Skip to content

Emerging Threats

Italian IoT devices abused for cyber attacks

· frtg · 2 min read

The FortPot honeypot network identified numerous brute force attacks. The majority of these originate from devices compromised by malware (for example Mirai) subsequently leveraged as propagation vectors. Systems connected to the IP addresses presented in this article conducted access attempts against SSH and TELNET services in November 2018. Credential enumeration campaigns of this nature typically employ T1110 (Brute Force) techniques against T1021.004 (SSH) and T1021.005 (Telnet) protocols, with infected hosts acting as distributed attack sources under T1570 (Lateral Tool Transfer) patterns. Organizations operating internet-facing authentication services should consult Cybersecurity Advisory resources to establish baseline defenses against such volumetric credential attacks.

Some of these IP addresses may be associated with ADSL systems, frequently configured with dynamic public IP assignments.

Clicking on individual IPs in the tables below provides access to Talos Intelligence service for additional technical details.

Italian IP Statistics

The volume of attack sources originating from Italy is substantial, as evidenced by the count associated with each operator to which infected devices are connected.

AS ASN CNT
Telecom Italia
416

Vodafone Italia S.p.A.

220
Fastweb
124
KPNQWest Italia S.p.a.
90
CDLAN s.r.l.
90
Teleimpianti Srl
90
Wind Telecomunicazioni SpA
75
Aruba S.p.A.
46
Reti Telematiche Italiane S.p.A. (Retelit S.p.A.)
6

 

Source IP CNT
90
90
90
90
90
90
90
90
90
50

 

Attack Map and Global Statistics

At the global level, the numbers are substantial. Tens of thousands of compromised devices conduct brute force attacks.

Attack Map
Attack Map
Top 10 Countries
Top 10 Countries
Attacker Reputation
Attacker Reputation

 

 

 

 

 

AS ASN CNT
Orange
32 135
Rostelecom
10 618
Global Layer B.V.
5 928
Global Layer B.V.
5 120
No.31,Jin-rong Street
4 509
TELEFÔNICA BRASIL S.A
3 365
Solar Invest UK LTD.
2 841
CHINA UNICOM China169 Backbone
2 292
VNPT Corp
1 213
Telef