Executive Summary
Between June and July 2025, Ukrainian autonomous system FDN3 (AS211736) orchestrated large-scale brute-force and password spraying attacks targeting SSL VPN and Remote Desktop Protocol (RDP) devices across multiple regions. The campaign, identified and attributed by French cybersecurity firm Intrinsec, involved distributed login attempts to compromise organizations’ remote access infrastructure using stolen or weak credentials. This led to unauthorized system access, at-risk sensitive data, and the potential for further lateral movement inside target environments. The attack underscored the critical vulnerabilities that arise when VPNs and RDP servers are exposed without adequate security controls.
This incident is emblematic of the growing trend of threat actors exploiting internet-facing authentication portals with automated credential attacks. As organizations continue to rely on remote access solutions, adversaries are increasingly targeting SSL VPN and RDP endpoints to gain initial entry—a method further complicated by the prevalence of weak password policies, limited anomaly detection, and insufficient segmentation.
Why This Matters Now
Accelerated brute-force campaigns against remote access systems highlight an urgent need for improved credential hygiene and multi-factor authentication deployment. With automated attacks on the rise and attacker infrastructure proliferating globally, organizations must rapidly strengthen access controls and monitoring on VPN and RDP endpoints before attackers seize new footholds.
Attack Path Analysis
The adversary initiated their attack by launching massive brute-force and password spraying attempts against exposed SSL VPN and RDP endpoints to gain initial access. After successful credential compromise, they likely sought to escalate privileges within the target environment. Using compromised access, the attacker attempted lateral movement to access additional internal systems. Once internal access was established, outbound communication channels were set up for command and control to maintain persistence and execute further instructions. The actor possibly exfiltrated sensitive data or harvested additional credentials, and the attack posed risks of further disruptive actions or data loss as final impact.
Kill Chain Progression
Initial Compromise
Description
Attackers conducted large-scale brute-force and password spraying attacks against internet-exposed SSL VPN and RDP devices to obtain valid user credentials.
Related CVEs
CVE-2023-20269
CVSS 7.5A vulnerability in the remote access VPN feature of Cisco ASA and FTD Software allows unauthenticated, remote attackers to conduct brute-force attacks to identify valid credentials or establish unauthorized clientless SSL VPN sessions.
Affected Products:
Cisco Adaptive Security Appliance (ASA) Software – 9.6, 9.7, 9.8, 9.9, 9.10, 9.12, 9.13, 9.14, 9.15, 9.16
Cisco Firepower Threat Defense (FTD) Software – 6.2.2, 6.2.3, 6.3.0, 6.4.0, 6.5.0, 6.6.0, 6.7.0
Exploit Status:
exploited in the wildCVE-2024-20481
CVSS 5.8A vulnerability in the Remote Access VPN service of Cisco ASA and FTD Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service due to resource exhaustion.
Affected Products:
Cisco Adaptive Security Appliance (ASA) Software – 9.6, 9.7, 9.8, 9.9, 9.10, 9.12, 9.13, 9.14, 9.15, 9.16
Cisco Firepower Threat Defense (FTD) Software – 6.2.2, 6.2.3, 6.3.0, 6.4.0, 6.5.0, 6.6.0, 6.7.0
Exploit Status:
exploited in the wildCVE-2023-27997
CVSS 9.2A heap-based buffer overflow vulnerability in FortiOS and FortiProxy SSL-VPN allows unauthenticated attackers to execute arbitrary code via specifically crafted requests.
Affected Products:
Fortinet FortiOS – 6.0.0 to 6.0.16, 6.2.0 to 6.2.14, 6.4.0 to 6.4.12, 7.0.0 to 7.0.10, 7.2.0 to 7.2.4
Fortinet FortiProxy – 1.0.0 to 1.0.7, 2.0.0 to 2.0.10, 7.0.0 to 7.0.9, 7.2.0 to 7.2.3
Exploit Status:
exploited in the wildCVE-2025-40601
CVSS 7.5A stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows unauthenticated remote attackers to cause Denial of Service (DoS) attacks, potentially crashing the firewall.
Affected Products:
SonicWall SonicOS – Gen8, Gen7
Exploit Status:
no public exploitCVE-2025-9242
CVSS 9.3An out-of-bounds write vulnerability in WatchGuard's Fireware OS allows unauthorized remote code execution, impacting both mobile user VPNs and branch office VPNs configured with a dynamic gateway peer using IKEv2.
Affected Products:
WatchGuard Fireware OS – 11.10.2 to 11.12.4_Update 1, 12.0 to 12.11.3, 2025.1
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Brute Force
Password Spraying
Valid Accounts
External Remote Services
Remote Services: Remote Desktop Protocol
Exploit Public-Facing Application
Modify Authentication Process
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for Remote Access
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Security Standards and Controls
Control ID: Article 21
CISA ZTMM 2.0 – Enforce Strong Authentication Across Remote Access
Control ID: Identity pillar – Authentication
NIS2 Directive – Access Control Policy
Control ID: Article 21(2)(c)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Critical exposure to Ukrainian FDN3 brute-force attacks on SSL VPN/RDP systems compromising encrypted traffic, zero trust controls, and regulatory compliance frameworks.
Health Care / Life Sciences
High risk from credential access attacks targeting VPN infrastructure, threatening HIPAA compliance and patient data protection through lateral movement vulnerabilities.
Government Administration
Severe threat from state-linked Ukrainian network targeting government SSL VPN and RDP devices, compromising secure connectivity and multicloud visibility controls.
Information Technology/IT
Primary target for massive brute-force campaigns exploiting VPN/RDP infrastructure, requiring enhanced threat detection, segmentation, and egress security enforcement capabilities.
Sources
- Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP Deviceshttps://thehackernews.com/2025/09/ukrainian-network-fdn3-launches-massive.htmlVerified
- Cisco fixes bug under exploit in brute-force attackshttps://www.theregister.com/2024/10/24/cisco_bug_brute_force/Verified
- SonicWall tells customers to patch SonicOS flaw allowing hackers to crash firewallshttps://www.techradar.com/pro/security/sonicwall-tells-customers-to-patch-sonicos-flaw-allowing-hackers-to-crash-firewallsVerified
- NVD - CVE-2023-20269https://nvd.nist.gov/vuln/detail/CVE-2023-20269Verified
- NVD - CVE-2024-20481https://nvd.nist.gov/vuln/detail/CVE-2024-20481Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, East-West traffic security, and threat detection controls would have contained initial remote access attempts, detected anomalous brute-force activity, restricted unauthorized lateral movement, and prevented data exfiltration, significantly mitigating the attack's potential impact.
Control: Threat Detection & Anomaly Response
Mitigation: Abnormal access attempts detected and alerted in real time.
Control: Zero Trust Segmentation
Mitigation: Unauthorized privilege elevation attempts flagged or blocked.
Control: East-West Traffic Security
Mitigation: Unapproved east-west connections detected and prevented.
Control: Cloud Firewall (ACF)
Mitigation: Suspicious outbound communications blocked or logged.
Control: Egress Security & Policy Enforcement
Mitigation: Unauthorized data exfiltration attempts detected and stopped.
Malicious actions rapidly contained through centralized policy enforcement.
Impact at a Glance
Affected Business Functions
- Remote Access
- Network Security
- IT Operations
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive corporate data due to unauthorized access through compromised VPN and RDP systems.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate remote access endpoints from sensitive workloads and restrict lateral movement.
- • Deploy advanced anomaly detection and automated incident response to rapidly surface and block brute-force or password spraying attacks.
- • Enforce strict egress controls with FQDN filtering and policy-based restrictions to prevent unauthorized data exfiltration and C2 communications.
- • Centralize visibility and enforce least privilege access through both cloud-native and cross-cloud policy for better threat containment.
- • Continuously monitor for configuration drift and leverage microsegmentation to minimize the blast radius from potential credential compromise.



