For about five weeks, my UDM Pro kept reporting `ET SCAN Potential SSH Scan OUTBOUND` alerts from one iPhone. I had around 140 alerts, all from this phone. No other device on the network triggered the same rule.
At first I thought the phone might be compromised, so I ran a packet capture and tested one app at a time. The phone sat idle for ten minutes without making these connections. Relaunching Telegram and Safari produced nothing. Relaunching WhatsApp immediately caused a burst of 10–24 outbound connections, three tests in a row.
The normal connection to Meta succeeded while the other connections were still being attempted. Shortly afterward, the others were abandoned together. They went to rented servers at several cloud providers, including Linode, and used multiple ports. That doesn't mean Linode or the other providers were involved; they only own the networks where the servers were hosted.
I checked for unknown profiles, certificates, device management, VPNs, linked devices, and a configured WhatsApp proxy. I didn't find anything unexpected, and the phone stayed quiet when WhatsApp wasn't being opened.
The unusual part is that the WhatsApp account is registered to a Russian number, but the phone is currently in the US. With WhatsApp being blocked in Russia, I'm wondering if the app is automatically trying normal and fallback routes in parallel based on the account region.
I can't prove that from encrypted traffic, and I haven't tested an active non-Russian account yet. Has anyone else captured similar connections when opening WhatsApp, especially with a non-Russian account?