logo

Mysterious "LOVE" packet storms flood the internet since 2020

ID: 32923fc7-7879-5881-b6bf-c915ead560b1

STIX ID: report--32923fc7-7879-5881-b6bf-c915ead560b1

Feed Name: Bleeping Computer

Date Published: 2024-09-19

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

GreyNoise reports persistent “Noise Storms” of spoofed internet traffic since January 2020 that mimic legitimate activity—targeting TCP/443, embedding a “LOVE” string in ICMP, and tuning window sizes and TTLs to resemble real systems—while concentrating on certain ISPs and avoiding AWS; the purpose remains unclear (covert comms, DDoS signaling, C2, or misconfiguration), and GreyNoise has published PCAPs and requested community investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.