Deception CheckDeception Check← all research
Threat Research · Fleet Telemetry

The Week the Noise Quadrupled

For the last week of June, our honeypot fleet saw a steady, unremarkable background of around 600 distinct attackers a day. Then, on July 6, that number jumped to nearly 1,500 — and over the next four days it climbed past 2,800 and stayed there. This is what a real attack surge looks like in the data: not one loud event, but a broad, sustained rise in the sheer number of different machines knocking on the door. Here is what drove it, the two very different shapes the traffic took, and what a surge like this can and cannot tell you.

Deception Check · Threat Research · July 15, 2026 · Window 2026-06-27 → 2026-07-15 · global decoy fleet
The short version

Beginning July 6, 2026, the count of unique source IPs attacking the Deception Check fleet each day rose from a ~600/day baseline to a 2,700–2,900/day plateau — a roughly 4–5× increase that held for the rest of the window. Across the surge we logged 11,807 distinct IPs. The traffic sorted cleanly into two archetypes: broad fleet-wide scanners that reached at least 15 decoys across four continents, and single-target floods that fixated on one node and hammered it tens of thousands of times — the loudest being the Mirai-lineage IoT loader we dissect in a companion piece. The rise was not random noise: it contained clear structure, including several addresses from one flagged network block and coordinated /24 pairs. We report the counts and shapes our sensors recorded and stay deliberately cautious about attributing them to any campaign or actor.

4–5×
jump in daily attackers
11,807
unique IPs in the surge
Jul 6
the step change
15+
decoys, 4 continents
Unique attacking IPs per day
Each bar is the count of distinct source addresses seen across the fleet that day. The change on July 6 is abrupt and it holds.
010002000300006-2706-2907-0107-0307-0507-0607-0707-0807-0907-1007-1107-1207-1307-1407-15Jul 6 → surge

The step change

The most honest way to read a honeypot fleet is to stop looking at raw volume — which any single misbehaving bot can inflate — and look instead at how many different machines show up. That number is harder to fake and closer to a real measure of interest. Through late June it sat flat: 232, 578, 619, 565, 656, 601, 628, 531, 687 distinct IPs on successive days. A quiet, healthy baseline. Then July 6 landed at 1,442, July 8 at 2,755, and July 10 at 2,890, and the fleet never returned to its old floor. Whatever changed on the 6th did not spike and fade; it reset the baseline to four or five times what it had been.

We are careful not to over-read a single fleet's view of the internet. A rise like this can reflect a new scanning campaign, a botnet expanding its worker pool, a block of cloud or residential addresses being turned to the task, or simply our own decoys becoming better known and more indexed by the scanners that catalogue exposed services. Most likely it is some blend. What we can say without hedging is that the change was real, sharp, dated, and sustained — and that it showed internal structure rather than looking like uniform background hiss.

Two shapes of attacker

When we broke the surge down by what each source actually did, the top talkers split into two clean archetypes — and the split matters, because they represent different intentions.

175.107.0.198
PK · 175.107.0.0/19
83,734
5.61.209.43
fleet-wide
48,562
175.107.3.227
PK · 175.107.0.0/19
30,325
187.189.119.83
single node
22,449
46.205.244.93
single node
21,067
45.153.34.151
scanner pair
10,387
94.154.43.243
fleet-wide
9,584
175.107.0.91
PK · 175.107.0.0/19
8,712
Fleet-wide scanner — touched most/all nodesSingle-target flood — fixated on one decoy

Scanners spread themselves across the whole fleet. One address, 5.61.209.43, opened 48,562 sessions and reached at least 15 decoys across four continents; 94.154.43.243 did the same at smaller scale. These are the internet's cartographers — mapping what is exposed and where, feeding target lists. Floods do the opposite: they lock onto a single node and pound it. 175.107.0.198 threw 83,734 sessions at one decoy and nothing else; 187.189.119.83 and 46.205.244.93 each fixated on a single OT-style decoy. A flood is a bot that found something it liked and committed — usually an automated loader trying, over and over, to recruit what it believes is a vulnerable device.

Clusters, not chaos

The detail that separates a real campaign signature from ambient noise is repetition of structure. We saw it. Three of the heaviest single-target floods — 175.107.0.198, 175.107.3.227, and 175.107.0.91 — all originate from the same network block, 175.107.0.0/19, an address range that third-party reputation services flag as a source of repeated abuse. Separately, two coordinated pairs, 45.153.34.151/.167 and 45.156.87.253/.254, showed near-identical fleet-wide scanning behaviour from adjacent addresses. Neighbours behaving identically is the fingerprint of shared tooling or a shared operator — the difference between a crowd and a formation.

Stop looking at raw volume, which any single bot can inflate, and look at how many different machines show up. That number is harder to fake and closer to real interest.

What this tells you — and what it doesn’t

A surge in unique attackers is a genuine signal, and the useful thing it tells a defender is timing and shape: attention rose on a specific date, it is dominated by IoT-style telnet floods and broad service scanning, and it is coming from identifiable clusters you can watch. That is actionable. What it is not is proof of a coordinated operation or grounds to name a culprit. Scanners and loaders run overwhelmingly from compromised third-party devices and rented infrastructure; the addresses we list are far more likely to be waypoints and victims than the hand on the wheel. We publish the clusters and counts because they help you tune detections and blocklists, not because they identify anyone.

The honest framing These are counts and behavioural shapes recorded by our own sensors over a defined window. We do not attribute the surge to a named campaign, group, or country, and we treat the registered owners of the source networks as uninvolved absent specific evidence. A rise in one honeypot fleet’s traffic is a local observation of a global system; we report it as exactly that.

Top sources & defensive takeaways

Heaviest sources in the surge window — defang before use 5.61.209.43     48,562 sessions · fleet-wide scanner (across the fleet, 4 continents)
94.154.43.243   9,584 sessions · fleet-wide scanner (across the fleet, 4 continents)
45.153.34.151 / .167  coordinated scanner pair (9 nodes each)
45.156.87.253 / .254  coordinated scanner pair
175.107.0.198 / .3.227 / .0.91  single-target floods from 175.107.0.0/19 (flagged block)
187.189.119.83 · 46.205.244.93 · 164.90.148.8  single-target floods
Sources & method. All counts are computed directly from Deception Check honeypot session records across our global decoy fleet, 2026-06-27 to 2026-07-15 (July 15 partial). “Unique IPs per day” counts distinct source addresses; archetype classification is by number of distinct decoys each source touched. Network-block reputation context from third-party feeds, retrieved 2026-07-15. No attribution to any named actor or campaign is made. Companion analysis of the largest single source: “83,734 Knocks on One Door.”
About Deception Check

Deception Check runs a fleet of language-model-backed honeypots and edge decoys that imitate real enterprise and operational-technology equipment, so we can watch attackers from the other side, at the moment they reach an exposed system. This surge surfaced on its own from routine fleet telemetry. First-party data, honest caveats.

© 2026 Deception Check. All figures are computed from first-party honeypot telemetry over the stated window; source-network reputation context is third-party and dated. No attribution to any named actor or campaign is made.