Cisco ASA SSL VPN Appliances is a type of network security device that allows remote users to access a private network over the internet securely.
These appliances are mainly used by organizations to do the following things:-
Since March 2023, the managed detection and response (MDR) teams of Rapid7 have noted a surge in threats to Cisco ASA SSL VPN devices, both physical and virtual.
Threat actors often exploit weak passwords or launch targeted brute-force attacks on ASA appliances lacking MFA, resulting in several incidents of Akira and LockBit groups deploying ransomware.
Targets span various sectors with no distinct pattern, and here below, we have mentioned the sectors:-
However, researchers at Rapid7 have confirmed that they have not seen any successful MFA bypasses when properly configured.
From March 30 to August 24, 2023, 11 Rapid7 customers faced Cisco ASA intrusions. SSL VPN-using ASA appliances were compromised, with patch variations across them; no version stood out as unusually vulnerable.
Cybersecurity analysts noted overlap in IOCs like:-
Here below, we have mentioned all the common usernames that threat actors use to log into ASA appliances:-
Rapid7 monitors underground forums and Telegram for attacker discussions on ASA attacks. In Feb 2023, “Bassterlord,” a renowned initial access broker, sold a $10k corporate network access guide with SSL VPN brute forcing insights.
Moreover, the leaked manual reveals VPN hacking secrets of the threat actors, and it’s been confirmed that 4,865 Cisco and 9,870 Fortinet services were compromised.
Here below, we have mentioned all the mitigations offered by the security researchers:-
AnyDesk:
Other IP addresses that were observed conducting brute force attempts:
Log-based indicators:
Keep informed about the latest Cyber Security News by following us on Google News, Linkedin, Twitter, and Facebook.
Microsoft has introduced Project Zenith, a new developer-optimized Windows 11 experience built for a class…
A financially motivated threat group known as Toy Ghouls has begun using two custom Windows…
NodeStealer has returned with a more invasive toolkit. The Python-based information stealer can now record…
Attackers are using invisible Unicode characters to make phishing emails appear harmless while disrupting the…
Hackers have turned commercial AI models into working parts of a cyberattack operation. The campaign…
Microsoft has confirmed a fresh Exchange Online incident, tracked as EX1467029, causing delays for users…