VORANT. Threat Intelligence Sign in Get the full feed

Direwolf ransomware lists ION Xperiences as victim

high threat

Ransomware.live shows Direwolf ransomware group listed ION Xperiences as a victim, citing exposed FortiOS SSL-VPN credentials from the 2022 FortiBleed flaw.

A victim entry on ransomware.live attributes a compromise of the organization identified as ION Xperiences to the Direwolf ransomware operation. The listing, sourced from Hudson Rock cybercrime intelligence tooling, reports a modest exposure footprint: no directly compromised employees, 44 compromised user accounts, 113 third-party employee credential exposures, and 11 external attack surface findings. Notably, the entry states that the victim's FortiOS SSL-VPN credentials were exposed via the FortiBleed vulnerability (CVE-2022-40684), a known path-traversal flaw that allows unauthenticated attackers to read arbitrary files, including admin credentials, from Fortinet FortiOS/FortiProxy devices.

The posting provides no additional technical detail beyond DNS records and a leak screenshot, and does not describe the intrusion chain, ransomware payload behavior, or data exfiltrated. Defenders operating FortiOS SSL-VPN appliances should treat any unpatched CVE-2022-40684 exposure as a credential-theft risk and rotate VPN credentials, enforce MFA, and confirm patch levels, since infostealer-harvested or leak-derived credentials are a recurring precursor to ransomware deployment as highlighted by the Hudson Rock sponsorship note.

This is a routine victim-disclosure listing rather than a novel campaign report; there is no indication of a large-scale or targeted operation beyond the single named victim.

Mentioned in this report

Vulnerabilities CVE-2022-40684KEV
Threat actors Dire Wolf
Malware Direwolf

Source reporting: https://www.ransomware.live/id/aVNPTiBYUEVSSUVOQ0VTQGRpcmV3b2xm

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free