Hackers Attacking SonicWall Firewalls from 4,000+ unique IP Addresses to Exploit Vulnerabilities
A recent large-scale reconnaissance campaign has targeted SonicWall firewalls, utilizing over 4,000 unique IP addresses to identify vulnerable devices before potential exploitation. Between February 22 and February 25, 2026, threat actors initiated…
A recent large-scale reconnaissance campaign has targeted SonicWall firewalls, utilizing over 4,000 unique IP addresses to identify vulnerable devices before potential exploitation. Between February 22 and February 25, 2026, threat actors initiated 84,142 scanning sessions on SonicWall SonicOS infrastructure, originating from 4,305 IP addresses across 20 autonomous systems.
The campaign's focus was on the SonicOS REST API endpoint used to check SSL VPN status. This endpoint was accessed in 92% of recorded sessions, indicating an effort to construct a target list rather than immediate exploitation. The organized activity suggests a major exploitation wave may be forthcoming, posing significant risks to organizations globally.
GreyNoise researchers tracked this campaign, noting its operation through three distinct infrastructure clusters. The campaign mirrors earlier activity from December 2025, where attackers conducted nine million scanning sessions against Palo Alto and SonicWall infrastructure using over 7,000 IP addresses.
This campaign exposes a significant attack surface, with more than 430,000 SonicWall firewalls accessible on the public internet. Of these, over 25,000 SSL VPN devices have unpatched critical vulnerabilities, and approximately 20,000 are running unsupported firmware. Since March 2023, ransomware groups like Akira have exploited SonicWall VPN access, affecting at least 250 organizations.
The campaign's focus was on the SonicOS REST API endpoint used to check SSL VPN status.
Five of the seven SonicWall CVEs relevant to this situation are listed in CISA's Known Exploited Vulnerabilities catalog, with four linked to ransomware use. Additionally, scanning by six IPs based in Amsterdam indicates a broader mapping operation targeting both SonicWall and Cisco ASA devices.
A notable aspect of this campaign was the use of a commercial proxy service for scanning activities. Approximately 32% of the campaign's volume, or about 27,119 sessions, originated from 4,102 rotating exit IP addresses routed through Canadian-hosted proxy infrastructure. This service, which claims access to over 100 million IP addresses across 150 countries, served as an anonymization layer to obscure the true origin of the scanning traffic.
The proxy usage was designed to avoid detection, with sessions spread across exit IPs to remain below thresholds for rate-limiting or blocking. The management platform for this proxy service has been offline since December 2025, leaving exit nodes unmanaged for months before the campaign began.
Organizations using SonicWall devices should immediately address vulnerabilities by patching CVE-2024-53704, enforcing multi-factor authentication for SSL VPN users, and restricting management interface access to trusted IP ranges. Additionally, it is recommended to reset local user passwords, especially those from older firmware, monitor for HTTP/1.0 requests with modern browser user agents, and decommission end-of-life SRA appliances without patches for CVE-2021-20028 and CVE-2019-7481.
Based on reporting by Cyber Security News.
