Hunt.io Links UK Council Attack to SonicWall SMA1000 Exploitation Campaign

· Original article ↗

Summary

Hunt.io reports a campaign exploiting CVE-2026-15409 in SonicWall SMA1000 appliances to steal LDAP credentials and Active Directory secrets. It assesses with moderate confidence that the activity is linked to a cyberattack on a UK council.

Key points

  • The council detected an attack on 17 July 2026; Hunt.io assesses with moderate confidence that it was linked to the wider campaign.
  • The unnamed operator exploited CVE-2026-15409, an unauthenticated SSRF flaw in the SMA1000 WorkPlace interface, to reach a local Erlang service and execute commands.
  • Bulk scanning began on 16 July, two days after SonicWall disclosed the vulnerability; the operator adapted a public Rapid7 proof of concept.
  • The campaign recovered 534 LDAP configuration records from 168 appliances, covering 160 Active Directory domains and 255 internal LDAP endpoints, and decrypted stored passwords.
  • A standalone Linux build of Impacket secretsdump was run from compromised appliances to steal credentials from internal Windows systems.
  • SAM and LSA secrets were extracted from nine Active Directory environments; DCSync succeeded against seven domain controllers across five environments, exposing thousands of account records.
  • Targeting spanned multiple countries and sectors and appeared opportunistic; the campaign was not attributed to a named group or country.

Article Details

Attack Vectors
  • The operator used Shodan-derived target lists and multithreaded scanning to identify SonicWall SMA1000 appliances vulnerable to CVE-2026-15409.
  • A modified public proof of concept exploited the WorkPlace /wsproxy endpoint to reach a locally bound Erlang service and execute commands as the appliance's couchdb account.
  • The operator extracted LDAP configurations from policy_file.xml, decrypted stored passwords on attacker infrastructure, and used the credentials from compromised appliances to access internal Windows systems.
  • The operator deployed a standalone Linux build of Impacket's secretsdump on selected appliances to extract SAM and LSA secrets. Recovered domain-controller machine-account hashes were used for pass-the-hash authentication and DCSync.
Defensive Notes
  • The article identifies /tmp/secretsdump, /tmp/dump_[DC].out, and staged .ntds-related files as artifacts of the appliance-based credential-theft workflow.
  • Hunt.io notes that organizations typically have less visibility into security-appliance operating systems than into EDR-monitored hosts, potentially making this activity harder to detect.

Indicators of compromise

TypeIndicatorContext
IPV495[.]181[.]173[.]36Hosted the exposed campaign directory and served the Linux secretsdump payload.
SHA256690f5031deede7d3357d0ca24c89866ae8c60e6c63b3a2c8bba813a6ac10ae5bSHA-256 of the standalone secretsdump binary deployed to compromised appliances.
URLhxxp[:]//95[.]181[.]173[.]36/secretsdumpPayload URL used to download the standalone secretsdump binary onto compromised appliances.

MITRE ATT&CK

T1003.002 · Security Account ManagerSecretsdump remotely extracted SAM account hashes from internal Windows systems.T1003.004 · LSA SecretsSecretsdump recovered LSA secrets, including domain-controller machine-account credentials.T1003.005 · Cached Domain CredentialsThe initial credential-dumping workflow recovered cached domain logon hashes.T1003.006 · DCSyncThe operator requested directory secrets through DRSUAPI using recovered credentials and domain-controller machine-account hashes.T1041 · Exfiltration Over C2 ChannelThe operator retrieved credential output from appliances through further CVE-2026-15409 command-execution requests.T1059.004 · Unix ShellErlang RPC requests invoked os:cmd() to execute Linux commands as the appliance's couchdb account.T1074.001 · Local Data StagingCredential-dump output and .ntds-related files were staged beneath /tmp on compromised SonicWall appliances.T1105 · Ingress Tool TransferCompromised appliances downloaded a standalone Linux secretsdump binary to /tmp/secretsdump.T1190 · Exploit Public-Facing ApplicationThe operator exploited the public WorkPlace /wsproxy endpoint to reach a locally bound Erlang service and obtain command execution.T1550.002 · Pass the HashThe operator reused recovered domain-controller machine-account and Administrator NTLM hashes for authentication.T1552.001 · Credentials In FilesThe operator read policy_file.xml to obtain LDAP bind configurations and encrypted passwords.T1595.002 · Vulnerability ScanningA multithreaded scanner checked target appliances for CVE-2026-15409.T1596.005 · Scan DatabasesShodan-derived datasets were used to identify internet-facing SonicWall SMA 1000 appliances.

CVE

People

Vendors

Products

Tools

AttackCaptureThis campaign was identified by our researchers from an open-directory cloned on the 17th July from the IP address 95.181.173[.]36 with Hunt.io's AttackCapture capability:auto_dcsync.pywere service accounts with only enough privilege to query the directory. The operator therefore used auto_dcsync.py and dcsync_domains.py to test whether any recovered account had been granted directory-replicationauto_secretsdump.pyTo take the compromise further, using the initial CVE-2026-15409, the script auto_secretsdump.py was leveraged to drop Impacket secretsdump tooling to the network appliance and execute remotely, using previouslycve-2026-15409-check.pyThe operator used cve-2026-15409-check.py to process the target lists. This script was commented in Chinese:cve-2026-15409-exploit.pya Python proof of concept, on 15 July. Source comparison shows that the operator's cve-2026-15409-exploit.py is a direct refactor of Rapid7's public proof of concept. Its header explicitly credits Ryancve-2026-15409.pyRapid7 published cve-2026-15409.py, a Python proof of concept, on 15 July. Source comparison shows that the operator's cve-2026-15409-exploit.py is a direct refactor of Rapid7's public proof of concept. Its headerdcsync_bg.pyFig. 12. Domain-controller machine-account pass-the-hash DCSync in dcsync_bg.py/tmp/secretsdump -just-dc-user Administrator [DOMAIN]/[LDAP_USER]:[PASSWORD]@[DC]dcsync_domains.pywith only enough privilege to query the directory. The operator therefore used auto_dcsync.py and dcsync_domains.py to test whether any recovered account had been granted directory-replication rights.dcsync_machine_accounts.pyThe scripts dcsync_machine_accounts.py, dcsync_bg.py and test_dcsync_manual.py automated this escalation. They parsed the earlier files in dump_results, searched for account names ending in $, extracted the accompanyingdecrypt_ldap_password.pyFig. 08. Snippet of ldaps.txtThe LDAP passwords stored within the ldaps.txt file were encrypted. The script decrypt_ldap_password.py was used to decrypt these in bulk from the attacker's server:Impacketwere used as footholds into internal networks. The operator deployed a standalone Linux build of Impacket's secretsdump directly onto selected SonicWall appliances, enabling remote credential theft fromldap_extract.pyThe operator ran ldap_extract.py against the targets in vuln_all.txt. For each appliance, with command execution achieved via CVE-2026-15409, the script would simply retrieve the filesecretsdumpused as footholds into internal networks. The operator deployed a standalone Linux build of Impacket's secretsdump directly onto selected SonicWall appliances, enabling remote credential theft from internal WindowsShodan2,197 entries covering 1,517 unique hosts. Its name and formatting indicate that the targets came from Shodan results. Two larger inventories were also present. us/SonicWall_shodan.txt contained almost 197,000test_dcsync_manual.pyThe scripts dcsync_machine_accounts.py, dcsync_bg.py and test_dcsync_manual.py automated this escalation. They parsed the earlier files in dump_results, searched for account names ending in $, extracted the accompanying

Countries

CanadaThe wider target inventory spanned named gateways in the United Kingdom, Canada, Germany, Sweden, Poland, Hungary, South Korea and Hong Kong, among others.FranceConfirmed credential theft affected Active Directory environments in several countries, including France, India, Italy and the United States.GermanyThe wider target inventory spanned named gateways in the United Kingdom, Canada, Germany, Sweden, Poland, Hungary, South Korea and Hong Kong, among others.Hong KongThe wider target inventory spanned named gateways in the United Kingdom, Canada, Germany, Sweden, Poland, Hungary, South Korea and Hong Kong, among others.HungaryThe wider target inventory spanned named gateways in the United Kingdom, Canada, Germany, Sweden, Poland, Hungary, South Korea and Hong Kong, among others.IndiaConfirmed credential theft affected Active Directory environments in several countries, including France, India, Italy and the United States.ItalyConfirmed credential theft affected Active Directory environments in several countries, including France, India, Italy and the United States.PolandThe wider target inventory spanned named gateways in the United Kingdom, Canada, Germany, Sweden, Poland, Hungary, South Korea and Hong Kong, among others.South KoreaThe wider target inventory spanned named gateways in the United Kingdom, Canada, Germany, Sweden, Poland, Hungary, South Korea and Hong Kong, among others.SwedenThe wider target inventory spanned named gateways in the United Kingdom, Canada, Germany, Sweden, Poland, Hungary, South Korea and Hong Kong, among others.United KingdomThe wider target inventory spanned named gateways in the United Kingdom, Canada, Germany, Sweden, Poland, Hungary, South Korea and Hong Kong, among others.United StatesConfirmed credential theft affected Active Directory environments in several countries, including France, India, Italy and the United States.

Industries

Related Articles