Back to threat intel
Ransomware

Akira affiliates abusing unpatched SSL VPN appliances

SBS Incident Response19 August 20266 min read

Over the last quarter, Akira-linked affiliates have leaned heavily on internet-facing SSL VPN appliances as their front door into Nordic networks. In three separate engagements we traced the entire intrusion back to a single unpatched appliance — and in each case the path from first login to domain-wide access took less than four hours.

Initial access

The affiliates exploited a known authentication-bypass in an end-of-life SSL VPN firmware build. No zero-day was required — the appliances had simply missed two vendor patch cycles.

In every case the first successful login came from a hosting-provider IP that had never appeared in the environment before. There was no MFA prompt because the VPN was configured for password-only access for a handful of legacy service accounts.

Credential harvesting and lateral movement

Once inside, the operators dumped cached credentials from the appliance itself and pivoted to an internal jump host. From there they used legitimate remote-management tooling already present in the estate, keeping their footprint low.

Domain admin was reached by abusing a service account with excessive privileges — an account that had not logged in interactively for over a year.

What would have caught it

A simple alert on first-seen geographies for VPN logins would have fired within minutes. So would an alert on interactive logins from dormant service accounts.

The single highest-impact control, however, was the most boring one: patching the appliance and enforcing MFA on every remote-access path.

Key takeaways

  • Treat internet-facing appliances as tier-0 assets and patch them on the vendor's cadence, not yours.
  • Enforce MFA on every remote-access path — including legacy service accounts.
  • Alert on first-seen geographies and dormant-account logins; both are cheap and high-signal.