Full Report
The Huntress SOC is tracking an active credential stuffing campaign targeting SonicWall devices, compromising dozens of organizations since July 25.
Analysis Summary
# Incident Report: Widespread SonicWall Credential Stuffing Campaign
## Executive Summary
Since July 25, 2026, a broad and opportunistic credential stuffing campaign has targeted SonicWall VPN and firewall devices, resulting in unauthorized access to at least 30 organizations. The attack utilizes automated infrastructure to validate stolen credentials, posing a significant risk of initial access for subsequent ransomware or data exfiltration activities. No hands-on-keyboard activity has been observed yet, but historical trends suggest threat actors may pivot to domain controllers shortly after successful authentication.
## Incident Details
- **Discovery Date:** July 25, 2026, 18:02:21 UTC
- **Incident Date:** July 25, 2026 – Ongoing
- **Affected Organization:** Multiple (30+ unique organizations identified)
- **Sector:** Cross-sector (Opportunistic)
- **Geography:** Global / Distributed
## Timeline of Events
### Initial Access
- **Date/Time:** July 25, 2026, 18:02:21 UTC
- **Vector:** Credential Stuffing / Automated Brute-Force
- **Details:** Threat actors used automated scripts to test batches of credentials against SonicWall SSLVPN and firewall portals.
### Lateral Movement
- **Details:** While not observed in this specific campaign's current phase, historical telemetry from similar 2026 attacks shows threat actors pivoting to Domain Controllers within hours of initial VPN breach.
### Data Exfiltration/Impact
- **Details:** At this stage, the primary impact is the compromise of account integrity across 90+ unique user accounts. No data exfiltration was reported in the current advisory.
### Detection & Response
- **Discovery:** Detected by Huntress SOC via an anomalous spike in successful logins from a suspicious Autonomous System Number (ASN).
- **Response Actions:** Huntress engaged partners to provide details on compromised accounts and issued remediation guidance, including account resets and MFA enforcement.
## Attack Methodology
- **Initial Access:** Credential Stuffing (validating stolen credentials).
- **Persistence:** Maintaining access via valid VPN credentials.
- **Privilege Escalation:** Not reported (pending hands-on-keyboard activity).
- **Defense Evasion:** Use of distributed infrastructure (DigitalOcean) to bypass simple IP-based rate limiting.
- **Credential Access:** Automated validation of previously leaked or stolen usernames and passwords.
- **Discovery:** Probing SonicWall remote access portals.
- **Lateral Movement:** Historical precedent suggests RDP or SMB movement following VPN access.
- **Impact:** Unauthorized access to corporate networks; potential precursor to ransomware.
## Impact Assessment
- **Financial:** Potential for significant loss if access is sold to ransomware affiliates.
- **Data Breach:** Compromise of 92+ unique sets of corporate credentials.
- **Operational:** Disruption due to forced account lockouts and mandatory password resets across 30 organizations.
- **Reputational:** High risk for organizations failing to secure remote access points with MFA.
## Indicators of Compromise
### Network Indicators
- 157.245.88[.]153
- 162.243.31[.]111
- 167.71.150[.]1
- 209.97.151[.]148
- 64.227.15[.]20
- ASN: DigitalOcean, LLC
### Behavioral Indicators
- Spikes in successful logins at unusual hours.
- Successful logins originating from DigitalOcean infrastructure.
- Multiple failed login attempts followed by a single success (typical of stuffing).
## Response Actions
- **Containment:** Disabling affected user accounts immediately upon detection.
- **Eradication:** Terminating active VPN sessions associated with malicious IPs.
- **Recovery:** Mandatory password rotations and auditing of all account permissions.
## Lessons Learned
- **Credential Reuse:** The attack was successful because users reused credentials across different platforms.
- **MFA Gaps:** The primary enabler for this campaign was the lack of enforced Multi-Factor Authentication (MFA) on SSLVPN endpoints.
- **Automated Monitoring:** Rapid detection was only possible through real-time monitoring of authentication logs for anomalous ASN patterns.
## Recommendations
- **Enforce MFA:** Immediately require Multi-Factor Authentication for all SonicWall VPN and management interfaces.
- **IP Allow-listing:** If possible, restrict VPN access to known corporate or employee IP ranges.
- **Log Review:** Regularly audit SonicWall authentication logs for logins originating from VPS providers (e.g., DigitalOcean, AWS, Azure).
- **Geoblocking:** Implement geographic login restrictions if business operations are localized.