Massive multi-country botnet targets RDP services in the US
ID: 11123b43-46a9-5776-a0d3-c376d8b2759e
STIX ID: report--11123b43-46a9-5776-a0d3-c376d8b2759e
Feed Name: Bleeping Computer
Threat Score
A multi-country botnet campaign detected by GreyNoise is conducting large-scale RDP probing and account enumeration—using RD Web Access timing attacks and RDP web client login enumeration—originating from over 100,000 IPs across more than 100 countries; defenders are advised to block malicious IPs, avoid exposing RDP to the public internet, and implement VPN and MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
