CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

100,000+ IP Botnet Launches Coordinated RDP Attack Wave Against US Infrastructure

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1884

As cited

Copy frozen at (site build).

threat intel

100,000+ IP Botnet Launches Coordinated RDP Attack Wave Against US Infrastructure

GreyNoise has tracked a coordinated botnet operation since October 8, 2025 involving over 100,000 unique IP addresses from more than 100 countries targeting Remote Desktop Protocol (RDP) services in the United States. The campaign represents a large-scale, geographically distributed attack infrastructure.

Why it matters: US organizations exposing RDP services need to immediately audit access controls, require multi-factor authentication, and monitor for unauthorized connection attempts, as this active campaign directly targets their infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

100,000+ IP Botnet Launches Coordinated RDP Attack Wave Against US Infrastructure

Since October 8, 2025, GreyNoise tracked a coordinated botnet operation using more than 100,000 IP addresses across over 100 countries to target Remote Desktop Protocol (RDP) services in the United States. The attack wave represents a significant distributed infrastructure compromise aimed at systems exposed on public networks.

Why it matters: Organizations operating RDP services face immediate brute-force and credential-stuffing risk from this large-scale botnet; practitioners should audit RDP exposure, enforce multi-factor authentication, and monitor for anomalous login attempts.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary