A significant cybersecurity threat has emerged as nearly 2.8 million IP addresses are conducting a coordinated brute force password attack against major networking devices. The campaign, detected by The Shadowserver Foundation, primarily targets security equipment from manufacturers including Palo Alto Networks, Ivanti, and SonicWall.
The attack, which began last month, originates predominantly from Brazil (1.1 million IPs), followed by Turkey, Russia, Argentina, Morocco, and Mexico. The compromised devices executing these attacks are primarily routers and IoT devices from MikroTik, Huawei, Cisco, Boa, and ZTE.
The campaign specifically targets edge security devices such as firewalls, VPNs, and security gateways that are typically exposed to the internet for remote access purposes. Shadowserver indicates that the attacking infrastructure likely represents a botnet or residential proxy network operation.
Security Implications:
– Compromised devices could be used as proxy exit nodes
– Enterprise networks may unknowingly route malicious traffic
– High-quality proxy nodes are valuable for cybercriminal activities
Recommended Security Measures:
1. Implement strong, unique passwords
2. Enable multi-factor authentication
3. Use IP allowlisting
4. Disable unnecessary web admin interfaces
5. Keep firmware and security updates current
This campaign follows similar large-scale attacks reported by Cisco in April and Citrix in December, indicating a growing trend in credential-based attacks against network security infrastructure.
