thefts from the end of August.