Site navigation

New Research: Honeypot Findings From Over 42 Million Attacks

Graham Turner

,

North Korea Iran
The Outpost24 research team have released the results of attack data gathered from a network of honeypots deployed to gather actionable threat intelligence

In total, 42 million attacks were registered between January 1st and September 30th 2022, with 20 honeypots evenly distributed around the world.

A research report, which is available to view here, found that brute force attacks were the most repeated attack type with 73,860 total number of attacking IPs.

Among other key findings, the report also found that default credentials (username: root, password: root) were counted over 5.5 million times in brute force attempts and that Port 445 and 22 were the most targeted, this corresponds to Windows and Linux remote administration services.

A honeypot is a decoy system (computer, network, or software) that imitates a real system to attract malicious users and collect information about how they operate.

The collected information allows administrators to develop the right defences on production systems, like blocking known attack IPs, specific network traffic, and geolocations, as well as understanding how hackers operate within a network and prevent their strategies.

The Outpost24 research found that the most attack attempts registered against their honeypots came from IP addresses in Russia, United States and China. The research report also provides analysis of the captured data, including the credentials used in brute force attacks, targeted protocols, and explanations about the types of honeypots.


Recommended


“Honeypots are an essential part of threat intelligence gathering and provide us with critical source of fresh, real- world threat data to better understand our adversaries”, said Guillermo García, Head of Offsec at Outpost24.

He added: “The most frequent attack vectors in our study confirm that whilst cybercriminals are constantly looking for new opportunities to exploit technical and human vulnerabilities, known and easily fixable weaknesses like default credentials and open ports are just as dangerous. It further highlights the need for organisations to constantly monitor external threats and attack surface risk.”


Get all the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

Graham Turner

Sub Editor

Latest News

Events Featured Finance

Just One Week to Go Until Fintech Summit 2026

AI Business

Will Costs See Enterprises Abandon Third-party Agentic AI?

AI

AI Coding Tools Are Causing Outages and Incidents

AI Editor's Picks Recruitment Skills

AI Benefits Concentrated Among Minority of Workers, PwC Finds