# SSH botnets track geopolitical events, advisories

Published: 2026-06-18 · Severity: medium
Canonical: https://vorant.io/reports/95fb09b3-8fef-50fe-a0c7-ae7bfce37fff/ssh-botnets-track-geopolitical-events-advisories

> A DShield honeypot logged over 20 million SSH brute-force attempts across 100 days, showing coordinated botnet activity spiking in response to CISA advisories and Middle East tensions.

A DShield honeypot operated from February through May 2026 captured over 20 million SSH brute-force login attempts, revealing patterns of coordinated botnet activity that appeared to correlate with external events. The data shows baseline activity spiking over 2100% following CISA Emergency Directive 26-03 on Cisco SD-WAN vulnerabilities, and peaking at over 300,000 attempts per day during escalating Iran-Israel-US tensions in early March. Attack volumes remained elevated through mid-April before declining as geopolitical tensions eased.

Analysis of the top ten probing IP addresses revealed strong geographic and ASN clustering, with multiple attacks exhibiting identical HASSH fingerprints and SSH client versions occurring within seconds across different countries and ASNs. Over 702,000 events shared the same HASSH fingerprint (03a80b21afa810682a776a7d42e5e6fb), indicating use of a globally-deployed attack toolkit. The data also showed evidence of botnet quota assignment through throttled, uniform scan rates characteristic of programmed botnet operations.

The research demonstrates that threat actors rapidly adapt their SSH brute-force campaigns to capitalize on vulnerability disclosures and geopolitical events. The vast majority of attempts targeted the root user, and simple mitigations such as disabling root login, enforcing MFA, using SSH key authentication, and changing default ports would have prevented most observed attacks.

2 more detection artefacts for this report (IOC-atomic rules, Splunk/KQL/Elastic conversions, YARA, Suricata) are available to subscribers.

Source reporting: https://isc.sans.edu/diary/rss/33086

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/95fb09b3-8fef-50fe-a0c7-ae7bfce37fff/ssh-botnets-track-geopolitical-events-advisories.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
