TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

GreyNoise

Coordinated Credential-Based Campaign Targets Cisco and Palo Alto Networks VPN Gateways

2025-12-17 · Read original ↗

ATT&CK techniques detected

5 predictions
T1110Brute Force
86%
“on 12 december, greynoise observed a sharp surge in opportunistic bruteforce login attempts targeting cisco ssl vpn endpoints. daily unique attacking ips rose from a typical baseline of fewer than 200 to 1, 273 ips, representing a significant deviation from normal activity. the m…”
T1110Brute Force
81%
“cisco ssl vpn bruteforcer attacks new users can try greynoise block free for 14 - days. greynoise will continue monitoring this activity and make updates as necessary. — — — stone is head of content at greynoise intelligence, where he leads strategic content programs that transla…”
T1110Brute Force
58%
“##l vpn bruteforce activity sourced from 3xk infrastructure and marks the first time in the past 12 weeks that 3xk - hosted ips have been deployed at scale against cisco ssl vpn portals. observed request bodies indicate automated credential - based authentication attempts rather …”
T1110.003Password Spraying
53%
“##l vpn bruteforce activity sourced from 3xk infrastructure and marks the first time in the past 12 weeks that 3xk - hosted ips have been deployed at scale against cisco ssl vpn portals. observed request bodies indicate automated credential - based authentication attempts rather …”
T1078Valid Accounts
33%
“coordinated credential - based campaign targets cisco and palo alto networks vpn gateways greynoise is tracking a coordinated, automated credential - based campaign targeting enterprise vpn authentication infrastructure, with activity observed against cisco ssl vpn and palo alto …”

Summary

GreyNoise is tracking a coordinated, automated credential-based campaign targeting enterprise VPN authentication infrastructure, with activity observed against Cisco SSL VPN and Palo Alto Networks GlobalProtect services.