Skip to main content

Open directory exposes a full SonicWall SMA1000 credential-theft campaign: 250 targets, 5 domains fully replicated

0
Medium
Published: 09/10/2026 (09/10/2026, 17:51:25 UTC)
Source: Reddit ThreatIntel

Description

A threat actor exploited CVE-2026-15409, a critical unauthenticated server-side request forgery vulnerability in SonicWall SMA1000 appliances, to gain command execution and steal credentials. The attacker used a modified public proof-of-concept exploit to access internal Erlang services on the appliance, enabling remote code execution. This allowed extraction of LDAP configurations, Active Directory credentials, and deployment of tools to dump secrets from internal Windows systems. The campaign targeted at least 250 SonicWall SMA1000 devices across multiple countries and sectors, with confirmed credential theft in France, India, Italy, and the US. The attack leveraged compromised appliances as pivots into internal networks, exposing sensitive Active Directory data and enabling DCSync attacks against domain controllers. The targeting was opportunistic and technology-driven rather than sector-specific. The campaign was uncovered through an open directory left exposed by the attacker, providing a comprehensive view of the operation.

Reddit Discussion

r/threatintel·posted by u/Straight-Practice-99
00

The operator left their whole toolkit in an open directory, captured the same day it was still in use, which gave a fairly complete view of the campaign instead of a single victim.

Scope from the recovered files: 250 exploitable targets, LDAP config recovered from 168, 534 config records across 160 AD domains and 255 internal LDAP endpoints. SAM and LSA secrets from at least 9 domains, full DCSync against 7 DCs in 5 environments. Confirmed credential theft in France, India, Italy and the US, with the wider target list spanning the UK, Canada, Germany, Sweden, Poland, Hungary, South Korea and Hong Kong. Targeting looks opportunistic and technology-driven rather than sector-specific.

On attribution, several scripts carried extensive Chinese comments and logging, but that alone is not enough to attribute, so it is left open. One publicly reported victim, a UK council, lines up with the telemetry at moderate confidence. Full analysis and IOCs in the post.

https://hunt.io/blog/sonicwall-sma1000-uk-council-attack

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 17:52:25 UTC

Technical Analysis

The campaign exploited CVE-2026-15409, a critical SSRF vulnerability in SonicWall SMA1000 WorkPlace interface, disclosed on July 14, 2026, with a CVSS score of 10. The attacker used a modified Rapid7 proof-of-concept exploit to tunnel Erlang distribution protocol commands through a WebSocket proxy, authenticating with a hard-coded Erlang cookie to achieve OS command execution on the appliance. Post-exploitation scripts extracted LDAP configuration files and decrypted stored passwords, enabling access to internal Active Directory environments. A standalone Linux build of Impacket's secretsdump was deployed on compromised appliances to remotely extract SAM and LSA secrets from Windows systems. The attacker successfully performed DCSync attacks against seven domain controllers across five environments, exposing thousands of AD account records. The campaign affected at least 250 targets, spanning 160 AD domains and 255 internal LDAP endpoints, with victims in multiple countries including confirmed impacts in France, India, Italy, and the US. Attribution remains open, though some scripts contained Chinese comments. The campaign was identified by Hunt.io researchers from an open directory exposed by the attacker, providing detailed telemetry and indicators of compromise.

Potential Impact

The exploitation of CVE-2026-15409 allowed unauthenticated remote code execution on SonicWall SMA1000 appliances, leading to full credential theft campaigns against internal Active Directory environments. The attacker gained access to LDAP configurations and decrypted stored passwords, enabling lateral movement and extensive credential harvesting. The deployment of Impacket's secretsdump on appliances facilitated extraction of SAM and LSA secrets from Windows systems, and successful DCSync attacks against domain controllers exposed thousands of AD account records. This compromises the confidentiality and integrity of affected networks, potentially allowing persistent unauthorized access and further attacks. The campaign affected multiple countries and sectors, indicating a broad opportunistic threat.

Defensive Guidance

SonicWall disclosed CVE-2026-15409 on July 14, 2026, assigning it a CVSS score of 10 and reporting active exploitation. Organizations using SonicWall SMA1000 appliances should apply the official patches provided by SonicWall immediately. Hunt.io notified relevant national CERTs and affected organizations ahead of public disclosure. Since the vulnerability enables unauthenticated remote code execution, patching is critical. Additionally, affected organizations should audit their SonicWall appliances for signs of compromise, review LDAP and Active Directory credentials, and monitor for unauthorized DCSync activity. No vendor advisory content was provided in the input, so patch status should be confirmed via SonicWall's official channels. The vendor manages remediation for this appliance; check SonicWall advisories for the latest updates and guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
ThreatIntelligence+threatintel+websecurityresearch
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":30,"reasons":["external_link","newsworthy_keywords:campaign","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["campaign"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6aa2ee4a555a9c516207c83e

Added to database: 09/10/2026, 17:52:10 UTC

Last enriched: 09/10/2026, 17:52:25 UTC

Last updated: 09/10/2026, 18:47:21 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses