A cyberthreat gang that’s been active since 2020 exploited a now-patched zero-day vulnerability in the SonicWall SMA 100 Series appliance. The group, which FireEye calls UNC2447, exploited the vulnerability, tracked as CVE-2021-20016, to install the Sombrat backdoor and then a new ransomware variant. The gang encrypted and exfiltrated data, demanding a ransom in return for a decryptor and for refraining from exposing or selling the data.”]
Source: https://www.govinfosecurity.com/ransomware-gang-exploits-sonicwall-zero-day-flaw-a-16503

