Akira Ransomware: MFA Bypass in SonicWall VPN Exploits

Akira ‍Ransomware Exploits Stolen ⁣VPN Credentials, Bypassing MFA – ⁣What You Need to Know

A recent surge in attacks by the Akira⁢ ransomware group highlights a critical vulnerability impacting organizations using SonicWall⁤ VPNs. Even​ after applying security patches, ⁤threat actors are successfully ​breaching networks, demonstrating a elegant understanding of how‌ to leverage previously stolen credentials.‍ This article breaks down the ⁤threat, explains how it effectively works, and provides actionable steps you can take to protect your organization.

The Core Problem: ⁢Stolen⁤ Credentials & MFA Bypass

the Akira ‍group,‌ alongside another tracked as UNC6148,⁣ is exploiting‍ a‍ concerning trend: the reuse of credentials ⁤and one-time password (OTP) seeds stolen in earlier attacks.‌ This means even if you’ve patched your systems,attackers can still⁤ gain access using details compromised before the updates were applied. Crucially, these attacks are ⁢succeeding despite the presence of multi-factor authentication (MFA).

What’s Happening wiht SonicWall VPNs?

The focus⁤ is ⁢currently on⁢ end-of-life‍ SonicWall Secure Mobile Access (SMA) 100 series appliances. Though, the implications extend beyond this specific product. Here’s⁣ a breakdown of the key findings:

* Previous Breaches: Attackers are utilizing stolen OTP seeds likely obtained through zero-day exploits in past attacks ‍against SonicWall. The specific vulnerability used⁢ to ⁢initially steal these seeds remains unclear.
* Persistent Access: These stolen seeds allow attackers⁢ to bypass MFA and re-authenticate to accounts, even after patches are deployed.
* rapid network Movement: Once inside your network, Akira affiliates move quickly. arctic Wolf researchers observed internal network scanning ​within five minutes ⁣ of initial access.
* ⁣ Targeted Data Extraction: attackers are specifically targeting‍ Veeam Backup & Replication servers to steal MSSQL and PostgreSQL credentials, including sensitive DPAPI secrets. This allows them to escalate privileges and access even more data.

How ‌Attackers Are Gaining Access & Evading Detection

The attackers are employing ​a range ⁣of techniques to​ maintain persistence and avoid detection:

* Impacket⁣ & Standard Tools: They’re using common tools like ‌Impacket (for SMB session ⁢setup), RDP logins, ⁤and Active Directory enumeration tools (dsquery, SharpShares, BloodHound).
* BYOVD Attacks: A sophisticated technique called “Bring Your Own Vulnerable Driver” (BYOVD) is being used. This involves abusing Microsoft’s legitimate consent.exe executable to sideload malicious DLLs that load vulnerable drivers (rwdrv.sys, churchill_driver.sys).
* ⁢ Driver ‌Abuse: These vulnerable ⁢drivers are then used to disable endpoint protection, effectively allowing the ransomware to run unchecked.
* SonicOS 7.3.0 Isn’t a Silver ⁤Bullet: Even organizations running the recommended SonicOS 7.3.0 release are being impacted,highlighting the importance of addressing ⁤the root cause – compromised ‍credentials.

What You Need to Do Now to ‌Protect Your Organization

Don’t assume patching alone is enough. Here’s ⁢a thorough checklist:

  1. reset VPN Credentials: Instantly reset all VPN credentials for ⁤any device that previously used vulnerable SonicWall firmware. This is the most critical step.
  2. Assume Compromise: ⁤Treat any account that previously connected through a vulnerable ⁢VPN‍ as potentially compromised.
  3. Review VPN Logs: Thoroughly review your VPN logs for suspicious activity, looking for unusual login attempts or⁢ access patterns.
  4. Strengthen MFA: While MFA isn’t foolproof in this case, ensure you’re using the strongest MFA methods available (e.g.,⁢ hardware security​ keys rather of SMS-based ⁣codes).
  5. Monitor Backup Servers: ‌increase monitoring around ⁤your Veeam Backup & Replication ‌servers and any other systems storing sensitive credentials.
  6. Endpoint Detection & Response⁣ (EDR): Ensure you have a robust EDR solution in place to detect and respond to malicious activity, including⁢ BYOVD attacks.
  7. Regular Security Audits: Conduct regular security audits‍ to⁣ identify⁤ and address vulnerabilities in your infrastructure.
  8. Stay Informed: Keep up-to-date on⁤ the latest threat intelligence from sources like Google Threat​ Intelligence Group, Arctic Wolf, and SonicWall.

Resources:

* SonicWall Product Lifecycle: [https://wwwsonicwallcom/support/product-lifecycle-tables[https://wwwsonicwallcom/support/product-lifecycle-tables[https://wwwsonicwallcom/support/product-lifecycle-tables[https://wwwsonicwallcom/support/product-lifecycle-tables

Leave a Comment