Threat reportThreat IntelligenceTL-2026-1466
Concentrated 21-IP Cluster (AS213438/ColocaTel) Behind ~50% of Global RDP Internet Scanning
Concentrated 21-IP Cluster (AS213438/ColocaTel) Behind ~50% (TL-2026-1466), also tracked as 21-IP RDP Crawler Cluster, is a medium-severity tracked intrusion set, first published 2026-04-10. It has no confirmed attribution, affects Generic Internet-exposed RDP services (port 3389 and non-standard, maps to 15 MITRE ATT&CK techniques (T1046, T1078, T1110), and is covered by 9 detection rules and 25 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 25Indicators of compromise
Key facts for TL-2026-1466
- Threat ID
- TL-2026-1466
- Also known as
- 21-IP RDP Crawler Cluster, AS213438 RDP/PostgreSQL Scanning Campaign
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- all-sectors, government administration, finance, health, manufacturing, technology, education, retail
- Target regions
- Global, North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in Concentrated 21-IP Cluster (AS213438/ColocaTel) Behind ~50%
Malware and tooling: Go HTTP Client
How Concentrated 21-IP Cluster (AS213438/ColocaTel) Behind ~50% works
GreyNoise identified a cluster of just 21 IP addresses, tied to ASN AS213438 (ColocaTel Inc., Mahe, Seychelles), that generated 49.7% of all global RDP Crawler scanning activity over a 48-hour window (April 5-7, 2026), peaking at 67.4% of worldwide RDP scan volume on April 7 before a 99.9% single-day crash on April 8. The traffic also targeted non-standard RDP, PostgreSQL, and MySQL ports, and the same burst-and-crash pattern recurred roughly 30 days after an identical, larger episode in March 2026 (10.7M sessions).
Between April 5 and April 7, 2026, GreyNoise's Global Observation Grid (GOG) recorded a sharp concentration of internet-wide RDP (Remote Desktop Protocol) scanning traffic into a small, coordinated set of source infrastructure. Just 21 RDP Crawler IP addresses -- all mapped to autonomous system AS213438, RIPE-registered to ColocaTel Inc. of Mahe, Seychelles -- generated 49.7% of all RDP Crawler sessions observed globally across the 48-hour window, and spiked to 67.4% (1,856,167 of 2,753,274 global sessions) on a single peak day, April 7, 2026.
The 21 IPs concentrated into four /24 network blocks, split between hosting in Amsterdam and Lelystad, Netherlands: 193.142.147.0/24 (8 IPs, 715,147 sessions, hosted Amsterdam), 185.196.220.0/24 (5 IPs, 461,080 sessions, Lelystad), 79.124.8.0/24 (4 IPs, 368,557 sessions, Lelystad), and 45.134.225.0/24 (3 IPs, 290,092 sessions, Amsterdam). The single highest-volume IP was 193.142.147.111, first observed by GreyNoise in May 2025 and carrying the RDP Crawler, RDP Bruteforce Attempt, RDP Protocol, Web Crawler, Go HTTP Client, MySQL Protocol, and MySQL Login Attempt classification tags.
Scanning traffic was not limited to the standard RDP port 3389 -- it also probed the adjacent non-standard ports 3390, 3391, and 3392, consistent with fingerprinting RDP services deliberately moved off the default port. In parallel, the same infrastructure probed PostgreSQL on its default port 5432 and a wide spread of non-standard PostgreSQL alternates (5430, 5431, 5433, 5434, 15432, 25432, 30432, 35432, 55432), plus MySQL on port 3306 -- indicating the actor(s) behind this fleet are running multi-protocol database/remote-access discovery sweeps, not single-service RDP-only reconnaissance.
The geographic source profile shifted sharply during the window: the Netherlands' share of global RDP scanning rose from a 7.17% baseline to 53.86%, overtaking Romania as the top source country, and the Netherlands' daily scan rate jumped roughly 15.4x (from ~64,894 sessions/day baseline to ~997,200 sessions/day).
On April 8, 2026, the campaign collapsed 99.9% in a single day (from 1,856,167 sessions on April 7 to 1,795 on April 8, reaching zero by April 9) -- an abrupt burst-and-crash cadence. This is not a novel behavior for this operator: the same ColocaTel Inc./AS213438 identity produced an earlier, larger campaign the week of March 5-11, 2026, generating approximately 10.7 million RDP scan sessions, peaking at 3.7 million sessions on March 6 before collapsing 97.7% to 86,953 sessions on March 7, then going quiet for roughly 30 days before the April reappearance. The recurring ~30-day burst-and-crash cadence, the consistent RIPE registrant identity (same organization name, same Seychelles address, same abuse contact) across both episodes, and the tight infrastructure reuse indicate a persistent, professionally operated scanning-as-a-service or reconnaissance fleet rather than a one-off event.
GreyNoise explicitly declines to attribute this activity to a named threat actor or nation-state, noting that IP geolocation reflects where routing infrastructure is hosted (Netherlands, via a Seychelles-registered ASN) rather than where the operator is physically located. AS213438 is a young BGP network (~1 year old at time of reporting) peering with roughly 152 other networks via 5 upstream carriers, consistent with a bulletproof/offshore-registered hosting reseller rather than a legitimate enterprise ISP.
From a defensive standpoint this is pre-exploitation reconnaissance: mass internet-wide scanning for exposed RDP and database (PostgreSQL/MySQL) services, including services deliberately relocated to non-standard ports in an attempt at security-through-obscurity. Hosts found by this fleet are highly likely to be enumerated further and targeted with credential brute-forcing or exploit attempts by downstream actors purchasing or consuming this scan data, making the 21-IP/4-subnet cluster and the broader AS213438 ASN high-confidence blocklist candidates for any internet-facing RDP or database infrastructure.
MITRE ATT&CK techniques used in TL-2026-1466
Discovery
T1046 Network Service Discovery
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Credential Access
T1110 Brute Force; T1110.001 Password Guessing
Command and Control
Resource Development
T1583 Acquire Infrastructure; T1583.004 Server; T1583.005 Botnet
Reconnaissance
T1590 Gather Victim Network Information; T1590.005 IP Addresses; T1595 Active Scanning; T1595.001 Scanning IP Blocks; T1595.002 Vulnerability Scanning
Affected products and versions in Concentrated 21-IP Cluster (AS213438/ColocaTel) Behind ~50%
- Generic — Internet-exposed RDP services (port 3389 and non-standard 3390-3392)
Vulnerable versions: Any internet-reachable RDP listener
Fixed in: N/A - exposure/configuration issue, not a software vulnerability - PostgreSQL Global Development Group — PostgreSQL Server
Vulnerable versions: Any internet-reachable PostgreSQL listener on port 5432 or non-standard alternates
Fixed in: N/A - exposure/configuration issue, not a software vulnerability - Oracle / MySQL — MySQL Server
Vulnerable versions: Any internet-reachable MySQL listener on port 3306
Fixed in: N/A - exposure/configuration issue, not a software vulnerability
Remediation for Concentrated 21-IP Cluster (AS213438/ColocaTel) Behind ~50%
Immediate actions
- Block inbound traffic from the four identified /24 subnets: 193.142.147.0/24, 185.196.220.0/24, 79.124.8.0/24, 45.134.225.0/24
- Block or rate-limit inbound traffic from ASN AS213438 (ColocaTel Inc.) at the perimeter/firewall
- Block port 3389 (RDP) from direct internet exposure; do not rely on non-standard ports 3390-3392 as obfuscation
- Audit RDP and database authentication logs for connection attempts since April 5, 2026 originating from AS213438 or the listed /24 ranges
- Confirm no internet-facing RDP, PostgreSQL, or MySQL services are reachable on standard or the enumerated non-standard ports (5430-5434, 15432, 25432, 30432, 35432, 55432, 3306)
Workarounds
- Move RDP off port 3389 only as a defense-in-depth supplement, never as a primary control -- this campaign explicitly scans 3390-3392
- Enforce account lockout / rate-limiting on any RDP or database service that cannot be immediately firewalled from the internet
Longer-term hardening
- Eliminate direct internet exposure of RDP; require VPN or zero-trust broker with MFA before RDP reaches internal hosts
- Deploy an RD Gateway or equivalent brokered-access solution with Network Level Authentication (NLA) enforced
- Restrict PostgreSQL/MySQL listeners to internal networks only; never expose database ports directly to the internet regardless of the port number used
- Subscribe to or continuously ingest GreyNoise/threat-intel scanning-source feeds to proactively block emerging scanning fleets
- Track AS213438 and the ColocaTel Inc. RIPE registrant identity for future infrastructure reuse given the recurring ~30-day campaign cadence
Weaknesses (CWE) in Concentrated 21-IP Cluster (AS213438/ColocaTel) Behind ~50%
Timeline of Concentrated 21-IP Cluster (AS213438/ColocaTel) Behind ~50%
- Top individual scanning IP 193.142.147.111 (AS213438) first observed by GreyNoise's Global Observation Grid.
- AS213438/ColocaTel begins a large RDP scanning campaign, ultimately generating approximately 10.7 million RDP Crawler sessions during the week of March 5-11, 2026.
- March campaign peaks at 3.7 million RDP scanning sessions in a single day.
- March campaign collapses 97.7% overnight to 86,953 sessions, then goes largely quiet for roughly 30 days.
- A new, tighter 21-IP AS213438 fleet reappears, beginning a 48-hour window (April 5-7) that accounts for 49.7% of all global RDP Crawler scanning traffic.
- Campaign peaks at 1,856,167 RDP Crawler sessions in a single day -- 67.4% of the global total of 2,753,274 sessions observed worldwide. Netherlands' share of global RDP scanning source traffic rises from 7.17% baseline to 53.86%, overtaking Romania as top source country.
- Campaign volume collapses 99.9% in a single day, falling from 1,856,167 sessions to 1,795 sessions.
- AS213438 RDP Crawler session volume reaches zero, completing the burst-and-crash cycle.
- TL-Intel Harness ingests the GreyNoise disclosure via RSS hunt phase and opens threat skeleton TL-2026-1466.
- GreyNoise publishes blog analysis 'Just 21 IP Addresses Are Now Behind Nearly Half of All RDP Scanning on the Internet,' documenting the cluster, ASN, subnets, ports, and recurring cadence without threat-actor attribution.
Sources cited for Concentrated 21-IP Cluster (AS213438/ColocaTel) Behind ~50%
- Just 21 IP Addresses Are Now Behind Nearly Half of All RDP Scanning on the Internet
- AS213438 ColocaTel Inc. AS details
- Routing Information from AS213438
- AS213438 ColocaTel Inc.
- AS213438 ColocaTel Inc.
- AS Rank: AS213438 (ColocaTel Inc.)
- AS213438 Colocatel Network - BGP Network Information
- Disable Remote Desktop Protocol (RDP) (CM0025)
- Weak Security Controls and Practices Routinely Exploited for Initial Access
- GreyNoise Tags Documentation
- RDP Crawler | GreyNoise Visualizer Tag
Detection coverage for TL-2026-1466
As of 2026-04-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1466 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.