TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

GreyNoise

100,000+ IP Botnet Launches Coordinated RDP Attack Wave Against US Infrastructure

2025-10-10 · Read original ↗

ATT&CK techniques detected

2 predictions
T1584.005Botnet
76%
“targeting beginning this week is attributable to a multi - country botnet. discovery timeline spike in brazil - geolocated ips the botnet was discovered after greynoise detected an unusual spike in brazilian ip space this week, which prompted investigation into broader traffic pa…”
T1584.005Botnet
72%
“100, 000 + ip botnet launches coordinated rdp attack wave against us infrastructure update : 15 october 2025 greynoise is sharing an executive situation report ( sitrep ) for this event, providing leadership with actionable judgments and evidence to support decision making. updat…”

Summary

Since October 8, 2025, GreyNoise has tracked a coordinated botnet operation involving over 100,000 unique IP addresses from more than 100 countries targeting Remote Desktop Protocol (RDP) services in the United States.