From the information button in the top right corner:
Every second, Norse collects and analyzes live threat intelligence from darknets in hundreds of locations in over 40 countries. The attacks shown are based on a small subset of live flows against the Norse honeypot infrastructure, representing actual worldwide cyber attacks by bad actors. At a glance, one can see which countries are aggressors or targets at the moment, using which type of attacks (services-ports).
So they basically set up a large number of dummy computers and see who tries to attack them with what.
It’s interesting, but be careful drawing conclusions from it. What you see is limited and biased.