Massive Cyber Campaign: 24,000 IPs Launch Coordinated Attack on PAN-OS GlobalProtect Gateways


# Surge in Scanning Activity Targets Palo Alto Networks Gateways

Cybersecurity researchers have detected a significant increase in suspicious login scanning activity targeting Palo Alto Networks PAN-OS GlobalProtect gateways. Nearly 24,000 unique IP addresses have been observed attempting to access these portals, suggesting a coordinated effort to probe network defenses and identify vulnerable systems.

The scanning activity began on March 17, 2025, maintaining approximately 20,000 unique IP addresses daily before declining on March 26. At its peak, 23,958 unique IP addresses participated in the campaign, with 154 of these flagged as definitively malicious.

The United States and Canada were identified as the primary sources of this traffic, followed by Finland, the Netherlands, and Russia. Target systems were predominantly located in the United States, United Kingdom, Ireland, Russia, and Singapore.

While the motivation behind this activity remains unclear, experts believe it represents a systematic approach to testing network defenses that could precede future exploitation attempts.

“Over the past 18 to 24 months, we’ve observed a consistent pattern of deliberate targeting of older vulnerabilities or well-worn attack and reconnaissance attempts against specific technologies,” explained Bob Rudis, VP of Data Science at GreyNoise. “These patterns often coincide with new vulnerabilities emerging 2 to 4 weeks later.”

Organizations with internet-facing Palo Alto Networks instances are strongly advised to implement additional security measures for their login portals in response to this unusual activity.

Share This Article