The solution
In January 2020 GoSecure researchers Olivier Bilodeau and Andréanne Bergeron set up a virtual machine in the United States with a deliberately weak password and Microsoft's Remote Desktop Protocol — the same access point ransomware gangs use to walk into corporate networks. It was a trap: their homemade PyRDP tool recorded the machine's screen through every session and stealthily grabbed anything the intruders copied to their own clipboards.
Over three years the machine captured 21 million login attempts and more than 2,600 successful logins by attackers brute-forcing the password. The researchers recorded 2,300 of those sessions, collected 470 uploaded files, and analyzed 339 videos with useful footage — more than 100 hours that Bergeron called 'basically a surveillance camera that shows everything they do.' Attackers revealed their tooling — Masscan, NLBrute — their workflows, and sometimes themselves: one generated a password that may have included his own name; others logged into personal email accounts from inside the trap.
The footage became a field guide. The team sorted attackers into five types named for Dungeons & Dragons characters: 'rangers' doing immediate recon, 'barbarians' brute-forcing their way onward with IP and password lists, 'wizards' chaining the RDP into other machines, 'thieves' installing crypto miners and monetizing traffic, and lost 'bards' — one searched Google for the 'strongest virus ever,' others hunted porn on YouTube, always writing in Farsi. Little was automated: most attackers clicked around by hand. The study was presented at Black Hat in Las Vegas.
Why it worked
RDP is where intrusions already concentrate, so a weak RDP trap samples the real attacker population rather than a theoretical one.
Video beats logs: techniques and tooling can be read straight off the attacker's screen, with no forensic reconstruction needed.
Clipboard capture catches what attackers bring from their own machines — credentials and identities, even though some cannot legally be used.
Publishing the method raises attackers' cost: monitored intruders either slow down or change habits, and either outcome is defense.
What can be applied
A honeypot that stores logs tells you what ran; one that records the operator's session tells you who they are — attackers behave like people, and people leak.
Aftermath
Bilodeau said the haul — techniques, tooling, even attackers installing Telegram and logging in on the compromised system, exposing phone numbers and country codes — was intelligence technical logs had never provided, though some credentials unfortunately could not legally be used. GoSecure suggested companies run their own traps to show executives who is knocking, and floated seeding future traps with encryptable files to draw ransomware crews. An outside check by Malwarebytes' Mark Stockley underlined the exposure: the 10 honeypot RDPs he once ran were all attacked within 15 hours.
FOLLOW THE EVIDENCE