Dectrax
[SECURITY RESEARCH]

2026 Threat Landscape Report: Analysis of Automated SSH Brute-Force Vectors in South Asian Cloud InfrastructureAbstract

February 4, 2026By Robert Ryan
2026 Threat Landscape Report: Analysis of Automated SSH Brute-Force Vectors in South Asian Cloud InfrastructureAbstract

This report details the findings from a 60-day study conducted by DentiSystems Research Labs. By deploying a distributed network of low-latency Linux honeypots (utilizing the DentiGrid engine) across Dhaka and Rangpur nodes, we analyzed over 1.2 million inbound connection attempts. The data reveals a 300% year-over-year increase in automated botnet traffic targeting financial and telecommunications infrastructure in Bangladesh.

Introduction
As digital infrastructure in South Asia expands, so does the attack surface for Advanced Persistent Threats (APTs). While global reports often focus on Western targets, local data regarding threat vectors in Bangladesh remains scarce. This study aims to fill that gap by analyzing raw telemetry from local "listening posts" to identify the specific signatures of attacks targeting this region.


Methodology: The DentiGrid Network
To capture high-fidelity attack data without alert fatigue, DentiSystems deployed active deception nodes (honeypots) mimicking standard Linux server environments (Ubuntu 22.04 LTS).

  • Deployment Zone: Rangpur (Edge) and Dhaka (Core).
  • Duration: December 2025 – February 2026.
  • Detection Engine: DentiGrid proprietary behavioral analysis.

Key Findings: The "Silent" Noise
Our analysis isolated three distinct patterns in the attack traffic:

  • Targeted Port Scanning: 84% of all malicious traffic targeted Port 22 (SSH) and Port 8080 (Web Proxy), indicating a massive, automated effort to hijack compute resources for crypto-mining botnets.
  • Origin of Attacks: While IP spoofing makes attribution difficult, header analysis suggests a significant volume of traffic originating from compromised IoT devices in neighboring regions, specifically routed through proxy chains to evade geo-blocking.
  • Credential Stuffing: The study recorded an average of 4,500 brute-force login attempts per node per day, utilizing dictionaries specifically tailored to default OEM passwords common in the region's hardware.

The Failure of Static Firewalls
Standard firewall rules (WAF) proved ineffective against 60% of these incursions because the attackers utilized "Low-and-Slow" techniques—sending packets at intervals designed to stay below the threshold of traditional rate-limiting algorithms.

Conclusion
The data confirms that passive defense mechanisms are no longer sufficient for South Asian enterprises. The shift towards active defense—specifically the use of internal honeypots—is critical for early detection. Organizations must move from a posture of "block and ignore" to "trap and analyze" to understand the specific threat actors targeting their specific vertical.

Robert Ryan

AUTHOR

Robert Ryan

Research Lead, Dectrax