RDP Alert: Massive Surge in Scans Targets Vulnerable Portals – Are You Prepared?
GreyNoise has detected nearly 1,971 IP addresses scanning Microsoft Remote Desktop Web Access in a possible coordinated campaign. This marks a huge leap from the usual 3–5 IP addresses. The scans are likely testing timing flaws for future attacks, coinciding suspiciously with the US back-to-school season. Talk about a lesson in cyber sleuthing!

Hot Take:
Looks like the back-to-school season for hackers is in full swing! While students are busy picking out their backpacks and universities are gearing up for another academic year, cybercriminals are sharpening their pencils and targeting Microsoft Remote Desktop Web Access like it’s the new cool elective. Maybe it’s time to enroll in Cybersecurity 101, folks!
Key Points:
- Nearly 1,971 IP addresses involved in a coordinated reconnaissance campaign targeting RDP portals.
- Significant change in activity from the usual 3-5 IP addresses daily.
- Scans test for timing flaws to verify usernames, setting up future credential-based attacks.
- Predominantly originating from Brazil and targeting US IP addresses, hinting at a single botnet.
- Coincides with US back-to-school season, potentially exploiting predictable username formats.
Already a member? Log in here