Concentrated 21-IP Cluster (AS213438/ColocaTel) Behind ~50% of Global RDP Internet Scanning — Threadlinqs Intelligence
As of 2026-04-10, Concentrated 21-IP Cluster (AS213438/ColocaTel) Behind ~50% of Global RDP Internet Scanning is a medium-severity threat intel threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-1466 · Severity: MEDIUM · Status: ACTIVE · Category: THREAT_INTEL
GreyNoise identified a cluster of just 21 IP addresses, tied to ASN AS213438 (ColocaTel Inc., Mahe, Seychelles), that generated 49.7% of all global RDP Crawler scanning activity over a 48-hour window
Between April 5 and April 7, 2026, GreyNoise's Global Observation Grid (GOG) recorded a sharp concentration of internet-wide RDP (Remote Desktop Protocol) scanning traffic into a small, coordinated set of source infrastructure. Just 21 RDP Crawler IP addresses -- all mapped to autonomous system AS213438, RIPE-registered to ColocaTel Inc. of Mahe, Seychelles -- generated 49.7% of all RDP Crawler sessions observed globally across the 48-hour window, and spiked to 67.4% (1,856,167 of 2,753,274 global sessions) on a single peak day, April 7, 2026.
The 21 IPs concentrated into four /24 network blocks, split between hosting in Amsterdam and Lelystad, Netherlands: 193.142.147.0/24 (8 IPs, 715,147 sessions, hosted Amsterdam), 185.196.220.0/24 (5 IPs, 461,080 sessions, Lelystad), 79.124.8.0/24 (4 IPs, 368,557 sessions, Lelystad), and 45.134.225.0/24 (3 IPs, 290,092 sessions, Amsterdam). The single highest-volume IP was 193.142.147.111, first observed by GreyNoise in May 2025 and carrying the RDP Crawler, RDP Bruteforce Attempt, RDP Protocol, Web Crawler, Go HTTP Client, MySQL Protocol, and MySQL Login Attempt classification tags.
Scanning traffic was not limited to the standard RDP port 3389 -- it also probed the adjacent non-standard ports 3390, 3391, and 3392, consistent with fingerprinting RDP services deliberately moved off the default port. In parallel, the same infrastructure probed PostgreSQL on its default port 5432 and a wide spread of non-standard PostgreSQL alternates (5430, 5431, 5433, 5434, 15432, 25432, 30432, 35432, 55432), plus MySQL on port 3306 -- indicating the actor(s) behind this fleet are running multi-protocol database/remote-access discovery sweeps, not single-service RDP-only reconnaissance.
The geographic source profile shifted sharply during the window: the Netherlands' share of global RDP scanning rose from a 7.17% baseline to 53.86%, overtaking Romania as the top source country, and the Netherlands' daily scan rate jumped roughly 15.4x (from ~64,894 sessions/day baseline to ~997,200 sessions/day).
On April 8, 2026, the campaign collapsed 99.9% in a single day (from 1,856,167 sessions on April 7 to 1,795 on April 8, reaching zero by April 9) -- an abrupt burst-and-crash cadence. This is not a novel behavior for this operator: the same ColocaTel Inc./AS213438 identity produced an earlier, larger campaign the week of March 5-11, 2026, generating approximately 10.7 million RDP scan sessions, peaking at 3.7 million sessions on March 6 before collapsing 97.7% to 86,953 sessions on March 7, then going quiet for roughly 30 days before the April reappearance. The recurring ~30-day burst-and-crash cadence, the consistent RIPE registrant identity (same organization name, same Seychelles address, same abuse contact) across both episodes, and the tight infrastructure reuse indicate a persistent, professionally operated scanning-as-a-service or reconnaissance fleet rather than a one-off event.
GreyNoise explicitly declines to attribute this activity to a named threat actor or nation-state, noting that IP geolocation reflects where routing infrastructure is hosted (Netherlands, via a Seychelles-registered ASN) rather than where the operator is physically located. AS213438 is a young BGP network (~1 year old at time of reporting) peering with roughly 152 other networks via 5 upstream carriers, consistent with a bulletproof/offshore-registered hosting reseller rather than a legitimate enterprise ISP.
From a defensive standpoint this is pre-exploitation reconnaissance: mass internet-wide scanning for exposed RDP and database (PostgreSQL/MySQL) services, including services deliberately relocated to non-standard ports in an attempt at security-through-obscurity. Hosts found by this fleet are highly likely to be enumerated further and targeted with credential brute-forcing or exploit attempts by downstream actors purchasing or consuming this scan data, making the 21-IP/4-subnet cluster and the broader AS213438 ASN high-co
Weaknesses (CWE)
CWE-284, CWE-306
Target sectors: all-sectors, government administration, finance, health, manufacturing, technology, education, retail
Target regions: Global, North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, MEDIUM, threat intelligence, cybersecurity, T1595.001, T1595.002, T1595, T1590.005, T1590, T1583.004, T1583.005, T1583, T1133, T1190