logo

Malicious Scanning Waves Slam Remote Desktop Services

ID: 13c1fc85-51ee-5cde-aa36-35a125453cf2

STIX ID: report--13c1fc85-51ee-5cde-aa36-35a125453cf2

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-08-26

Date Updated: 2026-05-05

Author: Rob Wright

...
...

Threat intelligence from GreyNoise and reporting indicate two massive RDP scanning waves (Aug 21 and Aug 24) originating from thousands of IPs—largely consumer ISPs concentrated in Latin America—targeting US endpoints and probing Microsoft RD Web Access/RDP Web Client authentication flows to enumerate usernames and test for timing flaws that could presage a zero-day; the activity likely reflects a centrally controlled botnet or large proxy fleet and elevates the risk of credential-stuffing, password spraying, and follow-on intrusions against primarily education-sector targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.