Cisco SSL VPN and GlobalProtect credential-probing campaign
Campaign
Summary
Hide ▲
Show ▼
A coordinated credential-based campaign is now probing Cisco SSL VPN and Palo Alto Networks GlobalProtect portals at scale, raising the risk of unauthorized access attempts across enterprise VPN infrastructure. The activity used common username and password combinations and was observed on December 11-12, 2025. More than 10,000 unique IPs were involved against GlobalProtect, while 1,273 IP addresses hit Cisco SSL VPN endpoints. The consistent timing and infrastructure suggest a single campaign pivoting across multiple VPN platforms.
Related Happenings
First VPN Service as criminal VPN infrastructure for ransomware and fraud operators
Threat Actor Meta
First: 22.05.2026 20:35
Last: 22.05.2026 20:35
Sources 1
About this happening:
**First VPN Service** functioned as a criminal VPN layer that let ransomware, fraud, and data theft operators hide their identities, expanding the reach and resilience of undergro...
First VPN Service as criminal VPN infrastructure for ransomware and fraud operators
Threat Actor MetaAbout this happening: **First VPN Service** functioned as a criminal VPN layer that let ransomware, fraud, and data theft operators hide their identities, expanding the reach and resilience of undergro...
NCSC-UK joint advisory on covert botnets and proxy networks
Public Sector Action
First: 23.04.2026 15:28
Last: 23.04.2026 15:28
Sources 1
About this happening:
**NCSC-UK** and partner agencies issued a **joint advisory** warning that **China-nexus hackers** are using **hijacked consumer devices** as covert proxy networks to hide maliciou...
NCSC-UK joint advisory on covert botnets and proxy networks
Public Sector ActionAbout this happening: **NCSC-UK** and partner agencies issued a **joint advisory** warning that **China-nexus hackers** are using **hijacked consumer devices** as covert proxy networks to hide maliciou...
Storm-2561 fake enterprise VPN Hyrax infostealer activity
Malware Activity
First: 13.03.2026 15:23
Last: 13.03.2026 15:23
Sources 1
About this happening:
A fake enterprise VPN installer is now delivering **Hyrax infostealer** components that steal **VPN credentials** and maintain persistence on **Windows** systems. The operation ma...
Storm-2561 fake enterprise VPN Hyrax infostealer activity
Malware ActivityAbout this happening: A fake enterprise VPN installer is now delivering **Hyrax infostealer** components that steal **VPN credentials** and maintain persistence on **Windows** systems. The operation ma...
Palo Alto GlobalProtect login-attempt and SonicWall SonicOS scanning campaign
Campaign
First: 06.12.2025 17:18
Last: 06.12.2025 17:18
Sources 1
About this happening:
A **credential-based campaign** is hitting **Palo Alto GlobalProtect portals** and **SonicWall SonicOS API endpoints**, creating broad reconnaissance risk across remote-access and...
Palo Alto GlobalProtect login-attempt and SonicWall SonicOS scanning campaign
CampaignAbout this happening: A **credential-based campaign** is hitting **Palo Alto GlobalProtect portals** and **SonicWall SonicOS API endpoints**, creating broad reconnaissance risk across remote-access and...
Unattributed coordinated scanners linked across related activity clusters campaign shows victim surge
Campaign
First: 20.11.2025 19:08
Last: 20.11.2025 19:08
Sources 1
About this happening:
A coordinated **malicious scanning campaign** against **Palo Alto Networks GlobalProtect** VPN login portals surged **40x** in 24 hours, pushing activity to a **90-day high**. Gre...
Unattributed coordinated scanners linked across related activity clusters campaign shows victim surge
CampaignAbout this happening: A coordinated **malicious scanning campaign** against **Palo Alto Networks GlobalProtect** VPN login portals surged **40x** in 24 hours, pushing activity to a **90-day high**. Gre...
Timeline
-
18.12.2025 06:10 1 articles · 5mo ago
GlobalProtect portals probed with automated logins
Campaign Scope UpdateMore than 10,000 unique IPs attempted automated logins against exposed or weakly protected Palo Alto Networks GlobalProtect portals in the U.S., Pakistan, and Mexico using common username and password combinations.
Show sources
- Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances — thehackernews.com — 18.12.2025 06:10
-
18.12.2025 06:10 1 articles · 5mo ago
Cisco SSL VPN endpoints hit by brute-force attempts
Campaign Scope UpdateCisco SSL VPN endpoints saw a similar spike in opportunistic brute-force login attempts on 1,273 source IP addresses, with GreyNoise assessing the activity as large-scale scripted credential probing rather than vulnerability exploitation.
Show sources
- Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances — thehackernews.com — 18.12.2025 06:10
-
18.12.2025 06:10 2 articles · 5mo ago
GreyNoise discloses multi-platform VPN credential-probing campaign
Initial DisclosureGreyNoise disclosed a coordinated, automated credential-based campaign aimed at enterprise VPN authentication infrastructure, specifically probing exposed or weakly protected Cisco SSL VPN and Palo Alto Networks GlobalProtect portals, and said consistent infrastructure usage and timing indicated a single campaign pivoting across multiple VPN platforms.
Show sources
- Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances — thehackernews.com — 18.12.2025 06:10
- Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances — thehackernews.com — 18.12.2025 06:10