Cloud Server Abuse Leads to Huge Spike in Botnet Scanning

Cloud Server Abuse Leads to Huge Spike in Botnet Scanning

January 15, 2024 at 06:12AM

Security solutions provider Netscout has observed a significant increase in botnet scanning activity, with peak numbers reaching 43,000 devices on December 20. The use of free cloud and hosting servers by attackers to create botnet launch pads has risen, allowing for anonymity and low overhead. The scanning represents reconnaissance activity for finding vulnerabilities.

Key takeaways from the meeting notes:

– Netscout has reported a significant spike in botnet scanning activity, with a marked increase in the number of devices conducting internet scans on specific dates.
– There has been a surge in the use of free or cheap cloud and hosting servers by attackers to create botnet launch pads, thereby enhancing anonymity and reducing maintenance overhead.
– The scanning activity is believed to be reconnaissance, as hackers are searching for vulnerabilities to exploit.
– The botnets primarily target ports associated with HTTP, HTTPS, RDP, SIP, and email servers.
– Netscout has warned of a new wave of cybercrime, stressing the importance of being prepared to counteract this threat.

Let me know if you need any further details from the meeting notes!

Full Article