Akira Ransomware Exploits Stolen VPN Credentials, Bypassing MFA – What You Need to Know
A recent surge in attacks by the Akira ransomware group highlights a critical vulnerability impacting organizations using SonicWall VPNs. Even after applying security patches, threat actors are successfully breaching networks, demonstrating a elegant understanding of how to leverage previously stolen credentials. This article breaks down the threat, explains how it effectively works, and provides actionable steps you can take to protect your organization.
The Core Problem: Stolen Credentials & MFA Bypass
the Akira group, alongside another tracked as UNC6148, is exploiting a concerning trend: the reuse of credentials and one-time password (OTP) seeds stolen in earlier attacks. This means even if you’ve patched your systems,attackers can still gain access using details compromised before the updates were applied. Crucially, these attacks are succeeding despite the presence of multi-factor authentication (MFA).
What’s Happening wiht SonicWall VPNs?
The focus is currently on end-of-life SonicWall Secure Mobile Access (SMA) 100 series appliances. Though, the implications extend beyond this specific product. Here’s a breakdown of the key findings:
* Previous Breaches: Attackers are utilizing stolen OTP seeds likely obtained through zero-day exploits in past attacks against SonicWall. The specific vulnerability used to initially steal these seeds remains unclear.
* Persistent Access: These stolen seeds allow attackers to bypass MFA and re-authenticate to accounts, even after patches are deployed.
* rapid network Movement: Once inside your network, Akira affiliates move quickly. arctic Wolf researchers observed internal network scanning within five minutes of initial access.
* Targeted Data Extraction: attackers are specifically targeting Veeam Backup & Replication servers to steal MSSQL and PostgreSQL credentials, including sensitive DPAPI secrets. This allows them to escalate privileges and access even more data.
How Attackers Are Gaining Access & Evading Detection
The attackers are employing a range of techniques to maintain persistence and avoid detection:
* Impacket & Standard Tools: They’re using common tools like Impacket (for SMB session setup), RDP logins, and Active Directory enumeration tools (dsquery, SharpShares, BloodHound).
* BYOVD Attacks: A sophisticated technique called “Bring Your Own Vulnerable Driver” (BYOVD) is being used. This involves abusing Microsoft’s legitimate consent.exe executable to sideload malicious DLLs that load vulnerable drivers (rwdrv.sys, churchill_driver.sys).
* Driver Abuse: These vulnerable drivers are then used to disable endpoint protection, effectively allowing the ransomware to run unchecked.
* SonicOS 7.3.0 Isn’t a Silver Bullet: Even organizations running the recommended SonicOS 7.3.0 release are being impacted,highlighting the importance of addressing the root cause – compromised credentials.
What You Need to Do Now to Protect Your Organization
Don’t assume patching alone is enough. Here’s a thorough checklist:
- reset VPN Credentials: Instantly reset all VPN credentials for any device that previously used vulnerable SonicWall firmware. This is the most critical step.
- Assume Compromise: Treat any account that previously connected through a vulnerable VPN as potentially compromised.
- Review VPN Logs: Thoroughly review your VPN logs for suspicious activity, looking for unusual login attempts or access patterns.
- Strengthen MFA: While MFA isn’t foolproof in this case, ensure you’re using the strongest MFA methods available (e.g., hardware security keys rather of SMS-based codes).
- Monitor Backup Servers: increase monitoring around your Veeam Backup & Replication servers and any other systems storing sensitive credentials.
- Endpoint Detection & Response (EDR): Ensure you have a robust EDR solution in place to detect and respond to malicious activity, including BYOVD attacks.
- Regular Security Audits: Conduct regular security audits to identify and address vulnerabilities in your infrastructure.
- Stay Informed: Keep up-to-date on the latest threat intelligence from sources like Google Threat Intelligence Group, Arctic Wolf, and SonicWall.
Resources:
* SonicWall Product Lifecycle: [https://wwwsonicwallcom/support/product-lifecycle-tables[https://wwwsonicwallcom/support/product-lifecycle-tables[https://wwwsonicwallcom/support/product-lifecycle-tables[https://wwwsonicwallcom/support/product-lifecycle-tables
Worth a look