Hackers Actively Scanning to Exploit Microsoft Remote Desktop Protocol Services From 30,000+ IPs
ID: ead64614-cee5-5f58-aae8-ee02397e2068
STIX ID: report--ead64614-cee5-5f58-aae8-ee02397e2068
Feed Name: cybersecurityNews.com
A massive coordinated scanning campaign observed in August 2025 used over 30,000 unique IPs (with an initial wave of ~2,000 on Aug 21) to probe Microsoft RD Web Access and RDP Web Client for timing-based authentication/username enumeration; activity was heavily concentrated against U.S. educational RDP endpoints and showed uniform client signatures consistent with centralized botnet or APT infrastructure, indicating preparation for credential-based attacks or larger exploitation campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
