Fortinet SSL VPN and FortiManager Under Coordinated Brute-Force Campaign: August 2025 Threat Analysis
Riya4 min read

Fortinet SSL VPN and FortiManager Under Coordinated Brute-Force Campaign: August 2025 Threat Analysis

GreyNoise reports a record-breaking spike in brute-force attempts against Fortinet SSL VPN and FortiManager, raising concerns of a potential zero-day disclosure within weeks.

Share:

What GreyNoise Caught

On August 3, 2025, threat intelligence firm GreyNoise detected an unprecedented surge in brute-force login attempts targeting Fortinet SSL VPN appliances, with over 780 unique IP addresses involved in a single day.

Here's the part that makes my team sit up. Historically, 80% of similar brute-force surges are followed by public vulnerability disclosures, often within six weeks. If that pattern holds, defenders should prepare for the possibility of a zero-day or new CVE affecting FortiOS or FortiManager before late September.

I've watched this same playbook run against edge appliances before. The noise comes first, the CVE comes later, and the gap between them is where attackers do their quiet pre-positioning. We saw a comparable edge-device scramble in our coverage of the Citrix NetScaler zero-day CVE-2025-6543.


How the Campaign Unfolded

Initial spike, August 3, 2025

  • FortiOS SSL VPN profiles targeted.
  • A single distinct TCP signature observed, which suggests one specific brute-force tool.
  • Over 780 unique IPs participated, breaking prior records.

Evolution phase, August 5, 2025

  • The attack methodology pivoted.
  • A new TCP signature with distinct client fingerprints appeared, possibly indicating new tooling or updated modules.
  • Targeting expanded from FortiOS to include FortiManager (FGFM) services.

Where the Traffic Concentrated

Over the past 90 days, Hong Kong and Brazil have been the most targeted regions. A lot of this traffic is proxied, so geography isn't destiny here, but these hotspots may line up with high-value Fortinet deployments.


Two Distinct Waves

Wave Description Notes
One Long-term campaign Same TCP signature for weeks/months; persistent ops
Two Coordinated burst New TCP signature; simultaneous VPN and FGFM focus
  • Wave One: A stable TCP signature, likely running from established infrastructure.
  • Wave Two: Began August 5 with retooled methods and expanded targeting. My read is that these are the same operators iterating, not a new crew.

Infrastructure Tells

  • Residential proxy presence: GreyNoise observed a FortiGate device sitting at a residential ISP (Pilot Fiber Inc.), possibly used as a proxy, a compromised home device, or a test environment.
  • Toolset reuse: Several IPs active on August 3 link back to known malicious infrastructure, which points to shared resources between operations.

Why the Timing Worries Me

GreyNoise data shows that brute-force spikes against Fortinet often precede CVEs, with 80% resulting in a disclosure within six weeks. That makes August through September 2025 a critical monitoring period, not a quiet one.

Fortinet SSL VPN and FortiManager are key gateways into corporate networks, and they're usually exposed straight to the public internet. That makes them prime targets for:

  • Initial Access Brokers (IABs)
  • Ransomware affiliates

When you see brute-force at this scale, treat it as credential harvesting in preparation for whatever comes next, especially if a new vulnerability surfaces. The harvested-then-resold pattern is exactly what we documented in our look at the infostealer epidemic and MFA bypass.

A point most VPN-hardening checklists miss: brute-force tells you someone is knocking, but it can't tell you when a valid credential finally works. That's the detection gap deception fills. Seed your VPN and management tiers with credential honeytokens, and the first time stolen Fortinet creds get tried, you get a high-fidelity alert instead of a line buried in an auth log.


What Defenders Should Do Now

  • Restrict VPN access: Block risky regions where you can.
  • Rate limiting: Apply authentication rate limits.
  • Enforce MFA: Require it for all VPN and FortiManager accounts.
  • Patch now: Apply the latest security updates.
  • Watch Fortinet bulletins: Keep an eye on advisories for the next six weeks.
  • Audit logs: Check for unusual login failures or geolocation anomalies.
  • Block IOCs: Add them to your firewall, SIEM, and threat intel feeds.

If you take one thing from this analysis, let it be the calendar. The brute-force noise is the early warning. Want to see how deception turns that warning into a trap an attacker can't avoid tripping? Book a Mine2 demo and we'll walk your VPN and FortiManager exposure together.

M2

Riya

Principal Threat Researcher, Mine2 Labs

Riya tracks active threat campaigns and APT tradecraft at Mine2 Labs, translating real-world attacker behaviour into practical detection ideas.

Share this article

Secure Your Network Today

Ready to implement advanced cyber deception in your organization? See how MINE2 can transform your threat detection capabilities.