Threat Intelligence Briefing
Analysis period: 2026-02-02T00:00:01.736081 - 2026-02-02T06:00:01.736081 (6 hours)
Executive Summary
Global threat volume increased by 481.4% compared to the previous period, representing a significant deviation from typical baseline activity. This surge is primarily driven by spam and attack categories. The Nordic region shows a proportional increase, with Sweden (96 events) and Finland (58) seeing the highest volumes, though their threat mix of attacks and brute-force remains consistent with established patterns. The top threat IPs are concentrated in Russian and Dutch ASNs, all conducting SSH brute-force campaigns that have been active for weeks. Focus on the SSH brute-force campaign pattern emanating from ASNs in Russia (e.g., networks hosting <a href="https://ip.wayscloud.services/ip-intelligence/176.120.22.0" target="_blank">176.120.22.0</a>/24) and the Netherlands, rather than individual IPs. Consider implementing temporary rate-limiting on SSH services and review authentication logs for these source ranges. The spam surge is likely automated and can be deprioritized in favor of the more targeted credential attacks.