Alpha Cyber

Threat Spotlight: SonicWall VPNs Compromised by Stealthy Rootkit Backdoor

A sophisticated cyber campaign has been discovered targeting SonicWall VPN appliances, embedding a stealthy rootkit backdoor deep in the system, invisible to standard endpoint protection.

Alpha Cyber Research1 min readupdated 1 Apr 2026
SonicWall Rootkit Graph

SonicWall VPNs Compromised by Stealthy Rootkit Backdoor

A sophisticated cyber campaign has been discovered targeting SonicWall VPN appliances, embedding a stealthy rootkit backdoor deep in the system, invisible to standard endpoint protection.

The attackers leveraged hidden infrastructure across global networks to infiltrate organizations undetected, maintaining persistent access for extended periods.

What We Uncovered

Using advanced infrastructure mapping, our analysts traced the intrusion path from initial access at the VPN gateway to lateral movement within the internal network.

Key findings:

Rootkit installed directly on VPN firmware

Communication with encrypted C2 nodes via uncommon ports

No endpoint logs triggered, total stealth

Access maintained even after device reboots

How We Help
At Alpha Cyber, we provide:

  • Full visibility into VPN traffic & device-to-device communication
  • Real-time mapping of hidden backdoors & persistence mechanisms
  • Detection of rogue external connections to known C2s
  • Threat hunting & incident response for embedded malware

Table of IOCs to Block

TypeIOC / ValueDescription
IP Address94.140.114.173Known C2 node
IP Address104.244.73.10VPN traffic redirector
File Path/usr/lib/libcutils.soModified library (rootkit)
Port8443Encrypted C2 communication
Hash (SHA256)3f6f25d2c17c3b89f...Rootkit binary (dropper)

These indicators are linked to an active SonicWall-targeting campaign. Block and monitor accordingly.

See the Unseen Before It Spreads


Stealth rootkits don’t make noise. They make moves.
Let us help you map, monitor, and secure your network before attackers do.

Request an Infrastructure Risk Assessment Today

#CyberSecurity #VPNBackdoor #SonicWall #RootkitThreat #ThreatMapping #IOCBlocklist #APTActivity #InfrastructureSecurity #ZeroTrust

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]