Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices
Team Cymru Infrastructure Analysis (TL-2026-2517) is a high-severity ransomware operation, first published 2026-09-15. It is attributed to DragonForce (Malaysia) with medium confidence, affects SonicWall SonicOS (Gen5/Gen6/Gen7 TZ and NSa series SSL VPN), references 4 CVEs (CVE-2024-40766, CVE-2025-30406, CVE-2025-11371), maps to 15 MITRE ATT&CK techniques (T1021.001, T1048, T1071.001), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-2517
- Threat ID
- TL-2026-2517
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-09-15
- Last reviewed
- 2026-09-15
- Attribution
- DragonForce
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Malaysia
- Motivation
- FINANCIAL
- Target sectors
- small and medium enterprises, professional services, manufacturing, technology, health, education, legal, insurance, government administration, finance
- Target regions
- united kingdom, North America, Europe, australia, Global
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in Team Cymru Infrastructure Analysis
Malware and tooling: Agenda Ransomware, AgendaCrypt, Akira, AnyDesk, Clop, Cobalt Strike, DragonForce, Lynx, MedusaLocker, inc ransom, AnyDesk, Chisel
Team Cymru's year-long infrastructure analysis (April 2025-April 2026) of seven active ransomware operations finds heavy convergence on legitimate dual-use tools (Rclone, Cobalt Strike, AnyDesk, FileZilla, SimpleHelp, Chisel) over custom malware, VPN/Tor/SOCKS-proxy obfuscation, and exploitation of internet-facing SonicWall SSL VPN devices (CVE-2024-40766), the Gladinet CentreStack/Triofox managed file transfer service (CVE-2025-30406, CVE-2025-11371, CVE-2025-14611), and Fortinet FortiGate appliances.
How Team Cymru Infrastructure Analysis works
Team Cymru's Ransomware Infrastructure Analysis synthesizes 20+ incident investigations between April 2025 and April 2026 into cross-gang infrastructure and TTP patterns for seven active ransomware operations -- Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, and Lynx (a rebrand of INC Ransom sharing over 90% of its source code) -- with a LockBit3 (leaked-builder) incident also documented. The analysis, which primarily covers intrusions against UK small-to-medium enterprises, finds a decisive shift away from custom-coded malware toward abuse of legitimate dual-use tools: Rclone and FileZilla for exfiltration, Cobalt Strike for post-exploitation C2, and AnyDesk/SimpleHelp for hands-on-keyboard remote access -- a pattern Team Cymru's Scout platform tags consistently across all seven groups.
Initial access converges on three exploitation vectors. First, Akira's sustained 2025 campaign against SonicWall SonicOS SSL VPN devices via CVE-2024-40766 (CVSS 9.3), an improper access-control flaw in which local account passwords carried over from Gen5/Gen6 firmware migrations were never reset; CISA and Arctic Wolf documented dozens of intrusions moving from SSL VPN login to full encryption in under four hours, with some as fast as 55 minutes. Second, Clop's December 2025 mass-exploitation of internet-facing Gladinet CentreStack/Triofox managed file transfer servers, chaining a hardcoded IIS machineKey (CVE-2025-30406, CVE-2025-14611) with an unauthenticated local file inclusion flaw (CVE-2025-11371) into a ViewState deserialization remote code execution primitive, staged from commercial VPN egress (Cloudflare WARP, Private Internet Access) across AS396073, AS51852, and AS50049. Third, DragonForce's continued reliance on RDP brute-forcing for both initial access and lateral movement. Lynx's February 2026 incident followed exploitation of a Fortinet FortiGate appliance, a vector later connected to the wider 'FortiBleed' mass credential-theft campaign (86,644+ affected devices across 194 countries) that SOCRadar publicly attributed to INC Ransom and Lynx ransomware deployments in July 2026.
Post-compromise, the gangs converge again on VPN/Tor/SOCKS-proxy obfuscation: DragonForce anonymizes operator traffic over Tor; multiple groups route through commercial VPN services (1VPN, Cloudflare WARP, Private Internet Access) and low-reputation VPS hosting spread across dozens of distinct ASNs to frustrate attribution and takedown; and MedusaLocker's March 2026 incident chained an open-source Chisel tunneling implant with a Cloudflare Worker to stand up a reverse SOCKS proxy for covert command and control. Qilin and MedusaLocker both exfiltrated over SFTP/OpenSSH from single staging nodes supporting multiple post-compromise objectives, while Akira and INC Ransom relied on Rclone syncs to cloud storage. No group in this analysis window deployed custom-coded lateral-movement or C2 malware, consistent with CISA's Akira advisory (AA24-109A), which documents Akira's reliance on commodity tools (Mimikatz, AdFind, PowerTool/Zemana-driver AV killers, Cobalt Strike, AnyDesk) and living-off-the-land techniques -- including volume shadow copy deletion and EDR/AV tampering ahead of ChaCha20/RSA hybrid encryption -- over bespoke malware.
MITRE ATT&CK techniques used in TL-2026-2517
Lateral Movement
T1021.001 Remote Desktop Protocol
Exfiltration
T1048 Exfiltration Over Alternative Protocol; T1567.002 Exfiltration to Cloud Storage
Command and Control
T1071.001 Web Protocols; T1090 Proxy; T1090.003 Multi-hop Proxy; T1219 Remote Access Tools; T1572 Protocol Tunneling
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Impact
Resource Development
Reconnaissance
defense-impairment
Affected products and versions in Team Cymru Infrastructure Analysis
- SonicWall — SonicOS (Gen5/Gen6/Gen7 TZ and NSa series SSL VPN)
Vulnerable versions: Gen5; Gen6; Gen7 7.0.1-5035 and earlier
Fixed in: Gen7 builds after 7.0.1-5035, with mandatory local password reset - Gladinet — CentreStack and Triofox
Vulnerable versions: up to and including 16.1.10296.56315; builds prior to 16.12.10420.56791
Fixed in: 16.4.10315.56368; 16.12.10420.56791 - Fortinet — FortiGate SSL VPN / FortiClient EMS
Vulnerable versions: pre-patch builds affected by the FortiBleed credential-theft campaign
Fixed in: per Fortinet's January 2026 security advisories
Remediation for Team Cymru Infrastructure Analysis
Patches
- SonicWall SonicOS post-7.0.1-5035 (CVE-2024-40766)
- Gladinet CentreStack/Triofox 16.4.10315.56368 (CVE-2025-30406)
- Gladinet CentreStack/Triofox 16.12.10420.56791 (CVE-2025-11371, CVE-2025-14611)
Immediate actions
- Patch SonicWall SonicOS to a build beyond 7.0.1-5035 and force-reset all local SSL VPN account passwords, especially any migrated from Gen5/Gen6 firewalls (CVE-2024-40766)
- Enforce MFA on all SonicWall SSL VPN and other externally exposed VPN/RDP gateways
- Update Gladinet CentreStack/Triofox to 16.12.10420.56791 or later to remediate the hardcoded machineKey (CVE-2025-30406, CVE-2025-14611) and LFI (CVE-2025-11371) exploit chain
- Take internet-facing Gladinet CentreStack/Triofox instances offline or place them behind a VPN/IP allowlist until patched
- Disable direct internet exposure of RDP (TCP/3389); require VPN plus MFA for any remote desktop access
- Hunt for unauthorized installations of AnyDesk, SimpleHelp, and other RMM tools not sanctioned by IT
Workarounds
- Restrict SonicWall SSL VPN and Gladinet CentreStack/Triofox management interfaces to trusted IP allowlists
- Disable unused SSL VPN and legacy local accounts pending credential rotation
- Block outbound connections to known low-reputation VPS ASNs and alert on SOCKS/Tor egress at the perimeter
Longer-term hardening
- Deploy EDR/XDR with behavioral detection tuned for Rclone, Chisel, and Cobalt Strike beacon patterns rather than signature-only AV
- Implement egress filtering and alerting on outbound Tor, SOCKS proxy, and unexpected Cloudflare Worker/Tunnel traffic
- Establish a vulnerability management SLA that prioritizes internet-facing VPN/MFT/firewall appliances against the CISA KEV catalog
- Adopt zero-trust network segmentation to limit lateral movement via RDP/SSH between business units
CVEs associated with Team Cymru Infrastructure Analysis
CVE-2024-40766, CVE-2025-30406, CVE-2025-11371, CVE-2025-14611
Weaknesses (CWE) in Team Cymru Infrastructure Analysis
CWE-284, CWE-798, CWE-22, CWE-502
Timeline of Team Cymru Infrastructure Analysis
- Akira ransomware is first observed in the wild, operating as a closed RaaS using double extortion
- INC Ransom's source code is reportedly sold for $300,000 on the RAMP underground forum, later forming the basis for the Lynx rebrand
- Palo Alto Networks Unit 42 identifies Lynx ransomware as a rebrand of INC Ransom, sharing over 90% of its source code
- SonicWall discloses CVE-2024-40766 (CVSS 9.3), an improper access-control flaw where local SSL VPN passwords carried over from Gen5/Gen6 migrations were never reset
- CISA adds CVE-2024-40766 to the Known Exploited Vulnerabilities catalog, confirming active exploitation
- DragonForce introduces its Ransomware Cartel model, letting affiliates run independent ransomware brands on DragonForce's backend infrastructure
- Gladinet ships CentreStack/Triofox 16.4.10315.56368, fixing the hardcoded machineKey deserialization flaw CVE-2025-30406, which was already under active exploitation
- Arctic Wolf observes a sharp uptick in Akira ransomware activity against SonicWall SSL VPN devices, with roughly 40 attacks in July 2025 and some intrusions moving from initial access to full encryption in under an hour
- Huntress detects active exploitation of the unauthenticated Gladinet CentreStack/Triofox local file inclusion flaw CVE-2025-11371
- CISA adds CVE-2025-11371 to the Known Exploited Vulnerabilities catalog
- Clop launches a large-scale data-theft campaign against internet-facing Gladinet CentreStack servers, chaining hardcoded cryptographic keys into ViewState deserialization RCE; Team Cymru identifies five exploitation source IPs across AS396073, AS51852, and AS50049
- CISA adds CVE-2025-14611 (Gladinet hardcoded AES key) to the Known Exploited Vulnerabilities catalog, confirming Clop's use of the flaw
- Team Cymru documents a Lynx ransomware incident following exploitation of a Fortinet FortiGate appliance, using infrastructure on AS16276 and the 1VPN commercial VPN service
- Team Cymru documents a MedusaLocker incident chaining a Chisel implant with a Cloudflare Worker to build a reverse SOCKS proxy, spanning AS56694, AS49505, AS50340, and AS62212
- SOCRadar publicly links the FortiBleed mass FortiGate credential-theft campaign (active since at least February 2026, affecting 86,644+ devices across 194 countries) to INC Ransom and Lynx ransomware deployments
Sources cited for Team Cymru Infrastructure Analysis
- Ransomware Infrastructure Analysis
- #StopRansomware: Akira Ransomware
- CISA Known Exploited Vulnerabilities Catalog - CVE-2024-40766
- SonicWall SSL VPN Flaw and Misconfigurations Actively Exploited by Akira Ransomware Hackers
- Akira ransomware exploiting critical SonicWall SSLVPN bug again
- Smash and Grab: Aggressive Akira Campaign Targets SonicWall VPNs
- CVE-2025-30406: Investigating a CVSS Score That Didn't Add Up
- RCE flaw in MSP-friendly file sharing platform exploited by attackers (CVE-2025-30406)
- Active Attacks Exploit Gladinet's Hard-Coded Keys for Unauthorized Access and Code Execution
- CISA Adds Gladinet and CWP Flaws to KEV Catalog Amid Active Exploitation Evidence
- Clop ransomware targets Gladinet CentreStack servers for extortion
- CLOP targets Gladinet CentreStack servers in large-scale extortion campaign
- Lynx Ransomware: A Rebranding of INC Ransomware
- FortiBleed: The Campaign That Cracked 86,644 Firewalls
- FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
More in ransomware
- Ransomware Attack Disrupts IT Systems and Services in Ellis County, Kansas
- KRSID Ransomware Distributed via Fraudulent "UBP Asset" Home Trading System (HTS) Software
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed
- Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian Targets via Exchange/SharePoint Exploitation
- Magniber Ransomware: Rewritten 2022 Variant Uses MSI Installer, AES-NI Encryption, and UAC Bypass
Detection coverage for TL-2026-2517
As of 2026-09-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2517 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.