CTIPilot

SonicWall SonicOS

product · product:sonicwall-sonicos

Coverage timeline
1
first 2026-07-30 → last 2026-07-30
Peak priority
high
1 high
Sources cited
2
2 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
2
pinned v19.2 · see below

Hunting pivots

Releases covered
SonicWall SonicOS
ATT&CK techniques

ATT&CK techniques

2 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-07-30/huntress-sonicwall-credential-stuffing-92-accounts-30-orgs · ATT&CK page ↗

Persistence TA0003

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-07-30/huntress-sonicwall-credential-stuffing-92-accounts-30-orgs · ATT&CK page ↗

Credential Access TA0006

T1110.004Brute Force: Credential Stuffing×1

Adversaries may use credentials obtained from breach dumps of unrelated accounts to gain access to target accounts through credential overlap. Occasionally, large numbers of username and password pairs are dumped online when a website or service is compromised and the user account credentials accessed. The information may be useful to an adversary attempting to compromise accounts by taking advantage of the tendency for users to use the same passwords across personal and business accounts.

Evidence: 2026-07-30/huntress-sonicwall-credential-stuffing-92-accounts-30-orgs · ATT&CK page ↗

Story timeline

  1. 2026-07-30Huntress: a three-day credential-stuffing run logged into 92 SonicWall VPN and firewall accounts across 30 organisations, with no follow-on activity observed
    active-threatsValid credentials, not a CVE, opened 92 SonicWall remote-access accounts in 41 hours, and nobody came back to use them

Where this entity is cited

  • active-threats1

Source distribution

  • cyberscoop.com1 (50%)
  • huntress.com1 (50%)

explore in graph

Entries about SonicWall SonicOS (1)

2026-07-30 · view entry permalink →

HIGHNATOB2

Huntress: a three-day credential-stuffing run logged into 92 SonicWall VPN and firewall accounts across 30 organisations, with no follow-on activity observed

Huntress detected what it describes as an out-of-the-ordinary spike in successful SonicWall VPN and firewall logins starting on 2026-07-25 and continuing over the following two days (Huntress, 2026-07-28). The scale is stated day by day: "July 25: 26 unique user accounts compromised across 6 distinct organizations. July 26: 34 unique user accounts compromised across 16 distinct organizations. July 27: 32 unique user accounts compromised across 8 distinct organizations" (Huntress, 2026-07-28), 92 accounts and 30 organisations in total, which CyberScoop frames as 92 unique accounts compromised over 41 hours (CyberScoop, 2026-07-29).

The mechanism matters more than the numbers, because there is no vulnerability in it. These were successful authentications using credentials that already worked, not exploitation of a flaw in SonicOS, which means no patch addresses the exposure and no version check tells an operator whether they were affected. The traffic was also not distributed: Huntress states it "identified five primary malicious IP addresses driving this attack, all of which are registered to DigitalOcean, LLC" (Huntress, 2026-07-28), a handful of commodity cloud hosts rather than a residential-proxy pool or a botnet, which is the detail that makes retrospective log review practical.

The most operationally significant finding is what did not happen. Huntress states plainly: "We did not observe any post-compromise hands-on-keyboard activity from these attacks" (Huntress, 2026-07-28). An attacker validated working access to 92 accounts and then stopped. CyberScoop reads that pattern as intrusions that "could be pre-positioning for future attacks" (CyberScoop, 2026-07-29), that inference is CyberScoop's own, not something Huntress asserts, and the distinction is worth preserving because the two readings imply different urgency. What is not in dispute is the consequence of an unused valid credential: it stays valid. A Huntress analyst put the downstream risk as "with local network access, the sky is essentially the limit for most networks that do not have proper topology controls in place" (CyberScoop, 2026-07-29).

Where the credentials came from is unresolved and should be treated that way. Huntress's principal tactical response analyst offered candidate explanations; "this could be an aggregation of stealer malware logs, previously compromised SonicWall configuration files, or historic CVE compromise that resulted in more credentials than the adversary could use at the time" (CyberScoop, 2026-07-29), but that is explicitly hedged speculation, not a determination. SonicWall itself has not weighed in: "SonicWall hasn't released a security advisory about the malicious activity as of press time. A spokesperson told CyberScoop the company is still investigating and hopes to have more information soon" (CyberScoop, 2026-07-29).

Detection here is authentication-log work, not network-anomaly work. The telemetry class is remote-access authentication events with source-address attribution: successful logins to a VPN or firewall management portal whose source falls in cloud-hosting address space rather than the residential and mobile ranges legitimate remote users come from, clustered tightly in time across multiple accounts. Because the logins succeeded on the first or an early attempt, the classic brute-force signal (a burst of failures preceding a success) may be weak or absent, so keying detection on failure volume will miss this shape entirely. Hardening levers are credential-side rather than patch-side: rotate what may be burned, and constrain where remote-access authentication is accepted from.

Triage: a genuine remote worker authenticating to a SonicWall VPN arrives from a consumer ISP or mobile carrier range, at a plausible hour, usually to the same account over time. The discriminators for this activity are the source class and the fan-out: authentication from datacentre address space, several distinct accounts inside one organisation succeeding within a short window, and no subsequent session activity of the kind a real user generates after connecting. Any one of those alone is weak (a travelling user behind a VPN service can look like the first) but a datacentre-sourced success followed by silence is the shape to pull.

We did not observe any post-compromise hands-on-keyboard activity from these attacks.

July 25: 26 unique user accounts compromised across 6 distinct organizations. July 26: 34 unique user accounts compromised across 16 distinct organizations. July 27: 32 unique user accounts compromised across 8 distinct organizations.

We have identified five primary malicious IP addresses driving this attack, all of which are registered to DigitalOcean, LLC

Huntress 2026-07-28

SonicWall hasn't released a security advisory about the malicious activity as of press time. A spokesperson told CyberScoop the company is still investigating and hopes to have more information soon.

CyberScoop 2026-07-29
threat30 Jul 04:58Zmulti-sourceOpen finding ↗
Sources: Huntress · CyberScoop