Huntress warns about attack spree that hit 30 SonicWall customers in 2 days
Full article712 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Unknown attackers broke into 92 unique SonicWall user accounts with legitimate credentials, researchers said.
Listen to this article
0:00
Learn more.
Huntress researchers spotted an active and ongoing series of attacks targeting SonicWall VPN and firewall accounts, which compromised 30 organizations in less than two days, the company said in a threat advisory Tuesday.
The credential stuffing campaign started Saturday and grew rapidly, ultimately compromising 92 unique user accounts during the next 41 hours, according to Huntress. Researchers said the attacks were broad and opportunistic, hitting various SonicWall devices, rather than targeting specific types of organizations.
SonicWall hasn’t released a security advisory about the malicious activity as of press time. A spokesperson told CyberScoop the company is still investigating and hopes to have more information soon.
The attacks ended — at least for now — as abruptly as they began. The last compromise occurred Monday, according to Michael Tigges, principal tactical response analyst at Huntress.
“This fits campaign trends,” he said. “A rash of compromise will break out, followed by silence until the adversary rotates infrastructure.”
Attackers, which haven’t been identified, have also refrained from initiating any post-compromise activity, indicating the intrusions could be pre-positioning for future attacks.
“With local network access, the sky is essentially the limit for most networks that do not have proper topology controls in place,” Tigges said.
Huntress’ observations are limited to telemetry it collects from its customers, meaning all of the identified victims were Huntress customers using SonicWall devices, so the number of organizations impacted could be greater.
Researchers haven’t identified a root cause for the attacks, noting that they begin with authorized logins. Attackers are validating credentials against remote access portals to compromise as many vulnerable accounts as possible, the cybersecurity vendor and threat intelligence firm said.
“This could be an aggregation of stealer malware logs, previously compromised SonicWall configuration files, or historic CVE compromise that resulted in more credentials than the adversary could use at the time,” Tigges said.
In 2025, an undisclosed state-sponsored threat actor intruded SonicWalls’s cloud environment and stole firewall configurations of every customer.
SonicWall customers have also been hit by a barrage of actively exploited zero-days, including a pair of zero-days that were exploited for three weeks before the vendor disclosed and patched the defects earlier this month, and previously disclosed defects in SonicWall devices for years.
Seventeen defects affecting the vendor’s products have been added to CISA’s known exploited vulnerabilities catalog since late 2021. Ten of those defects are known to be used in ransomware campaigns, according to CISA, including a wave of about 40 Akira ransomware attacks between mid-July and early August 2025.
“Edge devices are one of the most targeted interfaces, comprising over 70% of active intrusions triaged by Huntress, including the overwhelming majority of ransomware deployments,” Tigges said. “Organizations that do not spend significant time architecting secure remote access solutions and networks that are resilient to edge-device compromise will likely continue to feel the burn in the coming months and years.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Jail time for Maine child in 764 marks turning point in federal law enforcement
Dogged Russia-based botnet dismantled after 23-year run
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/sonicwall-credential-attacks-vpn-firewall/