CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

A Spike in the Desert: How GreyNoise Uncovered a Global Pattern of VOIP-Based Telnet Attacks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1893

As cited

Copy frozen at (site build).

threat intel

A Spike in the Desert: How GreyNoise Uncovered a Global Pattern of VOIP-Based Telnet Attacks

GreyNoise detected a surge in botnet traffic from a rural New Mexico utility that led to discovery of a globally distributed botnet launching Voice over Internet Protocol (VoIP) based Telnet attacks. The analysis combined human expertise with AI-powered techniques to identify compromised devices and reveal attack patterns across infrastructure. The findings highlight the importance of monitoring anomalous network activity from critical infrastructure locations.

Why it matters: Utility operators and network defenders need to understand that VoIP devices can serve as botnet nodes for attacks on critical infrastructure, requiring immediate inventory and access control review of all VoIP systems and Telnet-exposed assets.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

A Spike in the Desert: How GreyNoise Uncovered a Global Pattern of VOIP-Based Telnet Attacks

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

A Spike in the Desert: How GreyNoise Uncovered a Global Pattern of VOIP-Based Telnet Attacks

Security researchers at GreyNoise identified a global botnet by investigating a spike in compromised traffic originating from a rural New Mexico utility. Analysis of the botnet revealed Voice over IP (VOIP)-based telnet attacks targeting devices across multiple sectors. The discovery highlights how anomalies in network traffic patterns can expose coordinated, distributed attack infrastructure.

Why it matters: Network defenders and infrastructure operators need to monitor for similar VOIP-based telnet exploitation patterns, as the botnet demonstrates tactics applicable to critical infrastructure and enterprise environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary