Mmastodon TechnologyCybersecurity first seen 19 h ago, last 19 h ago, peak #10
Honeypot Data Shows Surge of RDP Scans
Original: 2026-10-06 RDP # Honeypot IOCs - 299 scans Thread with top 3 features in each category and links to the full dataset # D
A honeypot operator published daily indicators of compromise from 299 RDP scans recorded on 6 October 2026. The most active source IP, 20.233.35.68, accounted for 170 scans, with network AS8075 dominating the source networks. The most common account targeted was 'hello'. The release includes links to the full dataset for defenders and incident response teams.
Why now: Security practitioners are sharing fresh indicators of compromise to help defenders block active RDP scanning sources.
RDP honeypotAS807520.233.35.68infosec.exchange
Evidence
- 2026-10-06 RDP # Honeypot IOCs - 299 scans Thread with top 3 features in each category and links to the full dataset # DFIR # InfoSec Top IPs: 20.233.35.68 - 170 104.196.118.248 - 15 82.85.225.167 - 13 Top ASNs: AS8075 - 179 AS396982 - 27 AS8612 - 13 Top Accounts: hello - 194… · rdpsnitch@infosec.exchange · 3
API: https://socialmediatrends-api.osmike.com/v1/trends/1300480