Skip to main content
Profiles below use public naming. Reyhford does not assert that every honeypot source IP belongs to a named group — we provide protocol and technique context so analysts can hypothesize and hunt.

Strategic (nation-state / APT)

Criminal / opportunistic

  • Ransomware affiliates targeting industrial verticals
  • Commodity botnet scanners hitting 502/102/10001
  • Hacktivist campaigns against energy and government portals

How to use profiles with Reyhford data

  1. Pull high-confidence ICS-protocol indicators via TAXII/API
  2. Enrich in your TIP with public APT reporting
  3. Ask: does this source also appear on your OT DMZ or VPN?
See Who attacks and Southeast Asia.