logo

Hiding in Plain Sight: Tracking Bulletproof Hosting and Abused RDP Infrastructure

ID: f8735a28-dd31-5fc0-9f3e-2b171f20eca9

STIX ID: report--f8735a28-dd31-5fc0-9f3e-2b171f20eca9

Feed Name: Censys Blog

Threat Score
78/100

Date Published: 2026-02-03

Date Updated: 2026-04-27

Author: Ivonne Francia; Himaja Motheram

...
...

This report demonstrates how abuse-tolerant "bulletproof" hosting is tracked by correlating reused Windows RDP hostnames, Censys scan data, and GreyNoise telemetry to reveal persistent malicious infrastructure—including templated Windows images reused across thousands of hosts, active C2/open directories, and brute-force-as-a-service artifacts—and recommends operationalizing aggregated hostname signals to proactively block risky infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.