HomeCyber BalkansHuntress Discovers Widespread Credential Stuffing Campaign Targeting SonicWall Devices

Huntress Discovers Widespread Credential Stuffing Campaign Targeting SonicWall Devices

Published on

spot_img

Managed detection and response provider Huntress has issued a critical threat advisory alerting to an active and escalating credential stuffing campaign that is currently targeting SonicWall VPN and firewall appliances. At the time of the advisory’s release, Huntress reported that the logins for 30 organizations had already been compromised, raising significant concerns among cybersecurity professionals.

According to Huntress’s Security Operations Centre (SOC), the unusual activity was first identified on July 25, 2026, around 18:02 UTC. Analysts at the SOC detected a sudden spike in successful logins related to SonicWall, which was traced back to a suspicious autonomous system. Importantly, the analysts noted that they had not yet seen any hands-on-keyboard activity following the initial logins. This indicates that attackers are likely still engaged in the credential validation phase rather than fully exploiting any acquired access.

The cybersecurity firm characterizes this campaign not as a targeted attack aimed at a specific organization, but rather as a broad and opportunistic effort. Instead of focusing on a single victim, the threat actors appear to be systematically testing large batches of stolen or guessed credentials against internet-facing SonicWall remote access portals. This strategy aims to identify valid combinations across various unrelated networks, significantly broadening the potential impact of their efforts.

Attack Volume Growing Daily

Data collected by Huntress reveals that the number of compromised accounts and organizations has been growing at an alarming rate since the onset of the campaign. The statistics are as follows:

  • On July 25, 26 unique accounts were compromised across 6 organizations.
  • By July 26, this number increased to 34 unique accounts across 16 organizations.
  • On July 27, analysts reported 32 unique accounts compromised across 8 organizations.

Moreover, four of the accounts that were compromised in this recent wave had previously been targeted in an earlier incident tracked back to May 22, 2026. This suggests that some of the compromised credentials had likely been circulating among threat actors long before the latest attack.

Part of a Wider Pattern

This current attack is part of a disturbing trend, as SonicWall’s remote access products have been under continuous threat for some time. Huntress referenced previous spikes in attack activity, such as in October 2025 and February 2026, when threat actors rapidly authenticated into multiple accounts using compromised SonicWall devices. Researchers assess that the present campaign aligns with a pattern of automated credential validation attacks against SonicWall’s infrastructure that has been observed throughout 2025 and into 2026.

Infrastructure and Indicators

Huntress identified five IP addresses associated with the credential stuffing attempts, all registered to the hosting provider DigitalOcean, LLC. The following table lists the specific indicators of compromise:

Indicator Description
157.245.88.153 Malicious IP (DigitalOcean, LLC) linked to SonicWall brute-force activity
162.243.31.111 Malicious IP (DigitalOcean, LLC) linked to SonicWall brute-force activity
167.71.150.1 Malicious IP (DigitalOcean, LLC) linked to SonicWall brute-force activity
209.97.151.148 Malicious IP (DigitalOcean, LLC) linked to SonicWall brute-force activity
64.227.15.20 Malicious IP (DigitalOcean, LLC) linked to SonicWall brute-force activity

Recommended Mitigations

In light of the ongoing threat, Huntress strongly urges any organization using SonicWall VPN or firewall infrastructure to undertake immediate precautionary measures, including:

  • Restricting WAN management and remote access wherever feasible.
  • Disabling or limiting inbound management protocols such as HTTP, HTTPS, SSH, and SSL VPN until credentials have been reset.
  • Resetting all local admin credentials, VPN pre-shared keys, and any LDAP/RADIUS/TACACS+ bind credentials.
  • Revoking and updating any API keys, dynamic DNS entries, and SMTP/FTP or automation secrets related to the firewall.
  • Enhancing logging capabilities and reviewing recent logins and configuration changes for signs of a breach.
  • Reintroducing services gradually after credential resets while closely monitoring for any unauthorized access.
  • Enforcing multi-factor authentication for all admin and remote-access accounts, alongside implementing least-privilege principles for management roles.

Huntress has assured stakeholders that its SOC teams are actively monitoring the evolving campaign and are collaborating directly with affected partners to identify compromised accounts. The firm is committed to providing updates as the investigation unfolds and as additional information becomes available.

The impact of this widespread credential stuffing campaign seeks to be mitigated through these recommended actions, reinforcing the need for vigilance in cybersecurity practices amidst the escalating threats presented to organizations relying on SonicWall products.

Source link

Latest articles

Anthropic Discovers Vulnerability in Hawk Post-Quantum Digital Signature Algorithm

New Insights into AES Cryptography Unveiled by AI-Driven Research In the rapidly evolving field of...

Average Cost of a Data Breach Increases to $5 Million

The average cost associated with data breaches has surged to nearly $5 million, reflecting...

Cyber Briefing – 2026.07.29 – CyberMaterial

Cybersecurity Briefing: The Current Landscape of Threats and Responses In a rapidly evolving digital landscape,...

Russian Intelligence Hackers Target Signal Backup Recovery Keys in Account Takeover Attacks

Russian Hackers Target Signal Users through Phishing Campaign A recent security alert has revealed that...

More like this

Anthropic Discovers Vulnerability in Hawk Post-Quantum Digital Signature Algorithm

New Insights into AES Cryptography Unveiled by AI-Driven Research In the rapidly evolving field of...

Average Cost of a Data Breach Increases to $5 Million

The average cost associated with data breaches has surged to nearly $5 million, reflecting...

Cyber Briefing – 2026.07.29 – CyberMaterial

Cybersecurity Briefing: The Current Landscape of Threats and Responses In a rapidly evolving digital landscape,...