Threat Intelligence Briefing
Analysis period: 2026-02-20T12:00:01.571548 - 2026-02-20T18:00:01.571548 (6 hours)
Executive Summary
Global threat volume increased by 20.9% versus the previous period, a significant deviation from the baseline. The primary driver is a surge in malware C2 activity (1049 events), alongside sustained brute-force and SSH attacks. Nordic regions remain stable with routine, low-volume noise; Sweden (11 events) and Finland (5 events) show activity consistent with their typical profiles, primarily consisting of attacks and brute-force attempts. The top threat IPs are concentrated in Bulgaria, Russia, and Australia, focusing on SSH brute-forcing. Consider temporarily blocking or rate-limiting traffic from ASNs and CIDR ranges associated with the top source countries (US, BR, IN) and the identified SSH brute-force clusters, rather than individual ephemeral IPs. Deprioritize the low-volume Nordic activity as it represents expected background noise.