logo

The Behavior of Coordinated SSH Brute Force Attacks over the last three months [Guest Diary], (Wed, Jun 17th)

ID: 3fc16edb-8ee8-56c6-81f9-039daa567b3d

STIX ID: report--3fc16edb-8ee8-56c6-81f9-039daa567b3d

Feed Name: SANS ISC Diary

Threat Score
60/100

Date Published: 2026-06-18

Date Updated: 2026-06-21

...
...

This guest-diary style report analyzes nearly 100 days of Cowrie/DShield honeypot logs that recorded over 20 million SSH brute-force attempts, highlighting coordinated botnet behavior (shared HASSH fingerprint, synchronized scans, and quota-assigned rates), correlating activity spikes with geopolitical events and public vulnerability disclosures, listing top probing IPs and ASNs, and providing practical mitigation and detection guidance such as disabling root login, enforcing MFA, using SSH keys, and centralized SIEM monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.