- Steal application credentials if posix perms or database privs are weak, attempt privilege escalation, install rootkit RATs Remote Access Trojans for persistence and hiding processes.
- Install Proxies, DDoS Agents, Bitcoin mining, proxy to SMTP servers, etc...
- If anything looks interesting on their console they will log in and poke around. The order of these events depends on the sophistication of the bot script. Most are very simple.
If you the target look like you have money they may install ransomware and encrypt some of your files. Now I want to watch the Beekeeper again as corny as it was, also a fun movie.
I presume that at least some of them just log the host as accessible and maybe some basic statistics into a list for an actual person to look at later on. That actual person would be the one to look more closely to see if there are any interesting credentials to steal or important data to steal or ransomware.