Huntress has detected widespread compromise of SonicWall SSLVPN devices across 16 customer environments, affecting over 100 accounts. Threat actors are authenticating rapidly using what appear to be valid credentials rather than brute force, with activity originating from a single IP address (202.155.8[.]73). Some intrusions led to post-exploitation activity including network scanning and attempts to access local Windows accounts. SonicWall separately disclosed that its MySonicWall cloud backup platform was breached, exposing encrypted firewall configuration files for all customers who used cloud backup — though a direct link to the SSLVPN compromises has not been confirmed. Recommended mitigations include restricting WAN management, disabling remote access services until credentials are reset, rotating all secrets and API keys, enforcing MFA, and increasing logging for forensic investigation.

3m read timeFrom huntress.com
Post cover image
Table of contents
SonicWall advisoryNext steps
1 Impression