← Threat Pulse
Pulse #28

Threat Pulse W40 — Mass Scan Surge & Critical RCE Campaign Blitz

Sensor traffic surged 55.6% week-over-week to 95,545 probes, driven by aggressive scanning against Telnet/SSH facades and simultaneous exploitation of five critical CVEs. GoDaddy-hosted IPs dominated scan volume, suggesting infrastructure abuse at scale.
Week of 28 Sep 2026

Executive Summary

The week of 2026-09-21 to 2026-09-28 recorded 95,545 inbound probes across all honeypot facades — a 55.6% spike versus the prior week. The surge was primarily scan-driven, with Telnet and SSH facades absorbing the bulk of traffic. Concurrently, five distinct critical-severity exploitation campaigns each registered identical hit counts (24,210), indicating a coordinated or automated multi-vector campaign framework actively targeting internet-facing infrastructure. Credential stuffing activity against database facades (Redis, PostgreSQL, MySQL, MongoDB) remained persistent and elevated.


Attack Volume & Trends

Metric This Week Change
Total Probes 95,545 +55.6%
Scans 71,341 Dominant category
Bruteforce 9,389 Elevated
Recon 9,283 Elevated
RCE Attempts 4,535 High
Exploit 990 Moderate
Auth Probes 13 Minimal

Facade breakdown:

Facade Hits Share
fake-telnet 44,941 47.0%
fake-ssh 25,748 27.0%
fake-redis 8,952 9.4%
fake-https 5,794 6.1%
fake-http 4,488 4.7%
fake-postgres 2,962 3.1%
fake-mysql 2,004 2.1%
fake-mongodb 656 0.7%

Telnet remains the single largest attack surface, absorbing nearly half of all traffic. The sustained pressure on fake-redis (8,952 hits) and database facades is consistent with automated tooling probing for unauthenticated or weakly authenticated data stores.


Top Threat Actors

Source Country ASN / Operator Events Primary Behavior
64.207.185.5 🇺🇸 US GoDaddy.com, LLC 23,170 Mass scan
83.171.227.54 🇫🇷 FR Baykov Ilya Sergeevich 7,504 Mass scan
50.62.135.24 🇺🇸 US GoDaddy.com, LLC 5,103 Mass scan
103.46.186.85 🇮🇩 ID PT Air Lintas Komunikasi 4,885 Mass scan
31.220.3.165 🇩🇪 DE Amarutu Technology Ltd 2,915 Mass scan

Key observations:

  • Two of the top three sources resolve to GoDaddy infrastructure, accounting for a combined 28,273 events (29.6% of total). This is a strong indicator of compromised shared hosting or VPS abuse within the GoDaddy network. Abuse reporting to the provider is warranted.
  • The French source (83.171.227.54) is attributed to an individual operator — a pattern associated with VPS-for-hire scanning services or a dedicated threat actor using commercial hosting.
  • Amarutu Technology Ltd (DE) is a known hosting provider frequently observed in threat intelligence feeds as a permissive bulletproof-adjacent host.

Active Campaigns

Five critical campaigns each recorded 24,210 hits this week — a statistically identical count that strongly suggests a single automated campaign framework cycling through multiple exploit modules simultaneously.

Campaign Severity Type Hits
Hikvision ISAPI RCE 🔴 Critical RCE 24,210
PHPUnit eval-stdin RCE 🔴 Critical RCE 24,210
Apache Path Traversal / RCE 🔴 Critical Path Traversal / RCE 24,210
GeoServer OGC Filter RCE 🔴 Critical RCE 24,210
Exchange ProxyLogon 🔴 Critical RCE 24,210

Analysis:

  • The uniform hit count across all five campaigns is anomalous and indicative of scripted multi-exploit toolkits (e.g., Mirai variant loaders, Pwnkit-style automation, or commercial scanner suites) that iterate through all payloads in a single pass per target.
  • Hikvision ISAPI and GeoServer OGC Filter RCE are IoT/OT and GIS infrastructure targets — suggesting the actor is not exclusively focused on enterprise web stacks but is casting a wide net across exposed services.
  • Exchange ProxyLogon (CVE-2021-26855) remains actively exploited despite being a 5-year-old vulnerability, confirming that unpatched legacy Exchange infrastructure continues to present viable targets.
  • PHPUnit eval-stdin (CVE-2017-9841) is similarly aged, reinforcing the pattern of opportunistic exploitation of known, unpatched vulnerabilities at internet scale.

Notable Paths & Techniques

The following were observed outside of tracked campaigns with significant hit volume:

Observed Path / String Hits Interpretation
/ (root HTTP request) 1,367 Generic HTTP fingerprinting / banner grab
sh / /bin/busybox 1,060 Telnet/SSH post-auth shell probe; Mirai-style IoT exploitation
database=postgres 885 PostgreSQL connection probing
pass=1234 763 Weak credential stuffing
pass=admin 580 Weak credential stuffing
sh (standalone) 530 Shell invocation attempt on interactive sessions
set 444 Redis/Telnet command probe
pass= (empty) 399 Null/blank credential attempt
UNSTABLE 356 Likely Mirai botnet variant handshake string
IZ1H9 337 Known Mirai variant identifier (IZ1H9 strain)

Key findings:

  • The strings UNSTABLE and IZ1H9 are confirmed Mirai botnet variant markers. IZ1H9 specifically corresponds to a known Mirai fork with a history of targeting routers and IP cameras. Their presence on the Telnet facade confirms active IoT recruitment activity.
  • /bin/busybox probing is a classic Mirai post-authentication technique to confirm the target is a Linux-based embedded device.
  • The set command against the Telnet facade may also target Redis (port 6379) being accidentally accessible through Telnet-like interaction, or represents Redis SET command injection attempts.
  • Credential patterns (pass=1234, pass=admin, pass=) confirm continued reliance on factory-default and trivially guessable credentials by automated tools.

Geographic Distribution

Country Events Notable Context
🇺🇸 United States 38,913 Dominated by GoDaddy-hosted scanners; infrastructure abuse
🇨🇳 China 8,175 Broad scan activity; consistent with prior weeks
🇫🇷 France 8,046 Single high-volume actor driving most of this volume
🇩🇪 Germany 5,350 Mixed hosting providers; includes Amarutu
🇮🇩 Indonesia 5,278 PT Air Lintas Komunikasi source prominent
🇰🇷 South Korea 3,387 Scan-heavy; consistent with regional botnet activity
🇹🇷 Turkey 2,696 Moderate volume; mixed residential/VPS sources
🇵🇰 Pakistan 2,409 Elevated; consistent with ISP-level botnet infections

The US topping the chart is a direct consequence of GoDaddy-hosted abuse. Geolocation alone is an unreliable attribution signal — the true operator origin for US-attributed traffic is likely elsewhere.


Recommendations

  1. Patch immediately — ProxyLogon, PHPUnit, Hikvision ISAPI, GeoServer: All five active campaigns target well-documented CVEs. Any internet-facing instance of Exchange, PHPUnit dev endpoints, Hikvision cameras, GeoServer, or Apache with unpatched path traversal should be treated as critically exposed.
  1. Block or rate-limit Telnet exposure: With 47% of all probe traffic targeting fake-telnet, any production Telnet service exposed to the internet should be disabled or placed behind strict IP allowlisting immediately.
  1. Report GoDaddy abuse: The two GoDaddy-attributed IPs account for ~29.6% of total weekly traffic. Submit formal abuse reports to GoDaddy's security team with log evidence. Blocking the identified ASN ranges at perimeter for non-business-critical inbound is advisable.
  1. Harden database facades and enforce authentication: The volume of Redis, PostgreSQL, MySQL, and MongoDB probing confirms that unauthenticated or default-credential database exposure is actively targeted. Enforce authentication, bind to localhost where possible, and audit firewall rules.
  1. Deploy Mirai IoT signatures: The confirmed presence of IZ1H9 and UNSTABLE strings warrants adding or refreshing Mirai variant detection signatures in IDS/IPS rulesets. Embedded Linux devices (routers, cameras, NAS) on network segments should be audited for default credentials and outdated firmware.
  1. Investigate uniform campaign hit counts: The 24,210-hit match across five distinct campaigns is operationally significant. Threat hunting teams should search for correlated hits across these five exploit types originating from the same source IPs within short time windows — a reliable indicator of a single automated actor.