Russia (RU) Threat Intelligence

RU

Russia has 194,695 malicious IP addresses with 4,988,909 abuse reports. Top threat categories include suspicious activity, tcp scan, high threat, malware distribution, severe abuse. Top attacking networks: Rostelecom (21,111 IPs), Biterika Group LLC (9,371 IPs), PJSC MegaFon (8,937 IPs). Data collected since 2022-08-23, last activity 2026-10-05.

Threat Assessment: Russia is one of the most significant sources of cyber threats globally, with an exceptionally high volume of malicious IP addresses. The dominant attack types are suspicious activity, tcp scan, high threat. The majority of threats originate from networks operated by Rostelecom and Biterika Group LLC.

Total Reports
4,988,909
Unique IPs
194,695
First Seen
2022-08-23
Last Activity
2026-10-05

Top Threat Categories

Suspicious Activity 574,051
Tcp Scan 567,025
High Threat 188,835
Malware Distribution 153,468
Severe Abuse 28,860

Top Attacking Networks

AS12389 Rostelecom
21,111 IPs
AS35048 Biterika Group LLC
9,371 IPs
AS25159 PJSC MegaFon
8,937 IPs

Most Reported IPs in Russia

45.91.64.7 1,641 reports
45.91.64.6 1,639 reports
185.94.111.1 1,482 reports
81.211.72.167 1,401 reports
81.23.173.32 1,397 reports

Access this data via API

Get Russia threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/RU

View full API documentation

See how we classify and verify threats →

Check any IP from Russia

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS12389 Intelligence AS35048 Intelligence AS25159 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...