Attacks on Palo Alto PAN-OS Global Protect Login Portals Surge from 2,200 IPs
As of Sat, Oct 7, 2025, over 2,200 unique IP addresses have been identified conducting reconnaissance operations targeting Palo Alto Networks PAN-OS GlobalProtect login portals. This marks a significant increase from the 1,300 IP addresses recorded…
As of Sat, Oct 7, 2025, over 2,200 unique IP addresses have been identified conducting reconnaissance operations targeting Palo Alto Networks PAN-OS GlobalProtect login portals. This marks a significant increase from the 1,300 IP addresses recorded earlier in the week, representing the highest scanning activity in the past 90 days, as per GreyNoise Intelligence.
Significant Increase in Scanning Activity
The reconnaissance campaign began on Mon, Oct 3, 2025, with a 500% increase in scanning activity observed by researchers, involving approximately 1,300 unique IP addresses. This initial surge was notable as the largest scanning event recorded in three months, with daily volumes previously not exceeding 200 IPs during the preceding 90-day period.
Analysis by GreyNoise indicates that 91% of the malicious IP addresses are geolocated in the United States, with additional clusters found in the United Kingdom, the Netherlands, Canada, and Russia. Approximately 12% of all ASN11878 subnets have been allocated to scanning Palo login portals, indicating a significant infrastructure commitment to the operation. The attacks are characterized by systematic iterations through large credential databases, indicative of automated brute-force operations against GlobalProtect SSL VPN portals.
GreyNoise has released a dataset containing unique usernames and passwords from Palo login attempts observed in the past week, aiding security teams in assessing potential credential exposure. Technical analysis reveals that 93% of participating IP addresses were classified as suspicious, while 7% were designated as malicious. The scanning activity exhibits regional clustering patterns with distinct TCP fingerprints, suggesting multiple coordinated threat groups operating simultaneously.
Technical analysis reveals that 93% of participating IP addresses were classified as suspicious, while 7% were designated as malicious.
Correlations with Other Reconnaissance Operations
Potential correlations have been identified between the surge in Palo Alto scanning and concurrent reconnaissance operations targeting Cisco ASA devices . Both campaigns share dominant TCP fingerprints linked to infrastructure in the Netherlands, along with similar regional clustering behaviors and tooling characteristics. This suggests a broader reconnaissance campaign against enterprise remote access solutions, though the exact relationship between these activities is still under investigation.
Security teams should consider the following measures:
Implement IP blocklisting of known malicious addresses. Enhance monitoring of GlobalProtect portal authentication logs. Implement additional access controls for remote VPN connections.
The targeted nature of these attacks suggests the use of public reconnaissance platforms like Shodan or Censys, or proprietary fingerprinting operations to identify vulnerable Palo Alto devices.
Based on reporting by Cyber Security News.
