Credential Stuffing Campaign Hits SonicWall | Huntress SOC Tracking
Cybersecurity Classified by Officially
Since July 25, Huntress has observed an active, broad, and opportunistic credential stuffing campaign resulting in successful unauthorized logins to SonicWall VPN and firewall accounts. So far, 30 organizations have been impacted.
The activity stems from five IPs and relies on infrastructure hosted on DigitalOcean to compromise numerous, seemingly unrelated organizations.
Current telemetry indicates this is an automated credential validation attack, consistent with similar campaigns targeting SonicWall VPNs throughout 2025 and 2026.
Organizations utilizing SonicWall infrastructure should immediately review authentication logs, disable affected accounts, and ensure multi-factor authentication (MFA) is strictly enforced.
Acknowledgments: Special thanks to Andrea Ochoa, Cristian Poenaru, Harry Godridge, Rob Stynes, Joshua Kiriakoff, Jordan Sexton, Anthony Gibbs, Austin Worline, Michael Tigges, Tyler Bohlmann, and Nick Roddy for their contributions to this investigation and response.
Starting on July 25, 2026, at approximately 18:02:21 UTC, the Huntress SOC detected an out-of-the-ordinary spike in successful SonicWall VPN and firewall logins. These logins originated from a suspicious Autonomous System Number (ASN). We did not observe any post-compromise hands-on-keyboard activity from these attacks.
Rather than a highly targeted strike on a single entity, our analysis indicates that this campaign is a broad, opportunistic attack. The threat actors are casting a wide net, systematically validating credentials against remote access portals to compromise as many vulnerable accounts as possible across unrelated organizations.
Our telemetry indicates that the threat actors are leveraging a specific set of infrastructure to conduct these credential stuffing attempts. We have identified five primary malicious IP addresses driving this attack, all of which are registered to DigitalOcean, LLC:
This is an extract. The publication continues at the source.
Read the original at the source: https://www.huntress.com/blog/sonicwall-credential-stuffing-campaign
Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Huntress — imported from official source
- Official source
- https://www.huntress.com/blog/rss.xml RSS
- Imported
- September 20, 2026 19:55
- Versions
- 1 recorded
- Identity
https://www.huntress.com/blog/sonicwall-credential-stuffing-campaign