Close Menu
TechurzTechurz
    What's Hot

    Kog is going deeper to squeeze more inference out of GPUs

    August 14, 2026

    Investors sue Selena Gomez alleging fraud tied to her mental health startup

    August 13, 2026

    Databricks wanted to raise $1B, investors wanted $15B. It settled on $5B at a $190B valuation.

    August 13, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • Kog is going deeper to squeeze more inference out of GPUs
    • Investors sue Selena Gomez alleging fraud tied to her mental health startup
    • Databricks wanted to raise $1B, investors wanted $15B. It settled on $5B at a $190B valuation.
    • Why Sandbar thinks itโ€™s voice-enabled ring can avoid the AI hardware graveyard
    • How a $250 million acquisition collapsed into allegations of fraud and forged signatures
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Cyber Reality - Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP Devices
    Cyber Reality

    Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP Devices

    TechurzBy TechurzSeptember 3, 2025Updated:May 10, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Massive Brute-Force Attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Cybersecurity researchers have flagged a Ukrainian IP network for engaging in massive brute-force and password spraying campaigns targeting SSL VPN and RDP devices between June and July 2025.

    The activity originated from a Ukraine-based autonomous system FDN3 (AS211736), per French cybersecurity company Intrinsec.

    โ€œWe believe with a high level of confidence that FDN3 is part of a wider abusive infrastructure composed of two other Ukrainian networks, VAIZ-AS (AS61432) and ERISHENNYA-ASN (AS210950), and a Seychelles-based autonomous system named TK-NET (AS210848),โ€ according to a report published last week.

    โ€œThose were all allocated in August 2021 and often exchange IPv4 prefixes with one another to evade blocklisting and continue hosting abusive activities.โ€

    AS61432 currently announces a single prefix 185.156.72[.]0/24, while AS210950 has announced two prefixes 45.143.201[.]0/24 and

    185.193.89[.]0/24. The two autonomous systems were allocated in May and August 2021, respectively. A major chunk of their prefixes has been announced on AS210848, another autonomous system also allocated in August 2021.

    โ€œThis network shares all its peering agreements with IP Volume Inc. โ€“ AS202425, a company based in Seychelles and created by Ecatelโ€™s owners, infamous for running an extensively abusive bulletproof hosting service in the Netherlands since 2005,โ€ Intrinsec noted.

    The entirety of prefixes that were moved from AS61432 and AS210950 are now announced by bulletproof and abusive networks fronted by shell companies like Global Internet Solutions LLC (gir.network), Global Connectivity Solutions LLP, Verasel, IP Volume Inc., and Telkom Internet LTD.

    The findings build upon prior disclosures about how multiple networks allocated in August 2021 and based in Ukraine and Seychelles โ€“ AS61432, AS210848, and AS210950 โ€“ were used for spam distribution, network attacks, and malware command-and-control hosting. In June 2025, some of the IPv4 prefixes announced by these networks were moved to FDN3, which was created in August 2021.

    Thatโ€™s not all. Three of the prefixes announced by AS210848, and one by AS61432, were previously announced by another Russian network, SibirInvest OOO (AS44446). Of the four IPv4 prefixes announced by FDN3, one of them (88.210.63[.]0/24) is assessed to have been previously announced by a U.S.-based bulletproof hosting solution named Virtualine (AS214940 and AS214943).

    Itโ€™s this IPv4 prefix range that has been attributed to large-scale brute-force and password spraying attempts, with the activity scaling to a record high between July 6 and 8, 2025.

    The brute-force and password spraying efforts aimed at SSL VPN and RDP assets could last up to three days, per Intrinsec. Itโ€™s worth noting that these techniques have been adopted by various ransomware-as-a-service (RaaS) groups like Black Basta, GLOBAL GROUP, and RansomHub as an initial access vector to breach corporate networks.

    The two other prefixes that FDN3 announced in June, 92.63.197[.]0/24 and 185.156.73[.]0/24, were previously announced by AS210848, indicating a high degree of operational overlap. 92.63.197[.]0/24, for its part, has ties to Bulgarian spam networks like ROZA-AS (AS212283).

    โ€œAll those strong similarities, including their configuration, the content they host, and their creation date, led us to assess with a high level of confidence the previously mentioned autonomous systems to be operated by a common bulletproof hosting administrator,โ€ Intrinsec explained.

    Further analysis of FDN3 has uncovered ties to a Russian company called Alex Host LLC that, in the past, has been linked to bulletproof hosting providers like TNSECURITY, which have been used to host Doppelganger infrastructure.

    โ€œThis investigation once again highlights a common phenomenon of offshore ISPs such as IP Volume Inc. enabling smaller bulletproof networks through peering agreements and prefix hosting overall,โ€ the company said. โ€œThanks to their offshore location, such as Seychelles, which provides anonymity to the owners of those companies, the malicious activities perpetrated through those networks cannot be directly imputed to them.โ€

    The development comes as Censys uncovered a connect-back proxy management system associated with the PolarEdge botnet thatโ€™s currently running on over 2,400 hosts. The system is an RPX server that operates as a reverse-connect proxy gateway capable of managing proxy nodes and exposing proxy services.

    โ€œThis system appears to be a well-designed server that may be one of the many tools used for managing the PolarEdge botnet,โ€ senior security researcher Mark Ellzey said. โ€œIt is also possible that this specific service is completely unrelated to PolarEdge and is instead a service that the botnet utilizes to jump between different relays.โ€

    attacks BruteForce Devices FDN3 launches Massive network RDP SSL Ukrainian VPN
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleIn under 18 months, my iPhone’s battery life has gone from great to terrible
    Next Article OpenAI starts building out its app team
    Techurz
    • Website

    Related Posts

    Opinion

    Runway launches AI model router as generative media gets crowded

    July 23, 2026
    Opinion

    Ultrahuman’s former hardware VP raises $5.5M for devices that control AI agents, not just record you

    July 16, 2026
    Opinion

    Pinwheel launches a retro-inspired landline phone for kids

    July 14, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,290

    12 Father’s Day E-Card Sites That Are Actually Good

    June 4, 202523

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202622
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.