ITSecurityGuru

Huntress Flags Widespread Credential Stuffing Campaign Hitting SonicWall Devices


Managed detection and response provider Huntress has issued a threat advisory warning of an active and rapidly growing credential stuffing campaign targeting SonicWall VPN and firewall appliances, with the company reporting that logins to 30 organisations’ accounts had already been compromised at the time of publication.

According to Huntress’s Security Operations Centre (SOC), the unusual activity was first detected on 25 July 2026 at around 18:02 UTC, when analysts noticed an anomalous spike in successful SonicWall logins traced back to a suspicious autonomous system. Crucially, the firm says it has not yet observed any hands-on-keyboard activity following the initial logins, suggesting the attackers are still in the credential-validation phase rather than actively exploiting access.

Huntress characterises the campaign as broad and opportunistic rather than a targeted strike against a single victim. Rather than focusing on one organisation, the threat actors appear to be systematically testing stolen or guessed credentials against internet-facing SonicWall remote access portals at scale, hoping to find valid combinations across as many unrelated networks as possible.

Attack Volume Growing Daily

Huntress’s telemetry shows the number of affected accounts and organisations climbing steadily since the campaign began:

  • 25 July: 26 unique accounts compromised across 6 organisations.
  • 26 July: 34 unique accounts compromised across 16 organisations.
  • 27 July: 32 unique accounts compromised across 8 organisations.

The firm also noted that four accounts compromised in this campaign had previously been targeted in a separate incident it tracked on 22 May 2026, suggesting some victim credentials may have circulated among threat actors for some time before this latest wave.

Part of a Wider Pattern

This is not the first time SonicWall’s remote access products have come under sustained attack. Huntress points to comparable spikes in October 2025, when attackers rapidly authenticated into multiple accounts across compromised devices, and February 2026, when compromised SonicWall SSL VPN credentials were used to gain initial network access. Researchers assess that the current campaign is consistent with this pattern of automated credential validation attacks against SonicWall infrastructure observed throughout 2025 and into 2026.

Infrastructure and Indicators

Huntress has attributed the credential stuffing attempts to five IP addresses, all registered to hosting provider DigitalOcean, LLC. The full list of indicators of compromise is below.

IndicatorDescription
157.245.88.153Malicious IP (DigitalOcean, LLC) linked to SonicWall brute-force activity
162.243.31.111Malicious IP (DigitalOcean, LLC) linked to SonicWall brute-force activity
167.71.150.1Malicious IP (DigitalOcean, LLC) linked to SonicWall brute-force activity
209.97.151.148Malicious IP (DigitalOcean, LLC) linked to SonicWall brute-force activity
64.227.15.20Malicious IP (DigitalOcean, LLC) linked to SonicWall brute-force activity
Recommended Mitigations

Huntress is urging any organisation running SonicWall VPN or firewall infrastructure to take immediate action, including:

  • Restricting WAN management and remote access wherever possible
  • Disabling or limiting HTTP, HTTPS, SSH and SSL VPN inbound management until credentials are reset
  • Resetting all local admin credentials, VPN pre-shared keys, and LDAP/RADIUS/TACACS+ bind credentials
  • Revoking and rolling any API keys, dynamic DNS, SMTP/FTP or automation secrets tied to the firewall
  • Increasing logging and reviewing recent logins and configuration changes for signs of compromise
  • Reintroducing services gradually after resets, monitoring closely for renewed unauthorised access
  • Enforcing multi-factor authentication on all admin and remote-access accounts and applying least-privilege principles to management roles

Huntress said its SOC teams are continuing to monitor the campaign and are working directly with affected partners to identify compromised accounts and support remediation. The company has pledged to update its advisory as the investigation develops.



Source link