How stolen VPN credentials became the entry point for ransomware and wipers
Kaspersky has published new research identifying three distinct threat clusters targeting Russian enterprises, and the common thread running through all of them is unsettling in its simplicity: compromised VPN credentials. Rather than relying solely on zero-day exploits or complex malware development, the attackers behind these campaigns reportedly used stolen or misused VPN login details to walk through the front door of corporate networks. From there, they deployed a mix of backdoors, ransomware, and destructive wiper malware.
This pattern reflects a broader trend that security researchers have been flagging across the industry. A compromised VPN credentials attack doesn't require the sophistication of a novel exploit. It only requires one valid username and password, often obtained through phishing, credential stuffing, or purchase from underground markets. Once an attacker has that access, a VPN designed to keep outsiders out instead becomes a trusted tunnel straight into the network, indistinguishable from legitimate remote employee traffic.
What the three threat clusters reveal about enterprise VPN security gaps
According to Kaspersky's findings, each of the three clusters pursued different end goals, ranging from establishing persistent backdoor access to encrypting data for ransom to deploying wipers designed purely to destroy systems rather than extract payment. What ties them together isn't shared tooling or attribution to a single group, but a shared method of initial access: VPN credentials that should never have been usable by an outsider.
That overlap matters. It suggests that Russian enterprises, like organizations elsewhere, are dealing with the same structural weakness: VPN access is often treated as a one-time authentication event rather than a continuously monitored trust relationship. Once a credential set is valid, many VPN configurations grant broad network access without additional verification, segmentation, or behavioral monitoring. Attackers exploiting that gap don't need to breach a firewall in the traditional sense. They just need a password that hasn't been rotated, flagged, or protected with multi-factor authentication.
This kind of credential-based intrusion often flies under the radar compared to headline-grabbing breaches. As covered in a recent roundup of Russian Zimbra spying and Stadler Rail extortion incidents, many of the most consequential attacks never make front-page news, even though they rely on the same infrastructure-level weaknesses seen in Kaspersky's report. Credential and access-based attacks are frequently underreported precisely because they lack the drama of a single dramatic exploit, but they are just as damaging.
Credential hygiene practices that prevent VPN-based breaches
The good news is that a compromised VPN credentials attack is one of the more preventable categories of intrusion, provided organizations treat VPN access with the same rigor as any other privileged system. A few practices consistently reduce this risk:
- Enforce multi-factor authentication on every VPN login, not just for administrator accounts
- Rotate credentials regularly and immediately after any suspected phishing incident
- Monitor VPN logs for logins from unusual locations, devices, or times that deviate from normal employee behavior
- Segment network access so that a single VPN login doesn't grant broad, unrestricted movement across internal systems
- Retire unused or dormant VPN accounts promptly, since forgotten credentials are frequently the ones attackers find easiest to exploit
None of these measures are exotic. They are standard identity and access management practices that many organizations already know about but fail to consistently enforce, especially across remote work environments where VPN usage has expanded rapidly in recent years.
What This Means For You
Most readers of this site aren't running enterprise VPN infrastructure, but the lesson from Kaspersky's research applies just as directly to personal VPN use. If you reuse passwords across services, skip multi-factor authentication, or hold onto old VPN accounts you no longer use, you're exposed to the same fundamental weakness that let these three threat clusters into Russian enterprise networks. A VPN is only as secure as the credentials protecting it.
For businesses, this report is a reminder that VPN security isn't a "set it and forget it" tool. It requires active credential management, monitoring, and periodic review, especially as remote and hybrid work continues to rely heavily on VPN access for daily operations.
Actionable Takeaways
- Enable multi-factor authentication on any VPN account you use, personal or professional
- Use a password manager to avoid reusing VPN credentials across multiple services
- Regularly audit and remove VPN accounts or devices you no longer use
- If you manage enterprise systems, treat VPN login anomalies as seriously as any other intrusion alert
- Stay informed about credential-based attack trends, since a compromised VPN credentials attack often causes as much damage as a sophisticated exploit, with far less fanfare




