A financially motivated threat actor used a zero-day vulnerability in SonicWall SMA 100 Series VPN appliances to deploy FiveHands ransomware on the networks of North American and European targets.
The threat analysts as UNC2447, exploited the CVE-2021-20016 SonicWall vulnerability to breach networks and deploy FiveHands ransomware payloads before patches were released.