Threat actors launched a large-scale, automated credential-stuffing campaign targeting enterprise VPN authentication infrastructure, specifically focusing on Palo Alto Networks GlobalProtect and Cisco SSL VPN gateways. The campaign, observed in mid-December 2025, involved millions of scripted login attempts over a short period, with attackers pivoting rapidly between the two vendors. GreyNoise intelligence identified that the attacks originated almost exclusively from centralized infrastructure hosted by Germany’s 3xK GmbH, utilizing uniform request patterns, common username-password combinations, and atypical browser user agents to probe for weak or exposed VPN portals. Over 1.7 million login attempts were recorded against GlobalProtect portals in just 16 hours, with more than 10,000 unique IPs participating, primarily geolocated to the United States, Pakistan, and Mexico.
Following the surge against Palo Alto, the attackers shifted focus to Cisco SSL VPNs, where a significant spike in unique attacking IPs was observed, rising from under 200 to 1,273 in a single day. The campaign did not exploit any zero-day vulnerabilities but relied on credential stuffing and password spraying techniques, indicating the use of potentially massive stolen credential lists. The uniformity in attack infrastructure, timing, and technical indicators across both VPN platforms underscores the persistent risk to remote access systems and highlights the need for robust authentication and monitoring of enterprise VPN endpoints.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Following public reporting on the campaign, Palo Alto Networks stated it was aware of the activity and emphasized that no vulnerabilities in its products were exploited. Reporting also noted GreyNoise found no evidence connecting the campaign to the recently disclosed Cisco AsyncOS zero-day CVE-2025-20393 or Cisco Talos' UAT-9686 activity.
GreyNoise published research describing the two-day campaign against Cisco and Palo Alto VPN gateways, attributing it to automated scripted login attempts using common credentials and consistent user agents. The company advised defenders to enforce MFA, strengthen passwords, audit edge devices, and block the identified malicious IPs.
Over the following day in mid-December 2025, the same coordinated infrastructure and tooling shifted to targeting Cisco SSL VPN authentication portals. GreyNoise said this marked the first large-scale use of 3xK-hosted IPs against Cisco SSL VPN portals in the prior 12 weeks and found the activity was credential-based rather than vulnerability exploitation.
In mid-December 2025, GreyNoise observed a large-scale automated password-spraying and credential-stuffing campaign targeting Palo Alto Networks GlobalProtect VPN portals. The activity generated roughly 1.7 million login attempts within 16 hours from more than 10,000 IPs, largely tied to infrastructure hosted by Germany-based 3xK GmbH.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcegreynoise.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.