SonicWall customers urged to patch up immediately amid new ransomware attacks

Bad Bots
(Image credit: Gonin / Shutterstock)

UPDATE:  SonicWall has issued the following statement, "Threat actors will take any opportunity to victimize organizations for malicious gain. This exploitation targets a long-known vulnerability that was patched in newer versions of firmware released in early 2021. SonicWall immediately and repeatedly contacted impacted organizations of mitigation steps and update guidance," the company told TechRadar Pro.

"Even though the footprint of impacted or unpatched devices is relatively small, SonicWall continues to strongly advise organizations to patch supported devices or decommission security appliances that are no longer supported, especially as it receives updated intelligence about emerging threats. The continued use of unpatched firmware or end-of-life devices, regardless of vendor, is an active security risk."

SonicWall has alerted a section of its users to an “imminent” ransomware campaign targeting Secure Mobile Access (SMA) 100 series and Secure Remote Access (SRA) products running end-of-life, unpatched firmware

The security vendor believes the malicious campaign exploits a known vulnerability that has already been patched in newer versions of the firmware for the affected devices.

“Organizations that fail to take appropriate actions to mitigate these vulnerabilities on their SRA and SMA 100 series products are at imminent risk of a targeted ransomware attack,” SonicWall said in itsnotice. 

TechRadar needs yo...

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and you can also choose to enter the prize draw to win a $100 Amazon voucher or one of five 1-year ExpressVPN subscriptions.

>> <a href="" data-link-merchant=""" target="_blank">Click here to start the survey in a new window <<

Playing with fire

The notice, which focuses more on remediation steps rather than sharing information about the threat itself, does acknowledge that the advisory is the result of collaboration between SonicWall and trusted third parties, particularly Mandiant. 

Reporting on the notice, ZDNet shares that while SonicWall did not identify the ransomware group that was targeting its customers, earlier this year, cybersecurity researchers ran into a new variant of the FiveHands ransomware that was attacking SonicWall appliances.

In any case, the company is urging users still running devices with the unmaintained firmware to quickly update to the recent version. 

It’s even coming to the rescue of customers with end-of-life devices that cannot upgrade to the newer patched firmware, by providing a complimentary virtual SMA 500v instance until October 31, 2021, giving them ample time to switch to a more recent product. 

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.