Cisco is advising customers to protect themselves from password-spraying attacks targeting Remote Access VPN (RAVPN) configured on Cisco Secure Firewall devices .

Password-spraying attacks are a technique hackers use to gain access to a user account. Instead of trying many different passwords on a specific account, attackers try a common password on multiple accounts.
This technique is effective because many users use simple and widely used passwords. Additionally, password-spraying attacks circumvent security systems that lock an account after a certain number of failed password attempts.
See also: Cisco patches critical vulnerabilities in IOS XR software
A key protection measure is using strong and unique passwords for each account. Additionally, using multi-factor authentication can add an extra layer of security.
Cisco's guide lists indicators of compromise (IoC) for this malicious activity to help identify and block attacks
For example, one indicator is the inability to establish VPN connections with Cisco Secure Client (AnyConnect) when Firewall Posture (HostScan) is enabled. Another sign is an unusual number of authentication requests ,recorded by system logs.
Cisco: Tips for defending against password-spraying attacks
- Enable logging to a remote syslog server to improve incident analysis and correlation.
- Securing default remote access VPN profiles by pointing unused default connection profiles to a sinkhole AAA server to prevent unauthorized access.
- TCP shun for manual blocking of malicious IPs.
- Configure control-plane ACLs to filter unauthorized public IP addresses when initiating VPN sessions.
- Use certificate-based authentication for RAVPN.
See also: Cisco: Patch released for serious vulnerability in Secure Client

How is it related to the Brutus botnet?
Security researcher Aaron Martin told BleepingComputer that the password-spraying attacks that Cisco has identified are likely related to a botnet he has dubbed “ Brutus .” The connection is based on the specific targeting scope and attack patterns .
Martin published a report on the Brutus botnet describing the unusual attack methods it uses. The botnet currently relies on 20,000 IP addresses worldwide, spanning infrastructure ranging from cloud services to home addresses.
See also: Cisco: Critical flaw exposes Expressway gateways to CSRF attacks
The password-spraying attacks that the researcher saw initially targeted SSLVPN devices from Fortinet, Palo Alto, SonicWall, and Cisco, but are now also targeting applications webthat use Active Directory for authentication.
Brutus rotates its IPs every six attempts to avoid detection and blocking.
Although Brutus' operators are unknown, Martin identified two IPs that have been associated with previous activities by APT29 (Midnight Blizzard, NOBELIUM, Cozy Bear), which is believed to work for the Russian Foreign Intelligence Service (SVR).
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
