Skip to main content
Emerging ThreatsMalware & Ransomware

SonicWall VPNs Targeted in Rapid Credential Stuffing Campaign

Network equipment sits on a rack in a neutral-colored tech room with visible cables.

“The credential stuffing campaign started Saturday and grew rapidly, ultimately compromising 92 unique user accounts during the next 41 hours,” Huntress researchers reported, describing an attack spree that compromised 30 organizations using SonicWall devices in less than two days.

Huntress: timeline, scale, and scope

Huntress said the activity began on Saturday and, over a 41-hour window, resulted in 92 unique user accounts being compromised and at least 30 customer organizations impacted. The activity “ended — at least for now — as abruptly as it began,” Michael Tigges, principal tactical response analyst at Huntress, told CyberScoop; the last recorded compromise occurred on Monday. Huntress emphasized its view is limited to telemetry it collects from its customers, meaning the number of organizations impacted could be greater than those the company observed.

Observed technique: credential stuffing against remote access portals

Researchers characterized the intrusions as a credential stuffing campaign that validated credentials against remote access portals on SonicWall VPN and firewall equipment. The attacks “were broad and opportunistic, hitting various SonicWall devices, rather than targeting specific types of organizations,” Huntress said. Because the sessions begin with authorized logins, researchers have not identified a single technical root cause in the observed data.

Post-compromise behavior and risk of pre-positioning

Huntress noted that attackers “have also refrained from initiating any post-compromise activity,” a pattern that suggests the access may be pre-positioning for future operations rather than immediate exploitation. Tigges warned that “with local network access, the sky is essentially the limit for most networks that do not have proper topology controls in place,” underscoring the risk that successful logins could become a foothold for later, more destructive activity.

Possible sources of the credential set, per Huntress

Huntress researchers listed several hypotheses for how attackers obtained the working credentials. “This could be an aggregation of stealer malware logs, previously compromised SonicWall configuration files, or historic CVE compromise that resulted in more credentials than the adversary could use at the time,” Tigges said. The company also noted the campaign’s rapid burst-and-quiet pattern matches broader campaign trends: “A rash of compromise will break out, followed by silence until the adversary rotates infrastructure.”

SonicWall response and a recent history of incidents

SonicWall had not published a security advisory about the malicious activity as of press time. A company spokesperson told CyberScoop that SonicWall is still investigating and “hopes to have more information soon.” Huntress placed the incidents against a backdrop of prior compromises and active exploitation affecting the vendor: in 2025 an undisclosed state-sponsored threat actor intruded into SonicWall’s cloud environment and stole firewall configurations of every customer. Customers have also faced “a barrage of actively exploited zero-days,” including a pair of zero-days that were exploited for three weeks before the vendor disclosed and patched the defects earlier this month.

Federal tracking also reflects recurring problems: 17 defects affecting SonicWall products have been added to CISA’s Known Exploited Vulnerabilities catalog since late 2021, Huntress noted, and CISA says ten of those are known to be used in ransomware campaigns. CISA-linked reporting cited a wave of about 40 Akira ransomware attacks between mid‑July and early August 2025 that used SonicWall-related defects.

What this means for technologists, procurement leaders, and affected enterprises

  • Technologists and security teams: Huntress reported that “edge devices are one of the most targeted interfaces, comprising over 70% of active intrusions triaged by Huntress,” and warned that organizations that lack “secure remote access solutions and networks that are resilient to edge-device compromise will likely continue to feel the burn.” Teams should treat successful authorized logins on edge devices as high-risk events.
  • Procurement and vendor-risk leaders: the history of a 2025 cloud compromise, repeatedly exploited zero-days, and multiple entries in CISA’s catalog are concrete signals to weigh when evaluating SonicWall products and vendor responsiveness to disclosures and patches.
  • Affected enterprises: because Huntress’ visibility is limited to its own customers, organizations should assume they could be among those impacted even if not yet contacted; the lack of observed post-compromise activity does not eliminate the risk that access will be used later.

The campaign’s abrupt burst, dependence on authorized logins, and the pause after Monday leave open two immediate questions: will SonicWall publish a full advisory identifying scope and mitigations, and will investigators trace the credential sources Huntress hypothesized? For now, Huntress’ telemetry paints a familiar portrait: rapid, opportunistic credential validation against remote access portals, followed by a quiet that may only signal the start of a larger operation.

Original story