Security firm Huntress has identified an active campaign targeting SonicWall customers, with attackers compromising 92 unique user accounts across 30 organizations in just two days. Unlike typical zero-day exploits, these attackers used legitimate credentials — suggesting they obtained them through phishing, credential stuffing, or insider compromise before pivoting into customer networks.
The attack pattern is notable because it bypasses many traditional detection mechanisms. By using valid credentials on real devices, the attackers avoided the suspicious behavior that would trigger alerts on zero-day exploits. Huntress’s analysis shows the attackers moved laterally across multiple customer environments, indicating a coordinated operation rather than opportunistic scanning.
Why This Matters: This campaign highlights a growing shift in attacker tactics — from exploiting software vulnerabilities to exploiting human and operational weaknesses. When attackers use legitimate credentials, traditional perimeter defenses become much less effective. Organizations running SonicWall devices (and VPN/firewall gear more broadly) should enforce multi-factor authentication on admin accounts, review recent admin logins, and monitor for unusual lateral movement patterns.
Source: CyberScoop
