(anonymous)
ID: 95568888-9e52-4ff4-a741-3da173ee4f3a
STIX ID: report--95568888-9e52-4ff4-a741-3da173ee4f3a
Threat Score
75/100
Uploaded: 2026-08-11
Published Date: 2026-04-01
Last Modified Date: 2026-04-01
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
GreyNoise analyzed 90 days of unsolicited internet traffic and found residential proxies and compromised consumer devices driving billions of malicious sessions: legacy SMB worms and Telnet-recruited IoT botnets create two separate supply chains while commercial proxy SDK fleets and VPN-routed reconnaissance enable large-scale, rotating, reputation-evasive scanning used by hundreds of threat groups (including state-affiliated actors). The report shows rapid IP turnover and single-touch rotation that defeats IP-based blocklists, identifies behavioral and fingerprinting signals (circadian patterns, JA4T/TCP fingerprints, port/protocol dominance) as higher-fidelity detections, and recommends blocking inbound residential SMB, preventing outbound Telnet from IoT/OT, credential hygiene, and behavioral detection focused on rotation patterns and device fingerprints.
