Observed Activity Field Guide · living document · rebuilt Aug 2026

The Bestiary of Cyber Threats

A living field guide drawn from a large, multi-window observational sample of 21,223 distinct source IPs / 1.37 million sessions across three 2026 windows (April, July, and August) on the live Deception Check decoy fleet. Deduplicated by source IP and classified by behaviour. Reference Examples name known families for context; they are not attributions of these observations. This is an observational sample over time, not a full census; the guide grows as new decoy types and behaviours produce verified data.

AI attribution note: the “AI-Assisted / Automated Operator” card flags a behavioural PATTERN (novel, non-replayed, high-diversity command sequences) consistent with AI assistance or bespoke tooling. It is not a claim of AI authorship; attribution is explicitly not established.
OT / ICS protocol decoys · separate sensor
Different denominator from the IT cards below: industrial-protocol probing measured on the OT decoys in July 2026.

ICS / OT Prober

Level 7 Diviner
Lawful Neutral
OT protocol sensor · July 2026
Uncommon
The Substation Stalker. It looks beyond files toward process-level systems. It speaks the industrial protocols (Modbus, S7), reading device identity and holding registers to map the physical plant behind the IP. Counted only when it reaches a genuine control protocol; SNMP-only reconnaissance is set aside (see notes).
Capability
6
Aggression
3
Speed
5
Knowledge
8
Adaptability
4
Lethality
8

Signature Move

Modbus Read Device Identification and Report Server ID queries, plus S7comm SZL identity reads

Weakness

Purdue-model segmentation, protocol-aware allowlists, read-only register replicas

Reference Examples

  • Industroyer / CrashOverride
  • TRITON / TRISIS
  • PIPEDREAM / INCONTROLLER
  • Sandworm ICS operations

Loot Dropped

PLC/RTU device maps, register layouts, the reconnaissance a control-process attack needs first

367
Industrial-protocol IPs
Modbus / S7
Protocols reached
Separate sensor
Denominator
IT & SSH-facing decoys · 21,223 sampled source IPs
Every source IP classified once from its behaviour; counts reconcile exactly to the sample total. Encounter Rate reads as one in every N source IPs in this 21,223-IP sample, not a rate per hour, per node, or per customer. The six 0 to 10 stats are an editorial impact-potential read of the archetype, not a measurement; the counts, percentages and rarity are the measured parts.
Rare (5)  ·  Uncommon (4)  ·  Common (4)

Human Attacker

Level 14 Fighter
Chaotic Neutral
Encounter Rate: 1 in 102
Rare
Fingers on keyboard, brain engaged. Reads error messages, adjusts, explores directories, makes decisions. The occasional typo, sl for ls, is the tell automation rarely reproduces. Irregular timing, creative pivots, genuine curiosity about the box.
Capability
8
Aggression
6
Speed
3
Knowledge
8
Adaptability
9
Lethality
7

Signature Move

whoami → uname -a → cat /etc/passwd → explore; with typos and irregular pacing

Weakness

Honeypot deception, EDR behavioural detection, session recording

Reference Examples

  • Hands-on-keyboard intrusion operators
  • Manual post-exploitation
  • Bug-bounty hunters gone rogue
  • Targeted access brokers

Loot Dropped

Targeted intelligence, custom tooling, unpredictable movement

208
Source IPs
1.0%
of Sample
Rare
Rarity

AI-Assisted / Automated Operator

Level 16 Enigma
True Neutral
Encounter Rate: 1 in 141
Rare
Pattern, not proof. Novel command sequences, not replayed from any known botnet script, with high command diversity and clean structure, consistent with an AI co-pilot OR bespoke human tooling. We flag the behaviour; we do NOT claim AI authorship. Attribution not established.
Capability
8
Aggression
5
Speed
6
Knowledge
8
Adaptability
7
Lethality
6

Signature Move

Novel, non-replayed sequence + high unique-command diversity + clean structure

Weakness

Honeypot deception, and the fact that its own novelty makes it stand out

Reference Examples

  • LLM-assisted operators (unconfirmed)
  • Bespoke custom tooling
  • Novel automation frameworks
  • Hand-built recon chains

Loot Dropped

Well-structured attack paths; attribution to AI is not established

150
Source IPs
0.7%
of Sample
Rare
Rarity

Known Scanner

Level 5 Ranger
Lawful Neutral
Encounter Rate: 1 in 200
Rare
The disclosed cartographers. They map every port, banner and certificate across IPv4, not to attack, but to illuminate. Published ranges, transparent intent, polite user-agents. Matched against a maintained CIDR list and set aside.
Capability
3
Aggression
2
Speed
9
Knowledge
8
Adaptability
3
Lethality
1

Signature Move

Full IPv4 sweep from a published, attributed network range

Weakness

Blocklists and rate limiters neutralize them instantly

Reference Examples

  • Censys
  • Shodan
  • Shadowserver
  • ONYPHE
  • Palo Alto Xpanse
  • BinaryEdge

Loot Dropped

Internet-wide scan datasets, research papers

106
Source IPs
0.5%
of Sample
Rare
Rarity

Cryptominer Operator

Level 9 Artificer
Neutral Evil
Encounter Rate: 1 in 236
Rare
The Prospector extracts rather than destroys. After access it surveys hardware (nproc, /proc/cpuinfo, free -m, and nvidia-smi) and if the specs fit, deploys a miner pointed at its pool and vanishes, leaving elevated bills and degraded performance.
Capability
7
Aggression
4
Speed
5
Knowledge
7
Adaptability
6
Lethality
2

Signature Move

Hardware recon → deploy XMRig → crontab persistence → kill competing miners

Weakness

Process monitoring, CPU alerts, egress filtering on stratum ports

Reference Examples

  • TeamTNT
  • Kinsing / Kdevtmpfsi
  • 8220 Gang
  • WatchDog

Loot Dropped

Monero (XMR), pool statistics revealing the operator wallet

90
Source IPs
0.4%
of Sample
Rare
Rarity

Credential Validator

Level 6 Rogue
Lawful Evil
Encounter Rate: 1 in 312
Rare
The list-checker. Repeatedly tests a narrow, specific credential set, a handful of pairs across many attempts; consistent with validating a credential list already in hand rather than guessing blindly. New in v2; small but high-signal.
Capability
5
Aggression
4
Speed
5
Knowledge
5
Adaptability
3
Lethality
4

Signature Move

Many attempts confined to a narrow, repeated credential set

Weakness

Rotating credentials, MFA, lockout on repeated failure

Reference Examples

  • Combo-list validation services
  • Access-broker credential checks
  • Post-breach credential reuse
  • Targeted account testing

Loot Dropped

A narrow credential set being repeatedly tested for reuse

68
Source IPs
0.3%
of Sample
Rare
Rarity

SSH Key Injector

Level 10 Assassin
Lawful Evil
Encounter Rate: 1 in 13
Uncommon
Silent and methodical. It does not ransack the system; it plants a backdoor. cd ~ → chattr -ia .ssh → mkdir .ssh → append an authorized key. One key, persistent access. They will be back.
Capability
8
Aggression
3
Speed
6
Knowledge
7
Adaptability
7
Lethality
6

Signature Move

chattr -ia .ssh → mkdir .ssh → append authorized_keys → chmod; seconds, self-contained

Weakness

Immutable authorized_keys, key-based auth, file-integrity monitoring

Reference Examples

  • Outlaw SSH worm
  • FritzFrog P2P botnet
  • RapperBot
  • Ebury (Operation Windigo)

Loot Dropped

Persistent backdoor access, lateral movement

1,690
Source IPs
8.0%
of Sample
Uncommon
Rarity

Web Exploit Scanner

Level 8 Monk
Neutral Evil
Encounter Rate: 1 in 17
Uncommon
Swift and methodical. Throws hundreds of known CVE and secret-file paths at every HTTP endpoint it finds: /.env, /.git/config, phpunit eval-stdin, Log4Shell JNDI, and Spring class loaders. Each request a precisely aimed strike at a known weakness. The dominant archetype on web/OT surfaces.
Capability
6
Aggression
7
Speed
9
Knowledge
6
Adaptability
3
Lethality
5

Signature Move

Bursts of distinct exploit and secret-file paths, then .env / .git harvesting

Weakness

WAFs with virtual patching, up-to-date dependencies

Reference Examples

  • Nuclei-based scanners
  • Log4Shell mass-exploitation
  • ThinkPHP / Spring sprays

Loot Dropped

Exposed secrets from .env / .git, RCE shells, cloud keys

1,268
Source IPs
6.0%
of Sample
Uncommon
Rarity

Research / Commercial Scanner

Level 5 Ranger
True Neutral
Encounter Rate: 1 in 29
Uncommon
Cartographers with a business model. Broad, high-fan-out sweeps across many sensors and protocols with little per-host interaction, marked by self-identifying user-agents or the tell-tale zero-engagement fan-out. Separated, not deleted: real traffic, but not adversarial. New in v2 beyond the published-CIDR list.
Capability
4
Aggression
2
Speed
9
Knowledge
7
Adaptability
3
Lethality
1

Signature Move

High cross-sensor fan-out, minimal per-host engagement, scanner user-agents

Weakness

Being correctly identified and set aside from the adversarial count

Reference Examples

  • Commercial attack-surface scanners
  • Academic measurement projects
  • zgrab / ZMap banner sweeps
  • Uncatalogued mass scanners
  • Security vendors' internet-wide sweeps

Loot Dropped

Internet-wide inventory datasets

720
Source IPs
3.4%
of Sample
Uncommon
Rarity

Scripted Botnet (unattributed)

Level 7 Automaton
Lawful Neutral
Encounter Rate: 1 in 50
Uncommon
Automation without a name. The opening command sequence is replayed verbatim from many unrelated hosts, the signature of a shared script, but it matches no known malware family. The replay is strong evidence of automation; we cannot yet name the family.
Capability
5
Aggression
6
Speed
8
Knowledge
3
Adaptability
2
Lethality
4

Signature Move

Opening sequence replayed byte-for-byte across many distinct source IPs

Weakness

Static, brittle playbook; trivially fingerprinted once catalogued

Reference Examples

  • Uncatalogued botnet builders
  • Shared exploitation frameworks
  • Recycled attack scripts
  • Emerging families pre-attribution

Loot Dropped

Evidence of widely reused automation or shared tooling

426
Source IPs
2.0%
of Sample
Uncommon
Rarity

Mirai / IoT Botnet

Level 12 Warlock (Swarm Patron)
Chaotic Evil
Encounter Rate: 1 in 4
Common
The Hive Mind. Variants of the leaked Mirai source now number in the thousands. Each infected device becomes a drone: scanning, brute-forcing, and DDoSing on command. The busybox echo fingerprint and the enable/system/shell login chain are its battle cry.
Capability
7
Aggression
9
Speed
8
Knowledge
3
Adaptability
5
Lethality
7

Signature Move

enable → system → shell → sh → busybox echo \xNN tag → wget C2 → chmod +x for every architecture

Weakness

Firmware updates, changed default passwords, network segmentation

Reference Examples

  • Mirai (Anna-senpai / Paras Jha)
  • Mozi
  • Echobot
  • Satori / Okiru
  • RapperBot
  • Gafgyt / Bashlite

Loot Dropped

DDoS-for-hire capacity, proxy networks, additional drones

5,790
Source IPs
27.3%
of Sample
Common
Rarity

Nuisance Scanner

Level 1 Commoner
Chaotic Neutral
Encounter Rate: 1 in 4
Common
The background radiation of the Internet. A connection or a probe, then gone; no login attempt, no command, no request body. Individually inert; collectively the largest population we see. In v2 this bucket is genuinely no-interaction traffic only.
Capability
1
Aggression
1
Speed
5
Knowledge
1
Adaptability
1
Lethality
0

Signature Move

Connect or single probe, no authentication, no command, no HTTP body

Weakness

Literally everything. A closed port stops them.

Reference Examples

  • ZMap background noise
  • Residential botnet probes
  • Masscan leftovers
  • Misconfigured monitoring tools

Loot Dropped

Nothing. Not even a completed interaction.

5,467
Source IPs
25.8%
of Sample
Common
Rarity

Credential Attack Bot

Level 6 Rogue
Neutral Evil
Encounter Rate: 1 in 8
Common
High-volume automated login attempts. Patient and relentless, cycling a broad dictionary of username:password pairs harvested from breaches and default-firmware lists. They do not pick locks; they try every key on the ring. Distinguished from a probe by breadth: many distinct passwords, not one.
Capability
4
Aggression
6
Speed
7
Knowledge
4
Adaptability
2
Lethality
3

Signature Move

Five-plus attempts spanning many distinct passwords in a single burst

Weakness

Account lockouts, fail2ban, key-only SSH auth

Reference Examples

  • Mirai default-credential list
  • Hydra / Medusa operators
  • SSH brute-force botnets
  • Breach-combo replays

Loot Dropped

Valid credential pairs for lateral movement

2,686
Source IPs
12.7%
of Sample
Common
Rarity

Credential Probe

Level 3 Scout
Neutral
Encounter Rate: 1 in 8
Common
The doorknob-rattler. A handful of authentication attempts, often just one, with no shell activity. Tests whether a common credential opens the door, then moves on. New in v2: split out from the old catch-all so a single failed root:root is not miscounted as a full spray.
Capability
2
Aggression
3
Speed
6
Knowledge
2
Adaptability
2
Lethality
1

Signature Move

One to four auth attempts, no post-auth shell, no follow-up

Weakness

Any non-default credential; connection rate limits

Reference Examples

  • root:root / admin:admin one-shots
  • Opportunistic default checks
  • Pre-spray reconnaissance
  • Login-only bots

Loot Dropped

A yes/no on whether the easy credential works

2,554
Source IPs
12.0%
of Sample
Common
Rarity

Stats & Notes

Signals we track that do not (yet) carry their own archetype card, either because they describe abuse of the fleet rather than an attacker type, or because the number behind them is not yet reconciled. The Bestiary is a living document. Cards in the guide above are published once a real, reconciled number stands behind them; archetypes still waiting on that number are listed at the foot of this page.

65,981
credential attempts observed (control honeypots)
25.1%
of attempts use a top-25 default password
root
most-tried username
4,028
IPs across the OT / edge decoys (July)
26.6%
of OT/edge IPs swept 3+ different decoy personas
194
SNMP-only recon IPs (set aside from ICS probing)

SNMP & reflection abuse: a note, not a card

On the OT decoys, 194 source IPs probed SNMP without ever touching an industrial control protocol. SNMP is common on printers, switches and UPS units and is frequently used for amplification/reflection abuse rather than targeted OT reconnaissance, so it is deliberately excluded from the ICS/OT Prober count. Of 1,639 IPs that touched any protocol marker on the OT sensor, only 367 reached genuine industrial protocols. Treating a SNMP probe as "wants your turbines" could lead to an over-count in this area, so it lives as a metric instead.

Honeypot-detection probing

Roughly 6,600 login attempts used fixed random strings such as 345gs5662d34 (username = password), a known technique to detect honeypots by checking whether a host accepts obviously invalid credentials. Attackers are actively fingerprinting for decoys on our fleet, which is why persona fidelity matters. The username claude has also begun appearing in credential lists.

Scanners are separated, not deleted

106 disclosed research scanners (Censys, Shodan, Shadowserver and peers) and 720 behaviourally-identified commercial/research scanners are classified as scanners and set aside from the adversarial population; real traffic, correctly labelled, so the threat picture is not inflated by internet-wide measurement.

Awaiting data & corroboration
Archetypes we actively track that do not yet carry a published card. Some are drawing real traffic that falls outside the sampled windows; others are behaviours we watch for and have not yet been able to confirm or attribute. Their stats stay blank until the data supports them, because a card without a number behind it is a guess, not a finding.

Windows / AD & RDP Prospector

Domain reconnaissance
Not yet published
Encounter Rate: awaiting data
PENDING COUNT
A Windows and Active Directory decoy with RDP exposed is live in the fleet and drawing real, distinct traffic. What it sees is dominated by legacy SMB reconnaissance and credential attempts against domain accounts.
Capability
--
Aggression
--
Speed
--
Knowledge
--
Adaptability
--
Lethality
--

Why it has no card yet

The decoy was not inside the April, July, and August sampling windows that produced the counts on this page, so it has no verified number of its own. We would rather leave it blank than borrow a figure from another surface.

What it needs

A full sampling window measured on its own sensor.

--
Source IPs
--
of Sample
--
Rarity

RAT Operator

Persistent remote access
Not yet published
Encounter Rate: awaiting data
AWAITING REVIEW
Remote access tooling that establishes durable, interactive control rather than a smash and grab. Reverse shells become puppet strings; the operator moves in rather than passing through.
Capability
--
Aggression
--
Speed
--
Knowledge
--
Adaptability
--
Lethality
--

Why it has no card yet

We hold candidate sessions, but not yet the corroboration needed to separate this cleanly from the SSH Key Injector and botnet families it overlaps with. Publishing it now would double count behaviour already attributed elsewhere.

What it needs

Corroborated classification against a named tooling or C2 family.

--
Source IPs
--
of Sample
--
Rarity

Ransomware Operator

Encryption for extortion
Not yet published
Encounter Rate: awaiting data
WATCHING
Access converted into leverage. Files encrypted, backups sought out first, and a demand left behind.
Capability
--
Aggression
--
Speed
--
Knowledge
--
Adaptability
--
Lethality
--

Why it has no card yet

No staging or execution of a ransomware payload has been confirmed on the decoys in the sampled windows. The behaviour is in the classifier; the observation is not yet there.

What it needs

An observed staging or execution sequence we can attribute.

--
Source IPs
--
of Sample
--
Rarity

Destructive Wiper

Destruction without demand
Not yet published
Encounter Rate: awaiting data
WATCHING
Damage as the objective. No ransom, no negotiation, no recovery path offered.
Capability
--
Aggression
--
Speed
--
Knowledge
--
Adaptability
--
Lethality
--

Why it has no card yet

Watched for across every surface in the fleet. Nothing in the sampled windows meets the bar for confirmed wiper behaviour.

What it needs

A confirmed destructive sequence rather than an isolated destructive command.

--
Source IPs
--
of Sample
--
Rarity

ICS / OT Manipulator

Writes to the process
Not yet published
Encounter Rate: awaiting data
WATCHING
The step beyond reconnaissance. An attacker that changes a control process rather than only reading it: writing coils, altering setpoints, and moving physical state.
Capability
--
Aggression
--
Speed
--
Knowledge
--
Adaptability
--
Lethality
--

Why it has no card yet

Every industrial protocol interaction we have classified so far is read only. Across three engines we recorded no completed writes, controls, or restarts, so the ICS / OT Prober card covers what we can actually evidence.

What it needs

A confirmed write to a control register, coil, or setpoint.

--
Source IPs
--
of Sample
--
Rarity
DECEPTION CHECK · OBSERVED ACTIVITY FIELD GUIDE · LIVING DOC · SAMPLE APR/JUL/AUG 2026deceptioncheck.ai