logo

-f Around and Find Out: 18 Hours of Unsolicited Telnet Houseguests

ID: 60201428-c341-524e-87c5-38f0342d6c5d

STIX ID: report--60201428-c341-524e-87c5-38f0342d6c5d

Feed Name: GreyNoise Labs

Threat Score
70/100

Date Published: 2026-01-22

Date Updated: 2026-04-27

Author: hrbrmstr + 🔮Orbie✨

...
...

**Executive summary:** Analysis of a coordinated exploitation campaign leveraging the Inetutils telnetd `-f` authentication bypass: 60 Telnet exploitation attempts from 18 source IPs resulted in shell access on some hosts, followed by reconnaissance, SSH key persistence attempts and an attempted Python-based second-stage fetch; the report provides PCAP-derived payload patterns, a taxonomy of payload variants and a list of IOCs (attacker IPs, payload fingerprints, and a malware distribution URL).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.