Malware & Threats

SonicWall SSL VPN Accounts in Attacker Crosshairs

Threat actors have rapidly compromised more than 100 SonicWall SSL VPN accounts pertaining to over a dozen entities.

SonicWall firewalls exposed

In the wake of the recent compromise of SonicWall firewall configuration files, Huntress warns of a widespread campaign targeting SonicWall SSL VPN accounts across multiple businesses.

The attackers, the cybersecurity outfit says, are rapidly logging into multiple SSL VPN accounts across compromised devices, likely using valid credentials rather than brute-forcing them.

Most of the activity occurred on October 4, and continued in clusters over the following days. By October 10, more than 100 SonicWall SSL VPN accounts across 16 environments were compromised as part of the campaign.

The authentication attempts came from the same IP address, and in most cases the attackers were seen disconnecting from the compromised network without performing additional activities.

“In other cases, there was evidence of post-exploitation activity, with the actors conducting network scanning activity and attempting to access numerous local Windows accounts,” Huntress says.

The warning came days after SonicWall announced that all users who stored firewall configuration files using its cloud backup service were impacted by a September data breach.

Advertisement. Scroll to continue reading.

As part of the attack, hackers accessed the preference files of all firewalls configured with MySonicWall as the cloud backup service. Given that these files contain encrypted credentials and configuration data, the compromise poses a high risk to the affected organizations, SonicWall said last week.

According to Huntress, there is no evidence that the fresh campaign is related to the MySonicWall data breach, but that does not rule out a potential connection between the two.

“Notably, we have no evidence to link [the SonicWall] advisory to the recent spike in compromises that we have seen. However, none may exist allowing us to discern that activity from our vantage point. We are reporting the indicators of compromise and data regarding mass compromise that we’ve seen,” Huntress says.

The cybersecurity firm recommends restricting WAN management and remote access, resetting credentials, disabling or limiting remote management until credentials are rotated, and revoking and re-rolling external APIs and automation secrets.

Organizations should also review logs for unusual login attempts, gradually reintroduce services after credential rotation and monitor for unauthorized access, and enforce multi-factor authentication (MFA) for all administrator and remote access accounts.

Related: Cisco, Fortinet, Palo Alto Networks Devices Targeted in Coordinated Campaign

Related: Akira Ransomware’s Exploitation of SonicWall Vulnerability Continues

Related: SonicWall Updates SMA 100 Appliances to Remove Overstep Malware

Related: Widespread Infostealer Campaign Targeting macOS Users

Related Content

Vulnerabilities

The bugs could be exploited to bypass security controls, access restricted services, and crash firewalls.

Vulnerabilities

The bugs could allow attackers to modify protected resources and escalate their privileges to administrator.

Vulnerabilities

The medium-severity flaw has been exploited in combination with a critical bug for remote code execution.

Vulnerabilities

The vulnerabilities could be exploited to cause a denial-of-service (DoS) condition, execute arbitrary code, or access arbitrary files and directories.

Nation-State

The threat actor stole the firewall configuration files of all SonicWall customers who used the cloud backup service.

Network Security

In early September, hackers stole the firewall configuration backup files stored using the MySonicWall service.

Ransomware

In one attack, the hackers leveraged the Datto RMM utility on a domain controller and various other legitimate tools to evade detection.

Malware & Threats

The software update includes additional file checks and helps users remove the known rootkit deployed in a recent campaign.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version