A hacker has published a list of usernames and plaintext passwords, along with IP addresses for over 900 Pulse Secure VPN servers. ZDNet, with the help of cybersecurity firm “KELA,” was able to obtain a copy of this list and verify its authenticity with multiple cybersecurity sources .

The list includes the following:
- Pulse Secure VPN server IP addresses
- SSH keys for each server
- Administrator account information
- VPN session cookies
- Pulse Secure VPN server firmware version
- A list of all local users and their hash codes
- Last VPN connections, including usernames and plaintext passwords

Bank Security, a threat analyst specializing in financial cybercrime, also discovered this list and shared it with ZDNet, and made an interesting observation about the list and its contents. Specifically, it reported that all of the Pulse Secure VPN servers on the list are running a firmware version that is vulnerable to the vulnerability identified as CVE-2019-11510. Furthermore, the company believes that the hacker who created this list scanned the entire Internet IPv4 address space for Pulse Secure VPN servers, exploited the CVE-2019-11510 vulnerability to gain access to systems, obtained information from the servers, including usernames and passwords, and then compiled all of the information into a central repository.
Based on the information mentioned in the list, it appears that the scan dates, or the date the list was compiled, are between June 24 and July 8, 2020.

Additionally, Bad Packets , a US -based threat analysis firm , has been scanning the Internet for vulnerable Pulse Secure VPN servers since August 2019, when the CVE-2019-11510 vulnerability was made public. The firm noted that out of 913 unique IP addresses found, Bad Packets identified 677 from its scans as vulnerable to the CVE-2019-11510 vulnerability when the exploit was made public in 2019.
From the list, it appears that 677 companies have not patched since Bad Packets’ first scan last year, while the June 2020 scans were performed by the hacker. Even if these companies patch their Pulse Secure servers, they will also need to change passwords to prevent hackers from abusing the credentials to take over devices and then spread to their internal networks. This is very important, as Pulse Secure VPN servers are commonly used as gateways to corporate networks, so that staff can remotely connect to internal applications from across the Internet. These types of devices, if compromised, can allow hackers to easily gain access to a company’s entire internal network. This is precisely why APT and ransomware gangs have often targeted these systems.

Additionally, the leaked list was shared on a hacking forum frequented by many ransomware gangs. For example, the REvil (Sodinokibi), NetWalker, Lockbit, Avaddon, Makop, and Exorcist ransomware gangs use the same forumto recruit members (developers) and collaborators (customers). Many of these gangs infiltrate corporate networks by exploiting devices such as Pulse Secure VPN servers and then deploy ransomware payloads and demand huge ransoms from their victims.
Publishing this list poses a lot of risks for any company that has failed to patch their Pulse Secure VPN in the past year, as some of the ransomware gangs operating on this forum are very likely to use the list for future attacks. Therefore, companies should patch their Pulse Secure VPNs and change their passwords.
