A large-scale brute force attack is underway, using nearly 2.8 million IP addresses to target networking devices from Palo Alto Networks, Ivanti, SonicWall, and others.
Brute force attacks involve systematically guessing login credentials to gain unauthorized access. Once successful, attackers can hijack devices or infiltrate networks.
According to The Shadowserver Foundation, this attack has been active since last month, with 1.1 million of the attacking IPs originating from Brazil, followed by Turkey, Russia, Argentina, Morocco, and Mexico. The targeted devices include firewalls, VPNs, and security appliances commonly exposed to the internet for remote access.
The attackers appear to be leveraging compromised MikroTik, Huawei, Cisco, Boa, and ZTE routers, as well as IoT devices. Shadowserver believes the attacks are conducted by a botnet or linked to residential proxy networks, which use real residential IPs to mask malicious activity.
Residential proxies make attacks harder to detect by routing traffic through consumer ISP networks, making it appear as if legitimate home users are behind the activity. Targeted gateway devices could be exploited as exit nodes for cybercriminals, enabling them to launch attacks from within trusted enterprise networks.
How to Protect Against Brute Force Attacks
To defend against these attacks, organizations should:
- Change default admin credentials to strong, unique passwords.
- Enforce multi-factor authentication (MFA).
- Restrict access using an allowlist of trusted IPs.
- Disable unnecessary web admin interfaces.
- Regularly update firmware and apply security patches.
Large-scale credential brute force campaigns have been a persistent threat. Cisco previously warned about attacks targeting Cisco, CheckPoint, Fortinet, SonicWall, and Ubiquiti devices. In December, Citrix also reported password-spraying attacks on Citrix Netscaler devices worldwide.
As brute force campaigns grow in scale and sophistication, securing edge devices remains critical to preventing unauthorized access and network breaches.














Comments