Threat Intelligence Briefing
Analysis period: 2026-02-22T12:00:01.631766 - 2026-02-22T18:00:01.631766 (6 hours)
Executive Summary
Global threat activity spiked by 97.3% compared to the previous 6-hour period, representing a significant deviation from typical baseline activity. This surge is primarily driven by malware C2 (1,110 events) and attacks (1,001 events), with the US, Germany, and Brazil as top source countries. Nordic activity remains stable and low, consistent with routine background noise. The top threat IPs are predominantly engaged in SSH brute-forcing, a persistent pattern originating from Russia, Turkmenistan, and India. Focus on the campaign-level activity, not individual ephemeral IPs. Prioritize monitoring for the surge in C2 and attack traffic, which poses the most immediate risk. Consider temporarily rate-limiting SSH access from high-risk ASNs associated with brute-force campaigns, particularly those in Eastern Europe and Central Asia, to mitigate this widespread activity.