Italian IoT devices abused for cyber attacks
The FortPot honeypot network identified numerous brute force attacks. The majority of these originate from devices compromised by malware (for example Mirai) subsequently leveraged as propagation vectors. Systems connected to the IP addresses presented in this article conducted access attempts against SSH and TELNET services in November 2018. Credential enumeration campaigns of this nature typically employ T1110 (Brute Force) techniques against T1021.004 (SSH) and T1021.005 (Telnet) protocols, with infected hosts acting as distributed attack sources under T1570 (Lateral Tool Transfer) patterns. Organizations operating internet-facing authentication services should consult Cybersecurity Advisory resources to establish baseline defenses against such volumetric credential attacks.
Some of these IP addresses may be associated with ADSL systems, frequently configured with dynamic public IP assignments.
Clicking on individual IPs in the tables below provides access to Talos Intelligence service for additional technical details.
Italian IP Statistics
The volume of attack sources originating from Italy is substantial, as evidenced by the count associated with each operator to which infected devices are connected.

| AS | ASN | CNT |
|---|---|---|
|
Telecom Italia
|
416 | |
|
Vodafone Italia S.p.A. |
220 | |
|
Fastweb
|
124 | |
|
KPNQWest Italia S.p.a.
|
90 | |
|
CDLAN s.r.l.
|
90 | |
|
Teleimpianti Srl
|
90 | |
|
Wind Telecomunicazioni SpA
|
75 | |
|
Aruba S.p.A.
|
46 | |
|
Reti Telematiche Italiane S.p.A. (Retelit S.p.A.)
|
6 |
| Source IP | CNT |
|---|---|
| 90 | |
| 90 | |
| 90 | |
| 90 | |
| 90 | |
| 90 | |
| 90 | |
| 90 | |
| 90 | |
| 50 |
Attack Map and Global Statistics
At the global level, the numbers are substantial. Tens of thousands of compromised devices conduct brute force attacks.



| AS | ASN | CNT |
|---|---|---|
|
Orange
|
32 135 | |
|
Rostelecom
|
10 618 | |
|
Global Layer B.V.
|
5 928 | |
|
Global Layer B.V.
|
5 120 | |
|
No.31,Jin-rong Street
|
4 509 | |
|
TELEFÔNICA BRASIL S.A
|
3 365 | |
|
Solar Invest UK LTD.
|
2 841 | |
|
CHINA UNICOM China169 Backbone
|
2 292 | |
|
VNPT Corp
|
1 213 | |
|
Telef
|