Malicious Scanning Waves Slam Remote Desktop Services
ID: 13c1fc85-51ee-5cde-aa36-35a125453cf2
STIX ID: report--13c1fc85-51ee-5cde-aa36-35a125453cf2
Feed Name: Dark Reading
Threat intelligence from GreyNoise and reporting indicate two massive RDP scanning waves (Aug 21 and Aug 24) originating from thousands of IPs—largely consumer ISPs concentrated in Latin America—targeting US endpoints and probing Microsoft RD Web Access/RDP Web Client authentication flows to enumerate usernames and test for timing flaws that could presage a zero-day; the activity likely reflects a centrally controlled botnet or large proxy fleet and elevates the risk of credential-stuffing, password spraying, and follow-on intrusions against primarily education-sector targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
