Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Samsung showed me its secret HDR10+ Advanced TV samples – and I’m almost sold

    November 8, 2025

    Starbucks barista’s side hustle brings in $1 million a month

    November 8, 2025

    A new Chinese AI model claims to outperform GPT-5 and Sonnet 4.5 – and it’s free

    November 8, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Huge multi-country botnet targets RDP services in the US
    Security

    Huge multi-country botnet targets RDP services in the US

    PineapplesUpdateBy PineapplesUpdateOctober 13, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Huge multi-country botnet targets RDP services in the US
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Huge multi-country botnet targets RDP services in the US

    A large-scale botnet is targeting Remote Desktop Protocol (RDP) services from over 100,000 IP addresses in the United States.

    The campaign began on October 8 and based on the source of the IPs, researchers believe the attacks were launched by a multi-country botnet.

    RDP is a network protocol that enables remote connection and control of Windows systems. It is commonly used by administrators, helpdesk staff, and remote workers.

    Attackers often scan open RDP ports or attempt to force logins, exploit vulnerabilities, or conduct timing attacks.

    In this case, researchers at threat monitoring platform Grenois found that the botnet relied on two types of RDP-related attacks:

    1. RD web access timing attack – RD probes web access endpoints and measures response-time differences during anonymous authentication flows to guess valid usernames
    2. RDP web client login count – Interacts with the RDP web client login flow to enumerate user accounts by observing differences in server behavior and responses

    Grenois discovered the campaign after an unusual traffic increase from Brazil, which was followed by similar activity from a broader geography, including Argentina, Iran, China, Mexico, Russia, South Africa, and Ecuador.

    The company says the full list of countries with compromised devices in the botnet exceeds 100.

    Increase in unusual activity from Brazil
    Increase in unusual activity from Brazil
    Source: Grenoise

    Almost all IP addresses share a common TCP fingerprint, and although there are variations in (maximum segment size), Researchers believe These are due to the groups creating botnets.

    To protect against this activity, system administrators are advised to block IP addresses launching attacks and check logs for suspicious RDP probes.

    As a general recommendation, a remote desktop connection should not be exposed to the public Internet. Adding a VPN and multi-factor authentication (MFA) adds a layer of security.


    PICS BAS Summit

    attend Breach and Attack Simulation Summit and experience future of security verificationHear from top experts and see how AI-powered BAS Changing breach and attack simulations.

    Don’t miss the event that will shape the future of your security strategy

    botnet huge multicountry RDP services Targets
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHacker accesses 100,000 IP addresses for RDP-Angriffe
    Next Article He moved to America and started a business worth $1B+
    PineapplesUpdate
    • Website

    Related Posts

    Security

    Your Uber driver has a new endeavor: training an AI for cash

    October 18, 2025
    Security

    American Airlines subsidiary Envoy confirms Oracle data breach attack

    October 18, 2025
    Security

    Government considers destroying its data hub after decade-long intrusion

    October 18, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    Samsung showed me its secret HDR10+ Advanced TV samples – and I’m almost sold

    November 8, 2025

    Starbucks barista’s side hustle brings in $1 million a month

    November 8, 2025

    A new Chinese AI model claims to outperform GPT-5 and Sonnet 4.5 – and it’s free

    November 8, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.