- Millions of devices, probably infected with malware, used in a hacking campaign
- Researchers discovered brute-force attacks against VPN and other Internet-connected devices
- The majority of IP addresses are located in Brazil
A wide range of virtual private network (VPN) and other network devices are currently under attack by threat players trying to break in to wider networks, experts have warned.
The threat surveillance platform Shadows Server Foundation warned of the ongoing attack on X, noting that someone is currently using approx. 2.8 million different IP addresses to try to guess the passwords for VPNs and similar devices built by Palo Alto Networks, Ivanti, Sonicwall and others.
In addition to VPNs, the threat actors go to gateways, security devices and other edges connected to the public Internet.
Brute Force
To carry out the attack, the threat actors use microtics, Huawei, Cisco, Boa and ZTE routers and other Internet-connected devices, probably compromised with malware or broken into themselves thanks to weak passwords.
Talking to Bleeping computerThe Shadows Server Foundation said the attack recently increased in intensity.
From these 2.8 million, the majority (1.1 million) are placed in Brazil, with the rest split between Turkey, Russia, Argentina, Morocco and Mexico.
This is a typical brute-force attack where threat actors try to log in to a device by submitting a huge amount of username/password combinations until successful. Brute-Force attacks are usually successful against devices protected with poor passwords (those that do not have a strong combination of uppercase and lowercase letters, numbers and special symbols). The whole process is automated, which makes it possible on a larger scale.
The automation part is made possible through malware. Usually, the devices used in the attack are part of a botnet or a housing proxy service. Housing Proxy is IP addresses assigned to real devices from ISPs (ISPs). They make it look like the user is reviewing from a legitimate housing location rather than a data center, making them an important target for cyber criminals.