SonicWall Firewall Backup Breach Enables Targeted SSLVPN Intrusions

A coordinated wave of cyber intrusions has put organizations worldwide on high alert after Huntress security researchers discovered a rapid-fire attack campaign targeting SonicWall SSL VPN devices.

More than 100 accounts have been compromised since early October, underscoring the severity and scale of the threat.

Evidence suggests adversaries are leveraging valid, exposed credentials rather than resorting to brute-force, raising alarm about the true depth of the breach.

Rapid Intrusions Signal Sophisticated Threat Operation

Security analysts detected the first signs of the campaign on October 4, observing a series of closely clustered authentication attempts spanning 16 customer environments.

Most of the malicious activity spiked over two days, indicating a premeditated effort. Notably, every attack originated from the single IP address 202.155.8.73, pointing to a centralized command and control infrastructure.

Attackers typically establish only brief connections before disconnecting, an indicator of reconnaissance or credential validation.

However, some incursions escalated rapidly, with threat actors initiating network scans and attempting to access local Windows accounts on compromised sites.

The coordinated and surgical nature of these attacks demonstrates a high level of operational proficiency and planning.

The surge in attacks aligns with SonicWall’s recent advisory disclosing that unauthorized parties had accessed firewall configuration backup files belonging to all customers utilizing the company’s cloud backup service via the MySonicWall platform.

These backups, although encrypted, contain sensitive configuration data and credentials that could dramatically lower the barriers to targeted attacks.

This revelation marks a significant shift from SonicWall’s initial September breach disclosure, which claimed the scope was limited to under 5% of firewall installations.

Though the vendor states there’s no confirmed link between the backup leak and ongoing SSL VPN compromises, the stark timing and methodical approach of the attackers suggest otherwise.

Security experts warn that such broad access to configuration files could enable attackers to orchestrate widespread exploitation campaigns with alarming precision.

With the potential for catastrophic data loss and further compromise, SonicWall is urgently advising customers to check their device status through MySonicWall.com and take comprehensive protection steps.

Immediate actions include restricting WAN management access, disabling all HTTP/S, SSH, and SSL VPN services until every credential is reset.

All local administrator accounts, VPN pre-shared keys, LDAP, SNMP, and any external API or dynamic DNS secrets must be changed without delay.

Organizations are also instructed to enable enhanced logging to detect recent configuration changes and suspicious login attempts.

After credential resets, services should be restored gradually, with robust continuous monitoring implemented.

Enforcing multi-factor authentication for all administrative and remote users and strictly limiting management privileges are now mandatory defensive measures.

As Huntress continues collaborating with partners on remediation, organizations are urged to act immediately.

The scale and effectiveness of this campaign illustrate the critical importance of a rapid and comprehensive response to halt further intrusions and protect sensitive networks worldwide.

Cyber Awareness Month Offer: Upskill With 100+ Premium Cybersecurity Courses From EHA's Diamond Membership: Join Today

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories