EXPLORE

Article

Akira Targeting SonicWall Devices (Again)

Arete Analysis

Threat Actors

Cybersecurity Trends

A recent wave of Akira ransomware attacks targets SonicWall firewall devices, exploiting a previously identified flaw. Since July, there have been multiple reports of ransomware intrusions leveraging unauthorized access to SonicWall SSLVPN connections. Arete has observed that in the majority of engagements attributed to Akira in July and August, the victim organization used SonicWall devices. Following the recent spike in Akira ransomware attacks, SonicWall released an update stating that the attacks were not related to any new zero-day vulnerability, but instead are correlated with CVE-2024-40766, an older SonicWall VPN access control flaw that was first detected in August 2024.

In line with similar attacks discovered since at least October 2024, attackers swiftly switched from initial network access via SSLVPN accounts to data encryption during this spike in ransomware activity, suggesting a persistent campaign aimed at SonicWall devices.

Akira Activity in 2025

Akira frequently exploits vulnerabilities and targets unsecured VPNs and firewalls, taking advantage of gaps in a target’s infrastructure. Akira’s affinity towards SonicWall is nothing new, as the group has repeatedly found success exploiting vulnerabilities in SonicWall products in the past.  

Akira was the most active threat group observed by Arete in 2024 and started 2025 as the top threat in January and February after successfully targeting another critical SonicWall VPN access control flaw (CVE-2024-40766) that multiple other threat groups also exploited. 

Following a short hiatus in the middle of 2025, possibly due to the group staging for new attacks, Akira returned to its typical high monthly activity levels. In the past few months, the group has dominated the threat landscape, responsible for over 36% of all ransomware and extortion activity seen by Arete in July and already accounting for over half of Arete’s new engagements in August.  

Analyst Comments

Akira remains a mainstay of the cyber ecosystem in 2025 and will likely remain one of the most active ransomware threats this year. Given the group’s past and present focus on vulnerable SonicWall products, it is especially important for users to be aware of this potential threat. Organizations are advised to review SonicWall firewalls with SSLVPN enabled for unauthorized logins, examine device settings, evaluate all configurations as possibly compromised, and carry out the necessary recovery procedures. SonicWall also advises users to disable SSLVPN whenever feasible, limit access to trusted IPs, activate security services like Botnet Protection and Geo-IP Filtering, enforce multi-factor authentication (although this may not completely stop the threat), delete unused accounts, particularly those with SSLVPN access, and use strong passwords. Protecting publicly accessible management interfaces is a fundamental security best practice. 

Sources

Back to Blog Posts

Article

Ransomware Trends & Data Insights: September 2026

The Akira ransomware group re-emerged as the most active ransomware threat observed by Arete in September. Overall activity remained relatively distributed among multiple threat groups, with 29 unique groups observed throughout the month. Alongside Akira, INC Ransom and the relatively new Storm group were among the three most active threat actors observed in September. Several new threat groups also emerged during the month, including Hades Team, Shiba, and Vortex (which is suspected to be part of the cluster of threat actors affiliated with the former BlackFile group).

Throughout the month, analysts at Arete identified several trends behind the threat actors perpetrating cybercrime activities: 

  •   In September 2026, the ShinyHunters threat group escalated its extortion activity by publicly targeting both the Clop ransomware group and the FBI. The group claimed to have breached and defaced Clop’s infrastructure, demanding an eight-figure ransom, while separately alleging the theft of sensitive FBI-related data and demanding the retraction of statements made in a prior public advisory. In both incidents, ShinyHunters employed similar pressure tactics, including website defacements, repeated public postings, and threats of data disclosure. 

  • ClickFix attacks remained prevalent in September 2026, with ransomware groups including Qilin, Helix, and The Gentlemen leveraging ClickFix lures to facilitate PowerShell-based payload execution and initial access. The technique continues to evolve, combining social engineering with legitimate tools and services to enable compromise and evade detection. 

  • September 2026 saw continued activity from the former BlackFile extortion ecosystem. BlackFile, a data theft and extortion operation active since at least October 2025, rebranded as Redact in May 2026, and since appears to have broken off into several affiliated brands, including Pink, Helix, Falcon, Cinder, and potentially Vortex. During September, some affiliates publicly disputed these associations and claimed to operate independently. However, the coordinated timing, messaging, and near-identical nature of these statements support the assessment that these groups remain part of a broader interconnected ecosystem operating under shared objectives or coordination.

Article

Attack Patterns in Settra Incidents

Recent Settra ransomware incidents demonstrate a consistent operational pattern involving compromised credentials, VPN access, and the deployment of ransomware executables tailored to victim environments. Researchers have observed Settra naming ransomware executables after the targeted organization's domain while following similar attack sequences across multiple intrusions. Arete has also identified overlapping tactics, techniques, and tools in Settra engagements observed from June to August, including the use of MeshAgent for remote access and Bring Your Own Vulnerable Driver (BYOVD) techniques to weaken endpoint security controls. 

What’s Notable and Unique 

  • Settra operators have been observed naming ransomware executables after the victim organization's domain, creating a direct association between the payload and the targeted environment.

  • Initial access vectors have included targeting exposed VPN infrastructure and the use of compromised credentials, reducing the need for traditional exploitation of vulnerabilities.

  • Arete observed MeshAgent in multiple Settra engagements, which provides threat actors with a mechanism for remote access and continued activity within compromised environments.

  • Settra engagements have also included Bring Your Own Vulnerable Driver (BYOVD) activity, which can be used to bypass or impair security controls by abusing legitimate but vulnerable drivers.

Analyst Comments

Recent Settra activity demonstrates how ransomware operators can combine credential-based access, remote management tooling, and security control evasion techniques to establish and maintain access before ransomware deployment. The repeated use of similar tools and operational patterns across incidents provides useful detection opportunities for defenders. Organizations should closely monitor VPN authentication activity, unusual use of compromised credentials, unexpected MeshAgent deployment, ransomware executables with victim-specific naming conventions, and suspicious driver activity associated with attempts to disable or bypass endpoint security controls.

Arete’s MDR practice detects Settra’s full attack chain, with special attention to the staging of BYOVD activity for defense evasion. However, for us to detect it, SentinelOne needs to be fully deployed across an environment. To support organizations with full deployment, Arete offers SentinelOne Deployment Assistance. This service is designed to ensure that SentinelOne is deployed across all eligible endpoints, eliminating coverage gaps that could otherwise expose the organization to ransomware, malware, credential theft, and other advanced threats. Through endpoint discovery, inventory reconciliation, and deployment assistance, Arete helps organizations achieve comprehensive protection and maximize the effectiveness of their SentinelOne investment. Contact clientcares@areteir.com to learn more.

Sources

  • Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM

Article

AI Agents Used in Campaign Against PaperCut

In late August, a threat actor used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG and MF servers. PaperCut is print management software, and researchers determined that the operation compromised at least 440 PaperCut instances linked to 395 distinct organizations across 48 countries. The AI agents were tasked with building, testing, and refining exploits for CVE-2026-81578 and CVE-2026-82078 both security flaws affecting PaperCut software and flagged as actively exploited earlier this month.  It is currently unclear if the threat actor is solely focused on access development to be handed off to other affiliated actors, or if they will directly leverage their access to achieve follow-on objectives such as data theft or ransomware deployment.

What’s Notable and Unique

  • Researchers observed three attack paths following the exploitation of vulnerable PaperCut servers. Threat actors would harvest credentials from LSASS memory and registry secrets to perform pass-the-hash attacks, leverage older unpatched Windows vulnerabilities (CVE-2021-42278 and CVE-2021-42287) to escalate privileges in unpatched environments, or, in some cases, directly add newly created accounts to the Domain Admins group when PaperCut was running with domain-level privileges.


  • Upon achieving remote code execution and credential harvesting within a self-hosted lab environment, the threat actor deployed hundreds of AI-powered agents that leveraged OpenAI Codex, DeepSeek models, and publicly available offensive security tools, including Mimikatz, SharpHound, Certipy, Rubeus, and Impacket, to automate reconnaissance, exploitation, and post-compromise activities. The attackers subsequently used a DCSync attack to obtain a database dump containing domain credentials. 

Analyst Comments

The observed activity demonstrates how threat actors are increasingly leveraging AI and large language models (LLMs) to accelerate cyber operations at unprecedented speed and scale. In this campaign, the adversary progressed from exploit development to remote code execution within hours and, in some cases, achieved Domain Administrator privileges in as little as five minutes. The AI-assisted workflow enabled rapid reconnaissance, exploitation, credential theft, privilege escalation, and lateral movement, allowing the compromise of multiple organizations within seconds. This activity highlights the growing threat posed by AI-enabled adversaries capable of conducting large-scale intrusions with greater efficiency and operational velocity. Organizations affected by the PaperCut vulnerabilities are strongly advised to apply the latest security updates and implement the vendor's recommended mitigation measures to reduce the risk of compromise and unauthorized access. 

Sources

  • Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF 

  • AI-powered attack exploited PaperCut flaws to hack 395 organizations 

  • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances 

Article

Adversarial AI Evolves from Prompting to Autonomous Attack Workflows

Cybercriminals and state-linked threat actors are increasingly incorporating artificial intelligence (AI) into multiple stages of offensive operations. Rather than relying on AI only for content generation or research, threat actors are now consistently using it to support reconnaissance, vulnerability discovery, credential theft, malware development, social engineering, and activities following initial compromise. The growing use of automated and agent-based workflows is allowing adversaries to coordinate offensive malicious activities with less manual involvement, potentially increasing the speed, scale, and efficiency of future campaigns.

What’s Notable and Unique

  •  In one observed campaign, threat actors used AI to plan, build, and conduct an automated credential-harvesting operation within just several hours, demonstrating how compromised infrastructure can be rapidly repurposed to support larger-scale malicious activity.

  • Arete has observed several threat groups using AI-assisted capabilities to facilitate the analysis of data obtained during exfiltration so far this year, including INC Ransom, FulcrumSec, and Settra.

  • Attackers are also attempting to reproduce proprietary AI capabilities. Large-scale automated prompting campaigns have been used to extract information about the behavior and capabilities of proprietary AI models. The use of numerous accounts and intermediary infrastructure can make these activities more difficult to identify and attribute.

Analyst Comments

AI is increasingly becoming an operational component in the threat landscape rather than simply a tool that improves attacker productivity. By connecting reconnaissance, development, credential operations, and other activities through automated workflows, threat actors can conduct campaigns more quickly and reduce reliance on continuous human input. This trend also impacts security requirements for organizations deploying AI technologies. AI models, development environments, cloud resources, identities, repositories, and automated workflows should increasingly be considered interconnected elements of the enterprise attack surface, and organizations should maintain visibility across these areas and ensure that security controls account for both conventional threats and AI-enabled attack techniques.

Sources

  • GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI