Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP Devices
Between June and July 2025, a Ukrainian IP network was the victim of extensive password-spraying and brute-force attacks by cybersecurity researchers against SSL VPN and RDP devices.
French cybersecurity firm Intrinsec claims that the activity started with an autonomous system called FDN3 (AS211736) located in Ukraine.
We are confident that FDN3 is a component of a larger abusive infrastructure that includes two other Ukrainian networks, VAIZ-AS (AS61432) and ERISHENNYA-ASN (AS210950), as well as an autonomous system TK-NET (AS210848) situated in Seychelles, according to a report released last week.
They were all assigned in August 2021, and in order to avoid blocklisting and carry on hosting abusive activities, they frequently trade IPv4 prefixes with one another read more about...


