SonicWall VPN accounts breached using stolen creds in widespread attacks
ID: 96fc9f92-2614-5cc5-94ee-859665057dba
STIX ID: report--96fc9f92-2614-5cc5-94ee-859665057dba
Feed Name: Bleeping Computer
Huntress observed a large-scale campaign beginning October 4 in which threat actors authenticated to and compromised over 100 SonicWall SSLVPN accounts across 16 environments using stolen valid credentials; activity included reconnaissance and attempts to access local Windows accounts and largely originated from IP 202.155.8.73. Huntress and SonicWall recommend immediate rotation of secrets and passwords, restricting WAN/remote access, enforcing MFA, revoking external API and automation secrets, and staged service re-introduction to monitor for suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
