We observed UNC2447, an aggressive financially motivated group, exploit SonicWall SMA 100 series VPN zero-day vulnerability prior to patch availability, use SOMBRAT malware, and finally deploy FIVEHANDS ransomware (Mandiant)
Comme le soleil, les machines ne se couchent jamais.