This bestiary is drawn from observations of over 6 million events captured on live nodes during a two-week period in April 2026. It is a representation of the types of threats Deception Check can help identify. Every attacker is classified into an archetype and rated on a 0 to 10 scale, with rarity tiers calculated from how often we see each one across the fleet.
IRC PRIVMSG β DDoS command dispatch across thousands of zombies
IRC C2 takedowns, behavioral detection of C2 beaconing, egress filtering
Persistent backdoor access, DDoS-for-hire capacity, credential dumps
Perfectly structured recon chain with zero typos, 2-4 second intervals, context-aware pivots
AI guardrails limiting truly novel attacks, behavioral analytics detecting too-perfect patterns
Well-documented attack paths, AI-generated exploit code, automated reporting
61-password IoT default blitz in under 30 seconds
Account lockouts, fail2ban, key-only SSH auth
Valid credential pairs for lateral movement
50+ phpunit path permutations in a single burst, then .env file harvesting
WAFs with virtual patching, up-to-date dependencies
Exposed credentials from .env files, RCE shells, cloud API keys
nvidia-smi -q β lscpu β nproc β deploy xmrig β set crontab persistence β kill competing miners
Process monitoring, CPU usage alerts, egress filtering on stratum ports
Monero (XMR) cryptocurrency, pool statistics revealing operator wallet
whoami β uname -a β cat /etc/passwd β ls /home β find / -name '*.conf' β genuine exploration
Honeypot deception (they trust what they see), EDR behavioral detection, session recording
Targeted intelligence, custom tools, unpredictable lateral movement
0.2-second inter-command gaps, 8+ unique commands, zero typos, systematic enumeration patterns no human would execute that cleanly
Brittle against unexpected environments, can be fingerprinted by timing analysis, easily confused by honeypot deception
Complete automated attack reports, zero-day chains, reproducible exploit playbooks
Full IPv4 port sweep in under 45 minutes
Blocklists and rate limiters immediately neutralize them
Internet-wide scan datasets, research papers
enable β system β shell β sh β busybox echo \\xNN tag β wget C2 β chmod +x β execute for all 12 architectures
Firmware updates, changed default passwords, network segmentation
DDoS-for-hire capacity, proxy networks, crypto mining rigs
chattr -ia .ssh β rm β mkdir β inject RSA key β chmod 700 β all in under 2 seconds
Immutable authorized_keys, key-based auth with agent forwarding disabled, file integrity monitoring
Persistent backdoor access, lateral movement capability across the network
SYN β RST in under 200ms, never to return
Literally everything. A closed port stops them.
Nothing. Not even a complete TCP handshake.