Ukrainian Networks Launch Massive Brute-Force and Password-Spraying Campaigns Targeting SSL VPN and RDP Systems
## Cybersecurity: Ukrainian Network Attacks on SSL VPN and RDP Systems
Cybersecurity: Ukrainian Network Attacks on SSL VPN and RDP Systems
In June and July 2025, a series of large-scale brute-force and password-spraying attacks were conducted by a network of Ukrainian-based autonomous systems, targeting SSL VPN and RDP infrastructure. These coordinated attacks, lasting up to three days, posed significant threats to enterprise remote access systems.
The attacks were primarily orchestrated by three Ukrainian autonomous systems: FDN3 (AS211736), VAIZ-AS (AS61432), and ERISHENNYA-ASN (AS210950), alongside a Seychelles-based network, TK-NET (AS210848). This network infrastructure, allocated since August 2021, frequently manipulates IPv4 prefixes to evade blocklisting and ensure operational continuity.
Researchers from Intrinsec identified the threat through extensive monitoring, noting attack patterns that peaked at over 1.3 million attempts during a three-day period in July 2025. The attacks involved multiple IP addresses executing identical patterns against exposed VPN endpoints and Remote Desktop Protocol services.
The infrastructure is supported by partnerships with bulletproof hosting providers, notably IP Volume Inc. (AS202425), which offers anonymity and resilience against law enforcement and blocklisting efforts.
In June and July 2025, a series of large-scale brute-force and password-spraying attacks were conducted by a network of Ukrainian-based autonomous systems, targeting SSL VPN and RDP infrastructure.
Network Infrastructure and Attack Mechanics
The technical setup of these attacks involves coordinated IP ranges, with prefix 88.210.63.0/24 as a central point for intensive campaigns. Attack logs show synchronized activation, with each IP address generating between 108,000 and 113,000 attack attempts during peak operations.
Attackers utilize password spraying techniques, targeting common passwords across numerous accounts to bypass account lockout mechanisms. This method is effective against organizations with weak password policies or inadequate rate limiting.
The campaigns specifically target Fortinet, Palo Alto, and Cisco VPN appliances to establish high-privilege access points, circumventing traditional endpoint detection and response solutions. Network traffic analysis indicates persistent command-and-control communications through Amadey malware panels hosted on the same autonomous systems.
Active command-and-control servers include 185.156.72.96 with 126 bot connections and 185.156.72.97 with 122 compromised endpoints, suggesting successful post-exploitation activities.
Based on reporting by Cyber Security News.



