TECH Signal 500
Citigroup, Idaho, and Build-a-Bear Launched a Coordinated Attack on Me
A researcher running a global honeypot observed that machines inside networks belonging to Citigroup, Build-A-Bear, the State of Idaho, Lockheed Martin, and roughly a dozen other organizations all probed his SIP servers as part of a single coordinated International Revenue Share Fraud campaign, and published a free, key-less API so any operator can check whether their own network appears in the da
If a bot inside your perimeter is willing to relay outbound SIP calls to a fraud ring, that machine has egress to arbitrary hosts on the public internet and very likely broader access to your internal network than it should. The published API lowers the cost of self-audit to a single curl call against your ASN or CIDR block, which makes routine checks feasible for teams that previously had no realistic way to know whether their IP space was being abused for toll fraud.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Over a 27-hour window starting August 1 (year as stated in the article), infected hosts across roughly fifteen organizations independently attempted the same IRSF pattern against honeypots in Los Angeles, New York, and Tokyo, converging on a single premium-rate target and a shared small set of spoofed caller IDs.
The operator has released a no-signup API at api.knock-knock.net that returns matching IPs from honeypot logs when given an ASN, a set of CIDR ranges, or a single address, and the same endpoint exposes data for SIP, SSH, RDP, SMB, and HTTP probes.
The list of affected organizations includes a global bank, a defense contractor, a national police force, multiple US state and local agencies, and a toy retailer, indicating that the bot reached corporate and government endpoints rather than only consumer or SMB networks.
THE CLUSTER
↗