logo

Massive SonicWall Reconnaissance Campaign Signals Imminent Ransomware Strikes

ID: 1b58fdb8-e068-5d70-b56d-33f53c9ba658

STIX ID: report--1b58fdb8-e068-5d70-b56d-33f53c9ba658

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-02-28

Date Updated: 2026-04-23

Author: Ddos

...
...

Between February 22–25, 2026, GreyNoise observed a highly coordinated reconnaissance campaign targeting SonicWall SonicOS devices: roughly 84,000 scanning sessions from over 4,300 unique IPs repeatedly queried SSL VPN-related endpoints to determine if VPN access was enabled. Attackers used commercial proxy services and rapid IP rotation to avoid detection; the activity is assessed as preparatory mapping for credential-stuffing/brute-force attacks and is linked in the report to ransomware groups (Akira, Fog). The report lists specific request paths to search for in logs, recommends immediate checks of active VPN sessions, firmware patching (citing CVE-2024-53704), enforcing MFA, and isolating legacy SRA appliances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.