logo

How Attackers Use Shodan & FOFA by Lucie Cardiet

ID: 8432718d-ee1b-54f5-8885-308ca1e866c5

STIX ID: report--8432718d-ee1b-54f5-8885-308ca1e866c5

Feed Name: Vectra AI Blog

Threat Score
75/100

Date Published: 2025-04-24

Date Updated: 2026-05-01

...
...

This report details how attackers use internet metadata search engines (Shodan, FOFA, ZoomEye) to enumerate exposed devices and services, then pursue credential brute-force and CVE-driven exploitation (highlighting CVE-2024-23897 against Jenkins) to achieve initial access—using Black Basta as an example—and describes how Vectra AI detects related anomalous behavior to disrupt these attack chains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.