logo

Unexplained ‘Noise Storms’ flood the Internet, puzzle experts

ID: 37dcfb5e-29d8-5dda-8c39-3b1eddc269f9

STIX ID: report--37dcfb5e-29d8-5dda-8c39-3b1eddc269f9

Feed Name: Bleeping Computer

Threat Score
45/100

Date Published: 2024-09-19

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

GreyNoise has observed recurring large waves of spoofed internet traffic called “Noise Storms” that originate from millions of spoofed IPs, concentrate on certain ISPs (e.g., Cogent, Lumen, Hurricane Electric), target TCP (notably port 443) and ICMP (recently containing an embedded "LOVE" ASCII string), and use packet attributes (TTL, window sizes) to mimic real hosts; GreyNoise released PCAPs and requests community assistance to determine whether this is covert comms, DDoS coordination, clandestine C2 activity, or a misconfiguration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.