Threat Pulse W40 — Mass Scan Surge & Critical RCE Campaign Blitz
Executive Summary
The week of 2026-09-21 to 2026-09-28 recorded 95,545 inbound probes across all honeypot facades — a 55.6% spike versus the prior week. The surge was primarily scan-driven, with Telnet and SSH facades absorbing the bulk of traffic. Concurrently, five distinct critical-severity exploitation campaigns each registered identical hit counts (24,210), indicating a coordinated or automated multi-vector campaign framework actively targeting internet-facing infrastructure. Credential stuffing activity against database facades (Redis, PostgreSQL, MySQL, MongoDB) remained persistent and elevated.
Attack Volume & Trends
| Metric | This Week | Change |
|---|---|---|
| Total Probes | 95,545 | +55.6% |
| Scans | 71,341 | Dominant category |
| Bruteforce | 9,389 | Elevated |
| Recon | 9,283 | Elevated |
| RCE Attempts | 4,535 | High |
| Exploit | 990 | Moderate |
| Auth Probes | 13 | Minimal |
Facade breakdown:
| Facade | Hits | Share |
|---|---|---|
| fake-telnet | 44,941 | 47.0% |
| fake-ssh | 25,748 | 27.0% |
| fake-redis | 8,952 | 9.4% |
| fake-https | 5,794 | 6.1% |
| fake-http | 4,488 | 4.7% |
| fake-postgres | 2,962 | 3.1% |
| fake-mysql | 2,004 | 2.1% |
| fake-mongodb | 656 | 0.7% |
Telnet remains the single largest attack surface, absorbing nearly half of all traffic. The sustained pressure on fake-redis (8,952 hits) and database facades is consistent with automated tooling probing for unauthenticated or weakly authenticated data stores.
Top Threat Actors
| Source | Country | ASN / Operator | Events | Primary Behavior |
|---|---|---|---|---|
| 64.207.185.5 | 🇺🇸 US | GoDaddy.com, LLC | 23,170 | Mass scan |
| 83.171.227.54 | 🇫🇷 FR | Baykov Ilya Sergeevich | 7,504 | Mass scan |
| 50.62.135.24 | 🇺🇸 US | GoDaddy.com, LLC | 5,103 | Mass scan |
| 103.46.186.85 | 🇮🇩 ID | PT Air Lintas Komunikasi | 4,885 | Mass scan |
| 31.220.3.165 | 🇩🇪 DE | Amarutu Technology Ltd | 2,915 | Mass scan |
Key observations:
- Two of the top three sources resolve to GoDaddy infrastructure, accounting for a combined 28,273 events (29.6% of total). This is a strong indicator of compromised shared hosting or VPS abuse within the GoDaddy network. Abuse reporting to the provider is warranted.
- The French source (
83.171.227.54) is attributed to an individual operator — a pattern associated with VPS-for-hire scanning services or a dedicated threat actor using commercial hosting. - Amarutu Technology Ltd (DE) is a known hosting provider frequently observed in threat intelligence feeds as a permissive bulletproof-adjacent host.
Active Campaigns
Five critical campaigns each recorded 24,210 hits this week — a statistically identical count that strongly suggests a single automated campaign framework cycling through multiple exploit modules simultaneously.
| Campaign | Severity | Type | Hits |
|---|---|---|---|
| Hikvision ISAPI RCE | 🔴 Critical | RCE | 24,210 |
| PHPUnit eval-stdin RCE | 🔴 Critical | RCE | 24,210 |
| Apache Path Traversal / RCE | 🔴 Critical | Path Traversal / RCE | 24,210 |
| GeoServer OGC Filter RCE | 🔴 Critical | RCE | 24,210 |
| Exchange ProxyLogon | 🔴 Critical | RCE | 24,210 |
Analysis:
- The uniform hit count across all five campaigns is anomalous and indicative of scripted multi-exploit toolkits (e.g., Mirai variant loaders, Pwnkit-style automation, or commercial scanner suites) that iterate through all payloads in a single pass per target.
- Hikvision ISAPI and GeoServer OGC Filter RCE are IoT/OT and GIS infrastructure targets — suggesting the actor is not exclusively focused on enterprise web stacks but is casting a wide net across exposed services.
- Exchange ProxyLogon (CVE-2021-26855) remains actively exploited despite being a 5-year-old vulnerability, confirming that unpatched legacy Exchange infrastructure continues to present viable targets.
- PHPUnit eval-stdin (CVE-2017-9841) is similarly aged, reinforcing the pattern of opportunistic exploitation of known, unpatched vulnerabilities at internet scale.
Notable Paths & Techniques
The following were observed outside of tracked campaigns with significant hit volume:
| Observed Path / String | Hits | Interpretation |
|---|---|---|
/ (root HTTP request) |
1,367 | Generic HTTP fingerprinting / banner grab |
sh / /bin/busybox |
1,060 | Telnet/SSH post-auth shell probe; Mirai-style IoT exploitation |
database=postgres |
885 | PostgreSQL connection probing |
pass=1234 |
763 | Weak credential stuffing |
pass=admin |
580 | Weak credential stuffing |
sh (standalone) |
530 | Shell invocation attempt on interactive sessions |
set |
444 | Redis/Telnet command probe |
pass= (empty) |
399 | Null/blank credential attempt |
UNSTABLE |
356 | Likely Mirai botnet variant handshake string |
IZ1H9 |
337 | Known Mirai variant identifier (IZ1H9 strain) |
Key findings:
- The strings
UNSTABLEandIZ1H9are confirmed Mirai botnet variant markers.IZ1H9specifically corresponds to a known Mirai fork with a history of targeting routers and IP cameras. Their presence on the Telnet facade confirms active IoT recruitment activity. /bin/busyboxprobing is a classic Mirai post-authentication technique to confirm the target is a Linux-based embedded device.- The
setcommand against the Telnet facade may also target Redis (port 6379) being accidentally accessible through Telnet-like interaction, or represents RedisSETcommand injection attempts. - Credential patterns (
pass=1234,pass=admin,pass=) confirm continued reliance on factory-default and trivially guessable credentials by automated tools.
Geographic Distribution
| Country | Events | Notable Context |
|---|---|---|
| 🇺🇸 United States | 38,913 | Dominated by GoDaddy-hosted scanners; infrastructure abuse |
| 🇨🇳 China | 8,175 | Broad scan activity; consistent with prior weeks |
| 🇫🇷 France | 8,046 | Single high-volume actor driving most of this volume |
| 🇩🇪 Germany | 5,350 | Mixed hosting providers; includes Amarutu |
| 🇮🇩 Indonesia | 5,278 | PT Air Lintas Komunikasi source prominent |
| 🇰🇷 South Korea | 3,387 | Scan-heavy; consistent with regional botnet activity |
| 🇹🇷 Turkey | 2,696 | Moderate volume; mixed residential/VPS sources |
| 🇵🇰 Pakistan | 2,409 | Elevated; consistent with ISP-level botnet infections |
The US topping the chart is a direct consequence of GoDaddy-hosted abuse. Geolocation alone is an unreliable attribution signal — the true operator origin for US-attributed traffic is likely elsewhere.
Recommendations
- Patch immediately — ProxyLogon, PHPUnit, Hikvision ISAPI, GeoServer: All five active campaigns target well-documented CVEs. Any internet-facing instance of Exchange, PHPUnit dev endpoints, Hikvision cameras, GeoServer, or Apache with unpatched path traversal should be treated as critically exposed.
- Block or rate-limit Telnet exposure: With 47% of all probe traffic targeting fake-telnet, any production Telnet service exposed to the internet should be disabled or placed behind strict IP allowlisting immediately.
- Report GoDaddy abuse: The two GoDaddy-attributed IPs account for ~29.6% of total weekly traffic. Submit formal abuse reports to GoDaddy's security team with log evidence. Blocking the identified ASN ranges at perimeter for non-business-critical inbound is advisable.
- Harden database facades and enforce authentication: The volume of Redis, PostgreSQL, MySQL, and MongoDB probing confirms that unauthenticated or default-credential database exposure is actively targeted. Enforce authentication, bind to localhost where possible, and audit firewall rules.
- Deploy Mirai IoT signatures: The confirmed presence of
IZ1H9andUNSTABLEstrings warrants adding or refreshing Mirai variant detection signatures in IDS/IPS rulesets. Embedded Linux devices (routers, cameras, NAS) on network segments should be audited for default credentials and outdated firmware.
- Investigate uniform campaign hit counts: The 24,210-hit match across five distinct campaigns is operationally significant. Threat hunting teams should search for correlated hits across these five exploit types originating from the same source IPs within short time windows — a reliable indicator of a single automated actor.