Mysterious "LOVE" packet storms flood the internet since 2020
ID: 32923fc7-7879-5881-b6bf-c915ead560b1
STIX ID: report--32923fc7-7879-5881-b6bf-c915ead560b1
Feed Name: Bleeping Computer
GreyNoise reports persistent “Noise Storms” of spoofed internet traffic since January 2020 that mimic legitimate activity—targeting TCP/443, embedding a “LOVE” string in ICMP, and tuning window sizes and TTLs to resemble real systems—while concentrating on certain ISPs and avoiding AWS; the purpose remains unclear (covert comms, DDoS signaling, C2, or misconfiguration), and GreyNoise has published PCAPs and requested community investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
