Huntress Threat Advisory: Widespread SonicWall Credential Stuffing Campaign

Key Takeaways

  • Since July 25, Huntress has observed an active, broad, and opportunistic credential stuffing campaign resulting in successful unauthorized logins to SonicWall VPN and firewall accounts. So far, 30 organizations have been impacted.

  • The activity stems from five IPs and relies on infrastructure hosted on DigitalOcean to compromise numerous, seemingly unrelated organizations.

  • Current telemetry indicates this is an automated credential validation attack, consistent with similar campaigns targeting SonicWall VPNs throughout 2025 and 2026.

  • Organizations utilizing SonicWall infrastructure should immediately review authentication logs, disable affected accounts, and ensure multi-factor authentication (MFA) is strictly enforced.

Acknowledgments: Special thanks to Andrea Ochoa, Cristian Poenaru, Harry Godridge, Rob Stynes, Joshua Kiriakoff, Jordan Sexton, Anthony Gibbs, Austin Worline, Michael Tigges, Tyler Bohlmann, and Nick Roddy for their contributions to this investigation and response.

Background

Starting on July 25, 2026, at approximately 18:02:21 UTC, the Huntress SOC detected an out-of-the-ordinary spike in successful SonicWall VPN and firewall logins. These logins originated from a suspicious Autonomous System Number (ASN). We did not observe any post-compromise hands-on-keyboard activity from these attacks. 

Rather than a highly targeted strike on a single entity, our analysis indicates that this campaign is a broad, opportunistic attack. The threat actors are casting a wide net, systematically validating credentials against remote access portals to compromise as many vulnerable accounts as possible across unrelated organizations.

Technical Details 

Our telemetry indicates that the threat actors are leveraging a specific set of infrastructure to conduct these credential stuffing attempts. We have identified five primary malicious IP addresses driving this attack, all of which are registered to DigitalOcean, LLC:

  • 157.245.88[.]153 

  • 162.243.31[.]111 

  • 167.71.150[.]1 

  • 209.97.151[.]148

  •  64.227.15[.]20

Overall, at the time of publication we have seen 30 organizations compromised via this campaign. Because of the opportunistic nature of the attack, the volume of victims has grown rapidly over a short period. Here are the number of compromises we have observed each day of the campaign:

  • July 25: 26 unique user accounts compromised across 6 distinct organizations.

  • July 26: 34 unique user accounts compromised across 16 distinct organizations.

  • July 27: 32 unique user accounts compromised across 8 distinct organizations.

Timeline of SonicWall brute-force attacks

Based on available telemetry, we assess that this activity represents automated credential validation, with similar campaigns and incidents targeting SonicWall VPNs observed across 2025 and 2026. In one instance, the same four compromised user accounts observed in this event were previously targeted in a separate incident on May 22, 2026.

We have previously seen spikes in SonicWall SSLVPN device compromises over the past year, including one in October 2025 where threat actors authenticated into multiple accounts rapidly across compromised devices, and another in February 2026, where threat actors leveraged compromised SonicWall SSLVPN credentials to gain initial access to a victim network.

With this latest increase in activity, we are reporting indicators of compromise (IoCs) and data from the attacks so that businesses can be better informed. 

The Huntress SOC and SOC support teams are actively engaged in monitoring, containing, and responding to these threats for our partners. Upon confirming successful unauthorized access, our team has been working with partners to provide details on compromised accounts and remediation instructions. We will continue to monitor this campaign in the coming days and update this blog accordingly.  

Mitigation Guidance 

If your organization utilizes SonicWall VPNs or firewalls, we strongly recommend taking the following actions immediately to defend against credential stuffing/brute-force campaigns like this one:

  • Immediately restrict WAN management and remote access where possible.

  • Disable or limit HTTP, HTTPS, SSH, SSL VPN and inbound management until credentials are reset.

  • Reset all secrets and keys on affected devices now. This includes local admin accounts, VPN pre-shared keys, LDAP/RADIUS/TACACS+ bind credentials, wireless PSKs and SNMP credentials.

  • Revoke and roll any external API keys, dynamic DNS, SMTP/FTP credentials, and any automation secrets that touch the firewall or management systems.

  • Increase logging and review recent logins and configuration changes for suspicious activity. Retain forensic logs while you investigate.

  • After resets, reintroduce services one at a time and monitor for reappearance of unauthorised access.

  • Enforce MFA for all admin and remote accounts and apply least privilege to management roles.

Indicators of Compromise (IOCs)

Item

Description

157.245.88[.]153

Malicious IP (DigitalOcean, LLC) associated with SonicWall brute-force

162.243.31[.]111


Malicious IP (DigitalOcean, LLC) associated with SonicWall brute-force

167.71.150[.]1

Malicious IP (DigitalOcean, LLC) associated with SonicWall brute-force

209.97.151[.]148

Malicious IP (DigitalOcean, LLC) associated with SonicWall brute-force

64.227.15[.]20

Malicious IP (DigitalOcean, LLC) associated with SonicWall brute-force