Network attribution associated many of the source IP addresses with cloud and virtual-server infrastructure:
- 40 IP addresses associated with DigitalOcean networks—approximately 42.6% of the observed sources
- 9 associated with Hetzner networks—approximately 9.6%
- 7 associated with Microsoft Azure networks—approximately 7.4%
- 5 associated with Google Cloud networks—approximately 5.3%
Together, these four network groups represented approximately 65% of the observed source IP addresses. Other sources were associated with hosting networks, virtual private servers, and residential or business internet providers across several regions.
This attribution does not mean that any named provider conducted, authorized, or knowingly supported the activity. Attackers frequently misuse legitimate infrastructure, including compromised servers, stolen cloud accounts, temporary virtual machines, proxies, botnets, and poorly secured customer systems.
Cloud infrastructure is useful to attackers for the same reasons it is useful to legitimate businesses: it can be deployed quickly, offers reliable connectivity, and makes it possible to distribute activity across addresses and regions.