# Concentrated 21-IP Cluster (AS213438/ColocaTel) Behind ~50% of Global RDP Internet Scanning

> GreyNoise identified a cluster of just 21 IP addresses, tied to ASN AS213438 (ColocaTel Inc., Mahe, Seychelles), that generated 49.7% of all global RDP Crawler scanning activity over a 48-hour window (April 5-7, 2026), peaking at 67.4% of worldwide RDP scan volume on April 7 before a 99.9% single-day crash on April 8. The traffic also targeted non-standard RDP, PostgreSQL, and MySQL ports, and the same burst-and-crash pattern recurred roughly 30 days after an identical, larger episode in March 2026 (10.7M sessions).

- **Published:** 2026-04-10T00:00:00Z
- **Last reviewed:** 2026-04-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1466
- **ID:** TL-2026-1466
- **Severity:** MEDIUM
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Between April 5 and April 7, 2026, GreyNoise's Global Observation Grid (GOG) recorded a sharp concentration of internet-wide RDP (Remote Desktop Protocol) scanning traffic into a small, coordinated set of source infrastructure. Just 21 RDP Crawler IP addresses -- all mapped to autonomous system AS213438, RIPE-registered to ColocaTel Inc. of Mahe, Seychelles -- generated 49.7% of all RDP Crawler sessions observed globally across the 48-hour window, and spiked to 67.4% (1,856,167 of 2,753,274 global sessions) on a single peak day, April 7, 2026.

The 21 IPs concentrated into four /24 network blocks, split between hosting in Amsterdam and Lelystad, Netherlands: 193.142.147.0/24 (8 IPs, 715,147 sessions, hosted Amsterdam), 185.196.220.0/24 (5 IPs, 461,080 sessions, Lelystad), 79.124.8.0/24 (4 IPs, 368,557 sessions, Lelystad), and 45.134.225.0/24 (3 IPs, 290,092 sessions, Amsterdam). The single highest-volume IP was 193.142.147.111, first observed by GreyNoise in May 2025 and carrying the RDP Crawler, RDP Bruteforce Attempt, RDP Protocol, Web Crawler, Go HTTP Client, MySQL Protocol, and MySQL Login Attempt classification tags.

Scanning traffic was not limited to the standard RDP port 3389 -- it also probed the adjacent non-standard ports 3390, 3391, and 3392, consistent with fingerprinting RDP services deliberately moved off the default port. In parallel, the same infrastructure probed PostgreSQL on its default port 5432 and a wide spread of non-standard PostgreSQL alternates (5430, 5431, 5433, 5434, 15432, 25432, 30432, 35432, 55432), plus MySQL on port 3306 -- indicating the actor(s) behind this fleet are running multi-protocol database/remote-access discovery sweeps, not single-service RDP-only reconnaissance.

The geographic source profile shifted sharply during the window: the Netherlands' share of global RDP scanning rose from a 7.17% baseline to 53.86%, overtaking Romania as the top source country, and the Netherlands' daily scan rate jumped roughly 15.4x (from ~64,894 sessions/day baseline to ~997,200 sessions/day).

On April 8, 2026, the campaign collapsed 99.9% in a single day (from 1,856,167 sessions on April 7 to 1,795 on April 8, reaching zero by April 9) -- an abrupt burst-and-crash cadence. This is not a novel behavior for this operator: the same ColocaTel Inc./AS213438 identity produced an earlier, larger campaign the week of March 5-11, 2026, generating approximately 10.7 million RDP scan sessions, peaking at 3.7 million sessions on March 6 before collapsing 97.7% to 86,953 sessions on March 7, then going quiet for roughly 30 days before the April reappearance. The recurring ~30-day burst-and-crash cadence, the consistent RIPE registrant identity (same organization name, same Seychelles address, same abuse contact) across both episodes, and the tight infrastructure reuse indicate a persistent, professionally operated scanning-as-a-service or reconnaissance fleet rather than a one-off event.

GreyNoise explicitly declines to attribute this activity to a named threat actor or nation-state, noting that IP geolocation reflects where routing infrastructure is hosted (Netherlands, via a Seychelles-registered ASN) rather than where the operator is physically located. AS213438 is a young BGP network (~1 year old at time of reporting) peering with roughly 152 other networks via 5 upstream carriers, consistent with a bulletproof/offshore-registered hosting reseller rather than a legitimate enterprise ISP.

From a defensive standpoint this is pre-exploitation reconnaissance: mass internet-wide scanning for exposed RDP and database (PostgreSQL/MySQL) services, including services deliberately relocated to non-standard ports in an attempt at security-through-obscurity. Hosts found by this fleet are highly likely to be enumerated further and targeted with credential brute-forcing or exploit attempts by downstream actors purchasing or consuming this scan data, making the 21-IP/4-subnet cluster and the broader AS213438 ASN high-confidence blocklist candidates for any internet-facing RDP or database infrastructure.

## MITRE ATT&CK

- T1595.001 Scanning IP Blocks
- T1595.002 Vulnerability Scanning
- T1595 Active Scanning
- T1590.005 IP Addresses
- T1590 Gather Victim Network Information
- T1583.004 Server
- T1583.005 Botnet
- T1583 Acquire Infrastructure
- T1133 External Remote Services
- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1110.001 Password Guessing
- T1110 Brute Force
- T1046 Network Service Discovery
- T1219 Remote Access Tools

## Sources

- [Just 21 IP Addresses Are Now Behind Nearly Half of All RDP Scanning on the Internet](https://www.greynoise.io/blog/ip-addresses-behind-nearly-half-rdp-internet-scanning)
- [AS213438 ColocaTel Inc. AS details](https://ipinfo.io/AS213438)
- [Routing Information from AS213438](https://radar.cloudflare.com/routing/as213438)
- [AS213438 ColocaTel Inc.](https://bgp.tools/as/213438)
- [AS213438 ColocaTel Inc.](https://bgp.he.net/AS213438)
- [AS Rank: AS213438 (ColocaTel Inc.)](https://asrank.caida.org/asns?asn=213438)
- [AS213438 Colocatel Network - BGP Network Information](https://bgpview.io/asn/213438)
- [Disable Remote Desktop Protocol (RDP) (CM0025)](https://www.cisa.gov/eviction-strategies-tool/info-countermeasures/CM0025)
- [Weak Security Controls and Practices Routinely Exploited for Initial Access](https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-137a)
- [GreyNoise Tags Documentation](https://docs.greynoise.io/docs/greynoise-tags)
- [RDP Crawler | GreyNoise Visualizer Tag](https://viz.greynoise.io/tags/rdp-scanner)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1466
