What GreyNoise Caught
On August 3, 2025, threat intelligence firm GreyNoise detected an unprecedented surge in brute-force login attempts targeting Fortinet SSL VPN appliances, with over 780 unique IP addresses involved in a single day.
Here's the part that makes my team sit up. Historically, 80% of similar brute-force surges are followed by public vulnerability disclosures, often within six weeks. If that pattern holds, defenders should prepare for the possibility of a zero-day or new CVE affecting FortiOS or FortiManager before late September.
I've watched this same playbook run against edge appliances before. The noise comes first, the CVE comes later, and the gap between them is where attackers do their quiet pre-positioning. We saw a comparable edge-device scramble in our coverage of the Citrix NetScaler zero-day CVE-2025-6543.
How the Campaign Unfolded
Initial spike, August 3, 2025
- FortiOS SSL VPN profiles targeted.
- A single distinct TCP signature observed, which suggests one specific brute-force tool.
- Over 780 unique IPs participated, breaking prior records.
Evolution phase, August 5, 2025
- The attack methodology pivoted.
- A new TCP signature with distinct client fingerprints appeared, possibly indicating new tooling or updated modules.
- Targeting expanded from FortiOS to include FortiManager (FGFM) services.
Where the Traffic Concentrated
Over the past 90 days, Hong Kong and Brazil have been the most targeted regions. A lot of this traffic is proxied, so geography isn't destiny here, but these hotspots may line up with high-value Fortinet deployments.
Two Distinct Waves
| Wave | Description | Notes |
|---|---|---|
| One | Long-term campaign | Same TCP signature for weeks/months; persistent ops |
| Two | Coordinated burst | New TCP signature; simultaneous VPN and FGFM focus |
- Wave One: A stable TCP signature, likely running from established infrastructure.
- Wave Two: Began August 5 with retooled methods and expanded targeting. My read is that these are the same operators iterating, not a new crew.
Infrastructure Tells
- Residential proxy presence: GreyNoise observed a FortiGate device sitting at a residential ISP (Pilot Fiber Inc.), possibly used as a proxy, a compromised home device, or a test environment.
- Toolset reuse: Several IPs active on August 3 link back to known malicious infrastructure, which points to shared resources between operations.
Why the Timing Worries Me
GreyNoise data shows that brute-force spikes against Fortinet often precede CVEs, with 80% resulting in a disclosure within six weeks. That makes August through September 2025 a critical monitoring period, not a quiet one.
Fortinet SSL VPN and FortiManager are key gateways into corporate networks, and they're usually exposed straight to the public internet. That makes them prime targets for:
- Initial Access Brokers (IABs)
- Ransomware affiliates
When you see brute-force at this scale, treat it as credential harvesting in preparation for whatever comes next, especially if a new vulnerability surfaces. The harvested-then-resold pattern is exactly what we documented in our look at the infostealer epidemic and MFA bypass.
A point most VPN-hardening checklists miss: brute-force tells you someone is knocking, but it can't tell you when a valid credential finally works. That's the detection gap deception fills. Seed your VPN and management tiers with credential honeytokens, and the first time stolen Fortinet creds get tried, you get a high-fidelity alert instead of a line buried in an auth log.
What Defenders Should Do Now
- Restrict VPN access: Block risky regions where you can.
- Rate limiting: Apply authentication rate limits.
- Enforce MFA: Require it for all VPN and FortiManager accounts.
- Patch now: Apply the latest security updates.
- Watch Fortinet bulletins: Keep an eye on advisories for the next six weeks.
- Audit logs: Check for unusual login failures or geolocation anomalies.
- Block IOCs: Add them to your firewall, SIEM, and threat intel feeds.
If you take one thing from this analysis, let it be the calendar. The brute-force noise is the early warning. Want to see how deception turns that warning into a trap an attacker can't avoid tripping? Book a Mine2 demo and we'll walk your VPN and FortiManager exposure together.
Riya
Principal Threat Researcher, Mine2 Labs
Riya tracks active threat campaigns and APT tradecraft at Mine2 Labs, translating real-world attacker behaviour into practical detection ideas.
Recent Articles
FortiClient EMS Under Fire: CVE-2026-21643 Turns Endpoint Management Into an Attacker's Credential Goldmine
WinRAR Zero-Day Vulnerability CVE-2025-8088 Exploited by RomCom to Deliver Backdoor Malware
27 Seconds: What CrowdStrike's 2026 Threat Report Really Means for Your Detection Stack
Need Security Help?
Protect your organization with MINE2's cyber deception platform.
