1H 2026 Examination of Cyber Hostility and Operations

1H 2026 ECHO Report Insights: The Anatomy of an Akira Intrusion

Of all the ransomware operators CyOps tracked in the first half of 2026, Akira offered the cleanest illustration of a thesis that ran through the entire ECHO Report: attackers have stopped breaking security controls and started abusing them exactly as designed.

Akira posted 299 claimed victims to its leak site the first half of 2026, placing it firmly in the consolidated top tier of the ransomware ecosystem. Even as one of the most prolific threat actor groups globally, it was still striking to see that every Akira-aligned host breach CyOps root-caused in 1H 2026 entered through the same class of device: a SonicWall SSL-VPN gateway. After all, who needs new material when the hits still pay the bills?

Here’s what CyOps Threat Intelligence teams observed.

An Akira Case Study

One of our 1H 2026 engagements with a North American construction and timber firm tracks the Akira playbook almost stage for stage.

An Akira-aligned threat actor authenticated to the customer’s SSL-VPN gateway using compromised domain administrator credentials. From the internal address the gateway handed them, they opened RDP sessions straight into the first domain controller, then ran a pair of native Windows commands — nltest /domain_trusts and net.exe accounts /domain — to map the environment. They attempted to establish a reverse SSH tunnel to an external staging IP on TCP/22.

Then they went to work on the defenses. A third-party RMM agent was uninstalled through the legitimate Windows Installer pathway. Two Bring-Your-Own-Vulnerable-Driver attempts (UnknownKiller.sys and bdapiutil64.sys) were staged on the targeted hosts, the standard precursor to killing the endpoint security stack from kernel space. The intended finale was SMB-based mass encryption against shared folders, with the Akira readme dropped into the same locations.

The initial foothold started with a stolen identity, a pattern that has become the norm in modern intrusions.

The eight-stage kill chain

Across every Akira-aligned case in the docket, the sequence was remarkably uniform. We mapped it to MITRE ATT&CK:

  1. Stolen credentials — sourced from an infostealer log, an initial-access-broker sale, or a prior phishing wave (T1589.001)
  2. SSL-VPN authentication — external IP in, RFC1918 internal lease out; MFA reset or disabled (T1078 / T1133)
  3. RDP into the AD tier — lateral movement from the VPN-internal subnet (T1021.001)
  4. Native reconnaissancenltest, net.exe, Advanced IP Scanner; living-off-the-land only (T1018 / T1087)
  5. Data staging and exfiltration — rclone / WinRAR to Mega or cloud SFTP, setting up the double-extortion lever (T1567.002, T1560.001)
  6. BYOVD and EDR kill — vulnerable driver loads to silence the security stack (T1562.001)
  7. SMB mass encryption — Akira readme dropped into shared folders, sometimes in under an hour (T1486)
  8. Extortion and leak-site posting — negotiation chat opened; data published if the demand goes unmet (T1657)

Once the attacker is authenticated at the edge, almost nothing downstream relies on custom tooling. RDP, native Windows binaries, and a signed-but-vulnerable driver carry the entire intrusion. That’s what makes it fast, and that’s what makes it hard to catch with signature-based detection.

Why SonicWall, and why credentials beat MFA

Akira’s preferred initial-access vector through the period was strikingly stable: SSL-VPN compromise against SonicWall SOHO and small-enterprise firewalls. Open-source CTI from multiple incident-response firms has associated this pattern with CVE-2024-40766 (CVSS 9.3), an improper-access-control flaw in SonicOS. But the CyOps docket tells a subtler story — the entry point we saw time and time again was identity-based, usually originating from stolen credentials circulating in infostealer logs and access-broker markets.

A second SonicWall-specific exposure deserves its own callout, because it explains how these intrusions succeeded even where MFA was supposedly enforced. On certain firmware revisions, the Virtual Office Portal lets a user with valid credentials reset their own MFA / TOTP seed with no second factor. The practical implication is that any SonicWall SSL-VPN account whose password has been harvested by an infostealer is, in effect, a single-factor account, regardless of the MFA policy the administrator believes is in force.

The credential a broker is selling today is the credential an affiliate is using next quarter, and the MFA policy an admin trusts is only as strong as the reset path sitting behind it.

The lesson for defenders

The temptation after a case like this is to focus on the encryption stage: better backups, faster response. While important, those approaches focus on right of boom tactics instead of left of boom proactive defense. Hardening the attack surface changes the outcome in these SSL-VPN based attacks, while addressing other gaps that cyber criminals will look to exploit on their way to accessing critical systems.

A few priorities from the CyOps analysts who worked these cases:

  • Phishing-resistant MFA (FIDO2 / WebAuthn) on every SSL-VPN gateway and administrative path. Push-based MFA is no longer sufficient for high-value access.
  • Harden the MFA-reset path. If the appliance’s own management portal allows an MFA seed to be reset with only the account password, treat that path as the perimeter and assume MFA can be bypassed against any account whose password is known.
  • Treat the corporate VPN address pool as untrusted. In our docket, lateral movement from a VPN-issued internal address is operationally indistinguishable from external lateral movement. Monitor it with the same scrutiny.
  • Treat EDR / EPP uninstall passwords as Tier-0 secrets, equivalent to domain administrator credentials. That’s exactly what the BYOVD stage is trying to defeat.
  • Hunt continuously for nltest /domain_trusts, net.exe accounts /domain, and Advanced IP Scanner on non-administrator workstations. These are the post-edge reconnaissance fingerprints we saw across every Akira-aligned engagement.
  • Adopt an emergency patch cadence on internet-facing appliances when CISA KEV or in-the-wild exploitation is reported.

This case study is a reminder that the most damaging intrusions of 2026 were predictable and preventable. They required a valid credential, a gateway that trusted it, and a defender who wasn’t watching the identity layer as closely as the endpoint. Fortunately for defenders, none of it requires exotic countermeasures, just phishing-resistant MFA, an untrusted VPN pool, and eyes on the identity layer.

This is one of four anonymized case studies in the CyOps 1H 2026 ECHO Report. The full report includes the complete threat landscape, ransomware ecosystem analysis, a SOC & detection-engineering appendix, and MITRE ATT&CK mapping.

Read the full CyOps ECHO Report

SUBSCRIBE

Briefings in your Inbox

Original CyOps research, monthly threat intel, and early access to webinars. No fluff. Unsubscribe anytime.

Related Posts

DeadLock's Quiet Extortion Campaign
wp2shell: How Two “Low-Severity” WordPress Bugs Chain Into Full Remote Code Execution
The AI Model That Breached Hugging Face, and 848 Other Reasons July Was a Bad Month
ClickFix Reloaded: From Mass HijackLoader Infections to Stealth EtherHiding RATs
BYOVD Attacks: A CyOps Perspective on Gentlemen Ransomware and PoisonX 

Reading is great. Seeing is better.

See Cynet's unified AI-powered platform in a 30-minute walkthrough tailored to your environment.

Search results for: