Hackers Launch Widespread Attacks on Palo Alto GlobalProtect Portals from 7,000+ IPs
Recent activities have indicated an increase in exploitation attempts targeting Palo Alto Networks' GlobalProtect VPN portals. These actions are part of a broader campaign against remote access infrastructure.
Recent activities have indicated an increase in exploitation attempts targeting Palo Alto Networks' GlobalProtect VPN portals. These actions are part of a broader campaign against remote access infrastructure.
According to GrayNoise tracking, scans and exploitation efforts have been detected from over 7,000 unique IP addresses globally. This situation poses a significant concern for organizations utilizing GlobalProtect for secure remote access.
The attacks, first observed in late November 2025, exploit vulnerabilities in GlobalProtect gateways, specifically those accessible via UDP port 4501 on the internet.
Reports from Shadowserver and other threat intelligence sources indicate that the IP addresses involved originate from a variety of sources, including residential proxies, bulletproof hosting services, and compromised VPS instances across Asia, Europe, and North America.
Palo Alto Networks' GlobalProtect has been a frequent target due to its widespread use in enterprise environments. Unaddressed vulnerabilities, such as CVE-2024-3400, remain a risk for systems that have not been updated with the latest patches.
Recent activities have indicated an increase in exploitation attempts targeting Palo Alto Networks' GlobalProtect VPN portals.
Recent attacks leverage misconfigurations that allow pre-authentication access, such as default credentials or exposed admin portals. Attackers have been employing tools and scripts to enumerate portals, conduct brute-force login attempts, and deploy malware for persistent access.
Mandiant's latest threat report suggests that similar tactics have been used by groups affiliated with state actors, although no definitive attribution has been made for the current wave of attacks.
Unusual UDP traffic spikes to port 4501 HTTP requests to /global-protect/login.urd endpoints
Confirmed breaches have resulted in the exfiltration of session tokens, enabling further unauthorized access within corporate networks.
On December 5, Palo Alto Networks released an advisory recommending the enforcement of multi-factor authentication (MFA), restriction of portal exposure through firewall configurations, and application of the latest patches.
CISA has included relevant indicators of compromise (IOCs) in its Known Exploited Vulnerabilities catalog, advising federal agencies to apply patches within 72 hours.
Experts suggest air-gapping critical portals, implementing zero-trust segmentation, and monitoring for communications with command-and-control servers, particularly those hosted on platforms like AWS or Azure.
Based on reporting by Cyber Security News.
