Where Bot Traffic Comes From: What One Honeypot Network Saw

Home › Guides › Where Bot Traffic Comes From

✓ data: two open honeypot datasets published by CSIRT-UPJS (Pavol Jozef Šafárik University in Košice), CC BY 4.0, downloaded 2 October 2026 · method · caveats · download the data

Which countries does automated attack traffic come from? Honeypots are decoy servers that exist only to be attacked, so almost everything that reaches them is bots: scanners, password-guessers and malware spreading itself. We analysed two openly licensed datasets from one university security team’s honeypots. Between them they cover 26.5 million recorded attacks across 329 days, from November 2024 to December 2025.

Read this first. This is what one honeypot network saw, not a global ranking. The published files name only the top 10 source countries in each period. A handful of IP addresses can move a country up or down, and a country is where an IP address is registered, not where the person controlling it is. We did not use our own site’s traffic: Cloudflare has only just started logging it, so there is less than a day of data, and much of it is our own tools.

attacks recorded 26.5 milliontop source, Jul–Dec 2025 United States, 13.1%top source, Nov 2024–Apr 2025 Taiwan, 23.7%countries in both top 10s 7

Headline numbers

  1. Tens of thousands of attacks a day. The honeypots logged 14,768,895 attacks from 4 Nov 2024 to 3 Apr 2025 (97,807 a day) and 11,739,398 from 7 Jul 2025 to 31 Dec 2025 (65,952 a day).
  2. The top 10 countries account for about two-thirds of attacks. The ten named countries sent 67.1% of all attacks in the first period and 63.7% in the second. The datasets don’t break down the rest.
  3. The United States moved to the top. US addresses sent 13.1% of all attacks in July–December 2025, more than any other country, up from 7.9% (fourth place) in November 2024–April 2025. They were also among the steadiest: US attacks were recorded on all 178 days, and the five busiest days made up only 5.6% of the total.
  4. Rankings change a lot from one period to the next. Taiwan was the biggest source in the first period (23.7% of all attacks) and wasn’t in the top 10 in the second. The Netherlands wasn’t in the first top 10 and came second in the later one (11.2%). 7 countries made both lists: China, France, Germany, India, Indonesia, Russia and the United States.
  5. Some countries’ totals come from a few bursts. 85.1% of attacks from French addresses in the second period arrived on just five days. The busiest, 29 Nov 2025, brought 338,079. Germany (58.6% in the first period) and Vietnam (45.9% in the second) show the same pattern. Taiwan’s first-period lead was steadier: its five busiest days made up 12.0% of its total.
  6. A small number of sources does most of the work. In a typical half hour the honeypots saw a median of 38 distinct IP addresses in the first period and 36 in the second, generating a median of 1,549.5 and 898.5 attacks. That is dozens of attacks per address.
  7. Most attacks target remote logins. The SSH/Telnet honeypot (Cowrie) took 74.8% of attacks in the first period and 63.8% in the second. Dionaea, which imitates file-sharing, database and other services that malware targets, took 15.1% and 21.8%.

Share of attacks by source country

Share of all recorded honeypot attacks by source country, November 2024 to April 2025 and July to December 2025TaiwanTaiwan, p1: 23.7%23.7%not in top 10United StatesUnited States, p1: 7.9%7.9%United States, p2: 13.1%13.1%Netherlandsnot in top 10Netherlands, p2: 11.2%11.2%FranceFrance, p1: 8.5%8.5%France, p2: 9.9%9.9%ChinaChina, p1: 8.0%8.0%China, p2: 6.5%6.5%RussiaRussia, p1: 3.2%3.2%Russia, p2: 4.9%4.9%IndiaIndia, p1: 4.6%4.6%India, p2: 3.6%3.6%IndonesiaIndonesia, p1: 2.4%2.4%Indonesia, p2: 4.0%4.0%Singaporenot in top 10Singapore, p2: 3.7%3.7%Vietnamnot in top 10Vietnam, p2: 3.6%3.6%GermanyGermany, p1: 3.4%3.4%Germany, p2: 3.3%3.3%South KoreaSouth Korea, p1: 2.7%2.7%not in top 10EstoniaEstonia, p1: 2.6%2.6%not in top 10Nov 2024–Apr 2025Jul–Dec 2025
Each country’s share of all attacks the honeypots recorded in each period, for the countries that made either top 10. Source: CSIRT-UPJS, Attacks on Honeypots (DOI 10.17632/j9zm8nj76j.1 and 10.17632/y2vvn22zkx.1), CC BY 4.0.

November 2024 – April 2025

#CountryAttacksShare of all attacksDays with attacksShare on 5 busiest daysBusiest day (attacks)
1Taiwan3,504,45023.7%12612.0%22 Feb 2025 (93,407)
2France1,260,6678.5%14754.7%12 Feb 2025 (193,595)
3China1,174,4848.0%15114.0%10 Nov 2024 (64,213)
4United States1,163,0857.9%15126.3%15 Jan 2025 (111,305)
5India682,2374.6%15119.9%19 Dec 2024 (59,889)
6Germany508,9303.4%13758.6%10 Nov 2024 (250,217)
7Russia476,3933.2%14610.6%14 Dec 2024 (13,782)
8South Korea402,9752.7%14622.6%21 Feb 2025 (24,492)
9Estonia378,1062.6%6919.0%27 Jan 2025 (19,063)
10Indonesia357,5632.4%15011.3%15 Feb 2025 (12,160)

July – December 2025

#CountryAttacksShare of all attacksDays with attacksShare on 5 busiest daysBusiest day (attacks)
1United States1,532,40213.1%1785.6%23 Nov 2025 (19,009)
2Netherlands1,313,75211.2%17712.2%23 Nov 2025 (52,209)
3France1,160,2989.9%13485.1%29 Nov 2025 (338,079)
4China758,0556.5%17812.8%14 Sep 2025 (40,055)
5Russia579,0384.9%17616.3%16 Aug 2025 (21,459)
6Indonesia472,1754.0%1769.0%25 Sep 2025 (10,044)
7Singapore429,4193.7%15918.4%30 Nov 2025 (34,369)
8Vietnam423,0023.6%16845.9%26 Oct 2025 (131,570)
9India417,3753.6%17513.7%31 Aug 2025 (20,771)
10Germany391,5703.3%17325.4%7 Jul 2025 (51,244)

Month by month

Monthly honeypot attacks from five source countries0.0M0.4M0.8M1.2M1.6MNov2024DecJanFebMarAprJul2025AugSepOctNovDecTaiwan, 2024-11: 17,414Taiwan, 2024-12: 734,394Taiwan, 2025-01: 1,551,852Taiwan, 2025-02: 714,487Taiwan, 2025-03: 486,303Taiwan, 2025-04: 0TaiwanUnited States, 2024-11: 149,986United States, 2024-12: 311,767United States, 2025-01: 310,803United States, 2025-02: 234,422United States, 2025-03: 139,167United States, 2025-04: 16,940United States, 2025-07: 202,404United States, 2025-08: 299,640United States, 2025-09: 246,326United States, 2025-10: 312,906United States, 2025-11: 267,665United States, 2025-12: 203,461United StatesNetherlands, 2025-07: 68,545Netherlands, 2025-08: 99,684Netherlands, 2025-09: 97,622Netherlands, 2025-10: 226,507Netherlands, 2025-11: 277,292Netherlands, 2025-12: 544,102NetherlandsFrance, 2024-11: 426,604France, 2024-12: 56,356France, 2025-01: 62,984France, 2025-02: 531,333France, 2025-03: 180,304France, 2025-04: 3,086France, 2025-07: 15,260France, 2025-08: 17,724France, 2025-09: 19,096France, 2025-10: 19,282France, 2025-11: 1,053,337France, 2025-12: 35,599FranceChina, 2024-11: 253,125China, 2024-12: 233,645China, 2025-01: 261,506China, 2025-02: 200,130China, 2025-03: 203,832China, 2025-04: 22,246China, 2025-07: 77,397China, 2025-08: 110,204China, 2025-09: 178,484China, 2025-10: 141,036China, 2025-11: 105,973China, 2025-12: 144,961China
Monthly attacks from five source countries (UTC months). The datasets don’t cover April–June 2025. November 2024, April 2025 and July 2025 are partial months. A country has no line in a period when it wasn’t in that period’s top 10. Source: CSIRT-UPJS honeypot datasets, CC BY 4.0.

Steady sources and bursts

Share of each country’s attacks that came on its five busiest daysFrance (2025)France (2025): 85.1%85.1%Germany (2024–25)Germany (2024–25): 58.6%58.6%France (2024–25)France (2024–25): 54.7%54.7%Vietnam (2025)Vietnam (2025): 45.9%45.9%United States (2024–25)United States (2024–25): 26.3%26.3%Germany (2025)Germany (2025): 25.4%25.4%South Korea (2024–25)South Korea (2024–25): 22.6%22.6%India (2024–25)India (2024–25): 19.9%19.9%Estonia (2024–25)Estonia (2024–25): 19.0%19.0%Singapore (2025)Singapore (2025): 18.4%18.4%Russia (2025)Russia (2025): 16.3%16.3%China (2024–25)China (2024–25): 14.0%14.0%India (2025)India (2025): 13.7%13.7%China (2025)China (2025): 12.8%12.8%Netherlands (2025)Netherlands (2025): 12.2%12.2%Taiwan (2024–25)Taiwan (2024–25): 12.0%12.0%Indonesia (2024–25)Indonesia (2024–25): 11.3%11.3%Russia (2024–25)Russia (2024–25): 10.6%10.6%Indonesia (2025)Indonesia (2025): 9.0%9.0%United States (2025)United States (2025): 5.6%5.6%
Share of each country’s attacks in a period that came on its five busiest days. A high share means the country’s total depends on a few bursts, probably from a few addresses. Blue: November 2024–April 2025. Orange: July–December 2025.

Method

  • Source. “Attacks on Honeypots (October 2024 – April 2025)” (DOI 10.17632/j9zm8nj76j.1) and “Attacks on Honeypots (June 2025 – January 2026)” (DOI 10.17632/y2vvn22zkx.1), published on Mendeley Data by Vanda Matušíková (CSIRT-UPJS, Pavol Jozef Šafárik University in Košice) and licensed CC BY 4.0. We downloaded all eight CSV files on 2 October 2026 and checked each one against the SHA-256 hash Mendeley publishes.
  • Coverage. Despite their titles, the files run from 4 Nov 2024 to 3 Apr 2025 and from 7 Jul 2025 to 31 Dec 2025 (UTC), in half-hour intervals. The second dataset has 3 gaps longer than six hours, the longest in mid-July 2025.
  • Totals. “Attacks” is the dataset’s own count of attack events, summed over every half hour. Country totals come from the source-country file. Shares are a country’s attacks divided by all attacks in the overall attack-count file for the same period.
  • Bursts. For each country and period we added up attacks per UTC day and took the share that fell on its five busiest days.
  • Not used. The port files measure something different from the attack counts (their totals don’t match), so we leave them out. We checked other sources first. AbuseIPDB’s and GreyNoise’s terms don’t allow republishing their data on a commercial site. SANS ISC/DShield licenses its API data CC BY-NC-SA 4.0 (non-commercial), and its feeds page states different terms, so we would need written permission to use it here. We didn’t use Cloudflare Radar.
  • Verification. A separate script re-reads the raw CSV files and recomputes every number on this page and in our CSVs.

Caveats

  • One network’s view. The datasets come from one team’s honeypots and don’t say how many sensors there were or where they were hosted. Bots don’t scan everywhere evenly, so another network would see a different mix.
  • Top 10 only. About a third of attacks in each period come from countries the files don’t name. A country missing from a list may simply have been 11th.
  • A country is where an address is registered, not who controls it. Attackers rent cloud servers, use hijacked devices and route through proxies, so an attack from a country’s address space says little about who is behind it. Countries with big hosting industries, such as the US, the Netherlands, Germany and Singapore, may rank high partly for that reason. The dataset doesn’t say how locations were assigned.
  • A few addresses can dominate. With a few dozen distinct IP addresses in a typical half hour, one busy address can move a country’s rank. That is why we show the burst measure.
  • Honeypot attacks aren’t website traffic. These are mostly login attempts and exploit probes against network services, not scrapers or crawlers visiting websites. They show where automated attack traffic comes from, not where web-scraping traffic comes from.
  • Dated. The newest data ends on 31 December 2025.

Download the data

  • By country and period (CSV): attacks, share of all attacks, share of the top 10, days with attacks, share on the five busiest days and the busiest day, for each top-10 country.
  • Monthly (CSV): attacks by source country and UTC month.

Cite as: ProxyPicker, “Where Bot Traffic Comes From: What One Honeypot Network Saw”, 2 October 2026, https://proxypicker.com/where-bot-traffic-comes-from/. Data: Matušíková, V., “Attacks on Honeypots (October 2024 – April 2025)”, Mendeley Data, V1, doi:10.17632/j9zm8nj76j.1, and “Attacks on Honeypots (June 2025 – January 2026)”, Mendeley Data, V1, doi:10.17632/y2vvn22zkx.1, both licensed CC BY 4.0. We aggregated the data (country, daily and monthly totals); the original files are unchanged on Mendeley.

Related: Residential IP Supply by Country · Residential proxy botnet timeline · Anti-Bot Census · AI Crawler Census · What’s my IP? Proxy & VPN checker.

Press & data requests: email [email protected] for interviews, the raw data behind this page, or corrections. See also our contact page.