Extreme Threat
IP 198.235.24.243 is a high-risk address operating from Google Cloud Platform infrastructure within the United States, with a maximum threat rating of 10/10 and 162 independent abuse reports filed through automated honeypot sensors over approximately ten months between August 2025 and June 2026. The dominant threat category associated with this IP is general hacking activity, representing the vast majority of recent reports, with additional indicators of exploited-host behaviour and targeted IoT reconnaissance. Given the severity rating and the confirmed pattern of malicious connection attempts, this address poses a significant risk to any exposed services on the public internet.
The IP has been flagged by 20 distinct automated honeypot sensors, generating a total of 162 reports with an 82% confidence score and a moderate activity frequency rating of 4 out of 10. Network routing through AS396982 (Google Cloud Platform) indicates the source originates from a major cloud hosting provider commonly leveraged by threat actors for its reputation and geographic diversity. The reported activity includes honeypot events, malware or exploit-related behaviour, and IoT or industrial control system reconnaissance. A Suricata intrusion-detection alert specifically noted an SSH session in progress on an expected port, confirming active credential-attack operations against remote-administration interfaces.
The hacking activity linked to 198.235.24.243 reflects systematic unauthorized-access attempts, likely including brute-force credential guessing and vulnerability probing against exposed SSH services. Cloud-hosted infrastructure used for these attacks often indicates a sophisticated actor capable of scaling operations quickly while maintaining plausible deniability through legitimate provider networks. The additional IoT-targeted behaviour suggests this address may also be conducting reconnaissance against smart devices, cameras, or networked hardware with weak security postures. When combined with the exploited-host classification, these indicators suggest the address is actively weaponised for multi-vector intrusion campaigns.
Site operators should block 198.235.24.243 at the firewall or network edge immediately and implement rate-limiting on SSH and other remote-access services to reduce exposure to credential-guessing attacks. Deploying tools such as fail2ban or configuring account lockout policies can automatically penalise repeated authentication failures from this source. All exposed services should enforce strong, unique passwords and disable root or default accounts where possible. Continuous monitoring for the indicators associated with this address, including SSH sessions on non-standard ports and anomalous outbound connections from internal hosts, will help detect any successful intrusion attempts.