We plant fake cloud credentials. Attackers harvest them — and use them in the wild. This is the bait working, end to end.
No out-of-band API actions recorded in this window.
Traffic claiming to be a real AI crawler (GPTBot, ClaudeBot, PerplexityBot, and similar) — split against the share hitting credential/secret-harvest paths a genuine crawler never would. That split is a spoofed UA riding on conventional attacker tooling.
| Campaign | Class | Events | Countries | First seen |
|---|
Which fictional company (persona) draws which kind of attacker — a WordPress site and an exposed NVR/DVR admin panel should not see the same population.
Distinct TLS fingerprint tools first catalogued per week — — total to date.
5+ distinct source IPs sharing a TLS fingerprint within the same hour — evidence of coordinated botnet infrastructure. — total to date.
Usernames sprayed against the trap — only generic, well-known logins are published.
Structure of the sprayed passwords — never the values. “Target-domain derived” means mutated from the victim’s own domain.