Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices

Team Cymru Infrastructure Analysis (TL-2026-2517) is a high-severity ransomware operation, first published 2026-09-15. It is attributed to DragonForce (Malaysia) with medium confidence, affects SonicWall SonicOS (Gen5/Gen6/Gen7 TZ and NSa series SSL VPN), references 4 CVEs (CVE-2024-40766, CVE-2025-30406, CVE-2025-11371), maps to 15 MITRE ATT&CK techniques (T1021.001, T1048, T1071.001), and is covered by 9 detection rules and 27 indicators of compromise.

Key facts for TL-2026-2517

Threat ID
TL-2026-2517
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
2026-09-15
Last reviewed
2026-09-15
Attribution
DragonForce
Attribution confidence
MEDIUM
Nation-state nexus
Malaysia
Motivation
FINANCIAL
Target sectors
small and medium enterprises, professional services, manufacturing, technology, health, education, legal, insurance, government administration, finance
Target regions
united kingdom, North America, Europe, australia, Global
Detection rules
9
Indicators of compromise
27

Malware and tooling in Team Cymru Infrastructure Analysis

Malware and tooling: Agenda Ransomware, AgendaCrypt, Akira, AnyDesk, Clop, Cobalt Strike, DragonForce, Lynx, MedusaLocker, inc ransom, AnyDesk, Chisel

Team Cymru's year-long infrastructure analysis (April 2025-April 2026) of seven active ransomware operations finds heavy convergence on legitimate dual-use tools (Rclone, Cobalt Strike, AnyDesk, FileZilla, SimpleHelp, Chisel) over custom malware, VPN/Tor/SOCKS-proxy obfuscation, and exploitation of internet-facing SonicWall SSL VPN devices (CVE-2024-40766), the Gladinet CentreStack/Triofox managed file transfer service (CVE-2025-30406, CVE-2025-11371, CVE-2025-14611), and Fortinet FortiGate appliances.

How Team Cymru Infrastructure Analysis works

Team Cymru's Ransomware Infrastructure Analysis synthesizes 20+ incident investigations between April 2025 and April 2026 into cross-gang infrastructure and TTP patterns for seven active ransomware operations -- Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, and Lynx (a rebrand of INC Ransom sharing over 90% of its source code) -- with a LockBit3 (leaked-builder) incident also documented. The analysis, which primarily covers intrusions against UK small-to-medium enterprises, finds a decisive shift away from custom-coded malware toward abuse of legitimate dual-use tools: Rclone and FileZilla for exfiltration, Cobalt Strike for post-exploitation C2, and AnyDesk/SimpleHelp for hands-on-keyboard remote access -- a pattern Team Cymru's Scout platform tags consistently across all seven groups.

Initial access converges on three exploitation vectors. First, Akira's sustained 2025 campaign against SonicWall SonicOS SSL VPN devices via CVE-2024-40766 (CVSS 9.3), an improper access-control flaw in which local account passwords carried over from Gen5/Gen6 firmware migrations were never reset; CISA and Arctic Wolf documented dozens of intrusions moving from SSL VPN login to full encryption in under four hours, with some as fast as 55 minutes. Second, Clop's December 2025 mass-exploitation of internet-facing Gladinet CentreStack/Triofox managed file transfer servers, chaining a hardcoded IIS machineKey (CVE-2025-30406, CVE-2025-14611) with an unauthenticated local file inclusion flaw (CVE-2025-11371) into a ViewState deserialization remote code execution primitive, staged from commercial VPN egress (Cloudflare WARP, Private Internet Access) across AS396073, AS51852, and AS50049. Third, DragonForce's continued reliance on RDP brute-forcing for both initial access and lateral movement. Lynx's February 2026 incident followed exploitation of a Fortinet FortiGate appliance, a vector later connected to the wider 'FortiBleed' mass credential-theft campaign (86,644+ affected devices across 194 countries) that SOCRadar publicly attributed to INC Ransom and Lynx ransomware deployments in July 2026.

Post-compromise, the gangs converge again on VPN/Tor/SOCKS-proxy obfuscation: DragonForce anonymizes operator traffic over Tor; multiple groups route through commercial VPN services (1VPN, Cloudflare WARP, Private Internet Access) and low-reputation VPS hosting spread across dozens of distinct ASNs to frustrate attribution and takedown; and MedusaLocker's March 2026 incident chained an open-source Chisel tunneling implant with a Cloudflare Worker to stand up a reverse SOCKS proxy for covert command and control. Qilin and MedusaLocker both exfiltrated over SFTP/OpenSSH from single staging nodes supporting multiple post-compromise objectives, while Akira and INC Ransom relied on Rclone syncs to cloud storage. No group in this analysis window deployed custom-coded lateral-movement or C2 malware, consistent with CISA's Akira advisory (AA24-109A), which documents Akira's reliance on commodity tools (Mimikatz, AdFind, PowerTool/Zemana-driver AV killers, Cobalt Strike, AnyDesk) and living-off-the-land techniques -- including volume shadow copy deletion and EDR/AV tampering ahead of ChaCha20/RSA hybrid encryption -- over bespoke malware.

MITRE ATT&CK techniques used in TL-2026-2517

Lateral Movement

T1021.001 Remote Desktop Protocol

Exfiltration

T1048 Exfiltration Over Alternative Protocol; T1567.002 Exfiltration to Cloud Storage

Command and Control

T1071.001 Web Protocols; T1090 Proxy; T1090.003 Multi-hop Proxy; T1219 Remote Access Tools; T1572 Protocol Tunneling

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Impact

T1490 Inhibit System Recovery

Resource Development

T1583.006 Web Services

Reconnaissance

T1595 Active Scanning

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Team Cymru Infrastructure Analysis

  • SonicWall — SonicOS (Gen5/Gen6/Gen7 TZ and NSa series SSL VPN)
    Vulnerable versions: Gen5; Gen6; Gen7 7.0.1-5035 and earlier
    Fixed in: Gen7 builds after 7.0.1-5035, with mandatory local password reset
  • Gladinet — CentreStack and Triofox
    Vulnerable versions: up to and including 16.1.10296.56315; builds prior to 16.12.10420.56791
    Fixed in: 16.4.10315.56368; 16.12.10420.56791
  • Fortinet — FortiGate SSL VPN / FortiClient EMS
    Vulnerable versions: pre-patch builds affected by the FortiBleed credential-theft campaign
    Fixed in: per Fortinet's January 2026 security advisories

Remediation for Team Cymru Infrastructure Analysis

Patches

  • SonicWall SonicOS post-7.0.1-5035 (CVE-2024-40766)
  • Gladinet CentreStack/Triofox 16.4.10315.56368 (CVE-2025-30406)
  • Gladinet CentreStack/Triofox 16.12.10420.56791 (CVE-2025-11371, CVE-2025-14611)

Immediate actions

  • Patch SonicWall SonicOS to a build beyond 7.0.1-5035 and force-reset all local SSL VPN account passwords, especially any migrated from Gen5/Gen6 firewalls (CVE-2024-40766)
  • Enforce MFA on all SonicWall SSL VPN and other externally exposed VPN/RDP gateways
  • Update Gladinet CentreStack/Triofox to 16.12.10420.56791 or later to remediate the hardcoded machineKey (CVE-2025-30406, CVE-2025-14611) and LFI (CVE-2025-11371) exploit chain
  • Take internet-facing Gladinet CentreStack/Triofox instances offline or place them behind a VPN/IP allowlist until patched
  • Disable direct internet exposure of RDP (TCP/3389); require VPN plus MFA for any remote desktop access
  • Hunt for unauthorized installations of AnyDesk, SimpleHelp, and other RMM tools not sanctioned by IT

Workarounds

  • Restrict SonicWall SSL VPN and Gladinet CentreStack/Triofox management interfaces to trusted IP allowlists
  • Disable unused SSL VPN and legacy local accounts pending credential rotation
  • Block outbound connections to known low-reputation VPS ASNs and alert on SOCKS/Tor egress at the perimeter

Longer-term hardening

  • Deploy EDR/XDR with behavioral detection tuned for Rclone, Chisel, and Cobalt Strike beacon patterns rather than signature-only AV
  • Implement egress filtering and alerting on outbound Tor, SOCKS proxy, and unexpected Cloudflare Worker/Tunnel traffic
  • Establish a vulnerability management SLA that prioritizes internet-facing VPN/MFT/firewall appliances against the CISA KEV catalog
  • Adopt zero-trust network segmentation to limit lateral movement via RDP/SSH between business units

CVEs associated with Team Cymru Infrastructure Analysis

CVE-2024-40766, CVE-2025-30406, CVE-2025-11371, CVE-2025-14611

Weaknesses (CWE) in Team Cymru Infrastructure Analysis

CWE-284, CWE-798, CWE-22, CWE-502

Timeline of Team Cymru Infrastructure Analysis

  • Akira ransomware is first observed in the wild, operating as a closed RaaS using double extortion
  • INC Ransom's source code is reportedly sold for $300,000 on the RAMP underground forum, later forming the basis for the Lynx rebrand
  • Palo Alto Networks Unit 42 identifies Lynx ransomware as a rebrand of INC Ransom, sharing over 90% of its source code
  • SonicWall discloses CVE-2024-40766 (CVSS 9.3), an improper access-control flaw where local SSL VPN passwords carried over from Gen5/Gen6 migrations were never reset
  • CISA adds CVE-2024-40766 to the Known Exploited Vulnerabilities catalog, confirming active exploitation
  • DragonForce introduces its Ransomware Cartel model, letting affiliates run independent ransomware brands on DragonForce's backend infrastructure
  • Gladinet ships CentreStack/Triofox 16.4.10315.56368, fixing the hardcoded machineKey deserialization flaw CVE-2025-30406, which was already under active exploitation
  • Arctic Wolf observes a sharp uptick in Akira ransomware activity against SonicWall SSL VPN devices, with roughly 40 attacks in July 2025 and some intrusions moving from initial access to full encryption in under an hour
  • Huntress detects active exploitation of the unauthenticated Gladinet CentreStack/Triofox local file inclusion flaw CVE-2025-11371
  • CISA adds CVE-2025-11371 to the Known Exploited Vulnerabilities catalog
  • Clop launches a large-scale data-theft campaign against internet-facing Gladinet CentreStack servers, chaining hardcoded cryptographic keys into ViewState deserialization RCE; Team Cymru identifies five exploitation source IPs across AS396073, AS51852, and AS50049
  • CISA adds CVE-2025-14611 (Gladinet hardcoded AES key) to the Known Exploited Vulnerabilities catalog, confirming Clop's use of the flaw
  • Team Cymru documents a Lynx ransomware incident following exploitation of a Fortinet FortiGate appliance, using infrastructure on AS16276 and the 1VPN commercial VPN service
  • Team Cymru documents a MedusaLocker incident chaining a Chisel implant with a Cloudflare Worker to build a reverse SOCKS proxy, spanning AS56694, AS49505, AS50340, and AS62212
  • SOCRadar publicly links the FortiBleed mass FortiGate credential-theft campaign (active since at least February 2026, affecting 86,644+ devices across 194 countries) to INC Ransom and Lynx ransomware deployments

Sources cited for Team Cymru Infrastructure Analysis

More in ransomware

Detection coverage for TL-2026-2517

As of 2026-09-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2517 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats