A massive botnet comprising over 100,000 unique IP addresses from more than 100 countries has launched a coordinated campaign targeting Remote Desktop Protocol (RDP) services in the United States. The campaign, first detected by GreyNoise researchers on October 8, 2025, was identified after a significant spike in malicious traffic, particularly from Brazilian IP space, prompted a deeper investigation into global attack patterns. The botnet's activity is characterized by two primary attack vectors: RD Web Access timing attacks and RDP web client login enumeration, both designed to exploit weaknesses in RDP authentication and access mechanisms. Analysis revealed that the vast majority of attack traffic shared a similar TCP fingerprint, with only the Maximum Segment Size (MSS) varying, likely due to differences in the compromised botnet clusters. This technical uniformity, along with the synchronized timing and consistent attack patterns, strongly suggests centralized control by a single threat actor or group. The source IPs involved in the campaign span over 100 countries, including Brazil, Argentina, Iran, China, Mexico, Russia, South Africa, and Ecuador, indicating the global reach and scale of the botnet. The campaign's primary focus is on US-based RDP services, raising concerns about potential unauthorized access, data breaches, and lateral movement within targeted networks. The attacks are ongoing and have been described as highly coordinated, with the botnet operators likely activating the infected nodes specifically for this campaign. Security researchers have advised organizations to implement strict access controls for RDP services, such as restricting access via VPNs or firewalls, to mitigate the risk posed by such large-scale automated attacks. The use of login enumeration and timing attacks suggests the attackers are probing for valid credentials and weaknesses in authentication flows, which could lead to successful brute-force or credential-stuffing attempts. The campaign's discovery underscores the persistent threat posed by botnets leveraging globally distributed infrastructure to evade traditional geofencing and IP-blocking defenses. Organizations are urged to monitor RDP access logs for unusual activity, apply multi-factor authentication, and ensure that RDP endpoints are not exposed directly to the internet. The scale and sophistication of this botnet operation highlight the evolving tactics of cybercriminals targeting remote access services, especially in the wake of increased remote work and reliance on RDP. The coordinated nature of the attacks, as well as the technical indicators observed, provide valuable intelligence for defenders seeking to identify and block malicious RDP traffic. This incident serves as a reminder of the critical importance of securing remote access protocols and maintaining robust network segmentation to limit the impact of potential intrusions. Ongoing monitoring and threat intelligence sharing are essential to detect and respond to such widespread and rapidly evolving attack campaigns.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Security researchers reported a coordinated global campaign using more than 100,000 IP addresses to scan for exposed Remote Desktop Protocol services, with activity notably targeting systems in the United States. The two references describe the same large-scale RDP scanning operation and do not provide an earlier distinct event date.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.