An extensive cyber reconnaissance campaign has targeted SonicWall firewalls around the world, with attackers leveraging more than 4,000 unique IP addresses to map vulnerable devices before attempting to exploit them. The campaign was recorded between February 22 and 25, 2026, generating 84,142 scanning sessions from 4,305 distinct IP addresses across 20 autonomous systems (suggesting a high level of coordination and preparation for a potential wave of attacks).

Targeting the SSL VPN: Preliminary Scanning before Ransomware Attacks
The primary focus of the campaign was the SonicOS REST API endpoint that checks whether the SSL VPN is active (a prerequisite for attackers to more aggressively direct credential tests to confirmed targets). 92% of all sessions targeted this path, demonstrating that the primary intent of the attackers was to systematically record potential targets, rather than directly exploit them.
See also: Marquis sues SonicWall for breach that led to ransomware
SonicWall's SSL VPN has been a popular entry point for ransomware groups for years , as access to it allows them to compromise critical corporate networks.
Coordination and Scale of the Campaign
GreyNoise researchers closely monitored the campaign and identified three functionally distinct infrastructure clusters operating in concert throughout the four-day period. The activity is similar to a previous campaign in December 2025, which saw nine million scanning sessions against SonicWall and Palo Alto Networks VPN infrastructure .
Exposed Surface and Risk for Organizations
More than 430,000 SonicWall firewalls are accessible on the public internet, with over 25,000 SSL VPN appliances carrying critical vulnerabilities and approximately 20,000 running unsupported firmware.

The group Akira ransomware has exploited this surface to compromise over 250 organizations since March 2023, generating an estimated $244 million in ransom. Also, the Fog ransomware can fully encrypt networks in less than four hours.
See also: SonicWall patches zero-day vulnerability in SMA 100 series devices
Five of the seven SonicWall CVEs related to this threat are on CISA's list of known exploitable vulnerabilities.
Complexity and Use of Proxy Infrastructures
One of the most concerning features of the campaign was the use of a commercial proxy to cover approximately 32% of the total scan volume. Approximately 27,119 sessions originated from 4,102 rotating exit IP addresses via a proxy infrastructure in Canada, creating an anonymization layer and making traditional block lists less effective.
The management of the proxy platform was inactive for three months before the campaign, allowing uncontrolled scanning with statistical characteristics that stand out from legitimate Chrome connections.

Recommendations for Organizations
Organizations using SonicWall appliances should immediately apply updates for CVE-2024-53704 (CVSS 9.8, CISA KEV), enable multi-factor authentication for all SSL VPN users, restrict management access to trusted IP ranges , reset local passwords , and deactivate end-of-life SRA appliances that do not support critical updates. Additionally, monitoring HTTP/1.0 requests with modern browser user agents can help detect scanning activity.
See also: SonicWall SMA1000 vulnerability allows remote access
The scale and complexity of this campaign underscores the need for continued vigilance and strengthening of VPN infrastructure security as ransomware groups become increasingly effective at exploiting credentials and critical vulnerabilities. Prevention, awareness, and monitoring are now critical tools to protect organizations from potentially devastating attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
