Ukrainian Hackers Ramp Up Brute-Force and Password-Spraying Attacks on VPN and RDP Systems
In mid-2025, a coalition of Ukraine-based autonomous systems conducted extensive brute-force and password-spraying campaigns targeting SSL VPN and Remote Desktop Protocol (RDP) services. These operations overwhelmed security defenses, highlighting the…
In mid-2025, a coalition of Ukraine-based autonomous systems conducted extensive brute-force and password-spraying campaigns targeting SSL VPN and Remote Desktop Protocol (RDP) services. These operations overwhelmed security defenses, highlighting the increasing sophistication of state-linked cyber-infrastructure.
During a three-day period in July 2025, the network identified as AS211736 (“FDN3”) launched over 1.3 million login attempts against corporate VPN and RDP endpoints. Security researchers traced these coordinated attacks to a cluster of Ukrainian autonomous systems, including VAIZ-AS (AS61432), E-RISHENNYA-ASN (AS210950), and FDN3 (AS211736), which routinely exchanged IP prefixes with TK-NET (AS210848) in Seychelles to avoid blocklisting.
All four networks originated simultaneously in August 2021 and shared routing through IP Volume Inc. (AS202425), a Seychelles-based front for the Dutch bulletproof hosting provider Ecatel. The attack tactics resembled those used by emerging Ransomware-as-a-Service (RaaS) groups, characterized by low-and-slow credential stuffing for initial network access.
On July 6, 2025, the FDN3 prefix 88.210.63.0/24 initiated waves of login attempts across numerous VPN appliances and RDP servers, with individual IP addresses experiencing over 110,000 hits. Logging clusters revealed a near-uniform distribution of attempts between SSL VPN ports (TCP 443 and 8443) and RDP (TCP 3389), indicating a broad probing strategy.
Historical telemetry from April 2025 confirms that Telkom Internet LTD (AS210848) and IP Volume Inc. (AS202425) previously conducted similarly massive scanning operations through VAIZ and E-RISHENNYA prefixes. During that period, honeypot networks recorded over 27,000 attack attempts in a single week from AS210848 alone, with SANS Institute metrics logging tens of thousands of hits on port 5555 from these ASNs.
These operations overwhelmed security defenses, highlighting the increasing sophistication of state-linked cyber-infrastructure.
Analysis of WHOIS data links the administrative oversight of FDN3 to Russian-registered maintainer Alex Host LLC (“ru-alexgroup-1-MNT”), known for supporting illicit RaaS operators. Prefix transfers between UA- and RU-registered entities, such as the movement of 45.143.201.0/24 from TOV VAIZ PARTNER to Verasel Inc., suggest a strategic use of shell companies to hinder attribution and takedown efforts.
Bulgarian front networks, including ROZA-AS (AS212283) and SS-Net (AS204428), have also cycled Ukrainian prefixes to maintain access to abused IP ranges. In June and July 2025, SS-Net prefixes 83.222.190.0/24 and 83.222.191.0/24 recorded over 55,000 and 12,900 RDP login attempts, respectively, indicating a reliance on geographically diverse bulletproof hosting partners.
Experts recommend implementing stringent rate-limiting, multi-factor authentication, and comprehensive blocklisting of known abusive ASNs. Organizations should subscribe to reputable threat intelligence blocklists, such as those published by Spamhaus, to proactively deny traffic from high-risk networks.
As RaaS operations continue to refine initial access tactics, the security community must adapt by correlating BGP prefix movements with attack telemetry, enriching context for real-time defensive measures.
The July 2025 Ukrainian network campaigns demonstrate the increasing use of layered, multinational bulletproof hosting infrastructures to sustain intensive brute-force operations, emphasizing the need for coordinated global efforts to dismantle these abusive networks.
Based on reporting by GBHackers.
