If you run anything with an exposed management interface — a serial-to-IP converter in a hospital closet, a SystemBC-infected proxy node on your corporate LAN, a Shopify admin panel, a DeFi treasury wallet — the same pattern is hitting you this week. Attackers aren’t finding clever new zero-days. They’re scanning, probing, brute-forcing, and pivoting from compromised IPs they’ve used for months. That’s exactly the failure mode ipban is built for, and this week’s news is a clinic in why edge-level IP banning still earns its keep.
Four stories. One thread. Lantronix and Silex serial-to-IP converters with 20 new CVEs exposing OT and healthcare networks. The Gentlemen ransomware crew turning 1,570+ corporate hosts into a SystemBC proxy botnet. Seiko USA defaced with a Shopify database ransom demand. And Tyler Buchanan, the British Scattered Spider operator, pleading guilty in a U.S. court after running SMS phishing and credential theft against dozens of companies. None of these attacks needed novel tradecraft. They needed reachable IPs and time.
The Infrastructure You Forgot Is The Infrastructure They Found
Forescout’s disclosure on Lantronix and Silex is the one most sysadmins will skim past, and that’s the problem. Serial-to-IP converters are the quiet plumbing of OT networks, medical imaging gear, industrial printers, legacy SCADA consoles. Nobody logs into them. Nobody patches them. Most of them were installed by a contractor in 2016 and forgotten.
Now you’ve got 20 vulnerabilities, theoretical attack scenarios that aren’t theoretical once someone weaponizes them, and a fleet of devices that were never designed to be on a routable network in the first place. The firmware will take months to land. Some of these devices will never get patched because the vendor doesn’t exist anymore or the customer can’t take the downtime. What’s the interim control? It’s not EDR — these things don’t run agents. It’s not segmentation alone — they’re already segmented and still getting hit. It’s knowing which IPs have any business talking to them and rejecting everything else at the edge.
Scattered Spider and SystemBC Prove The Boring Stuff Still Works
Buchanan’s guilty plea is a reminder that Scattered Spider didn’t beat Okta and Caesars with magic. They beat them with phone calls, SIM swaps, and credential reuse from IPs that were already flagged across the threat-intel community. The Gentlemen ransomware affiliates running SystemBC are doing the same thing at scale: 1,570 hosts turned into a proxy mesh so outbound C2 and inbound reconnaissance look like legitimate corporate traffic. That’s a deliberate attempt to defeat IP reputation — and it works, until you flip the model.
Here’s the uncomfortable truth. If you’re only blocking known-bad IPs from a static list, you’re already behind. Modern brute-force protection has to be behavioral: failed auth counts, request cadence, protocol anomalies, geographic mismatch against the account’s history. The IPs themselves are disposable. The behavior from those IPs is what gives the attacker away in the first 30 seconds, before they even finish enumerating your usernames.
Consider what the SystemBC botnet actually buys the Gentlemen crew:
- Residential-looking source IPs that bypass geo-blocks
- Rotating infrastructure so any single ban has a short half-life
- Cover traffic that makes SIEM alerting noisy and unreliable
- A built-in proxy layer for credential stuffing against your VPN, RDP, and SSH endpoints
Static blocklists don’t touch that. Real-time behavioral banning does.
What To Actually Do This Week
Stop treating the edge as a commodity. The KelpDAO $290M Lazarus heist and Seiko’s Shopify defacement are on opposite ends of the sophistication spectrum, and both started with reachable endpoints and credentials that shouldn’t have worked from the IPs they worked from. Here’s the short list for the next seven days.
Audit, then enforce
Inventory every internet-facing management interface — serial converters, BMCs, jump hosts, admin panels, Shopify and SaaS admin logins tied to corporate SSO. For each one, ask whether the authentication endpoint has rate limiting, failed-attempt banning, and geographic controls that match the actual humans who use it. If the answer is “we trust the vendor’s defaults,” the answer is no.
Deploy a brute-force protection layer that watches authentication traffic in real time and bans source IPs on behavior, not just reputation. For Windows RDP, SSH, SMTP, and IIS — the protocols Scattered Spider and ransomware affiliates hammer first — IPBan Pro gives you automatic IP banning, shared threat feeds across deployments, and country-level blocking that kills a Lazarus or Gentlemen campaign before it finishes the first scan cycle. Pair it with your existing firewall and you’ve closed the gap the SystemBC botnet is designed to exploit.
Then turn on alerting for the weird stuff: authentication from ASNs you’ve never seen, login attempts against accounts that shouldn’t exist, probing on ports you didn’t know were open. The serial-to-IP converter nobody remembered installing will light up the first time an attacker finds it — but only if you’re watching.
The attackers in this week’s headlines aren’t geniuses. They’re patient, well-resourced, and betting that you’ve left at least one door unlocked. IP banning at the edge is how you make sure patience stops being enough.
Sources
- Serial-to-IP Converter Flaws Expose OT and Healthcare Systems to Hacking
- The Gentlemen ransomware now uses SystemBC for bot-powered attacks
- Seiko USA website defaced as hacker claims customer data theft
- British Scattered Spider Hacker Pleads Guilty in the US
- KelpDAO suffers $290 million heist tied to Lazarus hackers
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
