# T1595.001 Scanning IP Blocks

> As of 2026-10-05, T1595.001 (Scanning IP Blocks) appears in 35 tracked threats, first reported 2026-02-05 and most recently 2026-09-23, with linked actors including Static Tundra, FSB Center 16, FortiBleed operator; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 35 (17 critical, 13 high, 5 medium)
- **First seen:** 2026-02-05
- **Last seen:** 2026-09-23
- **Threat actors:** 6
- **Detection rules:** 46 (counts only; Blue tier and above)

## Key facts

- **ID:** T1595.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Reconnaissance
- **Matrix:** Enterprise
- **Parent:** T1595
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1595/001/

## Activity timeline

T1595.001 first appeared in tracked threats on 2026-02-05 and was most recently reported on 2026-09-23. The busiest month was 2026-07 with 15 reports, and 35 of the 35 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1595.001 Scanning IP Blocks is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of [T1595 Active Scanning](https://intel.threadlinqs.com/technique/T1595). Threadlinqs maps 35 of 2623 tracked threats (1.3%) to it; by severity that is 17 critical, 13 high, 5 medium.

Threats that use T1595.001 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (32 threats), [T1046 Network Service Discovery](https://intel.threadlinqs.com/technique/T1046) (24 threats), [T1595.002 Vulnerability Scanning](https://intel.threadlinqs.com/technique/T1595.002) (21 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (16 threats), [T1133 External Remote Services](https://intel.threadlinqs.com/technique/T1133) (16 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

6 tracked threat actors appear in the threats that use T1595.001; the most frequent are [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (2), [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) (1), [FortiBleed operator](https://intel.threadlinqs.com/actor/FortiBleed%20operator) (1), [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) (1), [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1595.001.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1595.001, per MITRE ATT&CK.

- Network Traffic — Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 2
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 1
- [FortiBleed operator](https://intel.threadlinqs.com/actor/FortiBleed%20operator) — 1
- [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) — 1
- [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) — 1
- [Lynx](https://intel.threadlinqs.com/actor/Lynx) — 1

## Tracked threats

The 30 most recent of 35 tracked threats that use T1595.001.

- [CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…](https://intel.threadlinqs.com/threat/TL-2026-2632) — critical — 2026-09-23
- [Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected…](https://intel.threadlinqs.com/threat/TL-2026-2463) — critical — 2026-09-12
- [GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706…](https://intel.threadlinqs.com/threat/TL-2026-2442) — critical — 2026-09-11
- [Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…](https://intel.threadlinqs.com/threat/TL-2026-2407) — critical — 2026-09-08
- [CVE-2026-20212: Critical Unauthenticated RCE in Cisco Nexus 9000 Series Switches (Silicon One ASIC)](https://intel.threadlinqs.com/threat/TL-2026-2319) — critical — 2026-09-03
- [CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…](https://intel.threadlinqs.com/threat/TL-2026-2080) — critical — 2026-08-20
- [CVE-2026-64849 — MLflow Server-Side Request Forgery (SSRF) Vulnerability in Model Registry Webhooks](https://intel.threadlinqs.com/threat/TL-2026-2077) — critical — 2026-08-19
- [CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russia](https://intel.threadlinqs.com/threat/TL-2026-2075) — high — 2026-08-19
- [Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349) Exploited for DoS via Crafted HTTP Requests to…](https://intel.threadlinqs.com/threat/TL-2026-1993) — high — 2026-08-12
- [SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities (CVE-2026-58231, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1984) — critical — 2026-08-11
- [OpenSSL Silently Patches "HollowByte" Memory-Exhaustion DoS Vulnerability](https://intel.threadlinqs.com/threat/TL-2026-1554) — medium — 2026-07-20
- [NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for…](https://intel.threadlinqs.com/threat/TL-2026-1455) — high — 2026-07-17
- [Progress ShareFile Zero-Day Path Traversal Flaw Forces Storage Zone Controller Shutdown](https://intel.threadlinqs.com/threat/TL-2026-1317) — high — 2026-07-14
- [US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB…](https://intel.threadlinqs.com/threat/TL-2026-1290) — medium — 2026-07-14
- [FSB Centre 16 (Berserk Bear/Energetic Bear) targets global critical national infrastructure via vulnerable…](https://intel.threadlinqs.com/threat/TL-2026-2375) — high — 2026-07-13
- [FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and…](https://intel.threadlinqs.com/threat/TL-2026-1283) — high — 2026-07-13
- [Internet-Wide Reconnaissance Scans Target MCP Servers and Claude/Cursor AI-Agent Credentials](https://intel.threadlinqs.com/threat/TL-2026-1278) — medium — 2026-07-13
- [Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint…](https://intel.threadlinqs.com/threat/TL-2026-1277) — high — 2026-07-13
- [CVE-2025-3248 & CVE-2026-5027: Langflow RCE and Path Traversal Chained for Flodrix Botnet Deployment](https://intel.threadlinqs.com/threat/TL-2026-1247) — critical — 2026-07-12
- [FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644…](https://intel.threadlinqs.com/threat/TL-2026-1232) — critical — 2026-07-11
- [CVE-2026-11405: Undocumented Authentication Backdoor in Tenda Router Firmware (FH1201, W15E, AC10, AC5, AC6)](https://intel.threadlinqs.com/threat/TL-2026-1188) — critical — 2026-07-10
- [CVE-2026-50746: Critical Unauthenticated Command Injection in Ubiquiti UniFi Connect Application (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1159) — critical — 2026-07-10
- [Multi-Malware Campaign Targeting Poorly Secured Linux SSH Servers — XMRig, ShellBot, MIG LogCleaner, XHide…](https://intel.threadlinqs.com/threat/TL-2026-1156) — medium — 2026-07-03
- [AI Compute Hijacking: Stolen Ollama Server Wired Into Autonomous "VAPT" Exploit Pipeline (Sysdig)](https://intel.threadlinqs.com/threat/TL-2026-1076) — high — 2026-07-02
- [FortiBleed Credential-Harvesting Campaign Feeds INC Ransom and Lynx Ransomware-as-a-Service Operations](https://intel.threadlinqs.com/threat/TL-2026-1056) — critical — 2026-07-02
- [CitrixBleed 2.0: CVE-2026-8451 NetScaler SAML IDP Memory Overread Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-1140) — critical — 2026-06-30
- [FortiBleed: Russian-Speaking Initial Access Broker Weaponizes FortiOS 'diagnose sniffer packet'…](https://intel.threadlinqs.com/threat/TL-2026-0927) — critical — 2026-06-24
- [Exposed RDP / RDWeb Misconfigurations Exploited for Initial Access and Lateral Movement (Huntress 2026)](https://intel.threadlinqs.com/threat/TL-2026-0775) — high — 2026-06-11
- [SolarWinds Serv-U DoS (CVE-2026-28318) — Actively Exploited Uncontrolled Resource Consumption via…](https://intel.threadlinqs.com/threat/TL-2026-0717) — high — 2026-06-08
- [WantToCry Ransomware — Remote SMB Encryption Campaign Targeting Internet-Exposed TCP 139/445 (Sophos CTU)](https://intel.threadlinqs.com/threat/TL-2026-0531) — high — 2026-05-19

## Related CVEs

CVEs referenced by the tracked threats that use T1595.001, most frequent first.

- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-59536](https://intel.threadlinqs.com/cve/CVE-2025-59536)
- [CVE-2025-59718](https://intel.threadlinqs.com/cve/CVE-2025-59718)
- [CVE-2025-59719](https://intel.threadlinqs.com/cve/CVE-2025-59719)
- [CVE-2025-68686](https://intel.threadlinqs.com/cve/CVE-2025-68686)
- [CVE-2026-19489](https://intel.threadlinqs.com/cve/CVE-2026-19489)
- [CVE-2026-19490](https://intel.threadlinqs.com/cve/CVE-2026-19490)
- [CVE-2026-20349](https://intel.threadlinqs.com/cve/CVE-2026-20349)
- [CVE-2026-21852](https://intel.threadlinqs.com/cve/CVE-2026-21852)
- [CVE-2026-21902](https://intel.threadlinqs.com/cve/CVE-2026-21902)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2026-33032](https://intel.threadlinqs.com/cve/CVE-2026-33032)
- [CVE-2026-34908](https://intel.threadlinqs.com/cve/CVE-2026-34908)
- [CVE-2026-34909](https://intel.threadlinqs.com/cve/CVE-2026-34909)
- [CVE-2026-34910](https://intel.threadlinqs.com/cve/CVE-2026-34910)
- [CVE-2026-39987](https://intel.threadlinqs.com/cve/CVE-2026-39987)
- [CVE-2026-44338](https://intel.threadlinqs.com/cve/CVE-2026-44338)
- [CVE-2026-5027](https://intel.threadlinqs.com/cve/CVE-2026-5027)

## Detection coverage

Threadlinqs maintains 46 detection rules mapped to T1595.001 (SPL 22, KQL 9, Sigma 15). Rule content is available to Blue tier accounts and above; this page shows counts only.

46 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1595 Active Scanning](https://intel.threadlinqs.com/technique/T1595) — 340 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1595.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
