Password Spraying Activity
ID: 2bc8ec3d-0584-5ecf-964d-9830a7a491d9
STIX ID: report--2bc8ec3d-0584-5ecf-964d-9830a7a491d9
Feed Name: Arctic Wolf Blog
Arctic Wolf observed an ongoing password-spraying campaign starting 28 Feb 2024 that targets web-based authentication on VPNs and firewalls across multiple vendors (including Cisco, Palo Alto Networks, and WatchGuard). The activity involves high-volume automated login attempts using random or non-existent usernames; no confirmed successful compromises have been seen. Arctic Wolf recommends implementing MFA, blocking or classifying hosting-provider traffic, enabling automated login blocking/throttling, forwarding VPN/firewall logs to MDR, and considering geolocation blocks to reduce exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
