How to interpret this jnettop output?
Could be that the attackers are using some exotic protocol on top of IP, that jnettop doesn't recognize.
You could try to use a network capture tool, with a filter such as not tcp and not udp
, and see what remains.