The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Heimdal Security’s 2024 investigation describes credential attacks against corporate and institutional networks in Europe, including attempts against SMBv1 and Remote Desktop Protocol (RDP) services. The company reported that many observed IP addresses were new or recently compromised and linked activity to locations and providers across Europe. Those figures and attribution claims are Heimdal’s analysis—not independently verified measurements of who controlled the infrastructure.
What did Heimdal’s brute-force report find?
Heimdal announced the investigation on July 25, 2024. Its investigation page, last updated November 28, 2024, describes activity targeting corporate and institutional networks in Europe. The figures below are the company’s reported findings for that investigation; they should not be read as independently validated rates or as a measurement of threats in 2026.
| Finding | Heimdal’s reported figure |
|---|---|
| Attack IPs described as new | More than 60% |
| Attack IPs described as recently compromised | Approximately 65% |
| Attacks assigned to an SMBv1 crawler | 32.4% |
| Attacks assigned to an RDP crawler | 27.4% |
| Attacks assigned to an alternative-RDP-port crawler | 8.1% |
Heimdal also reported that 40.1% of attacks originated from the Russian Federation, 12.9% from the Netherlands, and 5.7% from Belgium. It said 27.7% of attacks from Russia were attributed to Telefonica LLC. The public account does not provide enough detail about denominators, sampling, or classification to independently reproduce these percentages, so they are best understood as Heimdal’s categorization of its own investigation data. Heimdal’s investigation
Which systems and accounts were targeted?
Heimdal describes automated probing of SMBv1 and RDP, including RDP services on alternative ports. It says the activity targeted administrative accounts, with variations in capitalization and language. Its account also mentions web crawlers and possible Bad Rabbit/Petya activity; the malware connection is presented as a possibility, not a confirmed finding.
Recommended Free Tools
#1 Best Overall
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
Credential techniques described
- Password guessing: trying possible passwords against accounts.
- Password spraying: trying a small set of passwords across many accounts rather than concentrating attempts on one account.
- Credential stuffing: testing previously exposed username-and-password combinations.
- Weak or default credentials: attempting access where accounts retain easily guessed or unchanged credentials.
These methods can put internet-accessible remote services and administrative accounts at risk. The report identifies the techniques it observed or classified; it does not establish that every targeted service was breached.
Where did the attacks appear to come from?
Heimdal said more than half of the investigated attack IPs were linked to Moscow, with others associated with Amsterdam and Brussels. It named Edinburgh and Dublin among frequently targeted cities and discussed targets in the UK, Denmark, Hungary, and Lithuania. The company also said Microsoft infrastructure in Belgium and the Netherlands was used, and named Telefonica LLC and IPX-FZCO as abused providers.
These are reported associations based on IP and infrastructure analysis, not proof of an attacker’s physical location, identity, or government direction. An IP address may be routed through infrastructure controlled by someone other than its apparent provider or location. Heimdal’s founder, Morten Kjaersgaard, characterized the findings as evidence that “an entity in Russia is waging a hybrid war on Europe, and may have even infiltrated it.” That is his interpretation of the company’s findings; the public material does not independently establish state attribution or infiltration.
How Heimdal says it conducted the investigation
Heimdal says the data came through its Threat-Hunting & Action Center, using an Extended Threat Protection engine integrated with its Next-Generation Antivirus, Firewall, and Mobile Device Management products. It says it also incorporated external sources including Shodan, Cloudflare, Censys, and SIE Europe probing. Paul Vixie, co-founder of SIE Europe, said the organization does not traffic in personally identifiable information and described the case as showing the investigative value of cooperatively assembled public information. The company’s investigation page does not publish a complete dataset, a sufficiently detailed sampling frame, or a method that would let readers independently test its geolocation, campaign boundaries, or attribution.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
How can organizations reduce brute-force risk?
Heimdal’s release recommends stronger cloud security, multifactor authentication (MFA), regular security audits, and employee education. These are recommendations, not measures whose comparative effectiveness was tested in the investigation. In practice, they address different parts of the risk:
- Require MFA: Add a second authentication factor so a password alone is not enough for account access.
- Review exposed remote-access services: Identify internet-facing RDP and SMB services, remove exposure where it is unnecessary, and restrict access where it is required.
- Audit accounts and configurations: Check for default or weak credentials, unnecessary administrative accounts, and security settings that allow avoidable exposure.
- Educate employees: Explain password reuse and credential theft risks, and provide a clear way to report suspicious sign-in prompts or activity.
- Monitor authentication activity: Look for repeated failures, attempts across many accounts, and unusual access patterns so that suspicious activity can be investigated.
These are practical controls for credential-attack risk, not a ranking or a guarantee of prevention. The investigation does not report testing these measures against the activity it describes.
Quick Recap
Best Value
- Looks like a real book, a good choice to be hidden that will coordinate with your books on shelf.
- Combination diversion book safe is locked by security code( 3-number combination lock), No need to worry about losing key
- Enough space to hide cash, coins, jewelries, watch, passport, paper bill and other valuable items.
- Outer Dimensions: W2.17*D7.40*H10.0(inches); Inner Dimensions: W1.97*D5.90*H9.53(inches)
- Durable material imported from Japan.
Rank #4
- Looks like a real book, a good choice to be hidden that will coordinate with your books on shelf.
- Combination diversion book safe is locked by security code( 3-number combination lock), No need to worry about losing key by owing to Dial key
- Enough space to hide cash, coins, jewelries, watch, passport, paper bill and other valuable items.
- Outer Dimensions: W2.17*D7.40*H10.0(inches); Inner Dimensions: W1.97*D5.90*H9.53(inches)
- Durable material imported from Japan.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

