Saturday, August 15, 2026
LIVE
Ugandan villages still contest land titles as oil development advances///Nigerian Troops Repel Bandit Attack on Kebbi Workers///NLC Queries Lagos Chairman Over Ties to Pro-Tinubu Group///Côte d’Ivoire Names New Leader for Blé Goudé’s COJEP Party///United States Highlights Civilian Deaths in Nigeria Terror Fight///Zimbabwe Pledges New Ferry and Road Repair After Lake Kariba Disaster///Ebola death toll reaches two thousand in Democratic Republic of the Congo///Forced Conscription Reports Emerge Across Ethiopia Oromia Region///Ebola outbreak reaches displacement camps in eastern Democratic Republic of the Congo///Hacking Group Claims Data Theft from Shell and Other Global Firms///Turkey warns of radical measures if Israel rejects Gaza peace deal terms///Nigerian President Urged to Engage Niger Delta Leader for Reelection Campaign///Ugandan villages still contest land titles as oil development advances///Nigerian Troops Repel Bandit Attack on Kebbi Workers///NLC Queries Lagos Chairman Over Ties to Pro-Tinubu Group///Côte d’Ivoire Names New Leader for Blé Goudé’s COJEP Party///United States Highlights Civilian Deaths in Nigeria Terror Fight///Zimbabwe Pledges New Ferry and Road Repair After Lake Kariba Disaster///Ebola death toll reaches two thousand in Democratic Republic of the Congo///Forced Conscription Reports Emerge Across Ethiopia Oromia Region///Ebola outbreak reaches displacement camps in eastern Democratic Republic of the Congo///Hacking Group Claims Data Theft from Shell and Other Global Firms///Turkey warns of radical measures if Israel rejects Gaza peace deal terms///Nigerian President Urged to Engage Niger Delta Leader for Reelection Campaign///
Subscribe
Africa
Independent · Digital
The African Herald
PoliticsAI-assisted

Ukrainian Networks Launch Massive Brute-Force and Password-Spraying Campaigns Targeting SSL VPN and RDP Systems

## Cybersecurity: Ukrainian Network Attacks on SSL VPN and RDP Systems

Cybersecurity: Ukrainian Network Attacks on SSL VPN and RDP Systems

In June and July 2025, a series of large-scale brute-force and password-spraying attacks were conducted by a network of Ukrainian-based autonomous systems, targeting SSL VPN and RDP infrastructure. These coordinated attacks, lasting up to three days, posed significant threats to enterprise remote access systems.

The attacks were primarily orchestrated by three Ukrainian autonomous systems: FDN3 (AS211736), VAIZ-AS (AS61432), and ERISHENNYA-ASN (AS210950), alongside a Seychelles-based network, TK-NET (AS210848). This network infrastructure, allocated since August 2021, frequently manipulates IPv4 prefixes to evade blocklisting and ensure operational continuity.

Researchers from Intrinsec identified the threat through extensive monitoring, noting attack patterns that peaked at over 1.3 million attempts during a three-day period in July 2025. The attacks involved multiple IP addresses executing identical patterns against exposed VPN endpoints and Remote Desktop Protocol services.

The infrastructure is supported by partnerships with bulletproof hosting providers, notably IP Volume Inc. (AS202425), which offers anonymity and resilience against law enforcement and blocklisting efforts.

In June and July 2025, a series of large-scale brute-force and password-spraying attacks were conducted by a network of Ukrainian-based autonomous systems, targeting SSL VPN and RDP infrastructure.
Amara Diallo · The African Herald

Network Infrastructure and Attack Mechanics

The technical setup of these attacks involves coordinated IP ranges, with prefix 88.210.63.0/24 as a central point for intensive campaigns. Attack logs show synchronized activation, with each IP address generating between 108,000 and 113,000 attack attempts during peak operations.

Attackers utilize password spraying techniques, targeting common passwords across numerous accounts to bypass account lockout mechanisms. This method is effective against organizations with weak password policies or inadequate rate limiting.

The campaigns specifically target Fortinet, Palo Alto, and Cisco VPN appliances to establish high-privilege access points, circumventing traditional endpoint detection and response solutions. Network traffic analysis indicates persistent command-and-control communications through Amadey malware panels hosted on the same autonomous systems.

Advertisement

Active command-and-control servers include 185.156.72.96 with 126 bot connections and 185.156.72.97 with 122 compromised endpoints, suggesting successful post-exploitation activities.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories