Coordinated Reconnaissance Campaign Maps SonicWall SSL VPN Attack Surface via Commercial Proxy Infrastructure (84,142 Sessions / 4,305 IPs / 20 ASNs)

Coordinated Reconnaissance Campaign Maps SonicWall SSL VPN (TL-2026-1468), also tracked as SonicWall SSL VPN Reconnaissance Campaign Feb 2026, is a high-severity reconnaissance threat, first published 2026-02-25. It has no confirmed attribution, affects SonicWall SonicOS (physical and virtual firewalls, Gen5/Gen6/Gen7), references 8 CVEs (CVE-2024-53704, CVE-2024-40766, CVE-2021-20028), maps to 24 MITRE ATT&CK techniques (T1016, T1021, T1046), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-1468

Threat ID
TL-2026-1468
Also known as
SonicWall SSL VPN Reconnaissance Campaign Feb 2026, ByteZero SonicWall Scan Wave
Severity
HIGH
Status
ACTIVE
Category
RECONNAISSANCE
First published
2026-02-25
Last reviewed
2026-02-25
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
all sectors with internet-exposed sonicwall ssl vpn infrastructure, small and mid-sized enterprise, managed service providers
Target regions
Global
Detection rules
9
Indicators of compromise
20

Malware and tooling in Coordinated Reconnaissance Campaign Maps SonicWall SSL VPN

Malware and tooling: Akira, fog

GreyNoise observed a coordinated four-burst reconnaissance campaign between February 22-25, 2026, generating 84,142 scanning sessions from 4,305 unique IPs across 20 ASNs against SonicWall SonicOS infrastructure. 91.8% of sessions probed the /api/sonicos/is-sslvpn-enabled endpoint to fingerprint SSL VPN status ahead of likely follow-on credential attacks and Akira/Fog ransomware exploitation chains against KEV-listed SonicWall CVEs.

How Coordinated Reconnaissance Campaign Maps SonicWall SSL VPN works

Between February 22 and 25, 2026, GreyNoise detected a large-scale, structured reconnaissance campaign against SonicWall SonicOS firewall infrastructure. The campaign comprised 84,142 scanning sessions from 4,305 unique source IPs distributed across 20 distinct autonomous systems, arriving in four discrete bursts separated by an approximately 31-hour operational pause on February 23 -- a pattern consistent with a centrally coordinated tasking cadence rather than opportunistic independent scanning.

The overwhelming majority of traffic (91.8%, 77,253 sessions) targeted the undocumented management API endpoint /api/sonicos/is-sslvpn-enabled, a lightweight pre-authentication check used to determine whether a given device has SSL VPN services active. This is a reconnaissance-only probe: it does not exploit a vulnerability, but functions as an attack-surface fingerprinting step that lets an operator triage tens of thousands of candidate targets down to a list of devices with SSL VPN actually exposed, before committing scarce credential-attack or exploit resources. A secondary 7.9% of sessions (6,629) tested the NetExtender VPN login endpoint directly, indicating a subset of infrastructure was already pivoting from fingerprinting to active credential testing.

Four distinct infrastructure clusters were identified. The largest (32% of traffic) routed through the ByteZero commercial residential/datacenter proxy service (bytezero[.]io), egressing via 4,102 exit IPs within 154.208.64.0/21, transiting AS3257 (GTT Communications) with Canadian hosting, and deliberately throttled to an average of 6.6 sessions per IP across two surgical 7-and-9-hour windows to evade rate-limiting defenses -- textbook proxy-obfuscated mass reconnaissance tradecraft. A second cluster (28%) consisted of just 6 IPs inside AS211736 (Ukrainian-registered ASN, Amsterdam-hosted) sharing identical HASSH SSH fingerprints, indicating a common provisioning template, and cross-targeting both SonicWall and Cisco ASA devices in the same sessions -- evidence of a multi-vendor VPN-hunting toolkit. A third cluster (22%) was a single high-volume host, 130.12.180.29, registered to AS202412 (Omegatech, Seychelles), which alone generated 18,763 sessions against 20+ destination ports while rotating 26 distinct browser user-agent strings to defeat naive UA-based detection. A fourth, lower-volume but persistent cluster (8%, 156 IPs across four ranges) ran a continuous NetExtender login-endpoint baseline that did not pause during the February 23 lull affecting the other clusters, suggesting an independently operated, always-on credential-testing capability layered on top of the coordinated fingerprinting sweep.

A technical fingerprint anomaly further corroborates automated tooling: 69.5% of all sessions (58,510) presented a "Chrome 119 on Linux" User-Agent string while speaking HTTP/1.0, a protocol/UA mismatch impossible for any genuine modern browser and characteristic of a purpose-built scanning framework.

Actual exploitation attempts against known SonicWall CVEs were negligible in volume (single digits to low tens of sessions per CVE) relative to the fingerprinting traffic, confirming the campaign's primary purpose was attack-surface mapping rather than direct compromise. However, the CVEs referenced in the campaign are severe and under confirmed active exploitation by ransomware operators: CVE-2024-53704 (SSL VPN session-hijacking authentication bypass, CISA KEV, PoCs public, MFA-bypassing), CVE-2024-40766 (SonicOS improper access control, CISA KEV, exploited by Akira and Fog ransomware affiliates since September 2024, with encryption-to-compromise dwell times as short as 55 minutes), CVE-2021-20028 (SMA100 unauthenticated SQL injection, CISA KEV, end-of-life appliances, ransomware-leveraged), and CVE-2024-38475 (Apache mod_rewrite improper output escaping affecting SMA 100 series, CISA KEV, chainable with CVE-2023-44221 for full system compromise via credential/SSH-key exfiltration).

Given that 430,000+ SonicWall firewalls are publicly exposed and 25,000+ SSL VPN-enabled devices remain vulnerable to these critical flaws (with roughly 20,000 running unsupported firmware), this reconnaissance sweep represents a high-confidence precursor indicator: historical precedent (a 9-million-session Palo Alto/SonicWall reconnaissance campaign in December 2025) was followed by confirmed ransomware intrusion waves. Akira ransomware affiliates are attributed to roughly 75% of documented SonicWall VPN intrusions (250+ organizations, ~$244M in proceeds), with Fog ransomware responsible for the remaining ~25%, and both groups have demonstrated encryption within 4 hours of initial SSL VPN access.

MITRE ATT&CK techniques used in TL-2026-1468

Discovery

T1016 System Network Configuration Discovery; T1046 Network Service Discovery; T1518 Software Discovery

Lateral Movement

T1021 Remote Services

Initial Access

T1078.004 Cloud Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Command and Control

T1090.002 External Proxy; T1102 Web Service

command-and-control

T1090.003 Multi-hop Proxy

Credential Access

T1110.001 Password Guessing; T1110.004 Credential Stuffing; T1111 Multi-Factor Authentication Interception

Impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery

Resource Development

T1583.008 Malvertising; T1587.001 Malware; T1588.002 Tool

Reconnaissance

T1590.005 IP Addresses; T1595.001 Scanning IP Blocks; T1595.002 Vulnerability Scanning; T1596 Search Open Technical Databases

defense-impairment

T1601 Modify System Image; T1686 Disable or Modify System Firewall

Affected products and versions in Coordinated Reconnaissance Campaign Maps SonicWall SSL VPN

  • SonicWall — SonicOS (physical and virtual firewalls, Gen5/Gen6/Gen7)
    Vulnerable versions: 7.1.x (7.1.1-7058 and older); 7.1.2-7019 and older; 8.0.0-8035 and older; 7.0.1-5035 and older (Gen7); Gen5/Gen6 all supported versions prior to patch
    Fixed in: 7.1.1-7058 or later; 7.1.2-7019 or later; 8.0.0-8035 or later
  • SonicWall — Secure Mobile Access (SMA) 100 series
    Vulnerable versions: earlier than 10.2.1.13-72sv
    Fixed in: 10.2.1.13-72sv or later
  • SonicWall — Secure Remote Access (SRA) appliances (end-of-life)
    Vulnerable versions: all 8.x firmware; 9.0.0.9-26sv and earlier
    Fixed in: none -- end-of-life, disconnect required
  • Cisco — Cisco ASA (secondary co-target of Netherlands cluster AS211736)
    Vulnerable versions: not specified in source
    Fixed in: not specified in source

Remediation for Coordinated Reconnaissance Campaign Maps SonicWall SSL VPN

Patches

  • SonicOS 7.1.1-7058+ / 7.1.2-7019+ / 8.0.0-8035+ for CVE-2024-53704 (released 2025-01-07)
  • SonicOS patch for CVE-2024-40766 (Gen5/Gen6/Gen7 7.0.1-5035 and earlier affected)
  • SMA 100 series firmware 10.2.1.13-72sv+ for CVE-2024-38475 / CVE-2023-44221

Immediate actions

  • Patch CVE-2024-53704 (SonicOS SSL VPN session hijacking auth bypass) to versions 7.1.1-7058 or later / 7.1.2-7019 or later / 8.0.0-8035 or later
  • Patch CVE-2024-40766 (SonicOS improper access control) and verify firewall management access rules were re-applied post-patch
  • Patch CVE-2024-38475 and CVE-2023-44221 on SMA 100 series appliances (upgrade to 10.2.1.13-72sv or later)
  • Decommission or disconnect end-of-life SonicWall SRA appliances vulnerable to CVE-2021-20028
  • Enforce MFA on all SSL VPN accounts
  • Restrict SonicOS management interface (HTTPS/SSH) access to trusted management IP ranges only
  • Force-reset all local SonicWall account passwords, especially on devices with any history of internet-facing SSL VPN exposure
  • Block known reconnaissance/proxy infrastructure at perimeter: 154.208.64.0/21, 185.156.73.0/24, 88.210.63.0/24, 185.177.72.0/24, 204.76.203.0/24, and source IP 130.12.180.29

Workarounds

  • Disable SSL VPN service on internet-facing SonicWall interfaces where not operationally required
  • Restrict NetExtender login endpoint exposure to VPN gateway IPs only
  • Retire end-of-life SRA appliances rather than attempting to patch (CISA KEV required action for CVE-2021-20028)

Longer-term hardening

  • Deploy WAF/API-gateway rate-limiting and anomaly detection in front of SonicOS management APIs, specifically /api/sonicos/is-sslvpn-enabled
  • Implement geofencing and ASN-based reputation filtering on SSL VPN and management endpoints
  • Deploy EDR with behavioral detection tuned to Akira/Fog post-VPN-access lateral movement and rapid-encryption TTPs
  • Establish a SonicWall firmware patch SLA given documented sub-4-hour ransomware time-to-encrypt after initial VPN access
  • Monitor for HTTP/1.0 + modern-browser-UA protocol mismatches as a scanning-tool detection signature

CVEs associated with Coordinated Reconnaissance Campaign Maps SonicWall SSL VPN

CVE-2024-53704, CVE-2024-40766, CVE-2021-20028, CVE-2019-7481, CVE-2022-22274, CVE-2023-0656, CVE-2024-38475, CVE-2023-44221

Weaknesses (CWE) in Coordinated Reconnaissance Campaign Maps SonicWall SSL VPN

CWE-287, CWE-284, CWE-89, CWE-116

Timeline of Coordinated Reconnaissance Campaign Maps SonicWall SSL VPN

  • CVE-2021-20028 SQL injection in SonicWall SMA100/SRA appliances disclosed and added to CISA KEV as an end-of-life, ransomware-leveraged flaw.
  • CVE-2024-40766 (SonicOS improper access control) publicly disclosed by Qualys ThreatPROTECT.
  • CVE-2024-40766 added to CISA Known Exploited Vulnerabilities catalog; Arctic Wolf reports Akira affiliates already compromising SSLVPN accounts on vulnerable devices.
  • SonicWall releases SonicOS patches for CVE-2024-53704 (SSL VPN session hijacking authentication bypass).
  • Approximately 4,500 internet-facing SonicWall SSL VPN servers remain unpatched against CVE-2024-53704.
  • CVE-2024-38475 (Apache mod_rewrite output-escaping flaw affecting SonicWall SMA 100) added to CISA KEV alongside CVE-2023-44221.
  • ByteZero proxy management platform (bytezero[.]io) goes offline, though its previously provisioned exit-node infrastructure (154.208.64.0/21) remains active and is later reused in the February 2026 campaign.
  • A 9-million-session reconnaissance campaign targets Palo Alto and SonicWall infrastructure, serving as a direct predecessor pattern to the February 2026 campaign.
  • Coordinated reconnaissance campaign against SonicWall SonicOS begins; first of four scanning bursts detected by GreyNoise.
  • Approximately 31-hour operational pause observed across most clusters, except the persistent 156-IP NetExtender-testing cluster which continues uninterrupted.
  • Scanning resumes with additional bursts; ByteZero proxy cluster delivers 27,119 sessions across two surgical windows of 7 and 9 hours.
  • GreyNoise publishes "Active Reconnaissance Campaign Targets SonicWall Firewalls Through Commercial Proxy Infrastructure" blog with full IOC list and defensive recommendations.
  • Campaign activity concludes; GreyNoise totals 84,142 sessions from 4,305 unique IPs across 20 ASNs and publishes analysis.

Sources cited for Coordinated Reconnaissance Campaign Maps SonicWall SSL VPN

Threats related to Coordinated Reconnaissance Campaign Maps SonicWall SSL VPN

Detection coverage for TL-2026-1468

As of 2026-02-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1468 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats