Akira Ransomware Exploits SonicWall VPN

Akira Ransomware Exploits SonicWall VPN

The threat actor gained access via a compromised SonicWall VPN, discovered plaintext Huntress recovery codes on a user desktop, used them to log into the Huntress portal, remediate incident reports, and uninstall agents while Akira ransomware was executed on a workstation. Proper handling of recovery codes and credentials is critical to prevent MFA bypass and suppression of detection; this incident involved Akira, a malicious IP 104.238.221[.]69, and the Huntress platform. #Akira #104.238.221[.]69

Keypoints

  • Initial access occurred through a compromised SonicWall VPN, allowing the attacker to appear as internal DHCP-assigned hosts lacking EDR agents.
  • The attacker found plaintext Huntress recovery codes on a security engineer’s desktop and used them to bypass MFA and access the Huntress portal.
  • Using the portal, the attacker closed active incident reports and initiated removal of Huntress agents to suppress detection and response.
  • Akira ransomware (w.exe) executed on a workstation, but mass isolation by Huntress SOC limited environment-wide encryption.
  • Threat actors exported a certificate (thumbprint 1d967729be08ef8c4bf86874c9542b4e) to PFX files (C:tempcert.pfx and C:cert.pfx), indicating preparation for credential theft or impersonation.
  • Portal access was observed from a known malicious IP, 104.238.221[.]69, correlated with other SonicWall-related compromises.
  • Recommendations include avoiding plaintext storage of recovery codes, using encrypted password managers, encrypting offline storage, and rotating/monitoring recovery codes.

MITRE Techniques

  • [T1133] External Remote Services – Attacker used compromised SonicWall VPN to gain remote access and blend in with internal network traffic (“compromise of the organization’s SonicWall VPN”).
  • [T1078] Valid Accounts – Threat actor used recovered Huntress recovery codes to authenticate to the Huntress portal and perform actions as a security engineer (“used these codes to enter the client’s Huntress portal”).
  • [T1005] Data from Local System – Attacker enumerated administrative shares and user desktop files to find the plaintext recovery codes (“accessed a plaintext file containing Huntress recovery codes located on an internal security engineer’s desktop”).
  • [T1553] Subvert Trust Controls (Certificate Manipulation) – Attacker enumerated and exported certificates including private keys to PFX files to enable impersonation or persistence (“certutil -store My” and “certutil -exportPFX 1d967729be08ef8c4bf86874c9542b4e C:tempcert.pfx”).
  • [T1490] Inhibit Response Functionality – Threat actor closed incident reports and uninstalled EDR agents via the Huntress portal to suppress visibility and hinder response (“manually closing active incident reports to suppress visibility” and “removal of Huntress agents from compromised systems”).
  • [T1486] Data Encrypted for Impact – Akira ransomware executed on a workstation (w.exe) to encrypt files and impact availability (“running process of the Akira ransomware binary w.exe from the user’s desktop allowed the workstation to be encrypted”).

Indicators of Compromise

  • [File Hash] Ransomware executable – w.exe SHA256: 6f1192ea8d20d8e94f2b140440bdfc74d95987be7b3ae2098c692fdea42c4a69 (Akira ransomware executable).
  • [IP Address] Malicious access – 104.238.221[.]69 (IP that accessed the Huntress portal and previously linked to SonicWall compromises).
  • [File Name] Certificate export – cert.pfx (exported PFX files at C:tempcert.pfx and C:cert.pfx from a certificate with thumbprint 1d967729be08ef8c4bf86874c9542b4e).
  • [File Path] Plaintext credentials – Huntress_recovery_codes-.txt located on a user desktop accessed via 192.168.1.51c$UsersDesktop (plaintext recovery codes used to bypass MFA).


Read more: https://www.huntress.com/blog/dangers-of-storing-unencrypted-passwords