Hackers Attacking Remote Desktop Protocol Services With 30,000+ New IP Addresses Daily
## Cybersecurity: RDP Services Targeted by Botnet Campaign
Cybersecurity: RDP Services Targeted by Botnet Campaign
A recent campaign has been observed targeting Microsoft Remote Desktop Protocol (RDP) services . Attackers have been deploying over 30,000 new IP addresses daily to exploit timing-based vulnerabilities.
This operation, linked to a global botnet, has seen the number of unique IP addresses exceed 500,000 since September 2025, primarily targeting systems in the United States.
The attacks focus on two main vectors: RD Web Access anonymous authentication timing attacks and RDP web client login enumeration checks. These methods enable attackers to probe for vulnerabilities without triggering alerts, utilizing rapid IP rotations to evade traditional blocking mechanisms.
GreyNoise first identified the scale of this botnet on October 8, 2025. A significant increase in Brazilian-sourced traffic revealed similar TCP fingerprints across numerous endpoints.
By October 14, the botnet expanded to approximately 300,000 IPs, tripling in size within a few days and originating from over 100 countries.
Brazil accounts for 63% of the sources, followed by Argentina at 14% and Mexico at 3%, with the majority of targets located in the United States.
A recent campaign has been observed targeting Microsoft Remote Desktop Protocol (RDP) services .
This consistency in source-target dynamics suggests centralized control, potentially orchestrated by a single threat actor or group.
Daily activity charts from GreyNoise demonstrate the relentless pace, with total unique IPs and newly observed ones peaking above 40,000 in mid-October.
Cumulative graphs indicate a steep increase, surpassing 500,000 unique IPs by October 15, highlighting the evolving risk of infrastructure churn.
Experts note that static IP blocking is ineffective against this high-turnover botnet, as new nodes are activated daily to sustain the attack.
This campaign exemplifies a broader trend where attackers complicate attribution and evasion using disposable infrastructure.
As RDP remains a key entry point for ransomware and data breaches, U.S. entities, particularly those relying on remote access, face heightened exposure. GreyNoise continues monitoring, advising log reviews for unusual RDP probes linked to these tags.
The operation's growth from 100,000 to over 500,000 IPs indicates potential for further escalation, necessitating proactive defenses beyond conventional measures.
With the botnet's focus on U.S. infrastructure, immediate adoption of intelligence-driven blocking could help prevent widespread compromise.
Based on reporting by Cyber Security News.
