logo

Massive multi-country botnet targets RDP services in the US

ID: 11123b43-46a9-5776-a0d3-c376d8b2759e

STIX ID: report--11123b43-46a9-5776-a0d3-c376d8b2759e

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-10-13

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

A multi-country botnet campaign detected by GreyNoise is conducting large-scale RDP probing and account enumeration—using RD Web Access timing attacks and RDP web client login enumeration—originating from over 100,000 IPs across more than 100 countries; defenders are advised to block malicious IPs, avoid exposing RDP to the public internet, and implement VPN and MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.