Akira ransomware campaigns — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 6, 2025
Last Seen
November 22, 2025

Akira ransomware campaigns are a ransomware operation that SonicWall attributes to a state actor.

Overview

Akira ransomware campaigns are a ransomware operation that SonicWall attributes to a state actor. The campaigns exhibit standard ransomware behavior—initial access, rapid encryption, and data exfiltration with double extortion—making them noteworthy due to potential state sponsorship and the geopolitical risk they imply for cybersecurity.

Related Threat Clusters

  • SonicWall SonicOS Vulnerability Allows Remote DoS Attacks

    SonicWall has issued a security advisory regarding a critical vulnerability in its SonicOS operating system, identified as CVE-2025-40601. This high-severity flaw affects Gen7 and Gen8 hardware and virtual appliances,…

    9 articles · Updated November 20, 2025
  • SonicWall Blames State Actor for Customer Data Breach

    SonicWall reported that a state-sponsored threat actor conducted a brute-force attack on its MySonicWall cloud backup service, compromising firewall configuration files of all affected customers. An investigation by…

    3 articles · Updated November 6, 2025
  • SonicWall Investigates State-Backed Breach of Cloud Backup Service

    SonicWall reported a security incident involving unauthorized access to backup firewall configuration files stored in a cloud environment. The company attributed the breach to a state-backed threat actor and engaged…

    8 articles · Updated November 21, 2025
  • SonicWall Investigates State-Backed Breach of Cloud Backup Service

    SonicWall reported unauthorized access to backup firewall configuration files in September 2025, attributed to a state-backed threat actor. The company engaged Mandiant for an investigation and communicated with…

    11 articles · Updated November 26, 2025
  • SonicWall SonicOS Flaw Allows Remote Firewall Crashes

    SonicWall has disclosed a critical vulnerability in its SonicOS SSLVPN service, tracked as CVE-2025-40601, which allows remote, unauthenticated attackers to crash Gen7 and Gen8 firewalls. The flaw, caused by a…

    11 articles · Updated November 24, 2025

Recent Intelligence Reports

  • SonicWall Discloses Critical Buffer Overflow in SonicOS SSLVPN (CVE-2025-40601) — Webpronews · November 22, 2025
  • SonicWall fingers state-backed cyber crew for September firewall breach — Theregister · November 6, 2025
  • SonicWall fingers state — Theregister · November 6, 2025

CVSS v3.1 Breakdown