TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

GreyNoise

Surge in MOVEit Transfer Scanning Could Signal Emerging Threat Activity

2025-06-25 · Read original ↗

ATT&CK techniques detected

2 predictions
T1580Cloud Infrastructure Discovery
60%
“, amazon ( 94 ), and google ( 34 ). - top destination countries include the united kingdom, united states, germany, france, and mexico. - the overwhelming majority of scanner ips geolocate to the united states. confirmed exploitation attempts on june 12 greynoise also observed lo…”
T1595.002Vulnerability Scanning
31%
“, amazon ( 94 ), and google ( 34 ). - top destination countries include the united kingdom, united states, germany, france, and mexico. - the overwhelming majority of scanner ips geolocate to the united states. confirmed exploitation attempts on june 12 greynoise also observed lo…”

Summary

GreyNoise has identified a notable surge in scanning activity targeting MOVEit Transfer systems, beginning on May 27, 2025. Prior to this date, scanning was minimal — typically fewer than 10 IPs observed per day. But on May 27, that number spiked to over 100 unique IPs, followed by 319 IPs on May 29.