Background /What has happened?
SonicWall, a network and cyber security appliance vendor, is reporting that ransomware activity is currently targeting their Secure Mobile Access (SMA) 100 series comprised of SMA 200, 210, 400, 410 physical appliances and the SMA 500v virtual appliance) and Secure Remote Access (SRA) products running unpatched and end-of-life 8.x firmware versions. This ransomware activity is reported by SonicWall as abusing stolen credentials.
The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) is aware of stolen credentials affecting Australian organisations that were likely the result of unpatched and end-of-life SonicWall devices running 8.x firmware being exploited.
The ASD’s ACSC has previously issued an alert on a remote credential access vulnerability affecting SonicWall products.
Update 29 July 2021
This alert update clarifies that only end-of-life and selected unpatched devices are vulnerable to this activity.
Mitigation / How do I stay secure?
Australian organisations should review their networks for the presence of affected SonicWall products which are outlined in the security notice from SonicWall. If vulnerable products are identified, Australian organisations should review and implement the recommended mitigations provided by SonicWall.
Assistance / Where can I go for help?
The ASD’s ACSC is monitoring the situation and is able to provide assistance and advice as required. Organisations that have been impacted or require assistance can contact the ASD’s ACSC via 1300 CYBER1.