Attack traffic from Latvia
Honeypot telemetry for sources geolocated to Latvia
Observed by OffSeq honeypot sensors · last 30 days · last seen 2 days ago · first observed 2026-08-03 (30 days ago)
4,926
Attacks
38
Distinct source IPs
Attack traffic is led by SZ2999.
OffSeq honeypot sensors recorded 4,926 attacks from 38 distinct hosts geolocated to Latviain the last 30 days. Source addresses are aggregated to /16 networks — Mirage never publishes an individual attacker IP.
Techniques
- T1021.005 VNC2,755
- T1110 Brute Force1,136
- T1190 Exploit Public-Facing Application261
- T1595 Active Scanning181
- T1552 Unsecured Credentials31
- T1498.002 Reflection Amplification18
- T1059 Command and Scripting Interpreter10
- T1595.002 Vulnerability Scanning9
- T1046 Network Service Discovery9
- T1589.002 Email Addresses4
- T1210 Exploitation of Remote Services3
- T1078 Valid Accounts2