CVE-2026-15409 execution chain | Image: Hunt.io
At a Glance
| Category | Details |
|---|---|
| Actor or Group | Unattributed threat actor (Chinese-language artifacts observed) |
| Activity Type | Mass vulnerability scanning, credential harvesting, DCSync attacks |
| Targets or Victims | UK local government, healthcare, education, and finance sectors |
| Scale | 250 targets identified, 168 configurations exposed, 5 domains compromised |
| Jurisdiction Status | Under investigation by local authorities and security firms |
| Source | Hunt.io Threat Intelligence |
Executive Summary
A malicious operator compromised SonicWall appliances to breach internal enterprise networks worldwide. The attacker extracted stored credentials to pivot directly into corporate Windows environments. Consequently, the intrusion exposed sensitive records and compromised local government services.
Track every SonicWall CVE the moment it's exploited.
Get free email alertsWhat Happened in the Attack
The attacker exploited CVE-2026-15409, a critical flaw affecting SonicWall SMA1000 appliances. SonicWall disclosed this security issue on July 14, 2026. Shortly after disclosure, the operator began scanning the internet for unpatched systems.
The attacker used a modified public proof-of-concept script for mass exploitation. First, the script sent requests to the public WorkPlace WebSocket proxy endpoint. Next, it tunneled connections directly into a local Erlang service. The script authenticated using a hardcoded Erlang cookie.
After completing authentication, the script executed commands on the underlying operating system. The report describes the initial intrusion: “The operator gained command execution on appliances, extracted configurations, and recovered associated LDAP credentials used for follow-on attacks.”
Furthermore, the operator downloaded a configuration file named policy_file.xml from each device. This file stored encrypted credentials for administrative accounts. The actor then transferred these files back to attacker-controlled infrastructure.
Next, the intruder decrypted the stolen LDAP bind passwords in bulk. The software protected these passwords using a static encryption key. Once decrypted, these credentials gave the actor direct access to internal directory services.
Pivoting into Active Directory
With valid credentials in hand, the operator expanded the intrusion beyond the firewall. The actor deployed a custom Linux build of Impacket’s secretsdump tool into the temporary directory of each appliance.
The attacker used the compromised gateway as an internal proxy. According to the report, “This approach could help the actor evade detection, as organisations typically have substantially less visibility into the underlying operating systems of firewall and VPN appliances than into managed Windows and Linux hosts monitored by EDR.”
After launching the tool, the operator extracted security account manager data from internal domain controllers. In several networks, the intruder captured machine account hashes. The actor then used these hashes to conduct directory replication attacks.
Consequently, the attacker performed full DCSync operations without triggering typical network alarms. This activity allowed the operator to extract user passwords and Kerberos keys across compromised environments.
Who Is Behind the Campaign
Security analysts have not officially attributed the attack to a named cybercrime syndicate. However, researchers identified several clues within the attacker’s operational toolkit. Multiple Python scripts contained comments and log messages written in Chinese.
These linguistic indicators suggest a Chinese-speaking operator developed the scanning tools. Nevertheless, analysts caution that code markers alone do not confirm state sponsorship. The primary motivation appears focused on broad credential theft.
Hunt.io tracked the campaign by discovering an open server directory on July 17, 2026. Telemetry showed active scanning began on July 16, followed by intrusions the next day. Analysts assess with moderate confidence that this activity directly caused the disruption at the UK council.
Impact and Scale of the Intrusions
The consolidated data shows the widespread impact of this SonicWall SMA 1000 campaign. In total, the attacker processed 250 unique target identifiers. The operator successfully pulled directory configurations from 168 appliances.
These stolen files exposed 534 configuration records across 160 distinct Active Directory domains. Furthermore, the cache contained 255 internal directory server addresses. The actor recovered password hashes from nine separate Active Directory domains.
Most critically, the operator executed full directory synchronizations against five complete enterprise domains. This action exposed thousands of corporate accounts. Confirmed victims operate in France, India, Italy, and the United States.
Additionally, the targets included organizations in Canada, Germany, Sweden, and the United Kingdom. The affected organizations span local governments, healthcare networks, financial institutions, and universities. Researchers highlighted the broad scope: “Targeting was opportunistic and technology-driven, spanning multiple sectors rather than any single vertical.” The attacker simply hunted for exposed appliances.
What Comes Next and How to Stay Protected
Edge appliances remain high-value targets for initial access brokers. Attackers understand that defenders rarely monitor appliance operating systems. Therefore, organizations must update their boundary defenses immediately.
To defend against this active SonicWall SMA 1000 campaign, administrators must take decisive action:
- Apply official SonicWall firmware hotfixes to remediate CVE-2026-15409 immediately.
- Rotate all directory bind passwords configured on perimeter appliances.
- Reset computer account passwords for all domain controllers in affected environments.
- Inspect appliance file systems for unauthorized files placed in temporary directories.
- Restrict management interfaces so that only trusted internal networks can reach them.
- Audit Active Directory replication permissions to prevent unauthorized account synchronization.
Organizations should treat any unpatched gateway as potentially compromised. Performing thorough credential resets will help eliminate unauthorized access across internal enterprise networks.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!