Acknowledgments: Special thanks to Andrea Ochoa, Cristian Poenaru, Harry Godridge, Rob Stynes, Joshua Kiriakoff, Jordan Sexton, Anthony Gibbs, Austin Worline, Michael Tigges, Tyler Bohlmann, and Nick Roddy for their contributions to this investigation and response.
Background
Starting on July 25, 2026, at approximately 18:02:21 UTC, the Huntress SOC detected an out-of-the-ordinary spike in successful SonicWall VPN and firewall logins. These logins originated from a suspicious Autonomous System Number (ASN). We did not observe any post-compromise hands-on-keyboard activity from these attacks.
Rather than a highly targeted strike on a single entity, our analysis indicates that this campaign is a broad, opportunistic attack. The threat actors are casting a wide net, systematically validating credentials against remote access portals to compromise as many vulnerable accounts as possible across unrelated organizations.
Technical Details
Our telemetry indicates that the threat actors are leveraging a specific set of infrastructure to conduct these credential stuffing attempts. We have identified five primary malicious IP addresses driving this attack, all of which are registered to DigitalOcean, LLC:
157.245.88[.]153162.243.31[.]111167.71.150[.]1209.97.151[.]14864.227.15[.]20
Overall, at the time of publication we have seen 30 organizations compromised via this campaign. Because of the opportunistic nature of the attack, the volume of victims has grown rapidly over a short period. Here are the number of compromises we have observed each day of the campaign:
July 25: 26 unique user accounts compromised across 6 distinct organizations.
July 26: 34 unique user accounts compromised across 16 distinct organizations.
July 27: 32 unique user accounts compromised across 8 distinct organizations.
Timeline of SonicWall brute-force attacks
Based on available telemetry, we assess that this activity represents automated credential validation, with similar campaigns and incidents targeting SonicWall VPNs observed across 2025 and 2026. In one instance, the same four compromised user accounts observed in this event were previously targeted in a separate incident on May 22, 2026.
We have previously seen spikes in SonicWall SSLVPN device compromises over the past year, including one in October 2025 where threat actors authenticated into multiple accounts rapidly across compromised devices, and another in February 2026, where threat actors leveraged compromised SonicWall SSLVPN credentials to gain initial access to a victim network.
With this latest increase in activity, we are reporting indicators of compromise (IoCs) and data from the attacks so that businesses can be better informed.
The Huntress SOC and SOC support teams are actively engaged in monitoring, containing, and responding to these threats for our partners. Upon confirming successful unauthorized access, our team has been working with partners to provide details on compromised accounts and remediation instructions. We will continue to monitor this campaign in the coming days and update this blog accordingly.
Mitigation Guidance
If your organization utilizes SonicWall VPNs or firewalls, we strongly recommend taking the following actions immediately to defend against credential stuffing/brute-force campaigns like this one:
Immediately restrict WAN management and remote access where possible.
Disable or limit HTTP, HTTPS, SSH, SSL VPN and inbound management until credentials are reset.
Reset all secrets and keys on affected devices now. This includes local admin accounts, VPN pre-shared keys, LDAP/RADIUS/TACACS+ bind credentials, wireless PSKs and SNMP credentials.
Revoke and roll any external API keys, dynamic DNS, SMTP/FTP credentials, and any automation secrets that touch the firewall or management systems.
Increase logging and review recent logins and configuration changes for suspicious activity. Retain forensic logs while you investigate.
After resets, reintroduce services one at a time and monitor for reappearance of unauthorised access.
Enforce MFA for all admin and remote accounts and apply least privilege to management roles.
Indicators of Compromise (IOCs)
Item | Description |
|---|---|
| Malicious IP (DigitalOcean, LLC) associated with SonicWall brute-force |
| Malicious IP (DigitalOcean, LLC) associated with SonicWall brute-force |
| Malicious IP (DigitalOcean, LLC) associated with SonicWall brute-force |
| Malicious IP (DigitalOcean, LLC) associated with SonicWall brute-force |
| Malicious IP (DigitalOcean, LLC) associated with SonicWall brute-force |