CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Ghost Fleet: Half of All New Scanning IPs Last Week Geolocated to Hong Kong - Nearly None Completed a Connection

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1854

As cited

Copy frozen at (site build).

threat intel

Ghost Fleet: Half of All New Scanning IPs Last Week Geolocated to Hong Kong - Nearly None Completed a Connection

GreyNoise observed that 242,666 new scanning IP addresses geolocated to Hong Kong emerged in a single week, with 99.7% failing to establish TCP connections. This pattern suggests reconnaissance activity or scanning infrastructure that was not attempting actual exploitation. The finding highlights unusual scanning behavior concentrated in a specific geographic region.

Why it matters: Security teams need to understand whether this Hong Kong-based scanning activity represents a new threat campaign, reconnaissance for future attacks, or scanning infrastructure that may eventually be weaponized; identifying the source and intent helps prioritize defensive responses.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Ghost Fleet: Half of All New Scanning IPs Last Week Geolocated to Hong Kong - Nearly None Completed a Connection

GreyNoise observed that 242,666 new scanning IP addresses geolocated to Hong Kong emerged in a single week, with 99.7% failing to establish TCP connections. This pattern suggests reconnaissance activity or scanning infrastructure that was not attempting actual exploitation. The finding highlights unusual scanning behavior concentrated in a specific geographic region.

Why it matters: Security teams need to understand whether this Hong Kong-based scanning activity represents a new threat campaign, reconnaissance for future attacks, or scanning infrastructure that may eventually be weaponized; identifying the source and intent helps prioritize defensive responses.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary