Honeypot operators worldwide have long understood that their traps rarely run silent for long, with a constant background hum of scanning and malicious activity from the public internet.
However, the past few months have shattered previous expectations, as new records for daily log volumes have been set sometimes by orders of magnitude across all monitored honeypot systems.
What used to be rare incidents of sudden spikes in malicious activity have now become so frequent that “normal” levels of traffic from earlier in the year are barely discernible on trend charts.
Recent Spikes Driven Predominantly
In an analysis covering 13 to 14 months, it has become clear that the increase is not localized to a single deployment: both residential and cloud-based honeypots have experienced this dramatic uptick.
Previous years’ excessive spikes in log generation now seem negligible when placed alongside figures from April 2025 onwards.
Web honeypot sensors are driving the bulk of this traffic, often contributing over a million logs from a single /24 subnet in just 24 hours.
In some cases, daily log files have ballooned to exceed 20 GB; one unprecedented day recently saw nearly 58 GB of logs far surpassing the earlier peak of 35 GB.
The escalation in log data was so severe that, for analysis’ sake, researchers had to filter out high-activity /24 subnets (over 1 million logs per day) simply to visualize underlying patterns in “normal” background scans and attacks.
Even after removing these outliers, late 2024 and 2025 still reveal a persistent, growing trend in log generation, with previously anomalous traffic volumes now barely registering in retrospect.
Massive Volumes Straining Storage
Examining sources, the activity has been heavily concentrated in web honeypots. Analysis by subnet reveals a handful of /24s responsible for the lion’s share of traffic often fixating on a limited number of URL paths or endpoints across staggering numbers of requests and utilizing just a few IP addresses.

Subnets such as 45.146.130.0/24 and 179.60.146.0/24 have, on individual days, generated two hundred million or more hits, with the bulk of requests targeting endpoint URLs like / or /__api__/v1/config/domains.
The clear preference for these URLs could indicate botnet-driven automation seeking known vulnerable APIs or web interfaces.
When aggregating the overall data, the path / alone was accessed over 38 billion times across the dataset, closely followed by /__api__/v1/config/domains at 33 billion hits.
Lesser but still significant traffic focused on endpoints related to logging in, external API checks, or IP information services, all suggestive of both reconnaissance campaigns and targeted exploitation efforts.
According to the Report, these shifts in attack volume pose serious challenges to honeypot operators, especially for storage planning and incident response.
Web honeypot logs exceeding 20 GB per day are no longer exceptional, and multiple consecutive days can now reach such figures.
A simple seven-day log retention interval can now require well over 140 GB of disk space for just web honeypot archives, forcing a rethink in scheduling and compression: operators may need to archive and compress logs bi-daily or more frequently to keep pace with growth and avoid data loss.
While much of this unprecedented surge in hostile activity is still under investigation and deeper analysis of campaign goals and mechanisms is ongoing, the operational takeaway is clear.
Automation, possibly from large botnets, is aggressively probing and hammering exposed endpoints across the web at a rate and scale not previously recorded.
Operators are advised not only to review their own data handling and archiving practices, but also to remain watchful for shifts in adversary tactics as the landscape continues to evolve at a dramatic pace.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant updates