Threat Intelligence Briefing
Analysis period: 2026-01-09T00:00:01.705949 - 2026-01-09T06:00:01.705949 (6 hours)
Executive Summary
Global threat activity changed by several orders of magnitude (1,800 → 19,177 events), with spam, malware C2, and attacks dominating. The US and Netherlands were top origin countries, while Nordic activity remained stable compared to the 7-day average (Finland: 49 events, Sweden: 35). A cluster of Russian and Turkmenistani IPs (<a href="https://ip.wayscloud.services/ip-intelligence/45.140.17.124" target="_blank">45.140.17.124</a>, <a href="https://ip.wayscloud.services/ip-intelligence/91.202.233.33" target="_blank">91.202.233.33</a>) showed concentrated SSH brute-forcing, consistent with a 3-day-old campaign. This surge is abnormal, exceeding typical noise by an order of magnitude. Consider temporary rate-limiting for ASNs historically linked to SSH brute-forcing, particularly from RU/TM. Nordic defenders should prioritize monitoring for web attacks and spam, as these categories showed slight upticks in Sweden and Denmark. Deprioritize individual IP blocking unless part of the identified clusters.