Most traffic comes from China and Hong Kong — but the obvious reading is wrong.
The intuitive reading — "China is attacking us" — collapses on inspection. The data measures where compromised SSH-spreader infrastructure currently lives, not where the operators sit. Three structural conditions concentrate that infrastructure in CN + HK network space, and each is well-documented in the literature.
First, Alibaba Cloud HK uniquely permits password-based root SSH login on instances by default — a permissive posture repeatedly observed by Trend Micro[72] and SonicWall[154]. Cheap HK instances become trivially compromised and immediately convert into spreader nodes. Three of our top-15 attacker IPs sit in Alibaba Cloud HK; together they emit 33% of all events.
Second, the consumer-broadband pool that fed the original Mirai botnet in 2016 — millions of always-on, default-credential routers and ONTs — has not measurably shrunk in a decade. Antonakakis et al. measured 600k Mirai infections at peak[22,155]; our 111.72.138.102 (ChinaNet broadband, 20,663 events) is a textbook 2026 example of the same population still being recruited.
Third, source-IP geolocation is a victim measurement, not an actor measurement. The IMC 2025 long-term SSH honeynet study[151] makes this explicit: top source ASNs correlate with cloud-provider permissive defaults far more strongly than with country-of-operator. Blocking by country buys little; blocking by CIDR or ASN is what defeats the campaign.