Critical Threat
IP address 198.235.24.207 is a high-risk threat actor associated with 425 abuse reports and a maximum threat score, representing an active source of hacking, IoT exploitation and compromised-host activity originating from Google Cloud Platform infrastructure in the United States.
Automated honeypot sensors recorded 425 distinct reports attributed to this address over approximately ten months between August 2025 and June 2026, yielding a confidence score of 73 percent and an activity frequency rating of 8 out of 10. The overwhelming majority of recent reports—18 of the 20 most recent categorizations—classified the activity as general hacking attempts, while isolated reports also documented IoT-targeted reconnaissance and exploited-host behaviour. Network telemetry indicated repeated connection attempts, Suricata stream-layer anomalies suggesting packet manipulation or reassembly evasion, and broader malware or exploit activity consistent with automated scanning and intrusion tooling. The address operates within AS396982, which is allocated to Google Cloud Platform, indicating the malicious traffic originated from cloud-hosted infrastructure rather than a residential or business ISP.
The dominant hacking classification encompasses varied intrusion methodologies including vulnerability exploitation, credential attacks and unauthorized access attempts against exposed services. Combined with IoT-targeted activity, this IP demonstrates the hallmarks of automated reconnaissance campaigns that systematically probe internet-facing systems for entry points before deploying further payloads. The presence of exploited-host indicators alongside the cloud-hosted origin suggests this address may be functioning as a pivot point or bounce node within a larger attack chain, making it particularly dangerous as it could mask the true source of an ongoing compromise. Suricata stream anomalies further suggest attempts to circumvent detection systems by fragmenting or corrupting TCP acknowledgment sequences during the attack phase.
Operators with internet-facing services should immediately block IP address 198.235.24.207 at the network perimeter and implement defensive controls such as fail2ban or similar dynamic blocking tools that automatically respond to repeated connection attempts. Rate-limiting authentication endpoints, enforcing strong credential policies and applying vendor-issued security patches without delay will reduce the effectiveness of any intrusion attempts that do reach exposed systems. Network segmentation isolating IoT and ICS devices from critical infrastructure limits lateral movement if initial access is gained. Organizations may also consider filing an abuse report with Google Cloud Platform to alert the provider that their infrastructure is being weaponized for malicious activity.