Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Heimdal Security’s 2024 investigation describes credential attacks against corporate and institutional networks in Europe, including attempts against SMBv1 and Remote Desktop Protocol (RDP) services. The company reported that many observed IP addresses were new or recently compromised and linked activity to locations and providers across Europe. Those figures and attribution claims are Heimdal’s analysis—not independently verified measurements of who controlled the infrastructure.

What did Heimdal’s brute-force report find?

Heimdal announced the investigation on July 25, 2024. Its investigation page, last updated November 28, 2024, describes activity targeting corporate and institutional networks in Europe. The figures below are the company’s reported findings for that investigation; they should not be read as independently validated rates or as a measurement of threats in 2026.

Finding Heimdal’s reported figure
Attack IPs described as new More than 60%
Attack IPs described as recently compromised Approximately 65%
Attacks assigned to an SMBv1 crawler 32.4%
Attacks assigned to an RDP crawler 27.4%
Attacks assigned to an alternative-RDP-port crawler 8.1%

Heimdal also reported that 40.1% of attacks originated from the Russian Federation, 12.9% from the Netherlands, and 5.7% from Belgium. It said 27.7% of attacks from Russia were attributed to Telefonica LLC. The public account does not provide enough detail about denominators, sampling, or classification to independently reproduce these percentages, so they are best understood as Heimdal’s categorization of its own investigation data. Heimdal’s investigation

Which systems and accounts were targeted?

Heimdal describes automated probing of SMBv1 and RDP, including RDP services on alternative ports. It says the activity targeted administrative accounts, with variations in capitalization and language. Its account also mentions web crawlers and possible Bad Rabbit/Petya activity; the malware connection is presented as a possibility, not a confirmed finding.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)

Credential techniques described

  • Password guessing: trying possible passwords against accounts.
  • Password spraying: trying a small set of passwords across many accounts rather than concentrating attempts on one account.
  • Credential stuffing: testing previously exposed username-and-password combinations.
  • Weak or default credentials: attempting access where accounts retain easily guessed or unchanged credentials.

These methods can put internet-accessible remote services and administrative accounts at risk. The report identifies the techniques it observed or classified; it does not establish that every targeted service was breached.

Where did the attacks appear to come from?

Heimdal said more than half of the investigated attack IPs were linked to Moscow, with others associated with Amsterdam and Brussels. It named Edinburgh and Dublin among frequently targeted cities and discussed targets in the UK, Denmark, Hungary, and Lithuania. The company also said Microsoft infrastructure in Belgium and the Netherlands was used, and named Telefonica LLC and IPX-FZCO as abused providers.

These are reported associations based on IP and infrastructure analysis, not proof of an attacker’s physical location, identity, or government direction. An IP address may be routed through infrastructure controlled by someone other than its apparent provider or location. Heimdal’s founder, Morten Kjaersgaard, characterized the findings as evidence that “an entity in Russia is waging a hybrid war on Europe, and may have even infiltrated it.” That is his interpretation of the company’s findings; the public material does not independently establish state attribution or infiltration.

How Heimdal says it conducted the investigation

Heimdal says the data came through its Threat-Hunting & Action Center, using an Extended Threat Protection engine integrated with its Next-Generation Antivirus, Firewall, and Mobile Device Management products. It says it also incorporated external sources including Shodan, Cloudflare, Censys, and SIE Europe probing. Paul Vixie, co-founder of SIE Europe, said the organization does not traffic in personally identifiable information and described the case as showing the investigative value of cooperatively assembled public information. The company’s investigation page does not publish a complete dataset, a sufficiently detailed sampling frame, or a method that would let readers independently test its geolocation, campaign boundaries, or attribution.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can organizations reduce brute-force risk?

Heimdal’s release recommends stronger cloud security, multifactor authentication (MFA), regular security audits, and employee education. These are recommendations, not measures whose comparative effectiveness was tested in the investigation. In practice, they address different parts of the risk:

  • Require MFA: Add a second authentication factor so a password alone is not enough for account access.
  • Review exposed remote-access services: Identify internet-facing RDP and SMB services, remove exposure where it is unnecessary, and restrict access where it is required.
  • Audit accounts and configurations: Check for default or weak credentials, unnecessary administrative accounts, and security settings that allow avoidable exposure.
  • Educate employees: Explain password reuse and credential theft risks, and provide a clear way to report suspicious sign-in prompts or activity.
  • Monitor authentication activity: Look for repeated failures, attempts across many accounts, and unusual access patterns so that suspicious activity can be investigated.

These are practical controls for credential-attack risk, not a ranking or a guarantee of prevention. The investigation does not report testing these measures against the activity it describes.

Quick Recap

Bestseller No. 1
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
Made in USA - Proudly produced in Ohio by a Veteran-owned business
$22.99
Bestseller No. 4
Nakabayashi Co.,Ltd. Dictionary Book Secret Security Box with Number Combination Key(Large)
Nakabayashi Co.,Ltd. Dictionary Book Secret Security Box with Number Combination Key(Large)
Outer Dimensions: W2.17*D7.40*H10.0(inches); Inner Dimensions: W1.97*D5.90*H9.53(inches); Durable material imported from Japan.
$50.00
Bestseller No. 5
Nakabayashi Co.,Ltd. Dictionary Book Secret Security Box with Number Combination Key(Medium)
Nakabayashi Co.,Ltd. Dictionary Book Secret Security Box with Number Combination Key(Medium)
Outer Dimensions: W2.17*D7.40*H10.0(inches); Inner Dimensions: W1.97*D5.90*H9.53(inches); Durable material imported from Japan.
$62.49
Best Value
Nakabayashi Co.,Ltd. Dictionary Book Secret Security Box with Number Combination Key(Medium)
  • Looks like a real book, a good choice to be hidden that will coordinate with your books on shelf.
  • Combination diversion book safe is locked by security code( 3-number combination lock), No need to worry about losing key
  • Enough space to hide cash, coins, jewelries, watch, passport, paper bill and other valuable items.
  • Outer Dimensions: W2.17*D7.40*H10.0(inches); Inner Dimensions: W1.97*D5.90*H9.53(inches)
  • Durable material imported from Japan.
Rank #4
Nakabayashi Co.,Ltd. Dictionary Book Secret Security Box with Number Combination Key(Large)
  • Looks like a real book, a good choice to be hidden that will coordinate with your books on shelf.
  • Combination diversion book safe is locked by security code( 3-number combination lock), No need to worry about losing key by owing to Dial key
  • Enough space to hide cash, coins, jewelries, watch, passport, paper bill and other valuable items.
  • Outer Dimensions: W2.17*D7.40*H10.0(inches); Inner Dimensions: W1.97*D5.90*H9.53(inches)
  • Durable material imported from Japan.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.