GreyNoise late-August Cisco exposed-services reconnaissance campaign
Campaign
Summary
Hide ▲
Show ▼
Two large-scale reconnaissance campaigns probed Cisco ASA login portals and Cisco IOS Telnet/SSH services exposed online in late August, signaling broad interest in Cisco edge devices. The activity touched up to 25,000 unique IP addresses, suggesting high-volume target mapping rather than isolated scans. That scale matters because exposed systems were being profiled ahead of potential follow-on abuse.
Related Happenings
Forest Blizzard DNS hijacking token-theft campaign against older routers
Campaign
H score35
First: 07.04.2026 20:02
Last: 07.04.2026 20:02
Sources 1
About this happening:
Russia-backed Forest Blizzard is running a DNS hijacking campaign against older routers to steal Microsoft Office authentication tokens, putting accounts at risk acros...
Forest Blizzard DNS hijacking token-theft campaign against older routers
CampaignAbout this happening: Russia-backed Forest Blizzard is running a DNS hijacking campaign against older routers to steal Microsoft Office authentication tokens, putting accounts at risk acros...
APT28 FrostArmada DNS hijacking and AitM credential theft campaign
Campaign
H score45
First: 07.04.2026 18:51
Last: 07.04.2026 18:51
Sources 1
About this happening:
A multinational disruption effort has taken down FrostArmada, an APT28 campaign that hijacked router DNS settings to steal Microsoft account credentials and OAuth toke...
APT28 FrostArmada DNS hijacking and AitM credential theft campaign
CampaignAbout this happening: A multinational disruption effort has taken down FrostArmada, an APT28 campaign that hijacked router DNS settings to steal Microsoft account credentials and OAuth toke...
APT28 SOHO router DNS hijacking and credential theft campaign
Campaign
H score41
First: 07.04.2026 18:30
Last: 07.04.2026 18:30
Sources 1
About this happening:
APT28 is running two malicious campaigns that abuse vulnerable SOHO routers and attacker-controlled DNS/VPS infrastructure to reroute traffic and steal credentials...
APT28 SOHO router DNS hijacking and credential theft campaign
CampaignAbout this happening: APT28 is running two malicious campaigns that abuse vulnerable SOHO routers and attacker-controlled DNS/VPS infrastructure to reroute traffic and steal credentials...
Latest development: 08.04.2026 13:03
On April 7, 2026, the US Department of Justice and the FBI said they neutralized the US portion of APT28’s DNS hijacking network, which spanned more than 23 US states and used compromised SOHO routers, especially TP-Link routers, to redirect traffic through attacker-controlled DNS servers and steal credentials from targeted organizations. The FBI said it was working with ISPs to notify affected users, and court-authorized remediation steps can reset router DNS settings, remove APT28-installed resolvers, and prevent further abuse of the original access path.
Residential proxy traffic evades IP reputation feeds across malicious edge sessions
Trend
H score30
First: 02.04.2026 18:21
Last: 02.04.2026 18:21
Sources 1
About this happening:
Residential proxy traffic is increasingly evading IP reputation feeds, weakening source-based visibility into malicious edge activity. In a 4 billion-session measurement,...
Residential proxy traffic evades IP reputation feeds across malicious edge sessions
TrendAbout this happening: Residential proxy traffic is increasingly evading IP reputation feeds, weakening source-based visibility into malicious edge activity. In a 4 billion-session measurement,...
2025 Rise in legitimate-access intrusions across enterprise sectors
Trend
H score28
First: 01.04.2026 17:05
Last: 01.04.2026 17:05
Sources 1
About this happening:
Legitimate access abuse is now a leading intrusion pattern across 2025 investigations, increasing the risk of stealthy compromise across manufacturing, healthcare, MSPs,...
2025 Rise in legitimate-access intrusions across enterprise sectors
TrendAbout this happening: Legitimate access abuse is now a leading intrusion pattern across 2025 investigations, increasing the risk of stealthy compromise across manufacturing, healthcare, MSPs,...
Timeline
-
25.09.2025 19:49 3 articles · 9mo ago
GreyNoise detects large-scale probing of Cisco ASA and IOS services
Campaign Scope UpdateGreyNoise detected two large-scale campaigns targeting exposed Cisco ASA login portals and Cisco IOS Telnet/SSH services in late August, with activity reaching up to 25,000 unique IP addresses.
Show sources
- Cisco warns of ASA firewall zero-days exploited in attacks — www.bleepingcomputer.com — 25.09.2025 19:49
- Cisco warns of ASA firewall zero-days exploited in attacks — www.bleepingcomputer.com — 25.09.2025 19:49
- Surge in networks scans targeting Cisco ASA devices raise concerns — www.bleepingcomputer.com — 09.09.2025 00:44