Coordinated Reconnaissance Campaign Maps SonicWall SSL VPN Attack Surface via Commercial Proxy Infrastructure (84,142 Sessions / 4,305 IPs / 20 ASNs) — Threadlinqs Intelligence
As of 2026-02-25, Coordinated Reconnaissance Campaign Maps SonicWall SSL VPN Attack Surface via Commercial Proxy Infrastructure (84,142 Sessions / 4,305 IPs / 20 ASNs) is a high-severity reconnaissance threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1468 · Severity: HIGH · Status: ACTIVE · Category: RECONNAISSANCE
GreyNoise observed a coordinated four-burst reconnaissance campaign between February 22-25, 2026, generating 84,142 scanning sessions from 4,305 unique IPs across 20 ASNs against SonicWall SonicOS
Between February 22 and 25, 2026, GreyNoise detected a large-scale, structured reconnaissance campaign against SonicWall SonicOS firewall infrastructure. The campaign comprised 84,142 scanning sessions from 4,305 unique source IPs distributed across 20 distinct autonomous systems, arriving in four discrete bursts separated by an approximately 31-hour operational pause on February 23 -- a pattern consistent with a centrally coordinated tasking cadence rather than opportunistic independent scanning.
The overwhelming majority of traffic (91.8%, 77,253 sessions) targeted the undocumented management API endpoint /api/sonicos/is-sslvpn-enabled, a lightweight pre-authentication check used to determine whether a given device has SSL VPN services active. This is a reconnaissance-only probe: it does not exploit a vulnerability, but functions as an attack-surface fingerprinting step that lets an operator triage tens of thousands of candidate targets down to a list of devices with SSL VPN actually exposed, before committing scarce credential-attack or exploit resources. A secondary 7.9% of sessions (6,629) tested the NetExtender VPN login endpoint directly, indicating a subset of infrastructure was already pivoting from fingerprinting to active credential testing.
Four distinct infrastructure clusters were identified. The largest (32% of traffic) routed through the ByteZero commercial residential/datacenter proxy service (bytezero[.]io), egressing via 4,102 exit IPs within 154.208.64.0/21, transiting AS3257 (GTT Communications) with Canadian hosting, and deliberately throttled to an average of 6.6 sessions per IP across two surgical 7-and-9-hour windows to evade rate-limiting defenses -- textbook proxy-obfuscated mass reconnaissance tradecraft. A second cluster (28%) consisted of just 6 IPs inside AS211736 (Ukrainian-registered ASN, Amsterdam-hosted) sharing identical HASSH SSH fingerprints, indicating a common provisioning template, and cross-targeting both SonicWall and Cisco ASA devices in the same sessions -- evidence of a multi-vendor VPN-hunting toolkit. A third cluster (22%) was a single high-volume host, 130.12.180.29, registered to AS202412 (Omegatech, Seychelles), which alone generated 18,763 sessions against 20+ destination ports while rotating 26 distinct browser user-agent strings to defeat naive UA-based detection. A fourth, lower-volume but persistent cluster (8%, 156 IPs across four ranges) ran a continuous NetExtender login-endpoint baseline that did not pause during the February 23 lull affecting the other clusters, suggesting an independently operated, always-on credential-testing capability layered on top of the coordinated fingerprinting sweep.
A technical fingerprint anomaly further corroborates automated tooling: 69.5% of all sessions (58,510) presented a "Chrome 119 on Linux" User-Agent string while speaking HTTP/1.0, a protocol/UA mismatch impossible for any genuine modern browser and characteristic of a purpose-built scanning framework.
Actual exploitation attempts against known SonicWall CVEs were negligible in volume (single digits to low tens of sessions per CVE) relative to the fingerprinting traffic, confirming the campaign's primary purpose was attack-surface mapping rather than direct compromise. However, the CVEs referenced in the campaign are severe and under confirmed active exploitation by ransomware operators: CVE-2024-53704 (SSL VPN session-hijacking authentication bypass, CISA KEV, PoCs public, MFA-bypassing), CVE-2024-40766 (SonicOS improper access control, CISA KEV, exploited by Akira and Fog ransomware affiliates since September 2024, with encryption-to-compromise dwell times as short as 55 minutes), CVE-2021-20028 (SMA100 unauthenticated SQL injection, CISA KEV, end-of-life appliances, ransomware-leveraged), and CVE-2024-38475 (Apache mod_rewrite improper output escaping affecting SMA 100 series, CISA KEV, chainable with CVE-2023-44221 for full system compromise via credential/SSH-key exfilt
Weaknesses (CWE)
CWE-287, CWE-284, CWE-89, CWE-116
Target sectors: all sectors with internet-exposed sonicwall ssl vpn infrastructure, small and mid-sized enterprise, managed service providers
Target regions: Global
Detections & IOCs
As of 2026-07-21, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RECONNAISSANCE, HIGH, threat intelligence, cybersecurity, CVE-2024-53704, CVE-2024-40766, CVE-2021-20028, CVE-2019-7481, CVE-2022-22274, CVE-2023-0656, CVE-2024-38475, CVE-2023-44221, T1595.001, T1595.002, T1590.005, T1596, T1583.008, T1588.002, T1587.001, T1190, T1078.004, T1133