Cybersecurity researchers have identified a Ukrainian IP network for its involvement in massive brute-force and password spraying campaigns targeting SSL VPN and RDP devices between June and July 2025.
See also: Vulnerabilities in Sitecore Experience allow remote code execution

The activity originated from a Ukraine-based autonomous system, FDN3 (AS211736), according to French cybersecurity firm Intrinsec. They believe FDN3 is part of a broader malicious infrastructure that includes two other Ukrainian networks, VAIZ-AS (AS61432) and ERISHENNYA-ASN (AS210950), as well as a Seychelles-based autonomous system, TK-NET (AS210848). These networks were all split in August 2021 and frequently exchange IPv4 prefixes with each other to evade the block list and continue to host malicious activity.
The two autonomous systems were distributed in May and August 2021, respectively. A large portion of their prefixes have been announced in AS210848, another autonomous system that was also distributed in August 2021. This network shares all of its interconnection agreements with IP Volume Inc. – AS202425, a Seychelles-based company created by the owners of Ecatel, known for extensive malicious bulletproof hosting in the Netherlands since 2005.
The set of prefixes moved from AS61432 and AS210950 are now being advertised by bulletproof and malicious networks hosted by companies such as Global Internet Solutions LLC, Global Connectivity Solutions LLP, Verasel, IP Volume Inc., and Telkom Internet LTD. The findings build on previous revelations about how multiple networks that were compromised in August 2021 and are based in Ukraine and Seychelles – AS61432, AS210848, and AS210950 – were used to distribute spam, network attacks, and host command and control malware. In June 2025, some of the IPv4 prefixes advertised by these networks were moved to FDN3, which was created in August 2021.
See also: TeamFiltration attacks target 80,000 Microsoft Entra ID accounts

Additionally, three of the prefixes announced by AS210848 and one by AS61432 were previously announced by another Russian network, SibirInvest OOO (AS44446). Of the four IPv4 prefixes announced by FDN3, one of them (88.210.63[.]0/24) is believed to have been previously announced by an American bulletproof hosting solution called Virtualine (AS214940 and AS214943).
This IPv4 prefix range has been attributed to large brute-force and password spraying attempts, with activity escalating to record levels between July 6 and 8, 2025. Brute-force and password spraying attempts targeting SSL VPN and RDP assets could last up to three days, according to Intrinsec. These techniques have been adopted by various ransomware-as-a-service (RaaS) groups such as Black Basta, GLOBAL GROUP, and RansomHub as an initial means of access to compromise corporate networks.
Intrinsec explained that strong similarities, including configuration, hosted content, and creation date, led them to assess with a high level of confidence that the aforementioned autonomous systems are operated by a common bulletproof hosting manager.
Further analysis by FDN3 revealed links to a Russian company called Alex Host LLC, which has been linked to bulletproof hosting providers such as TNSECURITY, which have been used to host Doppelganger infrastructure. This research highlights a common phenomenon of offshore ISPs such as IP Volume Inc. enabling smaller bulletproof networks through interconnection and prefix hosting agreements. Thanks to their offshore location, such as the Seychelles, which provides anonymity to the owners of these companies, malicious activity committed through these networks cannot be directly attributed to them.
See also: Coordinated Brute-Force Attacks on Apache Tomcat Manager

Brute-Force attacks are a method of trying all possible combinations to “break” a password or access key. They are usually applied to login systems, where the attacker continuously tries different passwords until he finds the right one. Although time-consuming, it is effective when the passwords are simple or common. To prevent such attacks, it is recommended to use strong and unique passwords, activate rate limiting mechanisms, CAPTCHA, and multi-factor authentication (MFA). It is one of the most common forms of cyberattacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
