CyberSecurity SEE

Huntress Discovers Widespread Credential Stuffing Campaign Targeting SonicWall Devices

Managed detection and response provider Huntress has issued a critical threat advisory alerting to an active and escalating credential stuffing campaign that is currently targeting SonicWall VPN and firewall appliances. At the time of the advisory’s release, Huntress reported that the logins for 30 organizations had already been compromised, raising significant concerns among cybersecurity professionals.

According to Huntress’s Security Operations Centre (SOC), the unusual activity was first identified on July 25, 2026, around 18:02 UTC. Analysts at the SOC detected a sudden spike in successful logins related to SonicWall, which was traced back to a suspicious autonomous system. Importantly, the analysts noted that they had not yet seen any hands-on-keyboard activity following the initial logins. This indicates that attackers are likely still engaged in the credential validation phase rather than fully exploiting any acquired access.

The cybersecurity firm characterizes this campaign not as a targeted attack aimed at a specific organization, but rather as a broad and opportunistic effort. Instead of focusing on a single victim, the threat actors appear to be systematically testing large batches of stolen or guessed credentials against internet-facing SonicWall remote access portals. This strategy aims to identify valid combinations across various unrelated networks, significantly broadening the potential impact of their efforts.

Attack Volume Growing Daily

Data collected by Huntress reveals that the number of compromised accounts and organizations has been growing at an alarming rate since the onset of the campaign. The statistics are as follows:

Moreover, four of the accounts that were compromised in this recent wave had previously been targeted in an earlier incident tracked back to May 22, 2026. This suggests that some of the compromised credentials had likely been circulating among threat actors long before the latest attack.

Part of a Wider Pattern

This current attack is part of a disturbing trend, as SonicWall’s remote access products have been under continuous threat for some time. Huntress referenced previous spikes in attack activity, such as in October 2025 and February 2026, when threat actors rapidly authenticated into multiple accounts using compromised SonicWall devices. Researchers assess that the present campaign aligns with a pattern of automated credential validation attacks against SonicWall’s infrastructure that has been observed throughout 2025 and into 2026.

Infrastructure and Indicators

Huntress identified five IP addresses associated with the credential stuffing attempts, all registered to the hosting provider DigitalOcean, LLC. The following table lists the specific indicators of compromise:

Indicator Description
157.245.88.153 Malicious IP (DigitalOcean, LLC) linked to SonicWall brute-force activity
162.243.31.111 Malicious IP (DigitalOcean, LLC) linked to SonicWall brute-force activity
167.71.150.1 Malicious IP (DigitalOcean, LLC) linked to SonicWall brute-force activity
209.97.151.148 Malicious IP (DigitalOcean, LLC) linked to SonicWall brute-force activity
64.227.15.20 Malicious IP (DigitalOcean, LLC) linked to SonicWall brute-force activity

Recommended Mitigations

In light of the ongoing threat, Huntress strongly urges any organization using SonicWall VPN or firewall infrastructure to undertake immediate precautionary measures, including:

Huntress has assured stakeholders that its SOC teams are actively monitoring the evolving campaign and are collaborating directly with affected partners to identify compromised accounts. The firm is committed to providing updates as the investigation unfolds and as additional information becomes available.

The impact of this widespread credential stuffing campaign seeks to be mitigated through these recommended actions, reinforcing the need for vigilance in cybersecurity practices amidst the escalating threats presented to organizations relying on SonicWall products.

Source link

Exit mobile version