Remote Access Services at Internet Scale: RDP, VNC and Telnet Counts
The three services that ransomware reporting keeps naming
Public reporting on 2026 ransomware activity identified external remote services as the leading initial access path ahead of phishing attachments. Three protocols dominate that category, and measuring their internet-facing population gives a sense of how large the available surface is.
The measurements
Queried on 25 September 2026 through the ZoomEye SDK using the service field: service="rdp" returned 16,465,315 matching assets, service="vnc" returned 9,179,805, and service="telnet" returned 28,423,018. Counts represent service matches in ZoomEye's index at query time.
Reading each protocol separately
RDP is the standard remote administration interface for Windows systems, and its exposure includes servers, workstations, and jump hosts. A reachable RDP endpoint is the difference between a credential requirement and an internet-facing target list. Its scale also means that credential-based attacks against RDP are statistical rather than targeted.
VNC is a remote console protocol whose older implementations authenticate only for the session, and many deployments are configured with a shared password rather than per-user identity. That makes attribution after an incident difficult, which affects detection more than prevention.
Telnet has had no place on an internet-facing system for two decades. Its count is in the tens of millions, which reflects embedded devices, network equipment, building systems, and industrial controllers rather than servers. The relevant consideration is that many of these devices cannot run a modern remote access protocol, so the remediation path is network-level restriction rather than a replacement.
What the numbers justify
A count in the tens of millions does not mean tens of millions of vulnerable systems. It means the population where credential-based and protocol-level attacks are feasible is large enough that automated scanning finds targets continuously. For an operator, that is an argument for network-level controls rather than for per-service hardening:
- Restrict administrative protocols to a management network or an authenticated gateway, and audit which of the three services are reachable from untrusted networks in your own estate.
- Treat any device that exposes Telnet as a device requiring compensating network controls, since the protocol itself cannot be secured.
- Monitor for VNC session establishment without prior authentication events, because a shared password produces a session without an account-specific log entry.
Limitations
Service-field counts group products by protocol, so they include unrelated implementations under the same label, and they cannot confirm that a specific exposed service is unprotected. All figures are single-date observations collected in a single session.
References
- ZoomEye search, executed 25 September 2026:
service="rdp"returned 16,465,315 matching assets;service="vnc"returned 9,179,805;service="telnet"returned 28,423,018 (SDK, sub_type=all, total count) - Aliyun developer article on Japan first-half 2026 ransomware trends, identifying VPN and edge devices as the leading initial infection path: https://developer.aliyun.com/article/1763380
- MITRE ATT&CK T1133 External Remote Services: https://attack.mitre.org/techniques/T1133
Top comments (0)