ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Ransomware attackers used incorrectly stored recovery codes to disable EDR agents

criticalRansomwareimportance 60CVE-2024-40766

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-40766
Improper Access Control in SonicWall SonicOS Management (Gen 5/6/7 Firewalls)

CVE-2024-40766 is an improper access control flaw (CWE-284) in SonicWall SonicOS management access that can allow unauthorized access to protected resources and, under specific conditions, crash the affected firewall. It is network-exploitable without privileges or user interaction per its CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) and affects Gen 5 and Gen 6 appliances as well as Gen 7 devices running SonicOS 7.0.1-5035 or older. A successful attacker gains unauthorized access to resources behind or on the appliance and can potentially take the firewall offline, creating opportunities for follow-on attacks such as VPN account compromise and ransomware deployment. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-09 with known ransomware use, and recent reporting ties Akira ransomware activity — including MFA bypass on SonicWall VPNs affecting over 100 accounts — to this legacy bug combined with password reuse. No public PoC is known, but EPSS assigns an ~18.2% probability of exploitation within 30 days (97th percentile).

Do: Upgrade Gen 7 appliances to SonicOS 7.0.1-5037 or later (the fixed release beyond the affected 7.0.1-5035) and move Gen 5/6 devices to the latest SonicOS release SonicWall supports for those generations; per CISA KEV guidance, apply vendor mitigations or discontinue use if patching is not possible. Restrict WAN-side management and SSLVPN access to trusted sources, audit VPN accounts for password reuse, rotate credentials and any locally stored recovery codes, and review logs for signs of Akira-related compromise such as MFA bypass or disabled EDR agents.

9.818% KEV ransomware
  • SonicWall SonicOS (Gen 5 firewalls) Gen 5 appliances, all versions per the CISA advisory
  • SonicWall SonicOS (Gen 6 firewalls) Gen 6 appliances, all versions per the CISA advisory
  • SonicWall SonicOS (Gen 7 firewalls) SonicOS 7.0.1-5035 and older
mass≈100,000–500,000 internet-exposed SonicWall firewalls/SSLVPN endpoints (installed base of 1M+ appliances)
Full article563 words · extracted from helpnetsecurity.com · click to collapse

All target organizations are different, but ransomware attackers are highly adaptive and appreciate – and will exploit – any mistake you make.

The latest Akira ransomware attacks

Managed security service providers and external incident responders have had a front-row seat for observing many of the actions carried out by Akira ransomware affiliates in the last few months.

In early August 2025, both Arctic Wolf and Huntress researchers warned about the possibility of Akira affiliates using a zero-day vulnerability in SonicWall firewalls to perform pre-ransomware intrusions.

A few days later, though, SonicWall said that the attackers are actually still using CVE-2024-40766, a vulnerability that SonicWall had issued patches for in August 2024. The company claimed that some of the targeted organizations might have implemented the fix, but that they had migrated Gen 6 to Gen 7 firewalls without resetting the local user credentials, which had been apparently compromised beforehand.

During the same period, Huntress security experts began sharing tidbits about the attacks they witnessed.

“It is apparent that some of these attackers have at least part of the same playbook, or that they are adaptive to whatever situations they happen to encounter,” they said.

“Methodologies varied from utilizing tools brought in like Advanced_IP_Scanner, WinRAR, and FileZilla, to relying on various built-in tools (LOLBins), as well as installing various persistence mechanisms like new accounts, SSH, or full-blown RMMs like AnyDesk.”

Subsequent reports by other cybersecurity companies pointed out the attackers’ use of:

  • Legitimate (but vulnerable) Windows drivers (rwdrv.sys and hlpdrv.sys)
  • The -dellog argument to clear event logs
  • Built-in Windows tools (Set-MpPreference, netsh.exe) to disable the endpoint security solution (Microsoft Defender) and the firewall
  • A misconfiguration in the SonicWall firewalls’ SSLVPN Default Users Group setting and the devices’ Virtual Office Portal

Exploiting improperly stored recovery codes

In a blog post published on Monday, Huntress threat analysts also pointed out a crucial error made by a security engineer at one of the targeted organizations: they stored Huntress recovery codes in plain text, in a file whose name made this very obvious.

“These recovery codes serve as a backup method for bypassing multi-factor authentication (MFA) and regaining account access. If compromised, they effectively allow an attacker to circumvent MFA entirely, impersonate the legitimate user, and gain full access to the Huntress console, significantly increasing the risk of further compromise or tampering with detection and response capabilities,” analysts Michael Elford and Chad Hudson explained.

And that is what the attackers used them for: they logged into the console with the security engineer’s account, and began closing active incident reports, removing previously isolated (ransomware infected) systems from isolation, and attempting to remove Huntress EDR agents from compromised endpoints.

Akira ransomware disable EDR

How the attackers uninstalled the EDR agents through the portal (Source: Huntress)

“Organizations should treat recovery codes with the same sensitivity as privileged account passwords,” the threat analysts noted.

Plaintext storage is a no-no – credentials and recovery codes should either be stored in a an encrypted password manager with a strong passphrase and without the autofill option switched on, or stored in an encrypted, password-protected file on an encrypted USB drive or hard disk.

In addition to this, they advise organizations to periodically regenerate recovery codes (if possible) and monitor login access for unusual logins.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/09/16/akira-ransomware-disable-edr/