TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

GreyNoise

Coordinated Cloud-Based Scanning Operation Targets 75 Known Exposure Points in One Day

2025-05-27 · Read original ↗

ATT&CK techniques detected

7 predictions
T1190Exploit Public-Facing Application
79%
"##ti epmm, reinforcing the need to treat coordinated scanning as an early warning signal. a brief, coordinated reconnaissance operation on may 8, greynoise observed a highly coordinated reconnaissance campaign launched by 251 malicious ip addresses, all geolocated to japan and ho…"
T1190Exploit Public-Facing Application
55%
"1427 ( groovy sandbox bypass rce ) - atlassian confluence — cve - 2022 - 26134 ( ognl injection ) - bash — cve - 2014 - 6271 ( shellshock ) these cves, while disclosed years ago, continue to attract interest from opportunistic attackers — a pattern explored in our latest research…"
T1071.001Web Protocols
55%
". 207. 232. 1, 43. 207. 232. 100, 43. 207. 3. 58, 43. 207. 74. 241, 43. 207. 79. 249, 43. 207. 81. 76, 52. 192. 111. 156, 52. 192. 125. 55, 52. 192. 14. 49, 52. 192. 27. 19, 52. 192. 56. 196, 52. 192. 99. 140, 52. 194. 205. 49, 52. 194. 220. 244, 52. 194. 248. 125, 52. 194. 250. …"
T1588.006Vulnerabilities
53%
"1427 ( groovy sandbox bypass rce ) - atlassian confluence — cve - 2022 - 26134 ( ognl injection ) - bash — cve - 2014 - 6271 ( shellshock ) these cves, while disclosed years ago, continue to attract interest from opportunistic attackers — a pattern explored in our latest research…"
T1588.006Vulnerabilities
35%
"- up exploitation may come from different infrastructure, greynoise classified all 251 ips as malicious in real time. dynamic ip blocking using greynoise allows defenses to respond instantly to new scanning infrastructure as it appears, removing guesswork and reducing exposure wi…"
T1580Cloud Infrastructure Discovery
33%
"coordinated cloud - based scanning operation targets 75 known exposure points in one day key takeaways - 251 malicious ips, all hosted by amazon and geolocated in japan, launched a coordinated one - day scan on may 8. - these ips triggered 75 distinct behaviors, including cve exp…"
T1588.006Vulnerabilities
33%
"in patch cycles. the 2025 verizon dbir revealed the edge as a critical risk, reporting concerning trends across time - to - mass - exploit and remediation lags in edge technologies. infrastructure overlap suggests central control greynoise analysis revealed the following : - 295 …"

Summary

On May 8, GreyNoise observed a highly coordinated reconnaissance campaign launched by 251 malicious IP addresses, all geolocated to Japan and hosted by Amazon AWS. The infrastructure and execution suggest centralized planning.