Executive Summary
Between February and May 2026, a DShield honeypot recorded over 20 million SSH brute-force attempts, revealing a significant correlation between attack volumes and external events such as geopolitical tensions and cybersecurity advisories. Notably, a 2100% surge in attacks coincided with CISA's Emergency Directive 26-03 addressing Cisco SD-WAN vulnerabilities, and peaks in activity aligned with escalating conflicts involving Iran, Israel, and the United States. These findings underscore the adaptability of threat actors who exploit global events to intensify their malicious activities.
The study highlights the persistent threat posed by coordinated SSH brute-force attacks and the necessity for organizations to implement robust security measures. As attackers continue to leverage global events to orchestrate large-scale attacks, it is imperative for entities to enhance their defenses, monitor for unusual activity, and stay informed about emerging threats to mitigate potential breaches.
Why This Matters Now
The observed correlation between global events and surges in SSH brute-force attacks underscores the need for organizations to proactively strengthen their cybersecurity posture. With threat actors exploiting geopolitical tensions and public vulnerabilities, timely implementation of security measures is crucial to prevent potential breaches.
Attack Path Analysis
Attackers initiated a coordinated SSH brute-force campaign, attempting to gain unauthorized access to systems by systematically guessing credentials. Upon successful access, they escalated privileges to gain full control over the compromised systems. They then moved laterally within the network to identify and compromise additional targets. Established command and control channels allowed them to maintain persistent access and control over the compromised systems. Sensitive data was exfiltrated from the network to external servers controlled by the attackers. Finally, the attackers deployed ransomware to encrypt critical data, demanding payment for decryption keys.
Kill Chain Progression
Initial Compromise
Description
Attackers initiated a coordinated SSH brute-force campaign, attempting to gain unauthorized access to systems by systematically guessing credentials.
MITRE ATT&CK® Techniques
Password Guessing
Valid Accounts
Remote Services: SSH
Proxy
Acquire Infrastructure: Web Services
Compromise Infrastructure: Server
Application Layer Protocol: Web Protocols
Exploitation for Client Execution
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-Factor Authentication for All Access
Control ID: 8.3.6
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Critical exposure to coordinated SSH brute force attacks targeting infrastructure, requiring enhanced segmentation, encrypted traffic monitoring, and Zero Trust implementation.
Computer/Network Security
Direct impact from sophisticated botnet campaigns exploiting SSH vulnerabilities, necessitating advanced threat detection, anomaly response, and egress security controls.
Telecommunications
High risk from geopolitically-motivated attacks on network infrastructure, requiring multicloud visibility, east-west traffic security, and inline intrusion prevention systems.
Financial Services
Significant threat from automated brute force campaigns targeting critical systems, demanding compliance with HIPAA/PCI standards and robust authentication mechanisms.
Sources
- The Behavior of Coordinated SSH Brute Force Attacks over the last three months [Guest Diary], (Wed, Jun 17th)https://isc.sans.edu/diary/rss/33086Verified
- ED 26-03: Mitigate vulnerabilities in Cisco SD-WAN systemshttps://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systemsVerified
- CISA adds one known exploited vulnerability to cataloghttps://www.cisa.gov/news-events/alerts/2026/05/01/cisa-adds-one-known-exploited-vulnerability-catalogVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to gain unauthorized access may be constrained by enforcing strict access controls and monitoring for anomalous login attempts.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could be limited by enforcing least-privilege access and segmenting workloads to restrict access.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement would likely be constrained by enforcing east-west traffic controls, reducing the ability to reach other workloads.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command and control channels may be disrupted by monitoring and controlling outbound communications across multicloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts would likely be limited by enforcing strict egress policies and monitoring outbound data transfers.
The attacker's ability to deploy ransomware may be constrained by limiting lateral movement and enforcing strict access controls, reducing the spread of malware.
Impact at a Glance
Affected Business Functions
- Network Security Monitoring
- User Authentication Services
- Remote Access Management
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of system access logs and user credentials due to successful brute force attacks.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Enforce Multi-Factor Authentication (MFA) for SSH access to prevent unauthorized access.
- • Deploy Inline Intrusion Prevention Systems (IPS) to detect and block brute-force attempts.
- • Utilize Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing data exfiltration.
- • Establish comprehensive Threat Detection & Anomaly Response mechanisms to identify and respond to suspicious activities promptly.



