Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Attacking Remote Desktop Protocol Services With 30,000+ New IP Addresses Daily

## Cybersecurity: RDP Services Targeted by Botnet Campaign

Cybersecurity: RDP Services Targeted by Botnet Campaign

A recent campaign has been observed targeting Microsoft Remote Desktop Protocol (RDP) services . Attackers have been deploying over 30,000 new IP addresses daily to exploit timing-based vulnerabilities.

This operation, linked to a global botnet, has seen the number of unique IP addresses exceed 500,000 since September 2025, primarily targeting systems in the United States.

The attacks focus on two main vectors: RD Web Access anonymous authentication timing attacks and RDP web client login enumeration checks. These methods enable attackers to probe for vulnerabilities without triggering alerts, utilizing rapid IP rotations to evade traditional blocking mechanisms.

GreyNoise first identified the scale of this botnet on October 8, 2025. A significant increase in Brazilian-sourced traffic revealed similar TCP fingerprints across numerous endpoints.

By October 14, the botnet expanded to approximately 300,000 IPs, tripling in size within a few days and originating from over 100 countries.

Brazil accounts for 63% of the sources, followed by Argentina at 14% and Mexico at 3%, with the majority of targets located in the United States.

A recent campaign has been observed targeting Microsoft Remote Desktop Protocol (RDP) services .
John Mason · Thehackingpost

This consistency in source-target dynamics suggests centralized control, potentially orchestrated by a single threat actor or group.

Daily activity charts from GreyNoise demonstrate the relentless pace, with total unique IPs and newly observed ones peaking above 40,000 in mid-October.

Cumulative graphs indicate a steep increase, surpassing 500,000 unique IPs by October 15, highlighting the evolving risk of infrastructure churn.

Experts note that static IP blocking is ineffective against this high-turnover botnet, as new nodes are activated daily to sustain the attack.

Advertisement

This campaign exemplifies a broader trend where attackers complicate attribution and evasion using disposable infrastructure.

As RDP remains a key entry point for ransomware and data breaches, U.S. entities, particularly those relying on remote access, face heightened exposure. GreyNoise continues monitoring, advising log reviews for unusual RDP probes linked to these tags.

The operation's growth from 100,000 to over 500,000 IPs indicates potential for further escalation, necessitating proactive defenses beyond conventional measures.

With the botnet's focus on U.S. infrastructure, immediate adoption of intelligence-driven blocking could help prevent widespread compromise.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories