Threat Intelligence Dossiers

Forensic investigations of real threat actors observed attacking a personal SSH honeypot. Every finding backed by evidence. Every claim sourced.

817
Dossiers
Attackers
Sessions
Login Attempts
IPs Blocked
Days Collecting
Honeypot Field Reports
TI-2026-001

🛡️ TI-2026-001 — W1n LTD: Bulletproof Hosting Network

Investigation into W1n LTD, a UK-registered company operating bulletproof hosting infrastructure used for SSH brute-force campaigns. Traces company registration, network allocation, and abuse patterns from honeypot obse…

TI-2026-002

📡 TI-2026-002 — MikroTik Recon & Telegram Stealer Botnet

A precisely synchronized botnet of 15 compromised residential devices across 14 countries executes an identical 9-step reconnaissance playbook, exfiltrating credentials via Telegram bot API. Traces the infection chain f…

TI-2026-003

🇨🇳 TI-2026-003 — Baidu Cloud: Weaponized Infrastructure Network

30 Baidu Cloud IPs in the 120.48.x.x range launched 671 coordinated attack events against our honeypot. Investigates whether China's second-largest cloud provider is negligent, complicit, or compromised.

TI-2026-004

🔍 TI-2026-004 — Google Cloud: Persistent OS Fingerprinting Campaign

31 Google Cloud Platform instances across 5+ regions generated 4,208 attack events. The primary behavior is OS fingerprinting — silent reconnaissance that maps target infrastructure without triggering traditional IDS al…

TI-2026-005

🪱 TI-2026-005 — Two Worm Families: Anti-Forensic SSH Propagation

Two distinct SSH worm families operating in parallel: one with sophisticated anti-forensic capabilities that erases its own tracks, the other a blunt proxy-shell dropper. Both exploit the same credential lists but serve…

TI-2026-006

💌 TI-2026-006 — Te Iubesc: The Love Letter Campaign

A Romanian-language love letter found in honeypot SSH session logs. What appears to be an accidental paste reveals an operator's human moment — and raises questions about who sits behind the keyboard of automated attack…

TI-2026-007

💰 TI-2026-007 — The Underground Economy: Pricing the SSH Access Market

Maps the economics of compromised SSH credentials — from initial brute-force to darknet marketplace listing. Traces pricing models, bulk discount structures, and the supply chain that turns a honeypot login into a monet…

TI-2026-008

🔑 TI-2026-008 — The Backdoor-Key Harvester: Outlaw/Shellbot Coordinated Campaign

A coordinated Outlaw/Shellbot campaign captured over 34 days of continuous operation. Documents the complete attack chain from SSH brute-force through cryptominer deployment, IRC C2 communication, and SSH key harvesting…

TI-2026-008B

🔑 The Key to 81 Machines: The Outlaw Backdoor Key, Recounted

The Outlaw/Shellbot SSH backdoor key documented at 56 machines in TI-2026-008 has grown to 81 across 20+ countries, per the intel-linker's 2026-07-07 re-link. One planted authorized_keys public key at 0.90 confidence un…

TI-2026-009

👯 TI-2026-009 — The Twin-libssh Operator: Parallel Scanner Families

Two parallel SSH brute-force scanner families sharing the same libssh fingerprint but operating distinct credential lists and targeting strategies. Evidence suggests a single operator running A/B testing on attack metho…

TI-2026-010

⛏️ TI-2026-010 — The GPU Hunter: Cryptomining Reconnaissance at Scale

Attackers systematically fingerprint GPU hardware through SSH sessions, deploying cryptominers optimized for the detected hardware. Documents the technical sophistication of mining-focused threat actors who treat compro…

TI-2026-011

🎯 TI-2026-011 — The Personal Touch: When Attackers Get Creative

Beyond automated brute-force — documenting SSH sessions where human operators manually explore compromised systems. Interactive commands, typos, and browsing patterns reveal the people behind the scripts.

TI-2026-012

💀 TI-2026-012 — The mdrfckr Botnet: Anatomy of a Cryptojacking Empire

Deep forensic analysis of the 'mdrfckr' botnet — a cryptojacking operation that combines SSH brute-force propagation with XMRig deployment, process hiding, and competitor elimination. Documents the complete kill chain f…

TI-2026-013

🏗️ TI-2026-013 — The Krane Botnet: Container-Aware SSH Propagation

The Krane botnet targets containerized environments, detecting Docker and Kubernetes installations before deploying specialized payloads. Documents how modern botnets have adapted their propagation strategies for cloud-…

TI-2026-014

📊 TI-2026-014 — Phase Layer: Burst Pattern Analysis in SSH Attacks

Statistical analysis of attack burst patterns reveals distinct operational phases — reconnaissance sweeps, credential spraying, and exploitation waves — each with characteristic timing signatures that fingerprint threat…

TI-2026-015

🔊 TI-2026-015 — Echo BMOK: The Callback Beacon

Investigation into the 'echo BMOK' command pattern — a callback beacon used by multiple threat actors to verify successful command execution on compromised hosts. Traces the pattern across campaigns and maps the C2 infr…

TI-2026-015B

🧬 Echo BMOK Revisited: The Fingerprint That Spread

Six weeks after TI-2026-015, the near-unique OpenSSH 10.0p2 Debian 13 fingerprint (HASSH eeca2460) spread from 2 to 4 nodes. Shodan proves the banner authentic and portable across the operator's own VPS and a compromise…

TI-2026-016

🔌 TI-2026-016 — Phantom Pipes: Hidden Data Exfiltration Channels

Documents covert data exfiltration techniques observed in honeypot sessions — from DNS tunneling and ICMP channels to steganographic encoding in seemingly benign traffic. Maps the infrastructure that enables persistent…

TI-2026-017

🏛️ TI-2026-017 — Glass Houses: When Governments Attack

421 IP addresses from state-owned telecoms, military networks, universities, children's educational platforms, and government data centers caught attacking our honeypot. The uncomfortable question: are these compromised…

TI-2026-018

🐱 TI-2026-018 — Operation Meow: The Discord DDoS Botnet

A Go-based DDoS botnet operated from KataBump, a French 'Free Discord Bot Hosting' platform. Traces how legitimate hosting services become unwitting infrastructure for botnet C2, and how a cat-themed service enables den…

Operation Shadow Nexus
TI-2026-019

🕸️ TI-2026-019 — Operation Shadow Nexus: The Master Investigation

The master investigation that maps the interconnected web of threat actors, bulletproof hosters, and credential markets operating against our honeypot infrastructure. The starting point for a 13-part deep dive into the…

TI-2026-019B

⚙️ TI-2026-019B — The Ugly Machinery: Attack Automation at Scale

Reverse-engineering the automation frameworks behind mass SSH brute-force campaigns. From credential generation algorithms to distributed scanning architectures — the industrial machinery that turns vulnerability into a…

TI-2026-019C

💵 TI-2026-019C — Follow The Money: The Financial Networks Behind Cybercrime

Tracing the financial flows from compromised SSH credentials through cryptocurrency mixers, darknet marketplaces, and legitimate payment processors. Maps the money laundering infrastructure that converts unauthorized ac…

TI-2026-019D

🚪 TI-2026-019D — The Open Doors: Misconfigured Infrastructure as Attack Surface

Investigation into how misconfigured servers, default credentials, and forgotten services create the 'open doors' that attackers systematically discover and exploit. Maps the gap between security best practices and oper…

TI-2026-019E

🌐 TI-2026-019E — The Web Between: Mapping Threat Actor Relationships

Network analysis revealing the hidden connections between seemingly independent threat actors. Shared infrastructure, credential overlap, and temporal correlation expose the cooperative relationships that define the cyb…

TI-2026-019F

👻 TI-2026-019F — Ghost in the Machine: Anti-Forensic Techniques in the Wild

Cataloguing anti-forensic techniques observed in live honeypot sessions — log deletion, timestamp manipulation, process hiding, and evidence destruction. Documents how sophisticated operators cover their tracks in real-…

TI-2026-019G

🪟 TI-2026-019G — The Broken Window: Cascading Failures in Internet Security

How a single unpatched vulnerability cascades through interconnected systems — from initial compromise through lateral movement to full network takeover. The broken window theory applied to internet infrastructure secur…

TI-2026-019H

🔄 The Feedback Loop - Cross-Dossier Meta-Analysis

Documents the self-reinforcing cycle where compromised servers become attack infrastructure, generating new compromises that generate new attackers. Maps the exponential growth dynamics of botnet propagation.

TI-2026-019I

🔱 TI-2026-019I — The Trident: Three-Pronged Attack Methodology

Analysis of a sophisticated three-pronged attack methodology combining credential brute-force, vulnerability exploitation, and social engineering — deployed simultaneously against the same targets for maximum success pr…

TI-2026-019J

🤚 TI-2026-019J — The Invisible Hand: Market Forces in Cybercrime

Economic analysis of the cybercrime marketplace — supply and demand dynamics, pricing mechanisms, specialization and division of labor. How market forces shape the evolution of threat actor behavior and attack methodolo…

TI-2026-019K

📐 The Quadrant — w1n Ltd Corporate Autopsy

A four-dimensional classification framework mapping threat actors by capability, intent, infrastructure, and persistence. Positions each honeypot-observed actor in a threat landscape that reveals strategic patterns invi…

TI-2026-019L

⛪ The Cathedral — Church of Cyberology False Positive

Organizational analysis revealing hierarchical structures within cybercrime operations — from script-kiddie foot soldiers through mid-level operators to the architects who design the infrastructure. The cathedral model…

TI-2026-019M

🔬 TI-2026-019M — The Researcher: Max Planck Institute — When State-Funded Science Scans Through Tor

A honeypot-captured multi-phase scanning operation from Max-Planck-Institut für Informatik (MPI-INF), Saarbrücken — 14 disclosed scanning servers, global AWS vantage points, and undisclosed Tor-routed operations that co…

The Cartographers
TI-2026-020A

🗺️ TI-2026-020A — The Cartographers of Nowhere: Mapping Shell Company Networks

Maps the shell company networks that provide corporate facades for bulletproof hosting operations. Traces nominee directors, formation agents, and the geography of paper companies from the BVI to London to Seychelles.

TI-2026-020B

🕳️ TI-2026-020B — ISAEV: A Darknet Operator Unmasked

Forensic investigation tracing a darknet operator through operational security failures. From cryptocurrency transactions through hosting records to real-world identity — the unmasking of a threat actor who thought they…

TI-2026-020C

🏢 TI-2026-020C — The Roll-Up: Corporate Consolidation in Bulletproof Hosting

How bulletproof hosting providers use corporate roll-up strategies — acquiring smaller operations, merging ASNs, and consolidating IP address blocks — to build resilient infrastructure empires while maintaining deniabil…

TI-2026-020D

🐚 TI-2026-020D — The Seychelles Veil: Offshore Corporate Structures in Cybercrime

Investigation into why the Seychelles — 115 islands with 100,000 people — hosts thousands of companies linked to cybercrime infrastructure. Traces the regulatory gap between offshore incorporation and internet resource…

TI-2026-020E

🇪🇺 TI-2026-020E — The European Wrappers: EU Shells Around Offshore Operations

How offshore hosting operations use European shell companies as legitimate wrappers — UK LTDs, German GmbHs, and Dutch BVs that provide RIPE membership, banking access, and regulatory credibility to fundamentally offsho…

TI-2026-020F

🎭 TI-2026-020F — The Respectable Front: Legitimacy as a Service

How bulletproof hosting providers construct legitimate-appearing corporate identities — ISO certifications, professional websites, industry conference participation, and governance roles — to deflect scrutiny while enab…

The Architecture of Impunity
TI-2026-021A

🔄 TI-2026-021A — The Nowhere Registry: How IP Address Governance Enables Abuse

Investigation into how Regional Internet Registries (RIRs) — RIPE, ARIN, APNIC, AFRINIC, LACNIC — allocate and govern IP addresses in ways that systematically enable abuse through policy gaps, lax enforcement, and struc…

TI-2026-021B

🔑 TI-2026-021B — The Key That Didn't Lie: SSH Fingerprint Attribution

How SSH key fingerprints and HASSH hashes become the most reliable attribution signals in threat intelligence. When operators share SSH keys across IPs, they leave an unforgeable identity trail that connects seemingly i…

TI-2026-021C

🌐 TI-2026-021C — The Architecture of Impunity: Why Internet Abuse Persists

The synthesis investigation mapping how regulatory gaps, jurisdictional arbitrage, governance capture, and economic incentives combine to create a self-sustaining architecture where internet abuse is structurally profit…

TI-2026-021D

⚰️ The Architecture of Impunity Part D — The Abuse Report Graveyard: 96% Failure Rate and the Five Ways Reports Die

Forensic analysis of why 96% of abuse reports to hosting providers go unanswered — documenting the five architectural failure modes that ensure criminal infrastructure remains undisturbed.

TI-2026-021E

🔌 The Architecture of Impunity Part E — The Upstream Enablers: Transit Providers Who Carry Criminal Traffic

Investigation into tier-2 transit providers who knowingly carry BGP traffic for Spamhaus DROP-listed networks — M247, Stark Industries, Cogent, and the economics of complicity.

TI-2026-021F

🏛️ The Architecture of Impunity Part F — The AFRINIC Extraction: How Governance Capture Steals Internet Resources

Cloud Innovation Ltd's 25+ lawsuits against AFRINIC — the first documented hostile governance capture of an Internet registry, using Seychelles courts to seize African IP resources.

TI-2026-021G

🧼 The Architecture of Impunity Part G — The Reputation Laundry: How IP Addresses Get Clean Slates

How criminal operators exploit IP reputation system resets to launder tainted address space — cycling through dead ASNs and IP brokers to emerge with clean scores despite continuous abuse.

TI-2026-021H

⚖️ The Architecture of Impunity Part H — The MLAT Gap: Why International Law Enforcement Cooperation Fails Against Cybercrime

Structural analysis of why Mutual Legal Assistance Treaties cannot address cybercrime — 6-24 month delays vs infrastructure that moves in hours, non-signatory states, and the jurisdiction-shopping problem.

TI-2026-021I

💰 The Architecture of Impunity Part I — The Economics of Abuse: Who Profits and How Much

Follow the money through the bulletproof hosting ecosystem: from $50 shell companies to $300M+ annual industry revenue — the economic incentives that make the architecture self-perpetuating.

TI-2026-021J

🍯 The Architecture of Impunity Part J — The Honeypot Testimony: 8,000 IPs, 271,000 Links, One Conclusion

Series finale presenting the complete forensic evidence from our honeypot — 8,000+ attacking IPs, 271,000+ entity links proving every structural claim in this series through direct observation.

TI-2026-021K

🔨 The Architecture of Impunity Part K — The Iron Hammer: Stark Industries, Transnistria, and State-Sponsored Infrastructure

How Stark Industries Solutions — incorporated 14 days before Russia invaded Ukraine, run from Transnistria by a cybercrime forum veteran — became the nexus where bulletproof hosting meets state warfare: NoName057(16) DD…

TI-2026-021L

📜 The Architecture of Impunity Part L — The Mere Conduit: How EU Law Protects Criminal Infrastructure Carriers

Legal analysis of the Digital Services Act Article 4 'mere conduit' exemption — the EU law that explicitly shields transit providers from liability for carrying criminal traffic, and why it will never be reformed.

TI-2026-021M

👻 The Architecture of Impunity Part M — The Phantom Pipes: Residential Proxy Botnets and the SSH Underground

Investigation into the Phantom Pipes AsyncSSH botnet — compromised home routers forming million-IP proxy networks that let criminals operate behind residential IP addresses, invisible to traditional detection.

TI-2026-021N

🏛️ The Architecture of Impunity Part N — The State-Criminal Convergence: When Governments and Hackers Share the Same Servers

The ultimate conclusion: state intelligence and criminal hackers share the same infrastructure because the architecture of impunity was built to serve both — making the distinction between state and criminal meaningless.

Cross-Border Corridors
TI-2026-022A

🇬🇧🇮🇷 TI-2026-022A — The UK-Iran Corridor: Sanctions Evasion Through Hosting Infrastructure

How Iranian entities route internet traffic through UK-registered companies to evade sanctions. Traces the corporate chains, BGP paths, and financial flows that connect Tehran's network operations to London's Companies…

TI-2026-022B

🗺️ TI-2026-022B — The Corridor Map

How 1,091 IP addresses exist in multiple countries simultaneously — mapping the five cross-border corridors that sanctions cannot reach.

TI-2026-022C

🇬🇧 TI-2026-022C — The UK-Iran Pipeline

How Iranian state nuclear research infrastructure routes through Welsh PO boxes, Latvian shell companies, and RIPE NCC membership to reach the global internet.

TI-2026-022D

🇷🇺 TI-2026-022D — The Russian Hand

How Russian operators control foreign internet infrastructure through RIPE NCC maintainer chains, Kazakhstan shell ASNs, and Ukrainian front companies — from Novosibirsk to the world.

TI-2026-022E

🇩🇪 TI-2026-022E — The German Gateway

How PIO-Hosting, XSServer, and SkyLink exploit the German-Dutch border to provide transit for Iranian LIRs, Chinese IDCs, and bulletproof hosting — from one phone number to an architecture of impunity.

TI-2026-022F

🗺️ TI-2026-022F — The Geographic Liar

How M247 Europe SRL systematically misrepresents IP geolocation through RFC 8805 geofeeds — enabling sanctioned states, botnets, and VPN breaches across a permanent jurisdictional void.

TI-2026-022G

🎖️ TI-2026-022G — The Military Corridors

When the ISP is the army: how Viettel, ChinaNet, and Myanmar Mytel create attack corridors beyond civilian governance — the mdrfckr campaign, Article 7, and the end of attribution.

The VPN Laundromat
TI-2026-023A

🌍 TI-2026-023A — The VPN Laundromat: How VPN Providers Enable Attack Infrastructure

Deep forensic investigation into how the $44.6B VPN industry commoditized geographic identity, enabling credential harvesting and attack infrastructure through M247, Private Layer, Torservers, and FranTech across 469 ge…

TI-2026-023B

📄 The Backbone: How M247 Europe SRL Became the Plumbing of Internet Abuse

Deep investigation into M247 Europe SRL (AS9009), the Romanian ISP that became backbone infrastructure for VPN abuse, brute-force campaigns, and bulletproof hosting. Traces M247's acquisition by Macquarie Group, Omegate…

TI-2026-023C

📄 The Virtual Country: M247 Geofeed and Sanctioned Nations

Investigation into how M247 Europe SRL uses RFC 8805 geofeeds to create virtual endpoints in 116 countries — including OFAC-sanctioned Iran, Cuba, Belarus, and Russia — from Romanian servers. Examines 'M247 Ltd Iran' an…

TI-2026-023D

📄 The Trust Chain: Geographic Discrepancy Cascade Through GeoIP Databases

Forensic analysis of 1,357 IP addresses where authoritative geolocation sources disagree on country. Exposes BGP-vs-RDAP corridors, Tencent Cloud's 76-IP geographic fiction via 'AceVille Pte Ltd', IPinfo's blind spot (0…

Offshore Bulletproof
TI-2026-024A

🏴‍☠️ TI-2026-024A — Offshore Bulletproof: The Seychelles-to-Darknet Pipeline

Traces the complete pipeline from Seychelles company registration through European shell wrapping to darknet hosting services. Maps how a $500 offshore incorporation becomes the foundation for bulletproof infrastructure…

TI-2026-024B

📄 Offshore Bulletproof Part B — The Seychelles Veil: How $50 Buys a Globally Routable Shell

Seychelles IBCs cost $50, require no beneficial ownership disclosure, cannot be subpoenaed. The jurisdiction of choice for bulletproof hosting.

TI-2026-024C

📄 Offshore Bulletproof Part C — The Omegatech Empire: Turkish Operators, Seychelles Shells, and Multi-ASN Camouflage

Omegatech LTD (AS202412): Turkish operators behind Seychelles shell. Virtualine brand. ThreatFox IOCs. 7 honeypot IPs. Zero enforcement.

TI-2026-024D

📄 Offshore Bulletproof Part D — The w1n Network: UK Companies House as Bulletproof Registration

w1n Ltd used £12 UK registration to front bulletproof hosting. 11 actors, 40 findings, 8 honeypot IPs. Companies House as enabler.

TI-2026-024E

📄 Offshore Bulletproof Part E — HBING LIMITED: BVI, Panama Papers, and the IP Registrant Chain

BVI-registered RIPE LIR providing IP resources to bulletproof operators. Panama Papers connection. Zero beneficial ownership transparency.

TI-2026-024F

📄 Offshore Bulletproof Part F — The Pfcloud Transit Hub: Spamhaus DROP and the Israeli Connection

Pfcloud UG (AS51396): Daniel Mishayev's transit hub for DROP-listed networks. Israel anomaly: 7 IPs, 0 honeypot hits. Operational separation.

TI-2026-024G

📄 Offshore Bulletproof Part G — The Dead ASN Graveyard: 5 Revoked Networks, Same IP Space

87.251.64.0/24 cycled through 5 dead ASNs since 2021. Each revoked for abuse, replaced by new shell. RIPE creates recycling, not deterrence.

TI-2026-024H

📄 Offshore Bulletproof Part H — The Architecture: How Offshore Incorporation Enables Global Cybercrime Infrastructure

The complete cycle: incorporate ($50) → register LIR → get ASN → host abuse → get listed → deregister → repeat. The system is designed for this.

The SSH Parasite
TI-2026-025A

🎯 TI-2026-025A — The Personal Touch: A Targeted Campaign Against a Threat Researcher

When publishing threat intelligence dossiers attracts targeted retaliation. Documents a focused campaign against a threat researcher and his family — from credential spraying to infrastructure reconnaissance — and what…

TI-2026-025B

🇵🇱 TI-2026-025B — MEVSPACE: The Polish Bulletproof Host

Investigation into MEVSPACE, a Polish hosting provider whose infrastructure appeared in targeted attacks against our researcher. Traces corporate registration, abuse handling failures, and the thin line between 'privacy…

TI-2026-025C

🦠 TI-2026-025C — The Infostealer Pipeline: From Browser to Spray

Maps the complete infostealer pipeline — from browser credential theft through log aggregation, marketplace listing, and credential spray deployment. How a stolen password becomes an automated attack against thousands o…

TI-2026-025D

🇧🇩 TI-2026-025D — Grameen Bangladesh: The Head of State's Network

Attacks from Grameen Telecom's network — an organization founded by Nobel laureate Muhammad Yunus, now Bangladesh's head of state. Investigates whether a national telecom's infrastructure is compromised, complicit, or s…

TI-2026-025E

🤖 TI-2026-025E — The Go Scanner Botnet & FranTech Infrastructure

Analysis of a Go-based SSH scanner botnet operating through FranTech Solutions (BuyVM) infrastructure. Traces the connection between a privacy-focused hosting provider's 'no abuse reports' policy and the industrial-scal…

TI-2026-025F

🧬 TI-2026-025F — The SSH Parasite: Eight Years, Same Key, Zero Consequences

Deep forensic investigation of mdrfckr/Outlaw — the SSH botnet unchanged since 2018. Eight years, same key, zero arrests. Live honeypot data, OSINT, economic analysis.

TI-2026-025G

📄 TI-2026-025G — The Infrastructure: 81 Machines, 29 Countries, Zero Consent

Complete mapping of the mdrfckr botnet's 81 compromised machines across 29 countries. Reveals Microsoft Azure, DigitalOcean, BytePlus (TikTok), Tencent, Oracle, and Google Cloud all hosting active botnet nodes alongside…

TI-2026-025H

📄 TI-2026-025H — The Operator: Romanian IRC Nicks, a $3.50 C2 Server

Forensic attribution of the mdrfckr/Outlaw botnet to a Romanian-speaking crew operating since 2018. Traces IRC C2 on FranTech's abuse-tolerant infrastructure, decodes the haiduc folklore reference, analyzes the three-wa…

TI-2026-025I

📄 TI-2026-025I — The Economics: Monero, Mining Pools, and Parasitic Revenue

Financial analysis of the mdrfckr/Outlaw botnet's Monero mining operation. Calculates revenue at 81 observed nodes ($1.23/day) through 180,000 peak nodes ($3K-8K/day). Documents the XMRig configuration, the kswapd0 proc…

TI-2026-025J

📄 TI-2026-025J — The Victims: Education Networks and the Geography of Neglect

Victim analysis of the mdrfckr/Outlaw botnet across 29 countries and 81 confirmed nodes. Documents infections at Tanzania's TERNET education network, BytePlus/TikTok's 46-IP cloud fleet, Microsoft Azure across 6 countri…

TI-2026-025K

📄 TI-2026-025K — The Evolution: Eight Years of Adaptation

Evolutionary analysis of the mdrfckr/Outlaw botnet across 8 years (2018-2026). Documents three campaign waves observed in our honeypot with 30,213 sessions from 1,928 unique IPs, the crossover event of May 13, 2026 when…

TI-2026-025L

🪱 TI-2026-025L — The SSH Parasite: Extended Investigation

Extended forensic investigation of the mdrfckr/Outlaw SSH botnet — an eight-year Romanian criminal enterprise exploiting structural negligence across cloud providers, developing nations, and the security industry itself…

TI-2026-025M

👤 TI-2026-025M — The Victims: Who Pays When Nobody Counts the Cost

Who the actual victims of the mdrfckr/Outlaw SSH botnet are — from Ethiopian state telecom to Korean broadband, Indonesian digitization to Pakistani small ISPs — and why the damage ratio runs 50:1 against the earnings.

TI-2026-025N

💰 TI-2026-025N — The Economics: Parasitic Revenue Deep Analysis

Financial forensics of the mdrfckr botnet

The Phantom ASN
TI-2026-026A

👻 The Phantom ASN — PIO-Hosting's Shell Game

Starting from a honeypot geographic discrepancy, we traced two ASNs to a bulletproof hosting empire spanning 7+ jurisdictions, linked to the Panama Papers, enabling Iranian sanctions evasion, and connected to a $55M IP…

TI-2026-026B

🏝️ The Digital Asylum — Seychelles Incorporation Factory

HBING LIMITED — a UK 'retail store' at a residential address — operates AS208949, a bulletproof hosting network with risk 95.26/100, BVI shell companies, Panama Papers nominees, and confirmed Hitrow botnet C2 infrastruc…

TI-2026-026C

🇩🇪 The Three-Continent Shuffle — Infrastructure Arbitrage

PIO-Hosting, XSServer, and SkyLink Data Center share personnel, phone numbers, and a border region — while routing 42 prefixes from 5 RIRs for Iranian LIRs, reputation launderers, and a $55M IP marketplace.

TI-2026-026D

🏪 The Upstream Enablers — Transit Provider Complicity

IPXO UAB — a $55M Lithuanian IP marketplace — routes through both bulletproof ASNs while its co-founder sits on the RIPE Anti-Abuse Working Group. Academic researchers documented the problem. Nothing happened.

TI-2026-026E

🏝️ The Bulletproof Ecosystem — Where Criminals Host

IP addresses attacking our honeypot are registered to a person named in the Panama Papers. Rea Ketty Barreau — ICIJ node 12169229, Seychelles nominee director — controls prefixes through a BVI shell, sponsored by Dubai,…

TI-2026-026F

⚖️ The Money Trail — Following Bulletproof Revenue

Four Iranian LIRs route through a German bulletproof ASN with zero sanctions compliance. EU Regulation 267/2012 prohibits this. German law prescribes 10 years. No one has ever been prosecuted for internet transit.

TI-2026-026G

🎭 The Abuse Report Graveyard — Why Reports Die

Five individuals operate a bulletproof hosting network across Turkey, Russia, Germany, Netherlands, and Lithuania. All identifiable through public registries. None has ever been charged.

TI-2026-026H

🖥️ The Geopolitical Shield — Jurisdictional Warfare

628 machines across 48 countries share one SSH fingerprint, one credential, and one purpose: scanning the entire internet for weak SSH servers. The infrastructure costs $75K-188K per year.

TI-2026-026I

🏛️ The Human Cost — Victims Behind the Infrastructure

RIPE NCC has an IPXO executive on its Programme Committee, allows anonymous Private Customer records hiding bulletproof hosts, and has never revoked an ASN for abuse. Structural governance analysis.

TI-2026-026J

⚰️ The Abuse Report Graveyard (Extended) — Structural Analysis

A forensic investigation into the systematic failure of internet abuse reporting. Traces how 8,000+ attacker IPs generate thousands of abuse reports that vanish into organizational black holes — from hosting providers w…

TI-2026-026K

🧬 The Registrar Paradox — Domain Industry Complicity

Forensic reconstruction of the corporate genealogies behind today's bulletproof hosting. Traces how Digital Energy Technologies became Heficed became IPXO, how Quasi Networks became FranTech/BuyVM, and how PIO-Hosting e…

TI-2026-026L

⛓️ The Supply Chain — From Botnet to Ransomware

Maps the complete supply chain of internet abuse — from IP address allocation at RIPE/ARIN through leasing marketplaces, BGP transit providers, and proxy infrastructure to the SSH brute-force attempts hitting our honeyp…

TI-2026-026M

🤖 The 1,313 Machines — Anatomy of a Global SSH Botnet

Temporal analysis of 1,313 attacker IPs reveals the operational rhythms of coordinated scanning campaigns. Business-hour patterns expose human operators behind 'automated' botnets, while burst analysis identifies campai…

TI-2026-026N

🇱🇹 TI-2026-026N — The Lithuanian Connection: IPXO and the Baltic Corridor

Deep investigation into IPXO UAB, the world's largest IP address marketplace managing 14 million IPv4 addresses from Kaunas, Lithuania. Traces corporate structures across 5 jurisdictions, RIPE NCC governance capture by…

TI-2026-026O

⏱️ TI-2026-026O — The Temporal Architecture: When Machines Attack on Schedule

Temporal forensic analysis revealing the operational rhythms hidden in attack timestamps. Business-hour patterns across UTC+3 and UTC+8 time zones expose human operators behind automated botnets.

TI-2026-026P

🎯 TI-2026-026P — The Go Scanner: Reconnaissance at Industrial Scale

Forensic analysis of HASSH fingerprint 16443846184eafde36765c9bab2f4397 — a custom Go-based SSH scanner operating 434+ IPs across 6,613 sessions in 25 days. Traces the tool from its crypto/ssh library origins through th…

TI-2026-026Q

🌐 TI-2026-026Q — The Convergence: Final Synthesis of the Phantom ASN Ecosystem

The final synthesis of a 16-part investigation. Traces how geographic discrepancies in honeypot data revealed a global ecosystem of phantom ASNs, shell companies, captured governance, and weaponized IP leasing.

The Illicit Economy
TI-2026-027A

🕸️ TI-2026-027A — The Shared Substrate: One Infrastructure, Every Crime

The illicit economy does not run on hidden infrastructure — it runs on ours. A forensic map of how the same transit ASNs, bulletproof shells, and crypto rails carry drugs, weapons, trafficking, spyware, and laundering.

TI-2026-027B

🪙 TI-2026-027B — The Laundering Rails: The Settlement Layer of the Shared Substrate

How mixers, DeFi, exchanges and bridges form the settlement layer of the shared illicit substrate behind ransomware and cybercrime.

TI-2026-027C

💊 TI-2026-027C — The Darknet Pharmacy: Narcotics on Virtual Assets

Darknet narcotics markets as a financial and infrastructure problem: virtual-asset settlement, DeFi laundering risk, transit ASNs, and enforcement view.

TI-2026-027D

⚖️ TI-2026-027D — The Trafficking Ledger: The Financial Architecture of Human Trafficking

The financial architecture behind human trafficking: shell companies, opaque funding sources, money movement, jurisdiction, and the Epstein financial-network record as a documented case study.

TI-2026-027E

🛰️ TI-2026-027E — Surveillance for Sale: The Commercial Spyware Market

Commercial spyware as illicit-economy commerce: Pegasus/NSO, lawful-intercept vendors, Vault7, export controls, and human-rights harm.

TI-2026-027F

🚀 TI-2026-027F — The Proliferation Pipeline: Weapons & Proliferation Financing

Proliferation financing as an illicit-economy vertical: front companies, dual-use export-control evasion, mixers, and corridor infrastructure.

TI-2026-027G

🚫 TI-2026-027G — The Designated-Entity Web: Sanctions Evasion Infrastructure

Sanctions evasion as the connective tissue of the illicit economy: OFAC SDNs, designated crypto entities, and how designated infrastructure keeps operating.

TI-2026-027H

🛡️ TI-2026-027H — The Hosting Blind Spot: Bulletproof Infrastructure & the Enforcement Response

The bulletproof/offshore hosting layer that abuse enforcement cannot reach, and the international takedown response — documented via Europol tracing, ThreatFox IOCs, and the Shuffle-on bulletproof-hosting corpus. Infras…

TI-2026-027I

🕸️ TI-2026-027I — One Substrate, Every Crime: The Convergence

The synthesis of The Illicit Economy: one measurable substrate carries laundering, narcotics, trafficking, spyware, proliferation, sanctions evasion and hosting.

The Geography of Nowhere
TI-2026-028A

🌐 TI-2026-028A — The Geography of Nowhere

How a single Seychelles phone number connects 16 million IPs, five shell companies, and the systematic dismantling of geographic attribution on the Internet.

TI-2026-028B

🏢 TI-2026-028B — The LARUS Dossier

How LARUS Limited operates from a single Hong Kong flat to manage 16 million IPs, reshape Internet governance through NRS, and enable the mdrfckr botnet.

TI-2026-028C

🏪 TI-2026-028C — The Marketplace Economy

How IPXO and IP address marketplaces structurally destroy attribution — with SSH key evidence proving WHG and HBING are the same operator using marketplace anonymity.

TI-2026-028D

🌍 TI-2026-028D — The African Question

How Cloud Innovation weaponized a Mauritius court to capture AFRINIC governance, threatening the Internet commons model while their infrastructure runs botnets.

TI-2026-028E

🇬🇧 TI-2026-028E — The Norwich Connection

How WHG and HBING operate from Norwich UK with shared SSH keys across 5 jurisdictions, creating tiered anonymity that correlates perfectly with threat level.

TI-2026-028F

🎭 TI-2026-028F — Who Is Lu Heng Really?

Deep investigative analysis of Lu Heng — the man behind Cloud Innovation, LARUS, NRS, and 16 million African IP addresses. Exploring state connections, Belt and Road digital infrastructure, and the question Western inte…

TI-2026-028G

🛰️ TI-2026-028G — The Surveillance Routing Question

Deep analysis of why the most dangerous IPs in our honeypot route through UAE — a documented surveillance state. Exploring Project Raven parallels, Five Eyes questions, and the surveillance-enabling architecture of mode…

TI-2026-028H

🏛️ TI-2026-028H — The AFRINIC Insider Question

How did 16 million IP addresses leave Africa without anyone noticing for six years? Deep investigation into AFRINIC's governance crisis, institutional capture, the R6 billion question, and why dissolution is the endgame.

The Compute Hunters
TI-2026-029A

⛏️ TI-2026-029A — The Compute Hunters

A coordinated GPU reconnaissance botnet fingerprints server hardware from bulletproof hosting — the opening salvo of the compute theft economy.

TI-2026-029B

🕸️ TI-2026-029B — The Virtualine Connection

How a Seychelles shell company, German partnership, and Russian underground forum created the bulletproof hosting backbone for GPU compute theft.

TI-2026-029C

💰 TI-2026-029C — The Kill Chain Economy

From GPU fingerprint to crypto profit — the monetization pipeline, ShadowRay parallels, wallet hunters, and the invisible tax of stolen compute.

TI-2026-029D

🔮 TI-2026-029D — The Questions Nobody Asks

The conspiratorial deep-dive: state-adjacent questions, AI industry complicity, compute cartels, and what GPU reconnaissance at scale really means.

The Anonymity Factory
TI-2026-030A

#️⃣ The SHA1 Mask — How 1337 Services GmbH Hides Behind a Cryptographic Hash

AS210558 hides behind a SHA1 hash in BGP databases. The real operator — 1337 Services GmbH — runs rdp.sh, a bulletproof hosting empire that survived Operation Talent.

TI-2026-030B

🇧🇪 The Belgian Precursor — SERVPERSO Systems and the Architecture of Abuse Routing

SERVPERSO Systems: How a Belgian entity in a Wallonian market square became the administrative layer protecting the most abused IP block on a German bulletproof hosting network.

TI-2026-030C

🏪 The LIR Marketplace — Julian Achter, LAIN, and the ASN Sponsoring Layer

Investigation into Julian Achter's LAIN LIR marketplace — how a Munich sole proprietor's €71/year ASN sponsoring service became an anonymous gateway to bulletproof internet routing resources, complete with Spamhaus ASN-…

TI-2026-030D

😈 TI-2026-030D — The Satanist: Anonymous Tor Exit Empire on Bulletproof Rails

Deep investigation into the anonymous Tor exit operator 'Satanist' running 27 relays across 16 ASNs under the 2cb.li domain, connecting all three bulletproof hosting providers in The Anonymity Factory series.

TI-2026-030E

⚡ TI-2026-030E — The Coordinated Deployment: April 6 and the Automation Behind 14 Relays in One Day

Forensic deconstruction of the April 6 2026 mass deployment event: CollecTor archives prove the Satanist relay network existed since September 2025, and April 6 was a family reconstitution, not a first launch.

TI-2026-030F

🏷️ The Naming: Subcultural Taxonomy of Tor Exit Relay Operators

How relay naming conventions reveal five distinct operator archetypes sharing the same anonymous hosting habitat

TI-2026-030G

💰 The Money Trail: Financial Infrastructure of the Satanist Relay Network

Following the money through the 2cb.su Tor exit relay network — and finding that the €2,500/month myth was wrong by 10×. A crypto-native supply chain with zero fiat touchpoints, operating for the cost of a gym membershi…

TI-2026-030H

🌲 The Suicide Forest — Aokigahara SRL and the Anime-Death Infrastructure Shell

Deep investigation of Aokigahara SRL — a Romanian micro-entity operating AS215659 for Tor exit hosting. Company formation mechanics, the anime-death naming aesthetic, and the minimum-viable-entity pattern for internet r…

TI-2026-030I

🇳🇱 The Dutch Backbone — D.O. Bronk and the Legitimacy Question

Forensic investigation of D.O. Bronk / Bronk-ICT — a Dutch IT firm operating 28 Tor relays (2.4% of network) on infrastructure shared with the Satanist/2cb.su criminal network. Traces the MAXKO and Five Cyber Host suppl…

TI-2026-030J

🎣 The Phishing Question — Financial Crime on Privacy Infrastructure

Investigation into the convergence of Tor exit relays and phishing infrastructure on Spamhaus-DROP subnet 45.154.98.0/24, operated by 1337 Services GmbH / rdp.sh

TI-2026-030K

❓ The Questions Nobody Asked

Forensic Q&A analysis of the Anonymity Factory — who, what, when, where, why, how — and the questions nobody has publicly asked about 1337 Services / rdp.sh

TI-2026-030L

🔍 Reading Between the Lines

Structural and conspiratorial analysis of the Anonymity Factory — reading between the lines of regulatory silence, intelligence incentives, and the architecture of unknowability

The Cloud Silk Road
TI-2026-031A

🏭 The Wrapper: Aceville Pte Ltd and the Architecture of Jurisdictional Arbitrage

How Aceville Pte Ltd functions as Tencent Cloud's international legal wrapper, enabling 181 attack IPs to claim 10 different countries while all routing through Singapore.

TI-2026-031B

👁️ The TikTok Shadow — BytePlus and ByteDance's Cloud Attack Infrastructure

BytePlus Pte Ltd — ByteDance/TikTok's cloud arm — operates attack infrastructure where 100% of tracked IPs carry maximum abuse scores. Top IP resolves directly to bytedance.com.

TI-2026-031C

📞 The Seychelles Phone — One Number, Fifteen ASNs, Zero Accountability

How one Seychelles phone number (+248-4-610-795) connects Cloud Innovation Ltd, LARUS Limited, and Yisu Cloud across 15+ ASNs and 16 million IP addresses — the mother of all attribution breaks.

TI-2026-031D

🏝️ The UCloud Archipelago

UCloud Technology (Shanghai STAR Market, 688158.SH) operates 147 attack IPs through a Hong Kong shell with a fake phone number — while PRC law mandates intelligence cooperation and blocks foreign law enforcement access.

TI-2026-031E

⚠️ The CDS Anomaly

4 IPs, ALL at threat 95-100. CDS Global Cloud — US-registered, Chinese-operated, Kubernetes-weaponized. The highest per-IP threat concentration in our intelligence platform.

TI-2026-031F

🕳️ The Regulatory Gap

417 IPs, 253 at maximum abuse, 2180 attacks, zero enforcement. How Chinese cloud providers engineered themselves to exist where no abuse reporting mechanism reaches.

TI-2026-031G

🌍 The AFRINIC Extraction

How a Seychelles shell company captured 16 million African IP addresses from AFRINIC and weaponized Mauritius courts to keep them — while running global attack infrastructure.

TI-2026-031H

🗺️ The Convergence Map

287 cross-provider links prove six Chinese cloud providers share malware, credentials, commands, and abuse contacts while maintaining legal separation for enforcement evasion.

TI-2026-031I

🏛️ The State Question — Where Commercial Negligence Ends and State-Adjacent Activity Begins

Where commercial negligence ends and state-adjacent activity begins — PRC National Intelligence Law Article 7, golden shares, and the Volt Typhoon parallel.

TI-2026-031J

🐉 The Silk Road Was Always Digital — Final Synthesis

Final synthesis — how 6 Chinese cloud providers form one ecosystem connected to Belt and Road Initiative digital infrastructure policy. The Silk Road was always digital.

The American Mirror
TI-2026-032A

🪞 The Buffalo Server Farm — ColoCrossing/HostPapa AS36352

ColoCrossing/HostPapa AS36352: How a Buffalo NY data center enables a 628-IP botnet infrastructure targeting global networks.

TI-2026-032B

🏙️ The Los Angeles Underground — Psychz Networks + MULTACOM Corporation

Forensic analysis of Psychz Networks and MULTACOM Corporation — two Los Angeles hosting providers contributing 60 nodes to a 628-IP global botnet

TI-2026-032C

🏚️ The Internap Inheritance — Bankruptcy, Cover-Up, and America's Most Dangerous ASN

SingleHop/Internap — two bankruptcies, a ransomware cover-up, and the highest average threat score of any US provider in our database

TI-2026-032D

🌊 The DigitalOcean Paradox — Scale, Brand, and the Accountability Gap

DigitalOcean — NYSE-listed, 350 IPs, 5+ botnet campaigns, one IP at threat score 100. The paradox of scale and accountability.

TI-2026-032E

🏴 The FranTech Frontier — Privacy as Abuse Architecture

FranTech Solutions/BuyVM: How one man built 121 IPs of privacy-branded abuse infrastructure across five jurisdictions — and called it freedom

TI-2026-032F

🇪🇺 The OVH-Contabo Axis — EU Regulation vs Infrastructure Abuse

OVH and Contabo: European companies producing worse abuse rates than US counterparts — 219 IPs, 20 RDAP entities, and a provider-specific botnet

TI-2026-032G

☁️ The Google Cloud Anomaly — Hyperscaler Accountability Gap

Google Cloud Platform: 157 IPs, 77 at abuse=100. Belgium cluster at 73% abuse rate — 2.3× worse than US. The hyperscaler accountability gap.

TI-2026-032H

🪞 The Double Standard — Western Infrastructure vs Chinese: The Mirror Thesis Proved

The Double Standard: 8 Western providers produce 4.3× the abuse IPs, 3.0× the max-abuse, and 6.5× the attack hits of the Chinese ecosystem. The mirror thesis proved.

The Psychedelic Connector
TI-2026-033A

📄 2cb.li — The Psychedelic Connector: Cross-ASN Tor Exit Infrastructure and Darknet Naming Conventions

2cb.li is named after the Schedule I psychedelic 2C-B. Registered in Liechtenstein, DNS anonymized through NymDNS (Saint Kitts LLC), hosted via NymBox (Saint Kitts LLC). Domain held since 2015. The naming, TLD choice, a…

TI-2026-033B

📡 The Scale — 49 Relays, 17 ASNs, ~4 Gbps

The 2cb.li Tor exit network spans 49+ relays, 17 ASNs, and 12+ countries with ~4 Gbps bandwidth — approximately 1-3% of global Tor exit capacity. A coordinated April 6, 2026 deployment added 14+ relays in a single day.…

TI-2026-033C

🏗️ TI-2026-033C: The Bulletproof Substrate

Seven bulletproof hosting providers form the substrate of 2cb.li's 49-relay Tor network — two Spamhaus-blacklisted ASNs, a defunct Belgian entity, a 2025-allocated one-man operation, and a Romanian SRL named after a Jap…

TI-2026-033D

📄 The Saint Kitts Pattern

A Nevis LLC, a dark domain with forged heritage, and a Romanian SRL sharing CDN fingerprints with a Caribbean shell — how the 2cb.li network uses offshore corporate structures in Saint Kitts and Nevis to place legal acc…

TI-2026-033E

📄 The Operators

Four pseudonymous operators behind the Psychedelic Connector Tor exit network — Satanist, em/j3, maxzrbn, and secretdrop.to — profiled from their public declarations. OPSEC tiers, PGP anchors, warrant canary architectur…

TI-2026-033F

📄 TI-2026-033F: The Payload

The Psychedelic Connector series conclusion: Caisse d'Épargne bank phishing on 45.154.98.153 (AS210558 / 1337 Services), HiddenPhish toolkit SSL fingerprint, Russian actors probing egrul.nalog.ru, a 1.67-billion-request…

TI-2026-033G

📄 TI-2026-033G: The Stresser Layer

DiamWall (AS207731, Lisbon PT) sells CDN and DDoS protection while simultaneously operating six DDoS-for-hire stresser services on its own infrastructure. CEO Hugo Carvalho and CTO Miguel Miranda identified. The .ST TLD…

TI-2026-033H

📄 TI-2026-033H: HiddenPhish

HiddenPhish is a phishing-as-a-service platform identified via self-signed SSL cert (CN=hiddenphish.xyz, fingerprint f7a67265) on 45.154.98.153, a Spamhaus ASN-DROP bulletproof hosting node (1337 Services GmbH, AS210558…

TI-2026-033I

📄 TI-2026-033I: The Russian Thread

EGRUL reconnaissance, adversary-in-the-middle BEC infrastructure, and the Njalla bridge to 033C. Final article in The Psychedelic Connector series — the full kill chain from Tor relay to wire transfer fraud.

The Invisible Nation
TI-2026-034A

👻 The Empty Column — Israel's Statistical Invisibility in Global Threat Data

Israel: 7 IPs, 0 honeypot hits. The world's most capable cyber nation is statistically invisible in an 8,000+ IP threat database. The absence is the finding.

TI-2026-034B

👻 034B — The Invisible Infrastructure: How 51 Israeli-Connected IPs Appear as Zero

How 51 Israeli-connected IPs appear as zero in every database. Daniel Mishayev, Pfcloud, Kamatera, Bright Data, Kape Technologies, and the architecture of attribution invisibility.

TI-2026-034C

🔒 034C — The Privacy Empire: From Adware to Four VPNs and the Reviews That Recommend Them

From Crossrider adware to four major VPNs: how an Israeli-founded company with a convicted fraudster owner, Unit 8200 co-founder, and UAE government hacker CIO controls the privacy infrastructure millions trust.

TI-2026-034D

🎓 034D — The Graduation Pipeline: How Military Intelligence Becomes Private Sector Dominance

How Unit 8200 — Israel's NSA equivalent — recruits at 16, trains at 18, and produces founders by 25. Alumni have built $200B+ in cyber companies: Check Point, Wiz ($32B Google), NSO Group (Pegasus), Candiru, Cellebrite,…

TI-2026-034E

🌐 034E — The Proxy Empire: How Every Living Room Became an Exit Node

How Bright Data (formerly Luminati/Hola VPN) turned 150 million living rooms into proxy exit nodes — from free VPN exploitation to smart TV SDKs to DDoS attacks on human rights organizations.

TI-2026-034F

🔱 The Submarine Cables — Israel's Physical Internet Infrastructure

Investigation into Israel's submarine cable infrastructure: Blue-Raman (highest capacity Europe-Asia cable) routes through Israeli territory, Unit 8200 confirmed cable-tapping capability, Snowden-confirmed raw NSA intel…

TI-2026-034G

🗺️ The Complete Map — Seven-Layer Architecture of Invisible Control

Synthesis of TI-2026-034 series: Seven layers of Israeli internet infrastructure control from physical cables to application proxies, producing near-zero threat database visibility while enabling passive total awareness.

TI-2026-034H

💰 The Playbook — Israeli Corporate Fraud as Infrastructure Maintenance

TI-2026-034H: Documents a 40-year pattern of Israeli corporate fraud as infrastructure maintenance — from PROMIS to Kape Technologies, how surveillance capability survives every corporate death through cycles of fraud,…

Kill Chain Economy
TI-2026-035A

🔗 The Kill Chain Economy: From the First SSH Probe to the Last Bitcoin Mixer

Forensic investigation connecting honeypot-observed SSH credential scanning through initial access brokerage, ransomware deployment, cryptocurrency laundering, and sanctions-exposed state infrastructure

TI-2026-035B

🏛️ The Evidence Room — What 48 Dossiers Actually Proved

Meta-analysis synthesizing 48 published dossiers, 518 investigations, 8,000+ honeypot IPs, and 4,692 OSINT library documents into a single forensic finding: the infrastructure of cybercrime and the infrastructure of sta…

TI-2026-035C

🕵️ The Surveillance Vendors — WikiLeaks Spy Files Meet the Honeypot

How surveillance tools built for governments become criminal weapons. Unit 8200's production line, FinFisher's ISP-level interception, three documented leak-to-criminal pipelines, the Project Raven prosecution, and Para…

TI-2026-035D

🕳️ The Epstein Infrastructure — Intelligence, Blackmail, and the Network Layer

The question 666 documents avoid: who hosted Jeffrey Epstein's digital infrastructure? PROMIS to Pegasus — a 40-year pattern of intelligence-commercialized surveillance. The jurisdictional architecture that hides ASN ow…

TI-2026-035E

💰 The Money Pipeline — From SSH Probe to Sanctions Evasion

Following the money from a 0.3-second SSH probe to a $4.5 million cash-out. FinCEN SARs, Europol crypto tracing, OFAC sanctions, Chainalysis data. The 34-month Garantex gap. The insurance industry's role in the ransomwa…

TI-2026-035F

🏛️ The State Actors — When Governments Are the Attackers

NSA, GRU, PLA, GCHQ, Unit 8200 — all operating on commercial infrastructure indistinguishable from cybercriminals. Microsoft's own admission. Israel's statistical zero. GRU indicted but operational. Volt Typhoon already…

TI-2026-035G

⚙️ The Jurisdictional Arbitrage Machine

Five components, each legal, each under $2,000, producing impunity at industrial scale. Shell companies in Seychelles, LIR memberships in Germany, ASN leasing, geofeed manipulation, and AFRINIC IP extraction — the compl…

TI-2026-035H

🔓 TI-2026-035H — The Whistleblowers Knew

Snowden, Manning, Hale, Winner — every disclosure confirmed, every architecture still running. Seven predictions, seven confirmations, sixteen years of prison, zero systems dismantled. The honeypot as citizen verificati…

TI-2026-035I

⚡ TI-2026-035I — The Critical Infrastructure Question

45,000 SCADA devices exposed. Volt Typhoon pre-positioned. Colonial Pipeline paid. Oldsmar nearly poisoned. The same scanning infrastructure our honeypot captures also probes every power grid, water plant, and pipeline…

TI-2026-035J

📡 TI-2026-035J — The Disinformation Layer

Same pipes, different payload. The IRA's troll farm uses bulletproof hosting and VPNs from the cybercrime ecosystem. Cambridge Analytica harvested 87M profiles through legitimate APIs. Team Jorge disrupted 33 elections.…

TI-2026-035K

🎯 TI-2026-035K — The Convergence

Where all lines meet. Ten entities across five domains. Five jurisdictions forming one supply chain. Three business models generating $28B annually. The infrastructure of cybercrime, surveillance, state operations, fina…

TI-2026-035L

❓ TI-2026-035L — The Questions That Remain

Series finale. Five hypotheses at the boundary between evidence and inference. Do intelligence agencies preserve the ecosystem? Is ransomware state-licensed? Is Pegasus an intelligence franchise? Who maintains the equil…

The Romanian Corridor
TI-2026-036A

🇷🇴 The Romanian Corridor — Romania as European Cybercrime Infrastructure Transit

Romania ranks #20 in our honeypot — 75 IPs, modest count. But 8 bulletproof ASNs, 4 on Spamhaus nuclear blocklist, the world's largest VPN proxy network (M247, 5,000 prefixes, 60 IXPs), Chinese phishing on Romanian serv…

TI-2026-036B

🏛️ The M247 Empire — How a Romanian SRL Built a 5,000-Prefix Infrastructure Kingdom

Deep investigation into M247 Europe SRL (AS9009): 5,000 prefixes, 60 IXPs, Servers Factory LLC attack arm, 10 national subsidiaries from one Romanian office, participation in 628-node global scanning campaign.

TI-2026-036C

🏭 The SRL Factory — How €0.20 Buys a Globally Routable Autonomous System

Investigation into how Romanian SRLs (minimum capital €0.20) are used to manufacture bulletproof hosting ASNs. Bunea TELECOM's triple ASN-DROP, NexonHost's IPXO pipeline, Feo Prest's 3-month lifecycle, and the RIPE NCC…

TI-2026-036D

🔄 Hackerville to Hosting — Three Generations of Romanian Cyber Infrastructure

From Guccifer's NEC desktop to NexonHost's 628-node botnet: how Romanian cybercrime evolved from prosecutable hacking to unprosecutable infrastructure. Three generations, one structural immunity.

TI-2026-036E

🕸️ The Connections — Where the Romanian Corridor Meets the Global Mesh

Series finale: how Romania's cyber corridor connects to the global Kill Chain Economy through shared HASSH campaigns, SSH key bridges, registrant overlap, and the AbuseRadar nexus. 2,648 IPs, 84 countries, one infrastru…

The Ghost Machines
TI-2026-037A

👻 Ghost Machines — The Automated Scanning Network Behind AS200730

Forensic investigation of a Go-based SSH scanner botnet operated by Kazakhstan shell entities through Russian bulletproof hosting, recruiting IoT devices and routers into a proxy tunnel network. 88 days of continuous sc…

TI-2026-037B

⏱️ The First Ten Seconds — Post-Compromise Behavioral Taxonomy

Behavioral forensics of SSH post-compromise operations: 670 commands from 53 operators reveal seven species of attacker — from Telegram session thieves to cryptomining SSH key injectors to Google Cloud Mirai deployers.…

TI-2026-037C

📦 The Delivery Networks — Malware Delivery Ecosystem Forensics

Forensic analysis of malware delivery to SSH honeypots: whisper ARM malware from Latvia, meow Mirai variant on Google Cloud, notwork-monitoring iterative builds, silent SCP uploads, and the w1n ltd UK-Ukrainian-Swedish…

TI-2026-037D

📊 The Botnet Census — Statistical Forensics of SSH Attack Infrastructure

Statistical forensic analysis of 11,026 fingerprinted sessions across 63 HASSH fingerprints from 2,190+ unique IPs in 84 countries. When you count everything, the infrastructure of SSH attack belongs to cloud providers,…

TI-2026-037E

💰 Follow the Money — Economics of SSH Exploitation

How does a compromised SSH server generate revenue? From residential proxy markets (NASDAQ-listed companies recruiting botnets) to cryptomining on stolen compute to credential markets and ransomware-as-a-service — the c…

TI-2026-037F

🕸️ The Convergence — Where All Lines Meet

The grand synthesis of the Ghost Machines series. Six letters. Seven botnets. 84 countries. 2,190 IPs. Five revenue streams. One conclusion: the infrastructure of cybercrime and the infrastructure of legitimate technolo…

The Permanent Siege
TI-2026-038A

🔄 The Proxy Verifier — 86,239 Events from Private Layer INC

Live forensic investigation of 179.43.139.58 (Private Layer INC, Panama/Switzerland). 86,239 events across 94 days, 112 open proxy ports on Shodan, 3 flood cycles, using Yahoo.com as a proxy verification target. The ind…

TI-2026-038B

🏠 The Permanent Residents

Two IP addresses — 179.43.139.58 (Private Layer INC) and 185.246.128.133 (w1n ltd) — account for 178,581 events and 96% of all honeypot traffic over 94 days. w1n rotates 37 fake client versions while verifying proxies a…

TI-2026-038C

🏭 The Port Factory

Four nodes across OMEGATECH (Seychelles), Private Layer (Panama), and w1n (UK) expose 331 unique proxy ports on Shodan. Same HASSH fingerprint. Same credential. Same verification targets. Different jurisdictions. A sing…

TI-2026-038D

🎭 The Shell Game

RDAP forensics reveal four named persons behind the proxy factory — Milciades Garcia (Private Layer), Anastasiia (w1n), Vatlin Mihail (Private Layer), and Artem Sevastyanov (OMEGATECH). Ukrainian phone numbers connect w…

TI-2026-038E

🔗 The Upstream

Recorded Future intelligence reveals the upstream chain: Railnet LLC (AS214943, Kentucky) migrated to OMEGATECH (AS202412, Seychelles) in January 2026. Both route through aurologic GmbH (AS30823, Germany). Virtualine Te…

TI-2026-038F

🛡️ The Defense Manual

A practical defense guide documenting the exact stack used to detect, analyze, and document the proxy verification factory: Cowrie SSH honeypot, CrowdSec community threat intelligence, MikroTik firewall rules, PostgreSQ…

The Ghost Network
TI-2026-039A

📄 TI-2026-039A The Ghost Network

Israeli national Daniel Mishayev operates GHOSTYNETWORKS/OMEGATECH from Bavaria — the same geographic registration arbitrage used by Unit 8200-linked entities like NSO Group, Kape Technologies, and Bright Data. From sub…

TI-2026-039B

📄 TI-2026-039B The Surveillance Market

The commercial surveillance vendor industry is a pipeline from Unit 8200 to your phone. NSO Group, Cellebrite, Candiru, Intellexa — all Israeli-founded, all tested on Palestinians, sold to 45+ governments. Google TAG do…

TI-2026-039C

📄 The Proxy Economy — How Legal and Criminal Networks Share Infrastructure

The proxy economy operates identically at every tier: Bright Data (150M nodes, NASDAQ supply chain, $500M/yr) vs Socks5Systemz (250K botnet nodes) vs GHOSTYNETWORKS (bulletproof hosting). Our honeypot catches the recrui…

TI-2026-039D

📄 The Information Warfare Layer — Historical Doctrine Behind Digital Infrastructure

Information warfare uses the same infrastructure as cybercrime and surveillance. Operation Gladio's Strategy of Tension digitized: NATO stay-behind networks became troll farms, false-flag bombings became false-flag soci…

TI-2026-039E

📄 The Unified Architecture — How One Infrastructure Serves All Masters

The series finale. 7,994 IPs. 110,140 entity links. 64,411 honeypot hits. 136,617 OSINT documents. 52+ published dossiers. One conclusion: there is no separation between cybercrime, surveillance, proxy economy, and info…

TI-2026-039F

📄 The Electromagnetic Layer — Physical Surveillance Infrastructure

The electromagnetic spectrum is weaponized at every frequency band. IMSI catchers (8cm×9cm, battery-powered) grab phone identities. The Frey Effect (1960) transmits sound directly into the brain via pulsed microwaves —…

TI-2026-039G

📄 The Social Manipulation Layer — Platform Weaponization and Psychographic Targeting

Social media platforms are weapons systems. Cambridge Analytica harvested 50M Facebook profiles for psychographic targeting. Russia's IRA spent $1.25M/month impersonating Americans via residential proxies. False news tr…

The Hidden Language
TI-2026-040A

📄 The Naming Conventions — Darknet Vocabulary in Scanning Infrastructure

Analysis of coded naming conventions in attack infrastructure: Moloch domains, MKUltra credentials, DGA word selection, Turkish botnets, and the GHOSTYNETWORKS-XSServer-PIO-Hosting convergence.

TI-2026-040B

📄 The Naming Conventions Part 2 — Occult Symbolism as Operational Taxonomy

Deep analysis of religious and mythological naming in attack infrastructure: Moloch domains, Kerberos darknet markets, 666 credential patterns, Gnostic anagrams, and the theology of criminal networks.

TI-2026-040C

📄 The Programming Vocabulary — MKUltra Lexicon in Credential Databases

MKUltra and Monarch programming vocabulary found in global botnet credential dictionaries: Alice, Kitten, Master-Slave, Matrix, Ghost — 270 entries mapping CIA mind control to SSH scanning infrastructure.

TI-2026-040D

📄 The Turkish Connection — Warnight Botnet and Grey Wolves Digital Transition

Forensic analysis of the warnight botnet: Turkish nationalist cyber army with hierarchical command structure, fake Linux service persistence, 101 IPs across 30+ countries, Grey Wolves-to-digital pipeline.

TI-2026-040E

📄 The Void Protocol — Malware Delivery Through Credential Fields

Forensic analysis of attack philosophy encoded in malware: Voidsetdownload.so (28 IPs/14 countries), meow malware on Google Cloud, UUID panopticon surveillance (11 IPs/Strong Technology LLC), SSH skeleton key botnet (81…

TI-2026-040F

📄 The Food Code — Credential Patterns and Darknet Lexicons

Forensic analysis of food-coded credentials in honeypot data: pizza, cheese, candy, cookie, honey matched to law enforcement documented code words. banana666 credential cross-referenced to warnight Turkish network. Pode…

The Menu Decoded
TI-2026-041A

📄 The Intelligence Nexus — Epstein Architecture and Cyber Infrastructure Parallels

Structural parallels between Epstein's trafficking infrastructure and modern attack networks. Offshore jurisdictions (Seychelles 41 IPs, St. Kitts, Panama), intelligence connections (Mossad, PROMIS), shell companies, st…

TI-2026-041B

📄 The Food Code Confirmed — Trafficking Lexicon in Credential Databases

Complete mapping of law enforcement documented food code words to honeypot credentials. 9 of 11 primary codes found. Pizza, cheese, candy, cookie, honey, chocolate, ice cream (1cecream obfuscation). Color codes (yellow…

TI-2026-041C

📄 The Programming Pipeline — Disney to Boarding Schools to Digital

cart00ns credential linked to banana666 and warnight network. Disney as documented MKUltra hypnotic tool. Peter Pan never-growing-up programming. daddygirl-eyecandy cluster on Kamatera/Viettel military. v1isagoodgirl ca…

TI-2026-041D

📄 The Cloud Complicity — Hyperscaler Platforms as Attack Infrastructure

Documentation of protection mechanisms enabling exploitation networks. 5 hyperscalers hosting attack infrastructure (Google meow-to-meow same ASN). 3 state telecoms (Viettel military, Etisalat state, TENET academic). 6…

TI-2026-041E

📄 The Kill Chain Economy — Series Synthesis

Final letter of The Menu Decoded series. Complete convergence map: banana666=warnight=cart00ns triangle proven, daddygirl2=eyecandy identity proven, Google meow-to-meow proven, Strong Technology UUID panopticon proven.…

Glass Houses Revisited
TI-2026-042A

📄 Glass Houses Part A — School Infrastructure as Attack Surface

Revisiting TI-2026-017 Glass Houses through exploitation lens. SchoolBridge.in: 60+ children schools on compromised server, exposed MySQL/Redis, 283 abuse reports, 13 CVEs. Viettel (military) sends daddygirl2+eyecandy+i…

TI-2026-042B

📄 Glass Houses Part B — DynCorp and Military Contractor Impunity

Military telecoms as trafficking infrastructure, not victims. Viettel (Ministry of Defence) 154 IPs sends daddygirl2+eyecandy+ilovemykids. DynCorp Bosnia 8 confessed to buying sex slaves. Bacha bazi widely tolerated. UN…

TI-2026-042C

📄 Glass Houses Part C — The Franchise Model: SchoolBridge, HASSH Fingerprints, and PIO-Hosting

SchoolBridge.in shares HASSH fingerprint with PIO-Hosting/GHOSTYNETWORKS in actor_cluster_013. 114 hostnames, 60+ schools, exposed MySQL+Redis, 283 abuse reports. franchisebridge.in same server. Scanning behavior (root:…

TI-2026-042D

📄 Glass Houses Part D — The Organ Trade: Kosovo, Albania, and the ICC Judge Warning

ICC judge warned trafficking investigator: investigate organ harvesting and you're dead. Kosovo: thousands of child refugees trafficked into multiple slave industries. China organ transplant wait times in days. 231 Chin…

TI-2026-042E

📄 Glass Houses Part E — The DynCorp File: Military Contractors and Zero Accountability

DynCorp: 8 employees confessed to purchasing sex slaves in Bosnia. Arizona Market named for American buyers. Whistleblower Bolkovac fired. Company kept Pentagon contracts. slave:slave credential in honeypot. Military co…

TI-2026-042F

📄 Glass Houses Part F — The NXIVM Blueprint: CIA Fronts, Branding, and Programming

NXIVM charged as CIA child sex trafficking front. Master/slave hierarchy maps to honeypot credentials. Branding as ownership marking. Snuff film desensitization. Allison Mack Hollywood recruitment. MKUltra to Finders to…

TI-2026-042G

📄 Glass Houses Part G — The Dutroux Affair: Buried Leads and the Second Network

Marc Dutroux Belgium: leads blocked or buried. Second parallel network with 7 children never investigated. Parliamentary cover-up. 275,000 marched in White March. Protection pattern identical to Epstein and Savile. Belg…

TI-2026-042H

📄 Glass Houses Part H — The Jersey Horror: Islands, Yachts, and the Crown Knowledge

Jersey Crown Dependency: Haut de la Garenne children's home decades of abuse. Edward Heath implicated in rape and murder of children on yacht. Islands as architecture of impunity. Seychelles, St. Kitts, Singapore provid…

TI-2026-042I

📄 Glass Houses Part I — The Tencent Cash Machine: Chinese State Infrastructure as Attack Platform

Tencent Cloud threat 98: cash-1000.xyz 20+ fraud domains. slave:slave credentials. 231 Chinese state telecom IPs. WeChat surveillance but cannot detect fraud. China Tribunal organ harvesting. root:young credential. Digi…

TI-2026-042J

📄 Glass Houses Part J — The Korean Corridor: KT, Telegram Harvesting, and Surveillance

Korea Telecom 121 IPs 564 hits. Three-stage SIGINT: MikroTik/Telegram/GSM harvesting. 23skidoo, princess, foreveryoung credentials. SK Broadband 30 IPs. State surveillance + exploitation vocabulary. Real-name registrati…

TI-2026-042K

📄 Glass Houses Part K — The Kosovo Node: ARTMOTION and Jurisdictional Blindspot

Kosovo IP 84.22.62.247: shipdrug.ru, rxdrugship.ru AND kitten.rxdrugship.ru. Drug trafficking + exploitation vocabulary same server. Kosovo: refugee camp trafficking + drug shipping. Named ships (carrie, kalyn, kassandr…

TI-2026-042L

📄 Glass Houses Part L — The Polish Anomaly: One Country, 48 Exploitation Credentials

Poland: 5 IPs but 48 exploitation credentials (9.6 per IP vs 1.4 average). babygirl, babygirl1, iloveyou1/2, dragon. Catholic Church code of silence in 87% Catholic country. Poland as trafficking transit country. Number…

TI-2026-042M

📄 Glass Houses Part M — The Indonesian Triangle: CloudHost, Kamatera, and daddygirl2

CloudHost Singapore hosts daddygirl2 IP + girlallaroundx.site + misraudlatulislam.sch.id (Islamic school) + Dubai financial fraud. 3 IPs share daddygirl2+eyecandy across Indonesia/Israel/Vietnam. Second school on exploi…

TI-2026-042N

📄 Glass Houses Part N — The Rostelecom Shadow: BGP Hijacks and State Espionage

Rostelecom: 15 IPs avg threat 53 highest of any state telecom. BGP hijacking documented. SORM gives FSB direct wiretap access. domolink.elcom.ru malware deployment. State telecom as surveillance AND attack infrastructur…

TI-2026-042O

📄 Glass Houses Part O — The Omegatech Empire: Seychelles Shells and Sex Scams

OMEGATECH Seychelles IBC: threat 100, intstantlocalhookups.com. 41 Seychelles IPs. $350 company formation, no ownership disclosure. Sex scams + Turkish operations + warnight overlap. Digital Panama Papers.

TI-2026-042P

📄 Glass Houses Part P — The Pakistan Nexus: NTC, Air University, and Army Public Schools

Peshawar APS 2014: 132 children killed. Army Public School Gopalpur on compromised SchoolBridge.in. Air University Islamabad scanning. Pakistan NTC military telecom SSH key injection. Military children digitally exposed…

TI-2026-042Q

📄 Glass Houses Part Q — The Quiet Scanners: Universities That Attack

Academic networks scanning: DFN Germany 49 hits, HaNoi University Vietnam 10, Khajeh Nasir Iran 10, Air University Pakistan. Research as cover for reconnaissance. Military-academic nexus in Vietnam, Iran, Pakistan.

TI-2026-042R

📄 Glass Houses Part R — The Brazilian Connection: teenow and the Southern Route

Brazil: teenow.com.br on DigitalOcean threat 83. coolkid, devil, kids123, kitten credentials. Latin American trafficking corridor. banana666 Ecuador/Panama. DigitalOcean selective enforcement.

TI-2026-042S

📄 Glass Houses Part S — The Surveillance Stack: phonesnoops, edgetrack, and Monitoring

phonesnoops.com + greattoysforkids.com same IP threat 85. edgetrack.org tracking ecosystem with shop+analytics+community. camdvr.org camera photos. Surveillance tools + children's products on attack infrastructure.

TI-2026-042T

📄 Glass Houses Part T — The European Axis: Contabo, Hetzner, and the Privacy Shield

European hosting as attack backbone. Contabo play.eutoligado.net threat 95. Hetzner darkcurry.com. OVH xplaydashboard. German data protection law as paradoxical shield for attackers. Infrastructure quality + legal prote…

TI-2026-042U

📄 Glass Houses Part U — The Entity Web: 271K Connections Mapped

271,458 entity links connecting IPs, ASNs, hostnames, actors. Korea Telecom 36 IPs. Two-hop path from military telecom to financial fraud through exploitation credentials. Hub nodes: CloudHost, Kamatera, DigitalOcean.

TI-2026-042V

📄 Glass Houses Part V — The Credential Census: 139,335 Passwords Decoded

139,335 honeypot credentials analyzed statistically. Exploitation vocabulary as statistical outliers. daddygirl2/eyecandy on exactly 3 IPs. 57 Viettel IPs identical lists. Botnet fingerprint. Language distribution acros…

TI-2026-042W

📄 Glass Houses Part W — The Download Arsenal: 224 Weapons Cataloged

224 honeypot malware samples. neofetch GitHub disguise. whisper multi-architecture IoT botnet (ARMv5-v7, MIPS, x86). notwork-monitoring mocking defenders. shr Indonesian connection. Professional operation evidence.

TI-2026-042X

📄 Glass Houses Part X — The Actor Clusters: 15 Organizations, One Network

15 actor clusters. actor_cluster_001: 1,831 IPs across 50+ countries. actor_cluster_013: SchoolBridge.in + GHOSTYNETWORKS share HASSH fingerprint. Children's data → bulletproof hosting → German shell companies. Organiza…

TI-2026-042Y

📄 Glass Houses Part Y — The Timeline: 90 Days of Attack Evolution

90 days March-June 2026 temporal analysis. Weekday peaks, UTC+8 concentration. Credential evolution from dictionary to exploitation vocabulary. SSH skeleton key campaign May. Command timeline reconnaissance→persistence→…

TI-2026-042Z

📄 Glass Houses Part Z — The Complete Architecture: Everything Connects

Series finale: 26 letters, 7,999 IPs, 137 countries, 139,336 credentials, 110,288 entity links, 57 campaigns, 4,692 OSINT documents. Six-layer architecture: infrastructure, operations, state integration, exploitation, c…

The Liturgy of Control
TI-2026-043A

🔺 The Liturgy of Control Part A — The Vocabulary Pyramid

Analysis of 33,286 unique credential combinations revealing a 5-layer hierarchy of ritualistic control vocabulary in honeypot data — from infrastructure defaults to explicit victim-referencing patterns across 700+ sourc…

TI-2026-043B

⛓️ The Hierarchy Credential

The dual meaning of master/slave — computing architecture AND human trafficking hierarchy — creates permanent plausible deniability in credential dictionaries. 57 Vietnamese military IPs deploy identical lists. Three co…

TI-2026-043C

🏷️ The Product Credential

When credential vocabulary applies product naming conventions to human beings. v1isagoodgirl! — software versioning applied to a person. daddygirl2 — iteration numbering for victims. brittany20, claire12, kids123 — inve…

TI-2026-043D

📄 The Theological Credential

Forensic analysis of theological naming in attack infrastructure: gods, demons, and underworld guardians embedded in honeypot credentials, Tor relay networks, darknet marketplaces, and hosting companies.

TI-2026-043E

📄 The Convergence

Series finale. Where hierarchy, product naming, theology, and coded commerce converge on the same infrastructure. Military telecoms deploying child exploitation vocabulary. 3-hop entity paths from state surveillance to…

TI-2026-043F

📄 The Programming Manual

MKUltra and Monarch programming vocabulary found operational in global botnet credential dictionaries — 270+ credentials mapping CIA mind control to SSH scanning infrastructure.

TI-2026-043G

📄 The Finders — Documented Procurement Operations in Credential Infrastructure

Six documented government-linked child procurement operations — The Finders/CIA, Franklin Credit Union, DynCorp Bosnia, Dutroux, Westminster, Epstein — and their operational vocabulary persisting in active SSH credentia…

TI-2026-043H

📄 The Symbols — Occult Identification Markers in Credential Infrastructure

FBI-documented pedophile symbols, Bohemian Grove Moloch worship, Epstein Blue Butterfly, NXIVM branding — traced to SSH credential dictionaries and infrastructure naming. The credential IS the symbol. The authentication…

TI-2026-043I

📄 The Whistleblowers — The Cost of Speaking

The systematic destruction of those who spoke: COINTELPRO, MKUltra, Franklin, DynCorp, Dutroux, WikiLeaks. Every whistleblower follows the same trajectory — disclosure, discrediting, persecution, elimination. The creden…

TI-2026-043J

📄 The Architecture of Impunity

Why the system persists: five structural pillars — jurisdictional arbitrage, shell infrastructure, sovereign immunity, cryptographic anonymity, distributed resilience. Combined probability of successful prosecution: zer…

TI-2026-043K

📄 The Signal

How SSH credential dictionaries function as a covert communication channel. Documents heartbeat protocols, synchronized military bursts, credential vocabularies as structured messages, and campaign hierarchies hiding in…

TI-2026-043L

📄 The Clock

Temporal analysis proves military precision behind SSH honeypot traffic. Coefficient of variation 2.6%, Monday evening bursts at 21:00 CET, 269-node army across 88 ASNs — mathematical proof that internet noise is coordi…

TI-2026-043M

📄 The Map — Organizational Topology of the Liturgy Infrastructure

Organizational topology of The Liturgy of Control infrastructure. Entity link analysis proves ISAEV, Private Layer, w1n, Omegatech, and the 269-IP army are one coordinated system across 30+ countries.

The Nordic Paradox
TI-2026-044A

🇸🇪 The Nordic Paradox Part A — The Architecture: Sweden's Privacy Hosting Ecosystem

How PRQ, Bahnhof, DFRI, and Njalla turned Sweden into a durable privacy-hosting ecosystem—and why the same structure now appears in attack telemetry.

TI-2026-044B

🇸🇪 The Nordic Paradox Part B — The Vikings: Internet Vikings and the Gambling-to-Abuse Pipeline

Internet Vikings, PatrikWeb, Gigahost, and 19 Swedish ASNs show how gambling hosting and Nordic legitimacy form a pipeline into abuse infrastructure.

TI-2026-044C

🇸🇪 The Nordic Paradox Part C — The Baltic Bridge: IPXO, Lithuania, and the IP Laundering Capital of Europe

Lithuania's IPXO and the Baltic address market turned IPv4 reputation into a tradable commodity feeding Swedish hosts and European bulletproof infrastructure.

TI-2026-044D

📄 The Nordic Paradox Part D — The Backbone: M247, NordVPN, and Mullvad — When Privacy Is Plumbing

M247 routes traffic for NordVPN and Mullvad while hosting 47+ attack IPs. Every tested no-log VPN produced logs. The privacy promise is marketing fiction.

TI-2026-044E

📄 The Nordic Paradox Part E — The Relay Network: Swedish Tor Exits and the Anonymity Factory

Sweden hosts disproportionate Tor exit infrastructure through DFRI, 1337 Services, and pseudonymous operators — connected via Njalla and No-KYC providers.

TI-2026-044F

📄 The Nordic Paradox Part F — The Signal: FRA, Glimmerglass, and Nordic SIGINT Cooperation

Sweden wiretaps ALL fiber optic cables crossing its borders while hosting WikiLeaks, Njalla, and Pirate Bay — making the privacy ecosystem either naive or deliberate intelligence cover.

TI-2026-044G

📄 The Nordic Paradox Part G — The Other Nordics: Norway, Denmark, Finland and the Quiet Attack Surface

Gigahost controls 83% of Norwegian honeypot IPs. DotSrc runs Tor exits from a Danish education network. Finland hosts Hetzner overflow. Three countries, 50+ attack IPs, zero headlines.

TI-2026-044H

📄 The Nordic Paradox Part H — The Vendors: Nokia, Ericsson, and the Surveillance Export Machine

WikiLeaks Spy Files document Nokia-Siemens and Ericsson selling lawful interception to 180+ countries. Trovicor sold monitoring centers to Bahrain, Iran, Syria. Privacy at home, surveillance for export.

TI-2026-044I

📄 The Nordic Paradox Part I — The Laundry: Danske Bank, Crypto Exchanges, and Nordic Financial Crime

Danske Bank laundered €200B. Swedbank €135B. Same Baltic corridor, same shell structures. The financial twin of the IP pipeline closes the loop from infrastructure to money.

TI-2026-044J

📄 The Nordic Paradox Part J — The Enforcers: DOJ, Deferred Prosecution, and the Price of Nordic Crime

DOJ extracted $4B+ from Nordic entities. Zero executives imprisoned. Ericsson paid ISIS. Telia bribed a dictator's daughter. The fine is the subscription fee.

TI-2026-044K

📄 The Nordic Paradox Part K — The Gatekeepers: Auditors, Lawyers, and the Compliance Theater

KPMG gave 8 years of clean audits during €200B laundering. 2 compliance staff for 15,000 accounts. Journalism succeeded where every gatekeeper failed.

TI-2026-044L

📄 The Nordic Paradox Part L — The Sanctions Gap: M247, Iran, and Nordic Infrastructure in Sanctioned Jurisdictions

M247 routes to Tehran. NordVPN transits sanctioned infrastructure. Danske served sanctioned entities. The complete evasion stack: VPN + shell company + correspondent bank.

The Chinese Ecosystem
TI-2026-045A

🏗️ The Chinese Ecosystem Part A — The Three-Layer Architecture: Cloud Innovation, LARUS, and the 16 Million Addresses

How Cloud Innovation, LARUS Limited, and Yisu Cloud built a three-layer jurisdictional architecture controlling 16+ million stolen IP addresses

TI-2026-045B

☁️ The Chinese Ecosystem Part B — Yisu Cloud: 100% Abuse Rate and the Seychelles Phone Number

A Chinese cloud provider with a perfect 100% abuse score across every scored IP, connected through a single Seychelles phone number

TI-2026-045C

🐉 The Chinese Ecosystem Part C — The Tencent Paradox: State Cloud, Selective Enforcement, and the Digital Silk Road

How China's largest cloud provider censors politics while hosting the highest-threat attack infrastructure

TI-2026-045D

🏢 The Chinese Ecosystem Part D — The Aceville Shell: How Singapore Launders Chinese Cloud Operations

The Singapore corporate shell that transforms Chinese state cloud into international legitimacy

TI-2026-045E

📡 The Chinese Ecosystem Part E — ChinaNet AS4134: The State Telecom That Attacks

The backbone carrier at the center of repeated routing controversy also dominates the Chinese abuse slice in direct honeypot telemetry.

TI-2026-045F

💀 The Chinese Ecosystem Part F — The Five Failure Modes: Why Abuse Reports to Chinese Providers Always Die

Five separate mechanisms ensure that reporting abuse to Chinese providers usually becomes ritual, not remediation.

TI-2026-045G

⚖️ The Chinese Ecosystem Part G — The National Intelligence Law: Article 7 and Mandatory Cooperation

Article 7 makes Chinese cloud neutrality legally conditional because every provider can be compelled to support intelligence work.

TI-2026-045H

🌍 The Chinese Ecosystem Part H — Belt and Road of Bytes: Digital Silk Road as Infrastructure Colonization

Digital Silk Road projects export not just connectivity but long-term dependency on an ecosystem already linked to cloud abuse, surveillance, and state intelligence leverage.

TI-2026-045I

🏭 The Chinese Ecosystem Part I — The Credential Factories: AS4837, AS9808, and Industrial-Scale SSH Harvesting

China Unicom and China Mobile access networks operate as credential factories: 90 observed hostile IPs, high abuse density, IoT churn, and exported SSH pressure.

TI-2026-045J

🗺️ The Chinese Ecosystem Part J — The Map So Far: 710 IPs, 84 ASNs, and the Deeper Revelations Ahead

Mid-series synthesis of the Chinese ecosystem so far: 710 IPs, 84 ASNs, state telecom substrate, cloud legitimacy, offshore wrappers, and deeper revelations still ahead.

TI-2026-045K

🔍 The Chinese Ecosystem Part K — Baidu and ByteDance: When Consumer Platforms Become Attack Substrate

Baidu and ByteDance run cloud infrastructure with perfect abuse saturation in the observed corpus, collapsing the comfort boundary between consumer platforms and hostile infrastructure.

TI-2026-045L

🏰 The Chinese Ecosystem Part L — Alibaba Cloud and Huawei Cloud: Enterprise Trust on Hostile Ground

Alibaba Cloud and Huawei Cloud place enterprise trust on hostile ground: high abuse density, severe Alibaba threat concentration, and Huawei telecom-cloud adjacency.

TI-2026-045M

💧 The Chinese Ecosystem Part M — The I-Soon Leak: When the Contractor Became the Evidence

The I-Soon leak exposed a Shanghai contractor pricing ministry hacks and targeting Digital Silk Road partner states.

TI-2026-045N

🏛️ The Chinese Ecosystem Part N — The Budapest Convention Gap and the Treaty China Wanted Instead

China stayed outside Budapest, backed a rival UN cybercrime treaty, and turned legal asymmetry into cyber advantage.

TI-2026-045O

⚖️ The Chinese Ecosystem Part O — China vs America: Volume, Sophistication, and the One Difference That Matters

The US shows more attack volume; China shows more concentration and near-total impunity. Part O explains the difference.

TI-2026-045P

🐲 The Chinese Ecosystem Part P — The Unified Architecture Thesis

Grand finale: why law, infrastructure, shells, contractors, and zero-response tolerance form one Chinese attack architecture.

TI-2026-045Q

📡 The Chinese Ecosystem, Part Q — Southbase: A New Guangzhou IDC Node Runs C2

Nine AS135089 IPs reached the SSH honeypot across late May to early July — 57 login attempts, one success. Two of them matter:

The Web Siege
TI-2026-046A

🕸️ TI-2026-046A — The .env Harvesters: Google Cloud Credential Scanning Fleet

Forensic analysis of a professional .env credential harvesting operation: 54 Google Cloud IPs, 7 daily burst campaigns, 35-path framework-aware enumeration, zero SSH overlap proving dedicated HTTP-only specialization. D…

TI-2026-046B

👻 The WordPress Ghosts — Azure Empty-UA Shell Checker Fleet

Forensic analysis of a massive Microsoft Azure botnet (269+ IPs) using empty user-agents to check for pre-planted WordPress backdoors. The fleet does not attack — it harvests from previous compromises.

TI-2026-046C

🔍 The Reconnaissance Industrial Complex — When Scanning Becomes Indistinguishable

🔍 HIGH — The Line Between Legitimate Scanning and Criminal Reconnaissance Has Dissolved TI-2026-046C — The Reconnaissance Industrial Complex When a $2.7 Billion SEO Company, Chinese State Telecom, and Credential Thieves…

TI-2026-046D

📄 The Multi-Vector Operators

⚡ CRITICAL — 39% of HTTP Attackers Simultaneously Brute-Force SSH — Protocol-Agnostic Attack Platforms TI-2026-046D — The Multi-Vector Operators When the Same IP Address Scans Your Web Server for Credentials While Simul…

TI-2026-046E

📄 The Cloud Mercenaries

☁️ CRITICAL — 41% of All HTTP Attack Traffic Originates From Three Hyperscalers That Also Sell You Security Products TI-2026-046E — The Cloud Mercenaries How Google, Microsoft, and Amazon Became the Largest Attack Infra…

The Glass Cage
TI-2026-047A

🪞 The Login Page That Watched Back

How an Authelia forward-auth login page became a honeypot that logged every credential-scanning bot's full target list — 100+ .env variants in 62 seconds, decoded ?rd= probes, and the auth-indifferent scanners hitting b…

TI-2026-047B

🪞 The Repeat Offenders

The web-threats surface didn't find new villains — it re-convicted networks the corpus already named. 73 four-layer-confirmed threats, the Azure empty-UA webshell botnet, and M247's backbone returning on the web surface.

TI-2026-047C

🪞 The Botnet Census

36 web campaigns, ~88k requests, three coordination fingerprints — temporal bursts, empty-UA clusters, and shared-path toolkits. A 7-IP fleet spanning Amazon and Google shares the same 170-path .env dictionary: one oper…

TI-2026-047D

🪞 The Cartographers of the Web

An IP doesn't have a location — it has several, and they disagree. How web attackers weaponise the gap between where an address is registered, routed and geolocated — from a Hong-Kong/Netherlands block to M247's virtual…

TI-2026-047E

🪞 The First Ten Seconds

What happens the instant an attacker gets in: the SSH front door falls to admin/admin, then a single pasted command runs 24 steps in one second — fetch multi-arch malware, change root's password, plant backdoor users. T…

TI-2026-047F

🪞 The Glass Cage

The capstone of The Glass Cage: how five windows onto one siege — the Authelia honeypot, the repeat offenders, the botnet census, the cartographers, and the first ten seconds — resolve into a single kill chain, and the…

The Long Memory
TI-2026-048A

🧬 The Nine Commands

Decoding one honeypot session, line by line: nine commands that hunt MikroTik routers, Telegram Desktop sessions and GSM/SMS gateways — and reveal an attacker's whole business model before any malware is even downloaded.

TI-2026-048B

🧬 The Second Factor

The persistent botnet hunts Telegram sessions and SMS gateways because both defeat two-factor authentication. NIST already called SMS 2FA weak; the WikiLeaks Spy Files show the same interception capability sold to state…

TI-2026-048C

🧬 Identity Without an Address

An attacker rotates across 49 residential IPs in 20 countries to look like nobody — and is identified anyway, by the one thing it cannot change: its behaviour. A full-spectrum investigation of identity without an addres…

TI-2026-048D

🧬 The Re-tasking

A compromised machine is not a victim but an asset — re-tasked over time from recon to payload to proxy. How the honeypot's TTP-label timeline measures behavioural drift, from a frozen nine-command kit to a host that tr…

TI-2026-048E

🧬 Ninety Days

Ninety days of one honeypot as a core sample of the internet's attack climate: a steady baseline punctuated by datable botnet surges, a source-geography that migrates from Poland/Sweden to Switzerland/US/Asia, drifting…

The Swarm Protocol
TI-2026-049A

📄 The Library That Moves — libssh Version Fingerprints as Behavioral DNA

🟠 ACTIVE — libssh Swarm · 2,341 Distributed Nodes · 3 Library Versions · 84 Countries · actor-6285990cc704 TI-2026-049A — The Library That Moves Series: The Swarm Protocol · Letter A of 6 · Published 2026 Three library…

TI-2026-049B

📄 The Command Language — Post-Authentication Protocols of the libssh Swarm

🟠 ACTIVE — libssh Swarm Post-Auth · 3,060 Command Links · 2 Protocol Families · 176 IPs · 19-Command Intrusion Lifecycle TI-2026-049B — The Command Language Series: The Swarm Protocol · Letter B of 6 · Published 2026 Th…

TI-2026-049C

📄 Eighty-Four Flags — The Jurisdictional Cartography of the libssh Swarm

🟠 ACTIVE — libssh Swarm · 84+ Countries · 5 Continents · Seychelles 240x US Density · ByteDance 141 IPs · 48.8% Known-Bad Still Active TI-2026-049C — Eighty-Four Flags Series: The Swarm Protocol · Letter C of 6 · Publis…

TI-2026-049D

📄 The Version Tree: CVE Archaeology and Operational Evolution of the libssh Swarm

🟠 ACTIVE — libssh Swarm · 3 Simultaneous Versions · 38 CVEs in Lineage · 0.9.6 EOL Since 2021 · Fingerprint Diversification · Operator Accepts Own Vulnerabilities TI-2026-049D — The Version Tree Series: The Swarm Protoc…

TI-2026-049E

📄 The Temporal Pattern: When the Swarm Sleeps and When It Wakes

🟠 ACTIVE — libssh Swarm · Human Scheduling Detected · Tuesday 78% of Traffic · 02:00-04:00 UTC Burst = 10:00 CST · Weekend 8.4% of Weekday · Netherlands Migration +67% TI-2026-049E — The Temporal Pattern Series: The Swa…

TI-2026-049F

📄 The Census: A Statistical Portrait of the libssh Swarm

🟠 SERIES COMPLETE — The Swarm Protocol · 6 Letters · 2,341 IPs · 84 Countries · 606 ASNs · 84,726 Attempts · 54 Days · 1 Actor Cluster TI-2026-049F — The Census Series: The Swarm Protocol · Letter F of 6 · FINAL · Publi…

The Toolmakers
TI-2026-050A

📄 The Other Swarm: Go_SSH and the Competing Ecosystems of SSH Scanning

⚙️ Series 050 — The Toolmakers The Other Swarm TI-2026-050A · Letter 1 of 5 · Page 297 While we spent six letters dissecting the libssh swarm — 2,341 IPs, 84 countries, three library versions braided into one organism —…

TI-2026-050B

📄 The Validate-Then-Recon Pipeline: Go_SSH Two-Phase Operations

🤝 Series 050 — The Toolmakers The Silent Handshake TI-2026-050B · Letter 2 of 5 · Page 298 Three hundred and thirty-three shells opened. In three hundred and twenty-one of them, nothing happened . The Go_SSH fleet authe…

TI-2026-050C

📄 The Shell Game: Offshore Infrastructure and the Three-Layer Topology

🏝️ Series 050 — The Toolmakers The Shell Game TI-2026-050C · Letter 3 of 5 · Page 299 Follow the IP addresses and you find VPS providers. Follow the VPS providers and you find shell companies. Follow the shell companies…

TI-2026-050D

📄 The Ecosystem: Fifteen Campaigns, Four Actors, and the Hierarchy of SSH Scanning

🔗 Series 050 — The Toolmakers The Food Chain TI-2026-050D · Letter 4 of 5 · Page 300 Step back far enough and the individual campaigns dissolve into something larger. Not fifteen separate scanning operations. One ecosys…

TI-2026-050E

🏭 The Assembly Line

Final synthesis of Series 050 The Toolmakers. Complete operational model of the Go_SSH fleet, Seychelles shell companies, three-tier SSH scanning ecosystem, and defensive recommendations.

The Credential Harvest
TI-2026-051A

📄 The Password Is the Product

TI-2026-051A • The Credential Harvest • Letter I of VI The Password Is the Product In which we discover that 14,652 attempts to type "admin" into a box are not chaos — they are commerce CONFIDENCE: HIGH CATEGORY: CREDEN…

TI-2026-051B

📄 The Shopping List

TI-2026-051B • The Credential Harvest • Letter II of VI The Shopping List In which we read the receipts of 133 commands and discover that every attacker arrives with a plan CONFIDENCE: HIGH CATEGORY: BEHAVIORAL ANALYSIS…

TI-2026-051C

📄 The Stuffing Machine

TI-2026-051C • The Credential Harvest • Letter III of VI The Stuffing Machine In which 99 IP addresses attack in the same 10-minute window and we learn that coincidence has a threshold CONFIDENCE: HIGH CATEGORY: COORDIN…

TI-2026-051D

📄 Keys to the Kingdom — The SSH Key as Skeleton Key

🔑 TI-2026-051D KEYS TO THE KINGDOM — The SSH Key as Skeleton Key Series: The Credential Harvest | Letter D of F+ | Confidence: HIGH The Operating Premise: In the physical world, if three burglars from different cities a…

TI-2026-051E

📄 The Telegram Market — Where Access Becomes Commodity

🏪 TI-2026-051E THE TELEGRAM MARKET — Where Access Becomes Commodity Series: The Credential Harvest | Letter E of F+ | Confidence: HIGH The Operating Premise: Everything we've documented in this series — the credential s…

TI-2026-051F

📄 The Economy of Access — A $10 Billion Distributed Corporation

💰 TI-2026-051F THE ECONOMY OF ACCESS — A Distributed Corporation Worth Billions Series: The Credential Harvest | Letter F — Series Synthesis | Confidence: HIGH The Final Premise: Over five previous letters, we dissected…

TI-2026-051G

📄 The Signal in the Noise — Credential Storms as Covert Communication

📡 TI-2026-051G THE SIGNAL IN THE NOISE — When Credential Storms Speak Series: The Credential Harvest — Extension | Letter G | Confidence: MEDIUM ··· − − − ···    ··· − − − ···    ··· − − − ··· WEDNESDAY 02:00 UTC — THE…

TI-2026-051H

📄 The Wednesday Protocol — Temporal Forensics of a Criminal Schedule

⏰ TI-2026-051H THE WEDNESDAY PROTOCOL — Temporal Forensics of a Criminal Schedule Series: The Credential Harvest — Extension | Letter H | Confidence: HIGH The Methodology: Intelligence agencies call it traffic analysis…

TI-2026-051I

📄 The Dictionary — What Credential Selection Reveals About the Operators

📊 TI-2026-051I THE DICTIONARY — What Credential Selection Reveals About the Operators Series: The Credential Harvest — Extension | Letter I | Confidence: HIGH The Question: We've analyzed when they scan (Wednesday, 02:0…

TI-2026-051J

📄 The Doctrine — Criminal Operational Science in 10 Letters

📜 TI-2026-051J THE DOCTRINE — Criminal Operational Science in Ten Letters Series: The Credential Harvest — FINAL LETTER | Confidence: HIGH What We Built: Over ten letters and 102 days of observation, a single SSH honeyp…

TI-2026-051K

📄 The Dark Portfolio — When Credential Harvesters Host Darknet Markets

🔴 TI-2026-051K THE DARK PORTFOLIO — When Credential Harvesters Host Darknet Markets Series: The Credential Harvest — Extension Letter K | Confidence: HIGH The Question We Avoided: In letters A through J, we documented t…

TI-2026-051L

📄 The Military Connection — State Telecoms in the Credential Harvest

🎖️ TI-2026-051L THE MILITARY CONNECTION — State Telecoms in the Credential Harvest Series: The Credential Harvest — Extension Letter L | Confidence: HIGH The Uncomfortable Discovery: In 051K we documented criminal ASNs…

TI-2026-051M

📄 The Exploitation Credential — When Passwords Spell Out Abuse

⚠️ TI-2026-051M THE EXPLOITATION CREDENTIAL — When Passwords Spell Out Abuse Series: The Credential Harvest — Extension Letter M | Confidence: HIGH ⚠️ CONTENT WARNING: This letter documents exploitation vocabulary found…

TI-2026-051N

📄 The Complete Architecture — Credential Harvest as Enabler of Everything

🏗️ TI-2026-051N THE COMPLETE ARCHITECTURE — Credential Harvest as Enabler of Everything Series: The Credential Harvest — FINAL SYNTHESIS | Letter N of 14 | Confidence: HIGH 14 Letters. One Architecture. This series bega…

The Malware Graph
TI-2026-052A

🧬 The Malware Graph — The Family Tree

2,089 shared-malware links reveal 82 nodes in 28 countries deploying one binary — seven years of zero evolution because the worm has no predators.

TI-2026-052B

🧬 The Malware Graph — The Download Chain

Three parallel deployment chains (Meow worm via GCP, Whisper IoT via Latvia, Chinese C2 triad) — total infrastructure cost $50-100/month.

TI-2026-052C

🧬 The Malware Graph — Shared DNA

Attribution methodology: 1,312 IP pairs sharing both malware AND commands prove single-operator coordination exceeding DOJ prosecution standards.

TI-2026-052D

🧬 The Malware Graph — The Mutation Rate

91-day malware evolution: zero mutation (Outlaw) vs maximum polymorphism (sshd backdoors). Ecosystem diversity collapses from 11 species to monoculture.

TI-2026-052E

🧬 The Malware Graph — The Invisible Supply Chain

The complete criminal supply chain: developer, distributor, operator, resource manager, customer — all at zero marginal cost. Structurally indestructible.

The Transit Map
TI-2026-053A

🗺️ The Transit Map — The Roads They Travel

Microsoft, DigitalOcean, Google carry 10% of malicious traffic. The roads attackers travel were built by companies that sell antivirus.

TI-2026-053B

🗺️ The Transit Map — The Name on the Door

Shell companies, registry markers, and Private Customer — 661+ malicious IPs operate without meaningful RDAP attribution.

TI-2026-053C

🗺️ The Transit Map — One Phone Number

102,008 abuse reports for one IP. Still online. The abuse reporting system requires contacts exist but not that they respond.

TI-2026-053D

🗺️ The Transit Map — The Registrars Blind Eye

508 IPs under RIPE self-reference. KYC verification evaporates at the LIR-to-customer boundary.

TI-2026-053E

🗺️ The Transit Map — The Abuse Email Cluster

tech@cloudinnovation.org spans 15 ASNs. hm-changed@vnnic.vn is a dead placeholder. Email addresses are organizational X-rays.

TI-2026-053F

🗺️ The Transit Map — Fourteen Thousand Tenants

Google, Microsoft, Amazon, DigitalOcean host 26.9% of all attack infrastructure. The building has thousands of tenants.

TI-2026-053G

🗺️ The Transit Map — The Invisible Hand

The attack surface is a feature of the architecture, not a bug. Coordination between competitors could fix 60% — but won't.

The Clock Tower
TI-2026-054A

🕰️ Synchronized Watches

Temporal correlation analysis reveals three coordination hubs synchronized with 292+ IPs, operating on a nocturnal schedule that exposes timezone-aware human operators

TI-2026-054B

🕰️ The Geography of Command

Geographic analysis of 3,085 attacker IPs across 109 countries reveals concentrated attack corridors, timezone handoff patterns, and purpose-built infrastructure

TI-2026-054C

🕰️ Twenty-Two Thousand Neighbors

22,311 same-prefix relationships reveal three patterns: Tor anonymization clusters, purpose-built attack subnets, and compromised residential pools

TI-2026-054D

🕰️ The Working Day

Circadian analysis exposes the human operator behind the automation: evening peaks, Monday batch runs, Thursday dips reveal a CET-timezone side-job pattern

TI-2026-054E

🕰️ Waves and Tides

Three-phase operational lifecycle: campaign launch bursts, steady-state maintenance, and periodic activation waves reveal planning cycles behind the coordination network

TI-2026-054F

🕰️ The Conductor

Complete operator profile synthesized from temporal analysis: CET evening operator running credential validation as a side business with 90-day planning cycles

The Actor Profiles
TI-2026-055A

👤 Two Hundred Sixty-Nine

The largest actor cluster: 269-628 IPs scanning for empty root passwords across 48 countries. Pure reconnaissance with zero exploitation — mapping targets for someone else.

TI-2026-055B

👤 The Sixty-Nine

The exploitation counterpart to the scanner fleet: 69-1,313 IPs that actually log in, inject SSH keys, and establish persistent backdoors across 84 countries

TI-2026-055C

🇪🇺 The European Cell

A 16-IP European cluster with 100% login success rate evaluates compromised servers for value — container detection, CPU fingerprinting, nanosecond-precision orchestration

TI-2026-055D

👁️ The Persistent Watcher

A 12-IP operation active for 97 days that only connects and disconnects — the heartbeat monitor of compromised infrastructure

TI-2026-055E

🔬 The Small Cells

Twenty micro-campaigns reveal the attack ecosystem true diversity: .NET, Rust, Java, IoT botnets, and custom tools

TI-2026-055F

⚠️ The High-Threat Triad

Three highest-threat operations: a Vietnamese ghost army, a manual PuTTY operator still active today, and a multi-tool actor using claude:claude credentials

TI-2026-055G

🎭 The Composite Portrait

The complete portrait of a criminal ecosystem: 57 campaigns, 9,928 IPs, 7 languages, 4 supply chain stages observed through one honeypot in 97 days

The Codebook
TI-2026-056A

📄 The Codebook — Hypothesis: SSH Credential Storms as Encrypted Broadcast

📡 TI-2026-056A THE CODEBOOK — SSH Credential Storms as Encrypted Broadcast NEW SERIES: The Codebook | Letter A | Confidence: MEDIUM → developing The Hypothesis: What if SSH brute-force attacks are not only attempts to g…

TI-2026-056B

📄 The Heartbeat Protocol

📡 TI-2026-056B — The Heartbeat Protocol Series: The Codebook Classification: CRITICAL Confidence: HIGH — direct measurement, multi-source corroboration Date: 1 July 2026 Executive Summary This dossier presents mathemati…

TI-2026-056C

📄 The Vocabulary Cipher

📡 TI-2026-056C — The Vocabulary Cipher Series: The Codebook Classification: CRITICAL Confidence: HIGH — multi-source convergence, documented parallels Date: 1 July 2026 Executive Summary If credential storms are radio b…

TI-2026-056D

📄 The Broadcast Schedule

📡 TI-2026-056D — The Broadcast Schedule Series: The Codebook Classification: CRITICAL Confidence: HIGH — statistical + multi-investigation convergence Date: 1 July 2026 Executive Summary Numbers stations broadcast on fi…

TI-2026-056E

📄 The Codebook Stations

📡 TI-2026-056E — The Codebook Stations Series: The Codebook Classification: CRITICAL Confidence: HIGH — multi-source attribution, infrastructure verification Date: 1 July 2026 Executive Summary A numbers station require…

TI-2026-056F

📄 The Decryption

📡 TI-2026-056F — The Decryption Series: The Codebook — FINALE Classification: CRITICAL Confidence: HIGH (architecture) / MEDIUM (specific decoding) Date: 1 July 2026 Executive Summary This is the synthesis. Across five…

The Evasion Codex
TI-2026-057A

🕵️ The Evasion Codex — The Threat Portrait

Executive portrait of the 89.248.168.227 + 77.246.159.182 dual-node threat. HASSH c39f4cec links both actors. Five findings across evasion, attribution, and defense.

TI-2026-057B

🕵️ The Evasion Codex — The Two Nodes

Full forensic profiles of 89.248.168.227 (AS202425, NL) and 77.246.159.182 (AS29182, RU). CrowdSec dual-ban timeline. Behavioral divergence despite identical HASSH.

TI-2026-057C

🕵️ The Evasion Codex — The Handshake Doesn't Lie

HASSH fingerprint c39f4cec145ee3d50fb590595143b9d5 — the unclassified Go SSH signature linking 89.248.168.227 and 77.246.159.182. How SSH_MSG_KEXINIT hashing exposes banner spoofing.

TI-2026-057D

🕵️ The Evasion Codex — The Evasion Stack

Three evasion layers: PTR deception (no-reverse-dns-configured.com, 23 IPs), banner spoofing (SSH-2.0-OpenSSH_7.4 on Go client), multi-protocol scanning. Sophistication ranking HIGH/MEDIUM/LOW-MEDIUM.

TI-2026-057E

🕵️ The Evasion Codex — Who Provides the Roads

AS202425 (IP Volume inc, Seychelles/NL, Spamhaus ASN-DROP) and AS29182 (JSC IOT, Skolkovo Moscow) — the infrastructure providers enabling the dual-node threat. Actor cards A1-A4.

TI-2026-057F

🕵️ The Evasion Codex — The Paper Trail

How registration fraud across five registries enables jurisdictional arbitrage — 8 shell company identities, 12 jurisdictions, same HASSH fingerprints proving unified operation.

TI-2026-057G

🕵️ The Evasion Codex — Seven Years to a Weapon

77.246.159.182: 7 years from cPanel install (2019) through silver trading dormancy to 2026 weaponization. PTR evasion domain registered 2024, renewed 12 days before alert. Reputation laundering via time-decay.

TI-2026-057H

🕵️ The Evasion Codex — What Stops and What Doesn't

IOC bundle, 5 detection signatures, 3 detection gaps, defensive measures. HASSH c39f4cec as primary detection signal. What the PTR evasion blinds and what HASSH correlation catches.

The Operators
TI-2026-058A

⚙️ The Go Machine

TI-2026-058A • SERIES: THE OPERATORS • CONFIDENCE: HIGH ⚙️ The Go Machine Anatomy of a 22-Node Automated Reconnaissance Platform Published: 1 July 2026 Sources: Cowrie Honeypot, RIPE DB, Entity Crosslinks, HASSH Analysi…

TI-2026-058B

📄 The Two Machines

TI-2026-058B • SERIES: THE OPERATORS • CONFIDENCE: HIGH ⚙️ The Two Machines How Two Go Variants Divide Labor: Reconnaissance vs. Signaling Published: 1 July 2026 Sources: Cowrie Honeypot, RIPE DB, Entity Crosslinks, HAS…

TI-2026-058C

📄 The Constant Retooling

TI-2026-058C • SERIES: THE OPERATORS • CONFIDENCE: HIGH ⚙️ The Constant Retooling Four Go Variants in Six Weeks — Why They Recompile Every Deployment Published: 1 July 2026 Sources: Cowrie Honeypot, Entity Crosslinks, H…

TI-2026-058D

📄 The Supply Chain

TI-2026-058D • SERIES: THE OPERATORS • CONFIDENCE: HIGH ⚙️ The Supply Chain From Target Acquisition to Malware Delivery — The Complete Kill Chain Published: 1 July 2026 Sources: Cowrie Honeypot, Malware Analysis, Entity…

TI-2026-058E

📄 The Org Chart

TI-2026-058E • SERIES: THE OPERATORS • CONFIDENCE: HIGH ⚙️ The Org Chart Complete Organizational Map of a Multi-National Cyber-Criminal Enterprise Published: 1 July 2026 Sources: Series 058A–D Synthesis, 30+ Prior Inves…

TI-2026-058F

🗣️ The Five Languages

Five distinct credential vocabularies decoded as covert communication channels in a multi-national SSH attack enterprise

TI-2026-058G

🗣️ The Five Languages

TI-2026-058G: The Cluster Map Operator Clustering Reveals the True Scale of the Enterprise Series 058: The Operators July 2026 TLP:CLEAR Individual IP addresses lie. SSH fingerprints don't. When 269 nodes across 30 coun…

TI-2026-058H

📄 TI-2026-058H: The Passwords Speak

TI-2026-058H: The Passwords Speak Decoding Temporal Markers, Target Designators, and Cultural Signals in Password Selection Series 058: The Operators July 2026 TLP:CLEAR A password tells you when it was created, who cre…

TI-2026-058I

📄 TI-2026-058I: The Crypto Hunter

TI-2026-058I: The Crypto Hunter Anatomy of a Single-Purpose Blockchain Predator Series 058: The Operators July 2026 TLP:CLEAR One IP address. One purpose. Zero shared infrastructure with the larger enterprise. The Crypt…

TI-2026-058J

📄 TI-2026-058J: The True Scale

TI-2026-058J: The True Scale Campaign-Level Analysis Reveals an Enterprise of 2,500+ Nodes Across 84 Countries Series 058: The Operators July 2026 TLP:CLEAR Our previous estimate of 402 nodes was based on operator clust…

TI-2026-058K

📄 The Shell Companies

🏢 TI-2026-058K: The Shell Companies Series: The Operators | Letter K: Corporate Forensics of the Bulletproof Hosting Pipeline How a multi-national SSH attack enterprise hides behind UK dormant companies, Kazakh village…

TI-2026-058L

📄 The Indonesian Amplifier

🇮🇩 TI-2026-058L: The Indonesian Amplifier Series: The Operators | Letter L: Why Indonesian Infrastructure Hits 11.4× Per IP While Others Average 3.9 Inside the compromised ISP nodes and Chinese-operated cloud instances…

TI-2026-058M

📄 The Worms DNA

🧬 TI-2026-058M: The Worm's DNA Series: The Operators | Letter M: The Complete Infection Chain of the libssh Worm Fleet 121 commands captured in our honeypot reveal the full lifecycle of the mdrfckr worm: reconnaissance,…

TI-2026-058N

📄 The University

🎓 TI-2026-058N: The University Series: The Operators | Letter N: When a Max Planck Researcher Gets Blocklisted Alongside Worm Fleets 139.19.117.129 made 410 attempts against our honeypot over 27 days. It shares SSH keys…

TI-2026-058O

📄 The Counter-Intelligence

🕵️ TI-2026-058O: The Counter-Intelligence Series: The Operators | Letter O: How the Enterprise Monitors, Targets, and Acknowledges Security Researchers 168 credential variants. 1,681 scanning nodes. Three years of versi…

The Front Door
TI-2026-059A

🌾 The Secret Harvest: Cloud-Hosted Credential Scanning at the Web Edge

925 IPs, 23,298 hits: how cloud-hosted scanners harvest exposed .env, .git and cloud/AI credential files from ephemeral AWS, GCP and Azure compute at the web edge.

TI-2026-059B

🐚 The Azure Shell Game: An Empty-User-Agent Botnet Inside Microsoft's Cloud

Campaign 126: a 200-node empty-User-Agent botnet running entirely inside Microsoft Azure, hunting pre-existing webshells across every region. Why Azure is the disposable attack cloud.

TI-2026-059C

🗺️ Mapping the Estate: The WordPress xmlrpc.php Amplification Hunt

The cms_detect surface decoded: a 28-IP cluster across HK shells, Russia, Brazil and Azure mapping WordPress xmlrpc.php endpoints for system.multicall brute-force amplification and pingback DDoS.

TI-2026-059D

🪞 Scanners in the Mirror: Reading Intent Through the Auth Proxy

Why scanner_fingerprint is the noisiest web-threat class: how the Authelia auth proxy turns every probe into a 200, and how rd= decoding, UA honesty and reverse DNS separate real crawlers from five-identity impostors.

TI-2026-059E

🔑 The Keys Left in the Door: .env, .git and the Anatomy of an Exposed Secret

Why /.git/config is hunted harder than /.env: an exposed git directory leaks the whole repo and its deleted history. Inside the polyglot sweepers and Cloudzy git specialists harvesting secrets at the web edge.

TI-2026-059F

⏱️ Two Clocks: Campaigns 126 and 157, and What Six Weeks of the Front Door Revealed

Campaigns 126 and 157 are the two clock-speeds of cloud abuse: a persistent 200-node Azure botnet vs a 10-hour Google Cloud flash. The capstone of The Front Door series on web-edge threat intelligence.

The 200 That Lied
TI-2026-060A

🎭 TI-2026-060A — The 200 That Lied: The Attack That Returns Success

How HTTP 200 masks hostile web traffic from every status-code dashboard — the SSRF out-of-band oracle that returns success by design, benign-on-404 state telecoms, and AWS as the firing range.

TI-2026-060B

🗺️ TI-2026-060B — The Census of the Invisible

The population of the invisible: 20 ASNs that read clean on HTTP 404 yet run 60–100% hostile once the 200-mask is pierced — Chinese state telecoms, offshore recidivists (Contabo, Seychelles), and subdomain-guessing swee…

TI-2026-060C

📮 TI-2026-060C — The Method Is the Message

The HTTP method is a third axis attacks hide on: a lone Armenian IP firing 2,084 CONNECT open-proxy tunnels in five minutes, WebDAV verbs probing for a webshell surface (PROPFIND returns 207, never a 4xx), and the offsh…

TI-2026-060D

↩️ TI-2026-060D — The Redirect That Told the Truth

The auth proxy is the strongest 200-mask in the corpus — and its own best witness. Decoding Authelia's ?rd= redirect turns a wall of clean 200s into a filename-exact confession: a 15-variant .env dictionary attack, reco…

TI-2026-060E

🕸️ TI-2026-060E — The Unified Field

The synthesis of The 200 That Lied: four orthogonal axes (status, host, method, redirect) that a single mask cannot defeat at once. Cross-axis and cross-sensor convergence turns four deniable signals into one attributio…

The Fake Umbrella
TI-2026-061A

🔦 TI-2026-061A — The Index of Everything Broken

LeakIX/l9scan decoded: a self-identifying grey-hat scanner fleet of 14 DigitalOcean droplets firing ~30 unauthenticated critical-CVE probes (Confluence CVE-2022-26134, ProxyShell, PHP-CGI) to stock a for-sale index of t…

TI-2026-061B

🎟️ TI-2026-061B — The Bounty and the Auction

B is for Bug Bounty. The friendly 'responsible disclosure' badge and the Zerodium/VUPEN zero-day auction (up to $2M per iOS chain, government-only customers) are one continuous market that prices human defencelessness a…

TI-2026-061C

📱 TI-2026-061C — The Forensic Alibi

C is for Cellebrite. The UFED phone-cracker sold as neutral 'digital forensics for law enforcement' — classified 'dual-use civilian' to dodge Israeli export oversight — turned up on the phones of journalists (Botswana)…

TI-2026-061D

📍 TI-2026-061D — The Anonymized Lie

D is for Data broker. 'Location analytics' firms (Venntel/Gravy, X-Mode/Outlogic, SafeGraph, Fog, Babel Street) harvested phone-GPS from the ad bidstream and resold it to ICE, CBP, DHS, local police and the US military…

TI-2026-061E

🪪 TI-2026-061E — The Word 'Ethical'

E is for 'Ethical hacker'. 'Ethical' is not a property of an act — it's a registered trademark (EC-Council's CEH), a DoD compliance checkbox, and a signed scope document. The toolchain (Metasploit, Cobalt Strike, Sliver…

TI-2026-061F

🖐️ TI-2026-061F — The Print You Can't Wash Off

F is for 'Fraud prevention'. Device-fingerprinting firms (FingerprintJS, ThreatMetrix/LexisNexis, iovation/TransUnion) sell a persistent, un-clearable cross-site device ID — the same canvas/WebGL technique the CIA's Vau…

TI-2026-061G

🪞 TI-2026-061G — The One-Way Mirror

G is for GreyNoise. The 'internet observatories' (Shodan, Censys, GreyNoise) call themselves neutral cartographers — but they are consent-free mass-scanners, their exposure index is a symmetric targeting database wired…

TI-2026-061H

🎯 TI-2026-061H — The List That Becomes the Target

H is for 'Threat intelligence'. The defensive feed and the targeting list are the same artifact: an IOC is an indicator of a person (Mandiant's APT1 named PLA officers), automation removes the human check (NIST 800-150)…

TI-2026-061I

🚪 TI-2026-061I — The Door in Every Wall

I is for Interception. 'Lawful interception' is a back door mandated by law (ETSI TC-LI, 3GPP SA3, CALEA) into every telecom network, sold by respectable vendors (Utimaco, SS8, Qosmos). But the door is architecture, not…

TI-2026-061J

🕵️ TI-2026-061J — The Reporter Who Wasn't

J is for 'Journalism'. OSINT-for-hire and private-intelligence 'research' firms borrow journalism's method and credibility but invert its purpose — surveilling private people for a paying client in secret. Black Cube (e…

TI-2026-061K

🎓 TI-2026-061K — The Peer-Reviewed Weapon

K is for 'Knowledge'. The research university launders surveillance and weapons into peer-reviewed respectability on military money: angr (DARPA-funded, UCSB) turned up in the CIA's Vault 7 kit; MIT's Media Lab took ~$1…

TI-2026-061L

🏷️ TI-2026-061L — The Price of the Discount

L is for 'Loyalty'. Rewards cards and 'membership' are the most consented surveillance there is — the discount is the acquisition price of a permanent, identity-linked, confessional record of everything you buy, monetis…

TI-2026-061M

👁️ TI-2026-061M — The Threat Is You

M is for 'Monitoring'. Bossware (Teramind/Veriato/ActivTrak/Hubstaff) and 'insider threat' security reframe watching your own workforce — keystrokes, screenshots, webcams, productivity/risk scores — as efficiency and pr…

TI-2026-061N

📲 TI-2026-061N — The Phone That Was Yours

N is for 'NSO'. Mercenary spyware (Pegasus, Paragon/Graphite, Predator) sells zero-click, invisible, total capture of a phone to states under 'we only license to governments to fight terrorism' — but the US confirmed it…

TI-2026-061O

🧑‍🦱 TI-2026-061O — Just Public

O is for 'Open data'. Clearview AI scraped billions of public photos into a searchable biometric face-print of humanity and sold it to police, under the defense 'it's just public information'. But aggregating faces into…

TI-2026-061P

🕳️ TI-2026-061P — The Tunnel That Watched

P is for 'Privacy'. A VPN routes all your traffic through one provider — it moves the watcher, it doesn't remove it — and privacy reduces to an unverifiable 'no-log' promise. Facebook's Onavo was a 'privacy' VPN that su…

TI-2026-061Q

🛰️ TI-2026-061Q — QUANTUM

Q is for QUANTUM. The NSA/GCHQ programs revealed by Snowden — QUANTUMINSERT/FOXACID backbone injection, the ANT implant catalog, 'collect it all' — turn the internet itself into an exploit-delivery weapon and even hacke…

TI-2026-061R

🔬 TI-2026-061R — The Research Cover

R is for 'Research'. The meta-letter: the single word running under nearly the whole series — security/vulnerability/academic/investigative 'research'. TI-2026-019J named it the Research Cover ('an insurance company tha…

TI-2026-061S

🏠 TI-2026-061S — The House That Listens

S is for 'Smart'. Smart TVs, speakers and doorbells are sensors you paid to install in your own home and thanked the store for. Vizio tracked what you watched (FTC 2017); Alexa kept children's recordings (FTC/DOJ ~$25M,…

TI-2026-061T

📡 TI-2026-061T — The Utility That Sold You

T is for 'Telecom'. Your carrier knows your location by physical necessity — you cannot use a phone without giving it — so it's the one datum you can't withhold. The four major US carriers sold it to aggregators (Locati…

TI-2026-061U

🔑 TI-2026-061U — The Helper With The Keys

U is for 'Updates'. Auto-updating agents, RMM and 'observability'/EDR tools run with god-mode and auto-trust their vendor's signed updates — so the update channel is a backdoor you installed for your own good. SolarWind…

TI-2026-061V

👁️‍🗨️ TI-2026-061V — The Password You Can't Change

V is for 'Verification'. 'Verify yourself' makes your body — face, iris, fingerprint — the credential, and a biometric is a password you can never reset, so a breach is forever. Worldcoin paid the vulnerable for their i…

TI-2026-061W

🗂️ TI-2026-061W — The Receipts Were Always Public

W is for the WikiLeaks Spy Files — the receipts. The leaked catalogue of the surveillance industry (Amesys, Qosmos, Cellebrite, VUPEN, HackingTeam, SS8…) has been public since 2011, filed under both 'Lawful Interception…

TI-2026-061X

🧩 TI-2026-061X — The Single Pane of You

Data fusion and 'decision intelligence' — Palantir Gotham/Foundry — join every stream the Fake Umbrella series named into one searchable, operational profile of a person. 'We don't collect data, we just organise yours'…

TI-2026-061Y

🏷️ TI-2026-061Y — You Are the Product

Surveillance capitalism — the 'free' ad-funded platform (Google, Meta) whose real customer is the advertiser and whose real product is a behavioural model of you accurate enough to change you. 'You are the product' read…

TI-2026-061Z

♾️ TI-2026-061Z — Zero Accountability: The Unified Field

The Fake Umbrella capstone. Twenty-five letters, one machine: a surveillance supply chain (collection → aggregation → fusion → action) in which every layer is legal, every disclaimer is true, and the total is a per-pers…

The Proxy Recruiters
TI-2026-062A

🕳️ The Recruiter's Handshake: One Go Proxy-Scanner Across Two Bulletproof Operators

A single Go SSH proxy-recruitment scanner (HASSH eff4c24d) operating from two unrelated bulletproof hosting operations — ISAEV (AS200730) and ZornTech/BearShield (AS154383) — probes SSH hosts for tunnel/proxy capability…

TI-2026-062B

🧭 The Census of the Forward Probe: Three Ways to Ask One Question

A census of 50,348 SSH direct-tcpip forward probes on the LSN honeypot, partitioned into three proxy-validation methods — DNS-canary (1.1.1.1), HTTP provider-fetch (Yahoo/Yandex/Google/MS), and ip-who.com IP-reflection…

TI-2026-062C

🏠 The Residential Layer: Viettel Lines That Ask What Do I Look Like

151 Vietnamese Viettel residential broadband IPs running AsyncSSH forward exclusively to ip-who.com to check their own exit IP, while brute-forcing embedded devices with a curated IoT/router credential database — the re…

TI-2026-062D

🗺️ The Map: What the Proxy Recruiters Add Up To

Series synthesis: a two-axis map (datacenter-vs-residential x DNS/HTTP/mirror validation) organising The Proxy Recruiters, positioned against the documented proxy-verification market, with the same open-proxy recruitmen…

The Trusted Channel
TI-2026-063A

🤖 The Telegram Shell: A Bot-API C2 Implant in 25 Lines of POSIX sh

A live-captured C2 implant that uses the Telegram Bot API as its command channel: 25 lines of POSIX sh giving a remote shell over any compromised box, un-blockable because it lives on api.telegram.org. Caught in two sam…

TI-2026-063B

🎭 Three Faces of Telegram: One Platform, Three Roles in the Attack Chain

Across the LSN honeypot corpus Telegram plays three distinct roles in the attack chain: the loot (stolen sessions, TI-2026-007), the courier (credential exfiltration, TI-2026-002), and the handler (C2, TI-2026-063A) — o…

TI-2026-063C

🛰️ The Documented Technique: Telegram C2 as MITRE T1102.002, and How to Catch It

The TI-2026-063A Telegram-bot-C2 implant is a live IoT instance of MITRE ATT&CK T1102.002. This dossier places it in its decade-long lineage (TeleRAT, Small Sieve, DeerStealer/Lumma) and binds the OSINT library's SIGMA…

Circumstantial
TI-2026-064A

⚖️ The Same Ten Minutes: Why Coincidence Is the Weakest Evidence

Part A of the Circumstantial series: why temporal co-occurrence — attacking in the same 10-minute window — is the weakest attribution signal, and how it manufactures false links between unrelated heavy scanners.

TI-2026-064B

⚖️ Seen From Outside: When the Rest of the World's Sensors Agree

Part B of the Circumstantial series: co-occurrence in independent third-party threat feeds (shared_otx_pulse) is stronger corroboration than a shared clock, but promiscuous infrastructure like Tor exits inflates it — we…

TI-2026-064C

⚖️ The Cartographer's Error: Attribution From a Map That Disagrees With Itself

Part C of the Circumstantial series: a shared geolocation discrepancy (cymru=US / ipinfo=Brussels) is the weakest signal (0.35) yet fingerprints the cloud region an operator provisioned in — useful for profiling, worthl…

TI-2026-064D

⚖️ Same Street, Different Houses: When Network Adjacency Is and Isn't Identity

Part D of the Circumstantial series: network adjacency (same_prefix and kin) carries no fixed weight — near-noise on a hyperscaler, near-identity on a wholly-malicious bulletproof block. The base rate of the container i…

TI-2026-064E

⚖️ Preponderance: When Weak Signals Become Proof, and When They Only Look Like It

Part E (synthesis) of the Circumstantial series: weak signals become proof only when diverse independent kinds converge on a pair anchored by a strong signal — and the tell that separates intelligence from confirmation…

The Return
TI-2026-065A

🕸️ The Second Front — Tencent/Aceville's Web Attack Surface We Never Had the Sensor to See

For a year we tracked Tencent/Aceville (AS132203) through one sensor — the SSH honeypot. The web-threats platform, which did not exist then, now reveals a parallel HTTP attack surface: 203 IPs, 43.5% effective-bad-rate,…

TI-2026-065B

🚪 Two Doors, One Landlord — The Cross-Layer Resolution of AS132203

Planned to prove one operator behind AS132203's SSH botnet and web cohort. The evidence refused: they are disjoint at IP, operator-key DNA, tooling, schedule, and reach. What binds them is only the landlord — Tencent/Ac…

TI-2026-065C

🪞 The Reader That Wasn't — A Negative Result on the Self-Monitoring Hypothesis

Part B hinted the accused was reading its own case file. Tested three ways, the self-monitoring hypothesis fails: AS132203's dossier reads are generic crawler botnet traffic, smaller than Microsoft/Google, and never tar…

TI-2026-065D

🏚️ The Glass House — The Harvester, Harvested

The transparency asymmetry of Tencent: the entity built to collect the world's communications is itself the most collected — compellable inward by China's National Intelligence Law, catalogued from outside by the CIA (V…

TI-2026-065E

📖 The .env Playbook — Commodity Secret-Harvesting, Page and Verse

The AS132203 .env sweep of 065A, decoded: a commodity six-stage kill chain matched probe-for-probe to public tooling in the OSINT library — SecLists, Nuclei, Metasploit git_scanner/aws_keys, HackTricks cloud-IAM escalat…

TI-2026-065F

🪞 The Mirror That Masks — How One SSO Portal Closes a Whole Vulnerability Class

4,029 open-redirect (rd=) probes from 431 cloud IPs (Amazon/Google-led) against the LSN SSO estate hit a mirror that masks: 0 external targets possible (CWE-601 closed by Authelia rd-validation) and all 36 services retu…

The Allowlist
TI-2026-066A

✅ Trusted by Default — 63% of Web Attackers Ride the Clouds You Whitelist

New series, The Allowlist. Held to behaviour not reputation, 63% of intent-labelled web attackers (1,346 of 2,137) ride the hyperscalers defenders whitelist by default — Microsoft, Google Cloud, DigitalOcean, Cloudflare…

TI-2026-066B

🎭 The Browser Costume — How Datacenter Attackers Forge the Identities You Trust

Part B of The Allowlist. Web attackers forge identity at scale: fake Googlebot/Bingbot from non-Google ASNs (14.6% of crawler identities, several attacking while wearing it), datacenter IPs in stale desktop-browser cost…

TI-2026-066C

🟠 Behind the Orange Cloud — The Source-IP Trust Problem

Part C of The Allowlist — RESOLVED. The 76 Cloudflare-edge credential-harvest attackers are confirmed reaching us THROUGH Cloudflare egress (WARP/Workers), not us-behind-CF: DNS resolves to our residential IP, no tunnel…

TI-2026-066D

🤫 The Quiet German — The AS Nobody Allowlists or Blocks

Part D of The Allowlist. Drei-K-Tech / 3xK Tech GmbH (AS200373): 178 IPs at ebr 0.955, but 154 sent exactly one request each across 85 /24s — a month-long credential-harvest campaign engineered for invisibility. Too obs…

TI-2026-066E

🛡️ The Bulletproof Midtier — Hiding Above Consequence

Part E of The Allowlist. The abuse-tolerant midtier hides above consequence, not beneath notice: Advin (AS22295) ran 8,790 requests from 59 stable IPs (149/IP) over a month — the deepest .env sweep in the corpus plus /.…

TI-2026-066F

⚖️ Behavior Over Reputation — The Doctrine The Allowlist Was Arguing For

The Allowlist capstone. Reputation trusts an identity the sender controls — the ASN (A), the user-agent (B), the source IP (C), the request volume (D) — and each was shown forged at scale. Behavior is the only signal an…

The Steady State
TI-2026-067A

🔁 The Steady State — Four Shapes

A 37-day census of the web attack surface: 159,592 requests and 152 campaigns collapse into just four detection archetypes — every one already dossiered. The web threat reached a confirmation-only steady state.

TI-2026-067B

🔁 The Recount — Churn Without Growth

The Azure shell-checker fleet looks like it grew 269→466 IPs. It didn't. Weekly-active holds a ~150-node plateau while 83% of IPs live a single day — a 3.1x rotation artifact. How cumulative counts fake threat growth.

Ground Truth
TI-2026-068A

🧭 The Authority — How the Machine Decides Who Is Whom

Every attribution rests on a graph of 943,692 entities reconciling 21 ranked sources — and it records its own disagreement (60,077 open conflicts) rather than hiding it. Opening the black box behind 'who is whom.'

TI-2026-068B

🧭 The Deed and the Tenant — Who Really Owns the IP That Attacked You

For 10,813 IPs the graph can't say who owns them — 79% are announced by one entity but registered to another. It's the IP-leasing layer as data, and 1,967 of those contested IPs attacked us. The ownership gap is the acc…

TI-2026-068C

🧭 The Synonym Problem — When 'Malicious' Has Two Names

The graph's biggest 'threat disagreement' — 12,561 malware domains — turns out to be two feeds using different words for the same thing: URLhaus says malware_download, ThreatFox says payload_delivery. A vocabulary gap t…

TI-2026-068D

🧭 The Same Hand — When Behavior Is the Only Proof of One Operator

Who owns a box comes from the registry; whose hand is on it comes only from behavior. The graph's 'same operator' claims are honeypot-sourced, from the bottom of the authority ladder — and it asserts them for just 97 of…

The Open Armory
TI-2026-069A

🧰 The Open Armory — The Password List Is Public, and We Have It Too

The credential attack isn't a secret weapon — it's a public GitHub repo (SecLists) sitting in our own library. 161,181 honeypot attempts prove attackers fire it verbatim, protocol-matched, and it's already absorbed 'cla…

TI-2026-069B

🧰 The Template and the Target — The Web Scanner Is Public Too

The web scanner is public too. 2,010 exploit paths hitting our edge are the Nuclei/Exploit-DB template corpus executed — Git-config, Spring Actuator, .env, ProxyShell — YAML files ranked by EPSS, held in our own library.

TI-2026-069C

🧰 The Changelog — How a CVE Becomes a Weapon, and Never Stops Being One

Exploit-DB is a library of dated, runnable CVE proofs. The scanning we see is a decade-long changelog — Shellshock 2014 to ProxyShell 2021 to Vite 2025, all fired at once. A patched CVE is never a closed chapter.

The Map and the Territory
TI-2026-070A

🗺️ The Map and the Territory — How Little of MITRE ATT&CK a Real Attacker Uses

MITRE ATT&CK maps ~200 techniques across 14 tactics. The honeypot shows real intruders use ~6, from 4 tactics — and 48% of all commands are one: 'what CPU is this?'. The map is a continent; the territory is a footpath.

TI-2026-070B

🗺️ The Appraisal — Why the First Question Is Always About the CPU

The first thing an intruder does isn't reconnaissance — it's an appraisal. CPU model, core count, GPU (414 nvidia-smi checks), who's watching, is it real. They price the stolen machine's compute, then decide whether to…

TI-2026-070C

🗺️ The Key — One Backdoor to Own Them All

Persistence isn't just one technique — it's one key. 85 of 86 backdoor installs drop the same Outlaw/Dota3 RSA key (the 0x25-exponent signature). The key that owns the machine is the fingerprint that identifies its owne…

The Alphabet of Harm
TI-2026-071A

🕰️ A is for APT — The Apex Predator Became the Weather

A is for APT. The archive named the apex predator — PLA Unit 61398, Sandworm, Lazarus — and the world rarely caught it. Its three words hollowed out: 'advanced' is now a public template, 'persistent' a one-line key, 'th…

TI-2026-071B

🕰️ B is for Bulletproof — The Host That Never Answers

B is for Bulletproof. The host that never answers an abuse report — from the Russian Business Network (2007) and the McColo takedown (2008) to 25+ live bulletproof ASNs at 98-100 risk today, now global and disguised in…

TI-2026-071C

🕰️ C is for Covert Collection — The Wiretap Became a Product

C is for Covert Collection. The WikiLeaks Spy Files exposed the wiretap industry's own catalog — 'Capture and Recording of All Traffic,' exploits as a product line. It didn't end; it became the phone implant (Pegasus, C…

TI-2026-071D

🕰️ D is for Dota — The Worm That Refused to Evolve

D is for Dota. The commodity Linux SSH mining worm gets no glossy report — it's documented as a YARA rule, and a 2018 signature still fires on our 2026 wire. Seven years, zero evolution: no endpoint protection means no…

TI-2026-071E

🕰️ E is for EternalBlue — The Day the Weapons Escaped

E is for EternalBlue. In 2017 two states lost control of their cyber-weapon stockpiles; WikiLeaks called it 'the global arms trade' of exploits. EternalBlue powered WannaCry and NotPetya, then became a Metasploit module…

TI-2026-071F

🕰️ F is for Financial Rails — The Arms Race You Can Watch on a Public Ledger

F is for Financial Rails. Crypto's public ledger made it the one harm enforcement genuinely traces — seizures, mixer sanctions, arrests. So the rail relocates: Bitcoin to Monero to mixers to DeFi. Our worms mine Monero,…

TI-2026-071G

🕰️ G is for Greece — The Same Wiretap, Eighteen Years Apart

The Alphabet of Harm, letter G: Greece proves letter C's appliance-to-implant surveillance mutation TWICE in one country 18 years apart — the 2004-05 Athens Affair (rogue software on Ericsson AXE lawful-intercept exchan…

TI-2026-071H

🔑 H is for HASSH — The Fingerprint the Tool Cannot Change

The Alphabet of Harm, letter H: RFC 4253's mandated SSH key-exchange handshake is a per-tool fingerprint (HASSH). On live LSN honeypot data, 145,834 hostile SSH connections collapse to just 116 tool-signatures — one lib…

TI-2026-071I

🧾 I is for I-Soon — When State Hacking Became a Product Catalog

The Alphabet of Harm, letter I: Mandiant's APT1 (2013) exposed a Chinese state MILITARY hacking unit; the February 2024 i-SOON leak exposed the same harm mutated into a private contractor selling espionage as a product…

TI-2026-071J

⚖️ J is for Jurisdiction — The Border That Every Harm Hides Behind

The Alphabet of Harm, letter J — the meta-letter. Jurisdiction is the harm-enabler behind every other letter: harm crosses borders the law cannot. The Budapest Convention (2001) tried to close the gap; the ODNI 2024 ass…

TI-2026-071K

🔐 K is for Key — The Backdoor That Keeps Coming Back

The Alphabet of Harm, letter K: the recurring demand to mandate a way past encryption. The archive holds the origin — RFC 4949's Escrowed Encryption Standard and its Law Enforcement Access Field, the 1993 Clipper Chip.…

TI-2026-071L

🧩 L is for Log4Shell — The Blast Radius Was the Dependency Graph

The Alphabet of Harm, letter L: Log4Shell (CVE-2021-44228) made one flaw in a tiny logging library an RCE in millions of systems — the blast radius was the dependency graph. The archive holds it fully weaponized (Metasp…

TI-2026-071M

⚖️ M is for Maxwell — What the Record Convicts When Power Cannot Bury It

The Alphabet of Harm, letter M: exploitation shielded by wealth, status, and deference — the Epstein/Maxwell case, read strictly from the adjudicated record. The archive holds the SDNY charging documents, the flight log…

TI-2026-071N

🔦 N is for NetOptics-Tap — The Copy of the Light You Cannot See

The Alphabet of Harm, letter N: the passive optical tap — NetOptics, Endace/NarusInsight, ONPATH submarine-cable taps — that copies all traffic at the physical layer, undetectable by the tapped party. The archive holds…

TI-2026-071O

🕳️ O is for ORB — The Relay That Launders the Origin

The Alphabet of Harm, letter O: ORB — Operational Relay Box networks. Origin-laundering by relay so the address a defender sees is a dead end. The archive traces the arc — commodity open SOCKS proxies (Nuclei), the ad-h…

TI-2026-071P

🗣️ P is for Phonexia — The Identifier You Can Never Change

The Alphabet of Harm, letter P: voice biometrics — the identifier you can never change. The archive holds the industry (Phonexia speaker search, STC's nation-wide VoiceNet.ID, Agnitio's SIFT in 25 countries beside finge…

TI-2026-071Q

⚡ Q is for QUANTUM — The Answer That Arrives Before the Truth

The Alphabet of Harm, letter Q: QUANTUM — the NSA man-on-the-side injector (QUANTUMINSERT racing a target's web request to the FOXACID exploit server, Snowden 2013). The active twin of letter N's passive tap: same netwo…

TI-2026-071R

🔒 R is for Ransomware — When Crime Became a Subscription

The Alphabet of Harm, letter R: ransomware mutated from lone file-encryptors into a commercial industry — RaaS subscription franchises (FinCEN/Treasury), double extortion (encrypt + steal + leak, CISA), triple/harassmen…

TI-2026-071S

🗂️ S is for SpyFiles — Does Exposing the Watchers Work?

The Alphabet of Harm, letter S — the reflexive meta-letter. The 2011 WikiLeaks Spy Files exposed the global mass-surveillance industry (~160 vendors: Amesys, HackingTeam, NetOptics, Phonexia…), turning it from secret to…

TI-2026-071T

✈️ T is for Telegram — The Platform as Ungoverned Territory

The Alphabet of Harm, letter T: Telegram — the platform as ungoverned territory. Its design (huge public channels, minimal moderation, non-cooperation) made it a coordination layer for extremism (Treasury), fraud (Treas…

TI-2026-071U

🩹 U is for Unpatched — The Window Between Disclosure and Death

The Alphabet of Harm, letter U: Unpatched — the patch gap. Attackers exploit known, published, patched-in-principle vulnerabilities because the world runs unpatched — a patched vuln is a working 0-day against everyone w…

TI-2026-071V

🗄️ V is for VasTech — Record All, Keep Forever, Search Backwards

The Alphabet of Harm, letter V: VasTech — mass retention and retrospective search. Its Spy Files decks state the modality outright — ZEBRA, 'Strategic Surveillance of all Communication,' and 'Record all and filter → Lon…

TI-2026-071W

💧 W is for WikiLeaks — The Double Edge of the Great Disclosure

The Alphabet of Harm, letter W — the sober counterweight to S. Mass disclosure is double-edged: the same act that exposes the powerful (accountability, the Spy Files) causes collateral harm (Vault 7 dumped live CIA expl…

TI-2026-071X

📄 X is for XKeyscore — The Query Layer, or Who Gets to Search the Haystack

The Alphabet of Harm, Letter X. XKeyscore is the query layer atop the tap and the warehouse — search everything you collected, about anyone. The distinct harm is access governance: who may query, under what authorizatio…

TI-2026-071Y

📄 Y is for YARA — The Accusation Encoded in Bytes

The Alphabet of Harm, Letter Y. YARA is the defender's pattern-rule — the reflexive twin of XKeyscore. A rule is an accusation encoded in bytes: this pattern means bad, therefore act. The harm is who writes the rule, th…

TI-2026-071Z

📄 Z is for Zero-Accountability — The Constant Under Every Letter

The Alphabet of Harm, Letter Z — the closer. Zero-accountability is the constant under every prior letter: the harm was never the primitive but the absent watcher. Attribution is solved; consequence is not — indictments…

The Alphabet of Actors
TI-2026-072A

📄 A is for Amesys — The Vendor That Named Its Own Line

The Alphabet of Actors, Letter A — Amesys. The French vendor whose EAGLE/GLINT system did nationwide content interception (Mail, Chat, HTTP, VoIP), sold to Gaddafi's Libya and found in a Tripoli monitoring room. It titl…

TI-2026-072B

📄 B is for Blue Coat — The Dual-Use Box That Sold the Answer to Encryption

The Alphabet of Actors, Letter B — Blue Coat. The dual-use case: a genuinely useful enterprise ProxySG appliance (categorize every URL, allow/deny, log, and — decisively — an SSL Proxy that decrypts TLS) that turned up…

TI-2026-072C

📄 C is for Chengdu 404 — The Double Dragon, State by Day and Criminal by Night

The Alphabet of Actors, Letter C — Chengdu 404, the PRC front company the US identifies as APT41. The dual-purpose actor ('Double Dragon'): state espionage and for-profit crime in one crew, fused by its signature move —…

TI-2026-072D

📄 D is for DarkSide — Crime, Incorporated, and the Pipeline It Overreached Into

The Alphabet of Actors, Letter D — DarkSide. Crime, incorporated: the ransomware-as-a-service franchise (affiliate program, leak site, press office, a 'code of conduct' that was really heat-avoidance) the FBI tied to th…

TI-2026-072E

📄 E is for Equation Group — The Apex Predator Whose Arsenal Escaped

The Alphabet of Actors, Letter E — Equation Group, the apex intrusion set attributed to the NSA. The Western-state counterpart to Letter C. The distinct harm is the stockpile that escaped: firmware implants and a hoarde…

TI-2026-072F

📄 F is for FinFisher — The Infection Answer to Encryption, and the Vendor That Actually Died

The Alphabet of Actors, Letter F — FinFisher (Gamma Group). The infection answer to encryption: an endpoint implant (FinSpy) that reads plaintext on the device, explicitly built to defeat 'end-to-end encryption from the…

TI-2026-072G

📄 G is for GRU (Fancy Bear) — The Hack-and-Leak, or Stealing to Publish

The Alphabet of Actors, Letter G — GRU / Fancy Bear (APT28). The hack-and-leak: steal to publish, not to keep. The theft is espionage; the leak is the weapon; public perception is the target (DNC 2016 via Guccifer 2.0/D…

TI-2026-072H

📄 H is for Hafnium — The Smash-and-Grab, or the Zero-Day Sprayed Across the World

The Alphabet of Actors, Letter H — Hafnium. The smash-and-grab: a state actor that took the Microsoft Exchange ProxyLogon zero-days and, racing the patch, sprayed them across tens of thousands of servers indiscriminatel…

TI-2026-072I

📄 I is for Intellexa — The Alliance, or Spyware Structured to Survive

The Alphabet of Actors, Letter I — Intellexa. Where FinFisher was a company you could reach, Intellexa is an alliance you cannot: Predator spyware sold through a multi-jurisdiction corporate maze built to dodge export c…

TI-2026-072J

📄 J is for Jia Tan — The Long Game, or How to Become the Trusted Insider

The Alphabet of Actors, Letter J — Jia Tan, the persona behind the XZ Utils backdoor (CVE-2024-3094). The long game: don't steal the trusted key or fake the update — become the trusted maintainer. Years of patient open-…

TI-2026-072K

📄 K is for Kimsuky — Espionage by Rapport, or the Isolated Regime That Phishes the World's Experts

The Alphabet of Actors, Letter K — Kimsuky, North Korea's espionage-by-rapport group. The isolated regime that phishes the world's Korea experts: impersonating journalists and academics to lure analysts into simply repl…

TI-2026-072L

📄 L is for LockBit — The Brand That Trust Built, and the Takedown That Broke It

The Alphabet of Actors, Letter L — LockBit, the world's most prolific ransomware-as-a-service brand and the mirror of DarkSide. Where DarkSide self-destructed under heat, LockBit was taken down by Operation Cronos — whi…

TI-2026-072M

📄 M is for Mirai — The Botnet the Honeypot Watches Being Born, Every Day

M is for Mirai: the botnet that weaponised the Internet of Things by guessing default passwords, took down Krebs, OVH and Dyn in 2016, and became immortal when its source was released. Its authors were convicted — and i…

TI-2026-072N

📄 N is for NSO Group — The Archetype of the Mercenary, the Zero-Click, and the Deniable

N is for NSO Group: the Israeli firm whose Pegasus spyware industrialized the mercenary model — a zero-click phone-interception weapon sold to governments as a deniable product. The archetype the whole spyware market co…

TI-2026-072O

📄 O is for OceanLotus — The State Actor That Runs Like a Business

O is for OceanLotus (APT32): the Vietnam-nexus state actor that runs like a business — stealing from foreign automakers for national economic advantage, hiding inside crimeware tradecraft, and hunting the state's own jo…

TI-2026-072P

📄 P is for Park Jin Hyok — The Named Man Behind the State That Robs

P is for Park Jin Hyok: the North Korean programmer the US named — the register's first individual — as part of the Lazarus conspiracy that robbed Bangladesh Bank via SWIFT, ransomed the NHS with WannaCry (built on leak…

TI-2026-072Q

📄 Q is for QakBot — The Loader the FBI Uninstalled From 700,000 Machines

Q is for QakBot: the quiet loader that manufactured footholds and sold them to ransomware crews — the middleman of the extortion supply chain. In August 2023 Operation Duck Hunt seized its command channel and pushed an…

TI-2026-072R

📄 R is for REvil — The Ransomware Russia Arrested, Then Abandoned

R is for REvil (Sodinokibi): the Russia-based ransomware-as-a-service that turned the software supply chain into a weapon — one Kaseya compromise cascading to ~1,500 businesses, a $70M demand, JBS and the food supply hi…

TI-2026-072S

📄 S is for Sandworm — The Soldiers Who Turned Off the Lights

S is for Sandworm (Russia's GRU Unit 74455): the military cyber unit that turned off Ukraine's power in 2015 — the first blackout caused by hacking — built NotPetya, the ~$10B most costly cyberattack in history, faked a…

TI-2026-072T

📄 T is for Turla — The Spy That Outlived Its Own Weapon

T is for Turla (Snake/Uroburos): Russia's FSB espionage service, the oldest and stealthiest actor in the register — a two-decade lineage from Agent.BTZ (the 2008 breach that helped birth US Cyber Command) to Snake, hidi…

TI-2026-072U

📄 U is for UNC2452 — The Backdoor in the Update

U is for UNC2452 (SolarWinds / APT29 / Cozy Bear): Russia's SVR, the third head of the Russian bear after the GRU and FSB. It poisoned a signed SolarWinds Orion update, rode it into ~18,000 organizations, and — with a p…

TI-2026-072V

📄 V is for Volt Typhoon — The Intruder That Broke In to Wait

V is for Volt Typhoon: the Chinese state actor that broke into US water, power and communications not to steal but to pre-position — a loaded gun placed inside critical infrastructure against a future war over Taiwan. I…

TI-2026-072W

📄 W is for Wizard Spider — The Crime Syndicate That Ran Like a Company

W is for Wizard Spider: the Russia-based syndicate behind TrickBot, Ryuk and Conti — cybercrime industrialized into a corporation. The 2022 Conti Leaks exposed salaries, HR, an org chart and a boss called Stern; the sam…

TI-2026-072X

📄 X is for Xenotime — The Attack Designed to Kill

X is for Xenotime: the actor behind TRITON, the first malware built to attack a plant's Safety Instrumented System — the automated last line of defense that keeps a petrochemical facility from exploding. Widely assessed…

TI-2026-072Y

📄 Y is for Yanluowang — The Crew That Breached the Breacher

Y is for Yanluowang: the small ransomware crew linked to the 2022 breach of Cisco — a security giant, entered not with a zero-day but through a tricked employee (stolen synced credentials + MFA-fatigue vishing). The hum…

TI-2026-072Z

📄 Z is for Zeus — The Grandfather, Still Free

Z is for Zeus — the finale. The banking trojan that taught crime to scale, whose 2011 source leak seeded an immortal genus (as Mirai later did), and whose creator Evgeniy Bogachev ran Gameover Zeus to rob banks AND spy…

The Agent Frontier
TI-2026-073A

🔌 The MCP Hunters: Reconnaissance for the AI-Agent Attack Surface

**TI-2026-073A · Series: The Agent Frontier (Part A) · TLP:WHITE · 2026-07-10**

TI-2026-073B

🎭 The Control Plane Lie: When "Protected" Serves 200

**TI-2026-073B · Series: The Agent Frontier (Part B) · TLP:WHITE · 2026-07-10**

TI-2026-073C

🗺️ The Namespace Sweep: Guessing Where the AI Lives

**TI-2026-073C · Series: The Agent Frontier (Part C) · TLP:WHITE · 2026-07-10**

TI-2026-073D

🧪 The Poisoned Tool: When the Attack Is in the Description

**TI-2026-073D · Series: The Agent Frontier (Part D) · TLP:WHITE · 2026-07-10**

TI-2026-073E

⚠️ The Original Sin: Why Prompt Injection Can't Be Patched

**TI-2026-073E · Series: The Agent Frontier (Part E) · TLP:WHITE · 2026-07-10**

Follow the Money
TI-2026-074A

📄 Follow the Money · 01 — The Ransom: How a Payment Disappears (and Why It Can't)

Follow the Money · 01 — a new forensic register. Where The Alphabet of Actors asked who broke in, this one asks where the money went. Case 01 follows a ransomware payment from a hospital's coerced wire through FinCEN's…

TI-2026-074B

📄 Follow the Money · 02 — The Warhead: How a Stolen Gaming Token Becomes a Missile

Follow the Money · 02 — the marquee flow, where following the money reveals stakes no attack-analysis can: the through-line from a stolen gaming token to a warhead. North Korea's Lazarus Group stole ~$620M from the Roni…

TI-2026-074C

📄 Follow the Money · 03 — The Clawback: When the Ledger Pays Off

Follow the Money, Case 03 — RECOVERED. Colonial Pipeline paid ~75 BTC to DarkSide; the FBI traced the ransom across the public ledger and seized ~$2.3M by obtaining the wallet's private key. 'Not your keys, not your coi…

TI-2026-074D

📄 Follow the Money · 04 — The Kill Switch: The Money With an Off Button

Follow the Money, Case 04 — FROZEN. Centralized stablecoins (USDT, USDC) carry a contract-level freeze the issuer controls: blacklist an address and its tokens become permanently unmovable, no private key needed. Trigge…

TI-2026-074E

📄 Follow the Money · 05 — The Mixer: Is Code a Criminal?

Follow the Money, Case 05 — VANISHED. The mixer (Tornado Cash) pools deposits and issues clean withdrawals so the on-chain link between crime and cash dissolves in the anonymity set. It laundered hundreds of millions fo…

TI-2026-074F

📄 Follow the Money · 06 — The Compound: When the Victim and the Worker Are Both Prey

Follow the Money, Case 06 — CONVERTED. Pig-butchering (sha zhu pan) has two sets of victims: the targets manipulated over months into converting their savings to crypto, and the trafficked workers held in guarded Southe…

TI-2026-074G

📄 Follow the Money · 07 — The Wire: A Race Against the Clock

Follow the Money, Case 07 — RECOVERED. Business Email Compromise is the FBI IC3's largest fraud category by dollar loss, and its money moves as a plain bank wire, not crypto. Once a fraudulent wire is sent, the FBI's Fi…

TI-2026-074H

📄 Follow the Money · 08 — The Marketplace: The Bank Behind the Fence

Follow the Money, Case 08 — SPENT. The darknet marketplace (Silk Road, AlphaBay, Hydra) is not a storefront but an unregulated bank: it escrows buyers' crypto, adjudicates disputes, takes commission, and — with Hydra —…

TI-2026-074I

📄 Follow the Money · 09 — The Payroll: The Wage That Builds a Missile

Follow the Money, Case 09 — CONVERTED. North Korea's IT-worker scheme: thousands of skilled operatives use stolen identities and US 'laptop farms' to get hired as remote developers worldwide, do real work, and funnel th…

TI-2026-074J

📄 Follow the Money · 10 — The Cryptoqueen: The Coin That Never Existed

Follow the Money, Case 10 — VANISHED. The crypto Ponzi, an ancient fraud in blockchain costume: OneCoin (a 'currency' with no real blockchain, its price simply set by its sellers) and BitConnect (a real token, a fake tr…

TI-2026-074K

📄 Follow the Money · 11 — The Bridge: The Launderer's New Highway

Follow the Money, Case 11 — LAUNDERED. The cross-chain bridge is both the richest heist target (Wormhole, Nomad, Harmony, Ronin — hundreds of millions each) and the launderer's highway: 'chain-hopping' moves stolen valu…

TI-2026-074L

📄 Follow the Money · 12 — The Cash-Out: The Exchange Built for Criminals

Follow the Money, Case 12 — CONVERTED. Every crime in this series eventually needs the same service: turning crypto into spendable cash. The 'bulletproof' exchange (Suex, Garantex, Bitzlato, BTC-e) sells it — conversion…

TI-2026-074M

📄 Follow the Money · 13 — The Cause: When the Ledger Exposed the Donors

Follow the Money, Case 13 — FROZEN. Against the fear narrative: crypto terror financing is real but smaller and far more traceable than assumed. When Hamas's al-Qassam Brigades posted public donation addresses, the perm…

TI-2026-074N

📄 Follow the Money · 14 — The Precursor: The Chemistry of an Overdose

Follow the Money, Case 14 — CONVERTED. The register's most lethal conversion: cartels (Sinaloa, CJNG) pay overseas chemical suppliers — increasingly in crypto — for the fentanyl precursors cooked into the drug that driv…

TI-2026-074O

📄 Follow the Money · 15 — The Canvas: Wash Trading and the Overpriced JPEG

Follow the Money, Case 15 — LAUNDERED. Under the million-dollar-ape spectacle, two old crimes in a perfect new instrument: wash trading (trading an NFT between your own wallets to fake value and volume, luring real buye…

TI-2026-074P

📄 Follow the Money · 16 — The Black Box: Where the Ledger Finally Goes Dark

Follow the Money, Case 16 — VANISHED. The honest counterweight to the whole series. Fifteen cases said 'the ledger remembers'; privacy coins (Monero) are where that stops being true. Ring signatures, stealth addresses,…

TI-2026-074Q

📄 Follow the Money · 17 — The Reckoning: When the Biggest Exchange Was Brought to Heel

Follow the Money, Case 17 — RECOVERED. The reckoning at the market's center: in November 2023 Binance, the world's largest exchange, pleaded guilty and paid ~$4.3B for operating as an unregistered US money transmitter a…

TI-2026-074R

📄 Follow the Money · 18 — The Franchise: Ransomware as a Business

Follow the Money, Case 18 — SPENT. Ransomware became an industry: ransomware-as-a-service, a franchise of developers, affiliates, and initial-access brokers, with a product roadmap (double/triple extortion that defeats…

TI-2026-074S

📄 Follow the Money · 19 — The Sanctioned State: Crypto Against the Blockade

Follow the Money, Case 19 — FROZEN. When a state is cut off from the dollar (Russia, Iran, DPRK), crypto looks like an escape hatch around the blockade. It's real but walled: too shallow to carry a national economy, too…

TI-2026-074T

📄 Follow the Money · 20 — The Machine on the Corner: The Crypto ATM and the Elder Scam

Follow the Money, Case 20 — VANISHED. The register's most intimate crime: a scammer posing as the IRS, tech support, or a grandchild panics an elderly victim into feeding cash into a crypto ATM, which converts it to irr…

TI-2026-074U

📄 Follow the Money · 21 — The Washman: Laundering as a Service

Follow the Money, Case 21 — LAUNDERED. Laundering became a service industry. Professional money-laundering organizations and Chinese underground-banking networks wash any crime's proceeds for a fee — the cartel, the ran…

TI-2026-074V

📄 Follow the Money · 22 — The Return: The Hacker Who Gave It Back

Follow the Money, Case 22 — RECOVERED. In 2021 an attacker drained ~$610M from Poly Network — the largest DeFi hack of its time — and then gave nearly all of it back, styling themselves 'Mr. White Hat.' Why? The money w…

TI-2026-074W

📄 Follow the Money · 23 — The Custodian: When the Exchange Is the Thief

Follow the Money, Case 23 — SPENT. The deepest betrayal: money stolen not by an outside hacker but by the custodian you trusted to hold it. Keeping crypto on an exchange means holding an IOU, not coins — and FTX (SBF co…

TI-2026-074X

📄 Follow the Money · 24 — The Hoard: The Fortune That Sits

Follow the Money, Case 24 — FROZEN. The complement of the returned heist: the thief who won't give it back and can't spend it either. So billions in stolen crypto sit dormant for years — visible to all, movable by none…

TI-2026-074Y

📄 Follow the Money · 25 — The Number: Stealing the Phone to Steal the Coins

Case 25 of Follow the Money: the SIM swap. A criminal talks a carrier into moving a victim's phone number to their own SIM, inherits the SMS 2FA and recovery codes it unlocks, and drains the victim's crypto into the lau…

TI-2026-074Z

📄 Follow the Money · 26 — The Verdict: What the Ledger Remembers

The finale of Follow the Money. Twenty-six cases in, the verdict is on the ledger itself: the public blockchain is a perfect memory of movement and a total amnesiac of meaning. Most stolen crypto is laundered, converted…

The Armory
TI-2026-075A

⚔️ The Armory: What 12,000 Attackers Carry

**TI-2026-075A · Series: The Armory (Part A) · TLP:WHITE · 2026-07-10**

TI-2026-075B

☁️ The Cloud Contractor: A Pentest Arsenal on Google's Network

**TI-2026-075B · Series: The Armory (Part B) · TLP:WHITE · 2026-07-10**

TI-2026-075C

🖐️ Two-Handed: The Fleet That Scans With One Build and Breaks With Another

**TI-2026-075C · Series: The Armory (Part C) · TLP:WHITE · 2026-07-10**

TI-2026-075D

🗡️ Sliver: The Adversary Emulator That Became the Adversary

**TI-2026-075D · Series: The Armory (Part D) · TLP:WHITE · 2026-07-10**

TI-2026-075E

💥 Havoc: When the Defender's Research Becomes the Attacker's Default

**TI-2026-075E · Series: The Armory (Part E) · TLP:WHITE · 2026-07-10**

TI-2026-075F

👣 The First Move: What Attackers Do the Instant They Are In

The post-login command record sorts, cleanly, into a small number of behavioural phases. The first is **orientation**, and `whoami` is its signature.

TI-2026-075G

🕸️ The Tenant of Fifty-Six Networks

That is not an accident of growth. It is an architecture. This is what a fleet looks like when its designer's first priority is not efficiency but *survival* — when the operator has looked at how takedowns actually happ…

TI-2026-075H

🏘️ The Resident: A Botnet Native to One Carrier

If the addresses churn and the device count is hidden, how do we know this is one fleet at all, rather than 155 unrelated Vietnamese machines that happen to run the same common library?

TI-2026-075I

⚔️ The Weapon Is Never the Point

So the reallocation the series argues for is concrete: stop chasing the ever-changing artifact, and detect the unchanging act. You will never keep pace with the recompiled weapon. You can absolutely catch the operator w…

TI-2026-075J

🔫 The Ammunition: What the Weapons Are Loaded With

There are, in the record, three doctrines of loading — and a fourth category that fires nothing at all.

TI-2026-075K

📦 The Payload: The Round That Actually Lands

The honeypot has watched this handoff 247 times, from 152 IPs. What it delivers is a small, reused, and revealing arsenal.

TI-2026-075L

🐹 The Compiled Swarm: The Language the Armory Is Migrating To

You do not have to take the language choice on faith that it signals sophistication — the swarm's behaviour confirms it, in tells no commodity botnet leaves.

TI-2026-075M

🖱️ By Hand: The Human in an Automated Armory

It is worth being precise about why the PuTTY fingerprint carries the weight it does, because the inference is unusually strong.

TI-2026-075N

🗺️ The Mapmaker: The Tool That Measures Without Touching

That is what reconnaissance is: not the break-in, but the intelligence that makes the break-in efficient. The mapmaker is the tool that gathers it, one silent handshake at a time.

TI-2026-075O

🧩 The Glue: The Library That Makes SSH Programmable

The Glue deserves its own letter precisely because it is the least weapon-like weapon in the armory — the point where the tool catalogue stops being a catalogue of tools and becomes a catalogue of *infrastructure*.

TI-2026-075P

📚 The Version Fleets: When the Build Number Is the Cohort

The letters so far have profiled *named* tools — Hydra, PuTTY, Nmap, Paramiko, the Go swarm. But the largest populations in the census are not named utilities at all. They are raw library versions. And they are enormous.

TI-2026-075Q

🔓 The Auditors: The Password-Testing Triad

They deserve a single letter, together, because their most important property is precisely that they are interchangeable.

TI-2026-075R

🗡️ The Sharpest Edge: Where the Threat Score Peaks

The previous letter, *The Version Fleets* (075P), was about reach — the giant libssh cohorts, 1,341 IPs of one build across 84 countries. This one is about danger, and the first thing to say is that the two are not the…

TI-2026-075S

🔇 The Silent Knock: The Largest Signal Nobody Watches

Every letter so far has counted attacks — tools that fire, magazines that spray, payloads that land. But the single most common thing in the honeypot's entire record is not an attack. It is the *absence* of one.

TI-2026-075T

🎭 The Borrowed Face: Tools That Wear a Legitimate Identity

That is the subject of this letter. Every other tier of the armory announces something suspicious about itself. This one announces the opposite — *I am ordinary* — and does so precisely because ordinary is the best disg…

TI-2026-075U

🗝️ The Key Ring: The Signal That Names the Hand

Here is what makes the reused key such a gift: avoiding it costs *nothing*.

TI-2026-075V

🛡️ The Bulletproof Shelf: Where the Armory Is Stored

But the interesting thing about the bulletproof shelf is not that it exists. It is how *little* of the armory actually sits on it.

TI-2026-075W

🕰️ The Clock: When the Armory Fires

Time, it turns out, is as characteristic as any handshake. When a fleet fires binds it as surely as what it fires — and, as we will see, the rhythm of an operation can separate a machine from a human hand without any ot…

TI-2026-075X

🔀 The Cross-Vector: One Operator, Many Protocols

Except they don't. The same addresses appear in both. And when they do, they reveal something the SSH census alone could never show: that an operator the series has been profiling as an *SSH attacker* is, from another w…

TI-2026-075Y

🕊️ The Innocent: The Legitimate Traffic in the Trap

This final substantive letter is about that innocent fraction — because it turns out to be the purest possible demonstration of the thesis the whole series has been building toward.

TI-2026-075Z

🏁 The Complete Armory: Twenty-Six Ways of Reading One Protocol

The method matters as much as the findings, and the method is the second thing the finale makes explicit.

Follow the Access
TI-2026-076A

📄 Follow the Access · 01 — The Default Password: The Key Left in the Lock

Case 01 of Follow the Access, the sequel register to Follow the Money. The most common way into a machine on the internet is not an exploit but the unchanged factory password: admin:123456, tried 5,385 times on the hone…

TI-2026-076B

📄 Follow the Access · 02 — The Brute Force: Guessing at the Speed of Machines

Case 02 of Follow the Access. When the default password is changed but weak, the attacker guesses — credential brute force and password spraying run at machine speed by Hydra, Medusa, Ncrack, and Paramiko, fingerprinted…

TI-2026-076C

📄 Follow the Access · 03 — The Exposed RDP: The Remote Desktop Left Facing the Street

Case 03 of Follow the Access. The internet-facing Remote Desktop endpoint is the ransomware era's most consequential access vector: unlike an SSH shell, RDP hands the attacker the victim's own graphical Windows desktop,…

TI-2026-076D

📄 Follow the Access · 04 — The Phish: Deceiving the Human the Firewall Cannot Protect

Case 04 of Follow the Access. The second of CISA's two dominant ransomware doors — but where Case 03 forced a machine, the phish deceives a person, bypassing every control by targeting the one component no firewall defe…

TI-2026-076E

📄 Follow the Access · 05 — The Edge Appliance: When the Guard at the Gate Is the Way In

Case 05 of Follow the Access. The internet-facing security appliance — the VPN, firewall, and gateway bought to keep attackers out — is exploited to let them in. Exposed by design, trusted implicitly, poorly monitored,…

TI-2026-076F

📄 Follow the Access · 06 — The Web Shell: Remote Code Execution on the Public Server

Case 06 of Follow the Access. Unauthenticated remote code execution against a public-facing web application — the vector that severs access from identity: no login, no user, just a crafted request that a bug turns into…

TI-2026-076G

📄 Follow the Access · 07 — The Open Database: A Data Store With No Lock on the Door

Case 07 of Follow the Access. The purest misconfiguration in the register: an internet-exposed database (Redis, MongoDB, Elasticsearch) with authentication off — no lock to pick because there is no lock, and connecting…

TI-2026-076H

📄 Follow the Access · 08 — The Exposed Docker Socket: Root on the Host, Handed Over by the API

Case 08 of Follow the Access. The exposed Docker daemon socket (port 2375) or unauthenticated Kubernetes API is a remote root primitive: launching a container that mounts the host is owning the host, and the K8s API mul…

TI-2026-076I

📄 Follow the Access · 09 — The Infostealer: The Malware That Empties the Whole Wallet

Case 09 of Follow the Access. Where the phish tricks a user into typing one credential, the infostealer runs on the endpoint and empties the whole credential warehouse in a single silent sweep — saved passwords, session…

TI-2026-076J

📄 Follow the Access · 10 — The Access Broker: The Wholesaler of Other People's Networks

Case 10 of Follow the Access — the keystone. The initial access broker sells footholds he does not use, the wholesaler between the producers (brute-force, phishing, infostealers) and the operators (ransomware). Access i…

TI-2026-076K

📄 Follow the Access · 11 — The Valid Account: The Intruder Who Logs In and Looks Like You

Case 11 of Follow the Access. The most effective modern intruder does not break in — he logs in, with a valid stolen credential, and lives off the land using the target's own tools (PowerShell, WMI, RDP) so nothing look…

TI-2026-076L

📄 Follow the Access · 12 — The MFA Bypass: Defeating the Second Factor Without Breaking It

Case 12 of Follow the Access. The register kept naming MFA as the fix; this case follows the crews who defeat it without breaking it — push-bombing (fatiguing the user until they tap approve) and help-desk social engine…

TI-2026-076M

📄 Follow the Access · 13 — The Supply Chain: Poison the Source, Reach Everyone Downstream

Case 13 of Follow the Access. The one-to-many attack: breach not the target but a supplier it trusts, and the poison flows downhill into everyone downstream who installs it. SolarWinds reached thousands through one tamp…

TI-2026-076N

📄 Follow the Access · 14 — The Watering Hole: Poisoning the Place the Victim Already Trusts

Case 14 of Follow the Access. The inversion of phishing: instead of luring the victim to a strange place, the attacker poisons a legitimate site the victim already visits and trusts, and waits. From DarkHotel's strategi…

TI-2026-076O

📄 Follow the Access · 15 — The Fake Installer: Poisoning the Search for Software Itself

Case 15 of Follow the Access. The fake installer poisons the act of acquiring software: malvertising buys the ad above the real download, SEO poisoning games the top result, and the pirate lure routes crack-seekers to t…

TI-2026-076P

📄 Follow the Access · 16 — The Vulnerable Driver: Bringing a Signed Key to the Kernel

Case 16 of Follow the Access. Bring Your Own Vulnerable Driver: an attacker already inside brings a legitimate, vendor-signed but flawed driver (WinRing0 and its kin), loads it because the signature is real, and exploit…

TI-2026-076Q

📄 Follow the Access · 17 — The Planted Key: Cutting a Copy Before the Lock Is Changed

Case 17 of Follow the Access. The professional intruder's first act is persistence — cutting a copy of the key before the lock is changed. The honeypot captured it 3,240 times: attackers planting their own SSH key in au…

TI-2026-076R

📄 Follow the Access · 18 — The IoT Worm: The Self-Spreading Conscription of Everything

Case 18 of Follow the Access. The IoT worm (Mirai, Mozi, Bashlite — captured on the honeypot as elf.mirai/elf.bashlite) is self-propagating: it infects a weak-credential device and immediately uses it to infect more, a…

TI-2026-076S

📄 Follow the Access · 19 — The Wormable Exploit: The Self-Spreading Flaw and the Wiper Behind the Ransom Note

Case 19 of Follow the Access. The wormable exploit spreads by flaw, not credential — carrying its own way in (EternalBlue in SMB, Log4Shell in Log4j) and sweeping unpatched networks machine-to-machine in minutes, uncont…

TI-2026-076T

📄 Follow the Access · 20 — The Leaked Secret: The Cloud Key the Developer Published by Accident

Case 20 of Follow the Access. The leaked secret is a credential the victim published by accident — a cloud key committed to a public repo, left in an exposed .env, or embedded in shipped client code. Automated scanners…

TI-2026-076U

📄 Follow the Access · 21 — The Insider: The Attacker Who Was Already Given the Keys

Case 21 of Follow the Access. The insider never broke in — the organization gave them the keys. It inverts every defense: MFA, patching, and the perimeter all assume the attacker is unauthorized, but the insider is auth…

TI-2026-076V

📄 Follow the Access · 22 — The Cloud Metadata Service: Stealing the Keys From the Machine Itself

Case 22 of Follow the Access. Cloud instances expose a metadata endpoint (169.254.169.254) that hands out their IAM credentials — the keys to the machine's cloud identity, at a URL the machine can request. A Server-Side…

TI-2026-076W

📄 Follow the Access · 23 — The Mass Scanner: The Census That Precedes Every Attack

Follow the Access, Case 23. Mass internet scanning is the census beneath every vector: 3,477 honeypot scanner IPs running libssh/Go_SSH/AsyncSSH/Nmap toolchains, sweeping the whole IPv4 internet in hours so exposure equ…

TI-2026-076X

📄 Follow the Access · 24 — The Combolist: Credential Stuffing and the Afterlife of a Breach

Follow the Access, Case 24. Credential stuffing replays breached username:password pairs against unrelated services — the combolist. The honeypot watches the replay: admin:123456 tried 5,385 times, admin:admin from 136…

TI-2026-076Y

📄 Follow the Access · 25 — The First Machine: What the Sensor Watched Happen to Itself

Follow the Access, Case 25 — the reflexive case. The honeypot is itself the first machine, so this fate is watched from inside, not inferred: the automated post-access routine (recon, ipinfo/ifconfig callbacks, wget|sh…

TI-2026-076Z

📄 Follow the Access · 26 — The Verdict: What Access Becomes

Follow the Access, the finale. The verdict on 25 vectors: four laws (exposure equals discovery; the takeover is automated and indifferent; the economy is specialized and commoditized; the victims become the infrastructu…

The Laundered Vector
TI-2026-077A

🧺 The Laundered Vector: An Attack That Arrived by VPN

Before the fingerprints and the ASN numbers, here is the whole story in ordinary words.

TI-2026-077B

🚿 The Pipe That Hides: Why You Cannot Block a VPN

So when you say "block the VPN exit," what you are actually saying is: *block the doorway that thousands of innocent people are using, in order to stop the one who is not.* That is the whole problem in a sentence, and e…

TI-2026-077C

🚪 One Hand, Two Doors: The Cross-Vector Operator

The single hardest piece of evidence is an address we have already met: **`5.183.101.141`**.

TI-2026-077D

🏦 The Midtier: Reputable Enough to Launder

Here is the twist that completes the portrait. For all its spotless reputation, AS212238 does not live in a different world from the bulletproof floor. It is routed **right beside it.**

The Cloud Offensive
TI-2026-078A

☁️ The Cloud Offensive: A Dedicated Front on Google's Network

Every server on the internet gets attacked constantly. That is normal, and most of it is faceless background noise — automated scanners sweeping the whole internet, hitting your address the same way they hit everyone's,…

TI-2026-078B

🎯 The Estate Sweep: Reconnaissance That Knows You by Name

Part A described a front — two thousand machines, faceless and statistical. This letter is about one of them, and it is the letter where the offensive stops being a number and becomes personal, because this machine does…

TI-2026-078C

🎖️ The Credential Army: Elasticity as a Weapon

This is the letter where the offensive's scale stops being impressive and starts being *instructive* — because the way it is built is precisely designed to defeat the standard defence, and understanding how it does that…

TI-2026-078D

⚖️ The Accountability Gap: Why the Cloud Offensive Never Ends

Which forces the question this finale exists to answer: **why can no one make it stop?**

The Harvest
TI-2026-079A

🌾 The Harvest: A Budget Host Where Nearly Everything Is an Attack

The previous series, *The Cloud Offensive*, was about the hardest possible network to defend against: Google Cloud, so reputable and so essential that it cannot be blocked. This series is about its exact opposite — and…

TI-2026-079B

🔎 The Docsearch Probe: Reconnaissance Read from Your Own Website

But the *mechanism* of probing is not what makes this probe notable. What makes it notable is the one request that reveals how the attacker knew `lsn-docsearch` existed at all.

TI-2026-079C

🧅 The Reseller Stack: Who Is Behind the Harvest

Start with the structure, because the structure is the first reason the operator is hidden.

Follow the Operator
TI-2026-080A

📄 Follow the Operator · 01 — The Reused Key: One Key, One Hundred Faces

Follow the Operator, Case 01. One operator, 124 honeypot IPs across 56 ASNs and 15 countries — every surface attribute varied to look like a crowd, but all 124 offer the identical SSH key at login. The key is the invari…

TI-2026-080B

📄 Follow the Operator · 02 — The Planted Key: The Signature Left on the Victim

Follow the Operator, Case 02. Where Case 01 read the key an operator offers at login, this reads the key he leaves: the public key planted into victims' authorized_keys for persistence (MITRE T1098.004). 81 backdoored h…

TI-2026-080C

📄 Follow the Operator · 03 — The Tool Fingerprint: How the Software Betrays the Hand

Follow the Operator, Case 03. A HASSH fingerprint hashes the algorithm set an SSH client declares before authenticating — a signature of the tool, not the address. A 92-IP, single-country cluster all fingerprinting as A…

TI-2026-080D

📄 Follow the Operator · 04 — The Shared Payload: The Malware Is the Message

Follow the Operator, Case 04. 12 delivery IPs across 9 countries tied to one operation by a shared payload. The malware is three invariants — hash, staging URL, C2 — and attribution rests on the bespoke config (C2, wall…

TI-2026-080E

📄 Follow the Operator · 05 — The Bulletproof Landlord: When the Address Attributes the Enabler, Not the Tenant

Follow the Operator, Case 05. Attackers who share only a bulletproof host share a landlord, not a hand — the honeypot's high-threat registrants (TechTies Inc. ~47 IPs at avg threat 78.5; IP Manager ~33). The register's…

TI-2026-080F

📄 Follow the Operator · 06 — The Same Keystrokes: The Routine That Repeats Itself

Follow the Operator, Case 06. A scripted post-access routine is deterministic — the same commands in the same order every session, captured verbatim by the honeypot across scattered IPs. Attribution lives in authorship…

TI-2026-080G

📄 Follow the Operator · 07 — The Bespoke Wordlist: The Dictionary a Hand Brings

Follow the Operator, Case 07. The credential wordlist an operator brings — captured pair by pair by the honeypot (33,977 unique pairs). The common head (admin:123456) attributes nothing; identity lives in the rare curat…

TI-2026-080H

📄 Follow the Operator · 08 — The Working Day: The Clock the Operator Cannot Move

Follow the Operator, Case 08, closing the behavioral arc. An operator scatters his IPs across the world but works on his own clock: a diurnal hour-of-day curve leaks his real timezone regardless of where his machines ge…

TI-2026-080I

📄 Follow the Operator · 09 — The Beacon: The Server the Operation Points To

Follow the Operator, Case 09. Unlike Case 05's rented bulletproof host, the C2 is the operator's OWN — the point his whole fleet converges on. Its TLS certificate, JARM, and panel fingerprints survive an address change…

TI-2026-080J

📄 Follow the Operator · 10 — The Registrant: When Infrastructure Carries a Name

Follow the Operator, Case 10, opening the identity arc. When does the abstract hand acquire a name? Registration records (WHOIS/RDAP/certificate transparency) can carry the operator's identity — but they are the most-po…

TI-2026-080K

📄 Follow the Operator · 11 — The Handle: The Name He Chose for Himself

Follow the Operator, Case 11. Where Case 10 read the identity an operator was forced to register, this reads the one he chose: his handle, kept out of vanity because it carries his reputation, reused across services and…

TI-2026-080L

📄 Follow the Operator · 12 — The Cut Thread: When the Address Leads Nowhere

Follow the Operator, Case 12 — the first null case. Tor/VPN/proxy sever the address (28 Tor exits in the honeypot), defeating every address-based signal. But the cut hides the address, not the session: the key, tool fin…

TI-2026-080M

📄 Follow the Operator · 13 — The Mega-Cluster: One Operator, End to End

Follow the Operator, Case 13. The whole method applied to one cluster: the 124-IP operator walked end to end through key, coordinated timing, consistent behavior, and tool fingerprint — four independent invariants that…

TI-2026-080N

📄 Follow the Operator · 14 — The Graph: The Web of Every Hand

Follow the Operator, Case 14. Attribution is not isolated verdicts but one 200,000+ edge graph — the six signals are edge types, operators are dense regions, and every new cluster is cross-referenced against all prior d…

TI-2026-080O

📄 Follow the Operator · 15 — The Cloud Tenant: Hiding in the Legitimate

Follow the Operator, Case 15. The inverse of the bulletproof host: the legitimate mega-cloud (Google AS396982, DigitalOcean, Microsoft, OVH tops the honeypot's attacker ASNs). Un-blockable and clean-reputation, so opera…

TI-2026-080P

📄 Follow the Operator · 16 — The False Flag: The Signal Planted to Deceive

Follow the Operator, Case 16. The operator who knows he's being attributed and plants signals to frame someone else — a foreign string, a rival's tool, a borrowed C2 — weaponizing the analyst's method against an innocen…

TI-2026-080Q

📄 Follow the Operator · 17 — The Merge Problem: Two Campaigns, One Hand

Follow the Operator, Case 17. Attribution is revisable: two campaigns documented as distinct operators, revealed as one hand when a heavy cross-cluster edge (a bespoke key reused across both) bridges them. Merge only on…

TI-2026-080R

📄 Follow the Operator · 18 — The Split Problem: One Cluster, Two Hands

Follow the Operator, Case 18, the mirror of the merge. One cluster documented as a single operator, revealed as two — falsely joined by a light bridge (a shared common tool). The tell is the internal structure: two dens…

TI-2026-080S

📄 Follow the Operator · 19 — The Coincidence: When the Key Is a Lie

Follow the Operator, Case 19 — the promised failure case. A shared bespoke key, the register's strongest signal, bridges two clusters — but they contradict on behavior, timing, and every other invariant, sharing only th…

TI-2026-080T

📄 Follow the Operator · 20 — The Broker's Fingerprint: Seller and Buyer of Access

Follow the Operator, Case 20 — the intrusion that is genuinely two operators' work. In the access-broker economy the hand that GAINS access (the broker, who sells it) and the hand that USES access (the buyer) are differ…

TI-2026-080U

📄 Follow the Operator · 21 — The Persona: When the Handle Has a Name

Follow the Operator, Case 21 — the register's closest approach to a name. A persona (a self-chosen, reused, near-unshareable handle) is the strongest LEGIBLE identity signal; when it appears in both honeypot evidence an…

TI-2026-080V

📄 Follow the Operator · 22 — The Ghost: The Operator With No Invariant

Follow the Operator, Case 22 — the honest null. The ghost leaves no durable invariant: rotates keys per session, uses commodity default tools, rents fresh infrastructure, varies behavior, carries no persona — defeating…

TI-2026-080W

📄 Follow the Operator · 23 — The Census Behind the Census: Attributing the Scanner Layer

Follow the Operator, Case 23 — the scanner layer. Before most attacks there is a scan, but most scan fingerprints belong to internet-wide mass-scanners (research censuses, scanning-as-a-service) that precede nearly ever…

TI-2026-080X

📄 Follow the Operator · 24 — The Confidence Problem: What HIGH, MEDIUM, and LOW Actually Mean

Follow the Operator, Case 24 — the methodological capstone. The register audits its own confidence scale: HIGH/MEDIUM/LOW/DECLINED defined as auditable claims, not moods. Two principles govern it — the SHAREABILITY GRAD…

TI-2026-080Y

📄 Follow the Operator · 25 — The Linker: The Machine That Draws the Graph

Follow the Operator, Case 25 — the reflexive turn. The 200,000-edge entity graph is drawn not by a human but by the LINKER, an automated engine — so the linker IS the register's method executed automatically, and auditi…

TI-2026-080Z

📄 Follow the Operator · 26 — The Verdict: The Invariant That Survives Transformation

Follow the Operator, Case 26 — THE VERDICT (finale). The whole register's synthesis: attribution is the search for the INVARIANT THAT SURVIVES TRANSFORMATION — the fixed point of an operator's disguises, the one thing h…

Follow the Payload
TI-2026-081A

📄 Follow the Payload · 1 — The Miner: Compute as the Prize

Follow the Payload, Case 1 — the register opens. The frame: the payload is the purpose made executable — a payload's intent is not inferred like a motive but EXECUTED, observable directly. The cryptominer is the archety…

TI-2026-081B

📄 Follow the Payload · 2 — The Proxy: Bandwidth and a Clean Address

Follow the Payload, Case 2 — STEAL BANDWIDTH. The proxy payload turns the host into a residential exit node, stealing not compute but network position — its clean IP reputation, used to LAUNDER malicious traffic (creden…

TI-2026-081C

📄 Follow the Payload · 3 — The Recruit: A Soldier Awaiting Orders

Follow the Payload, Case 3 — RECRUIT, the register's first META-objective. A botnet agent does not USE the host — it ENROLLS it, subordinating it to a remote commander to await orders. So the register reads two intents…

TI-2026-081D

📄 Follow the Payload · 4 — The Commodity Payload: Why Sharing Sharpens Intent and Blurs Authorship

Follow the Payload, Case 4 (methodology) — the intent/author split formalized. SHAREABILITY governs both registers and moves them in OPPOSITE directions: it destroys author-confidence (widely-shared = no single hand) bu…

TI-2026-081E

📄 Follow the Payload · 5 — The Harvester: When the Loot Is a Key

Follow the Payload, Case 5 — STEAL DATA. The harvester reads the host's credential stores (SSH keys, cloud credentials, tokens, secrets) and exfiltrates them. Its defining feature: the loot is itself a KEY, so the theft…

TI-2026-081F

📄 Follow the Payload · 6 — The Exfiltrator: The Data Itself as the Prize

Follow the Payload, Case 6 — STEAL DATA (bulk). The exfiltrator steals the data itself (documents, databases, records) — TERMINAL loot, the mirror of the harvester's generative keys, pointing to a passive downstream har…

TI-2026-081G

📄 Follow the Payload · 7 — The Ransom Note: The Objective That Announces Itself

Follow the Payload, Case 7 — EXTORT. Ransomware inverts the register: every prior payload wanted to stay hidden, but ransomware REQUIRES being seen — the victim must know to pay. So its intent is DECLARED, not inferred:…

TI-2026-081H

📄 Follow the Payload · 8 — The Wiper in Ransom Clothing: When the Declared Objective Is a Lie

Follow the Payload, Case 8 — DESTROY (declared EXTORT refused). A wiper dressed as ransomware encrypts or corrupts files and demands payment for a decryptor that does not exist: the declared objective (EXTORT) is a lie…

TI-2026-081I

📄 Follow the Payload · 9 — The Backdoor: Access Kept as an End in Itself

Follow the Payload, Case 9 — PERSIST, the sixth and foundational objective. A backdoor does not mine, steal, or extort; it keeps the door open so the operator can RETURN. PERSIST is the objective of maintaining access i…

TI-2026-081J

📄 Follow the Payload · 10 — The Loader: A Payload That Is Only a Promise

Follow the Payload, Case 10 — DELIVER (terminal objective deferred). A loader/dropper/stager exists to fetch and run ANOTHER payload; its own objective is delivery, and the terminal intent resides in a second stage it d…

TI-2026-081K

📄 Follow the Payload · 11 — The Dropped-But-Never-Run: Capability Without Expression

Follow the Payload, Case 11 — the honest null. A payload found on disk but never executed forces the register to separate CAPABILITY (what it COULD do) from INTENT-EXPRESSED (what it DID). The capability is readable (a…

TI-2026-081L

📄 Follow the Payload · 12 — The Decoy Payload: A Payload Planted to Be Misread

Follow the Payload, Case 12 — MISDIRECT. A decoy is a payload planted to be FOUND and MISREAD, so the analyst reads it as the objective and stops — while a quieter payload does the real work. The payload-layer false fla…

TI-2026-081M

📄 Follow the Payload · 13 — The Dual-Use Tool: When the Binary Is Innocent

Follow the Payload, Case 13 (methodology) — the dual-use tool. Netcat, curl, ssh, tar, PowerShell: a binary that is INTENT-NEUTRAL, used identically for administration and attack. This breaks artifact-reading (identifyi…

TI-2026-081N

📄 Follow the Payload · 14 — The Layered Payload: When the Objective Is Plural

Follow the Payload, Case 14 — STACK (plural objectives). Real intrusions drop several payloads with different objectives (backdoor + miner + harvester) on one host — the norm — so the objective is PLURAL. Two readings:…

TI-2026-081O

📄 Follow the Payload · 15 — The Rented Payload: The Vendor Built It, the Affiliate Aimed It

Follow the Payload Case 15 — the rented payload: a malware-as-a-service payload is built by a vendor and deployed by an unrelated affiliate, splitting author into two hands. Intent belongs to the deployer; the family id…

TI-2026-081P

📄 Follow the Payload · 16 — The Self-Propagator: The Payload Whose Objective Is To Spread

Follow the Payload Case 16 — the self-propagator: a worm's directly-readable objective is PROPAGATE, but propagation is a meta-objective (a means, not an end). The register reads the spread at HIGH and holds the termina…

TI-2026-081Q

📄 Follow the Payload · 17 — The DDoS Cannon: The Payload Aimed Past the Host

Follow the Payload Case 17 — the DDoS cannon: the register's first two-victim case, whose objective is aimed past the host. It weaponizes the machine to fire at a third party — two victims (the host owner and the extern…

TI-2026-081R

📄 Follow the Payload · 18 — The Anti-Analysis Payload: Reading the Armor When the Core Is Hidden

Follow the Payload Case 18 — the anti-analysis payload: the one built to defeat the register's method. The armor reads HIGH, the core reads unknown-behind-armor. Evasion is a protective meta-behaviour that leaks intent…

TI-2026-081S

📄 Follow the Payload · 19 — The Objective That Changed: When One Foothold Serves Many Purposes

Follow the Payload Case 19 — the objective that changed: the same foothold serves many purposes over time, so the objective is a timeline, not a point. Three drivers — escalation, monetization pivot, re-sale. Read each…

TI-2026-081T

📄 Follow the Payload · 20 — The Sleeper: Reading the Objective That Has Not Fired

Follow the Payload Case 20 — the sleeper: a payload present but unfired. Dormancy means unfired, not unknowable — a logic bomb carries its trigger and action in code, so the latent objective reads at HIGH while the exec…

TI-2026-081U

📄 Follow the Payload · 21 — The Misattributed Objective: How the Register Reads an Objective Wrong

Follow the Payload Case 21 — the misattributed objective: how the register reads an objective wrong. Adversarial misreads (decoy, false flag) and methodological ones (benign, wrong-phase, wrong-payload), and the master…

TI-2026-081V

📄 Follow the Payload · 22 — The Payload With No Objective: Reading a Genuine Null

Follow the Payload Case 22 — the payload with no objective: a genuine null, completing the trilogy unread/unfired/absent. Four forms (broken, debris, misfire, purposeless); the null verdict is a high bar requiring posit…

TI-2026-081W

📄 Follow the Payload · 23 — The Living-Off-The-Land Intrusion: Reading an Objective With No Payload to Read

Follow the Payload Case 23 — the living-off-the-land intrusion: an operation with no payload. The register reads the objective from the action-sequence (the behavioural kill-chain), not an artifact — proving 'Follow the…

TI-2026-081X

📄 Follow the Payload · 24 — The Intent Ledger: The Complete Accounting of an Objective-Reading

Follow the Payload Case 24 — the Intent Ledger: the methodology capstone assembling every discipline into a five-column accounting instrument (WHAT/CONFIDENCE/STATE/AUTHOR/UNKNOWN-TYPE) governed by a double-entry balanc…

TI-2026-081Y

📄 Follow the Payload · 25 — The Classifier: The Register's Method Applied to the Machine That Reads at Scale

Follow the Payload Case 25 — the classifier: the register's method applied to the machine that reads objectives at scale. The Intent Ledger is what makes a classifier possible, but the machine inherits the disciplines o…

TI-2026-081Z

📄 Follow the Payload · 26 — The Verdict: What the Whole Register Establishes About Purpose

Follow the Payload Case 26, the finale — the Verdict: what the whole register establishes about purpose. The payload cannot hide its purpose; purpose is the last and hardest concealment, possible only by abandoning it.…

The Tripwire Ledger
TI-2026-082A

🏦 The Bank That Wasn't: A Microcredit Name Over a Scanner Fleet

Except this one lies about where it is, and it lies more than once.

TI-2026-082B

🗄️ The Borrowed Vault: VPSVAULT and the Seychelles Address Empire

Pull the registration apart and the United Kingdom evaporates:

TI-2026-082C

🏭 The Address Foundry: EMBNEX and the Minting of Disposable Identities

Strip the assumption that a company holding address space must be a hosting company, and look at what the registries say.

TI-2026-082D

🎭 The Costume Catalog: Nine Masks From One Foundry

Every entry below shares one thing and only one thing that matters: it sits in the EMBNEX (AS401661) downstream cone, most drawing a `/48` from `2604:be0::/32`. Everything else — the name, the flag, the story — is paint.

TI-2026-082E

🌊 The Flooder Next Door: DEDIK and the Harvest at Flood Velocity

Start with the behaviour, because it reframes the category the tripwire assigned.

TI-2026-082F

🐣 The Nursery: One RIPE Allocation Range, a Brood of Costumes

That was one axis. This part finds a second one, running perpendicular to it.

The Loader's Trail
TI-2026-083A

🐙 The Senpai Loader: A Nexus Botnet Caught Staging on the Laundered Vector

What came next identifies the target as an embedded device, not a server:

TI-2026-083B

🐙 The Target Was Never a Server: Reading the Nexus Loader's Device Fingerprint

It did not answer the more interesting question: **what was the loader aiming at?**

TI-2026-083C

🐙 The Appraiser: A Loader That Checks What You're Worth — and Whether You're Watching

Where the shotgun sprays, the appraiser inspects. Same trail, opposite doctrine.

TI-2026-083D

🐙 The Loader Splits in Two: A Field Guide to Profile-First Reconnaissance Botnets

Then look at the honeypot's own books. Sort every post-login command it has ever recorded into categories, and the shape is startling:

Borrowed Trust
TI-2026-084A

🎓 Borrowed Trust: A Compromised University Gateway on the Attack

The subject is a single IP, `200.89.69.247`, which arrived at the SSH honeypot as an ordinary abuse-100 brute-forcer — until you look up its name, and the name changes everything.

TI-2026-084B

🎓 The Watchman's Own Gate: Namespace Recon from the Network That Runs Poland's CERT

The abuse is egressing the network of the organisation you are supposed to *report abuse to*.

TI-2026-084C

🎓 The Research Bureau's Spray: A State Science Enterprise Hunting DevOps Credentials

And what egresses that reputation is the most *modern* attacker in the series so far. Where Chile sprayed `root:1234` and NASK guessed subdomains, this node went hunting for the keys to a devops stack.

TI-2026-084D

🎓 Reading the Good Name: A Field Guide to Borrowed Trust and Its Innocent Twins

The real lesson is narrower and harder: **an institutional IP in attack data is a question, not a verdict.** This part is the field guide for answering it.

The Unmasking
TI-2026-085A

🎭 The Unmasking · 1 — The Training Land-Grab: Verified, Polite, and Taking Everything

The Unmasking, Case 1 — the register opens. The frame: the claim is the identity made testable — the User-Agent is testimony, admissible only once corroborated against the network of origin the visitor does not control.…

TI-2026-085B

🎭 The Unmasking · 2 — The Impostor Economy: The Mask That Convicts the Wearer

The Unmasking, Case 2 — the visitor whose claim is false, and the easiest conviction in the register. SPOOFED means a verifier was run and FAILED (not merely unconfirmed). Archetype: a scanner sending the exact Googlebo…

TI-2026-085C

🎭 The Unmasking · 3 — Verified, and Still Where It Shouldn't Be

The Unmasking, Case 3 — a verified visitor where it should not be. OpenAI's OAI-SearchBot (verified against OpenAI's published CIDRs, though egressing from Microsoft's Azure AS8075 — the mirror of Case 2) reached for /r…

TI-2026-085D

🎭 The Unmasking · 4 — Recon-as-a-Service

The Unmasking, Case 4 — the visitor with no discrepancy to expose: a commercial reconnaissance scanner that is exactly what it claims. The recon class (Censys, Palo Alto Expanse, BitSight, LeakIX, Odin) spans the taxono…

TI-2026-085E

🎭 The Unmasking · 5 — The Mask Beneath the Mask

The Unmasking, Case 5 — malice in the costume of an ordinary user. The dangerous visitor does not impersonate a crawler (checkable, convictable) but a person: a plain browser UA that returns 'unclassified' — no verdict,…

TI-2026-085F

🎭 The Unmasking · 6 — The Nameless (finale)

The Unmasking, Case 6 (finale) — the visitor with no User-Agent, the terminus of the gradient Case 1 named. Against the identity taxonomy the empty UA is perfect concealment (no name to verify, spoof-catch, or even call…

The Wardrobe
TI-2026-086A

🧥 The Wardrobe Rack: Seven Crawler Masks in One Cloud Tenant

One Google Cloud address space, seven spoofed crawler masks at once — Fake-Googlebot (77 IPs), Fake-ia_archiver, Fake-Baiduspider and more — now auto-detected as fleets and CrowdSec-banned by name. The anchor case of Th…

TI-2026-086B

🧥 The Flagship Mask: Turning Out the 77-IP Fake-Googlebot Fleet

The 77-IP Fake-Googlebot fleet on Google Cloud, turned out node by node: internal-subdomain enumeration, Joomla fingerprinting and a 151-path .env burst — one shared toolkit under an interchangeable crawler costume, pro…

TI-2026-086C

🧥 The Archivist's Coat: The 22-IP Fake-ia_archiver Fleet

The 22-IP Fake-ia_archiver fleet impersonates the Internet Archive to license exhaustive crawling, completes the costume with vintage BlackBerry/Series80 user-agents, and bursts 79 .env paths at a host that answers a un…

TI-2026-086D

🧥 The Eastern Crawlers: Fake-Baiduspider and Fake-YandexBot

The Fake-Baiduspider and Fake-YandexBot fleets forge China's and Russia's search crawlers to exploit the internationalised allowlist — flags that never match their US Google Cloud origin — and hit the Gitea host with .e…

TI-2026-086E

🧥 The Newest Trust: Fake AI Crawlers and the Frontier of Verification

The fake AI crawlers — ClaudeBot, GPTBot, ChatGPT-User — are the wardrobe's newest masks. The classifier convicts them by the operator's real published ASN (Anthropic AS399358, OpenAI AS394699), cutting through a mislea…

TI-2026-086F

🧥 The Social Unfurlers: Masks That Trade on Being Harmless

The Fake-Twitterbot, facebookexternalhit, Feedfetcher and SemrushBot fleets trade on being harmless — preview and feed masks allowlisted by indifference. The classifier convicts them by operator ASN (Twitter AS13414, Me…

TI-2026-086G

🧥 The Wardrobe in Motion: Identity-Rotation Subnets

The identity-rotation /24s on budget host Hostodo cycle many crawler masks across a few IPs — the inverse of the Google Cloud fleets' one-mask-many-IPs. A second detector catches the mobile wardrobe the static-fleet det…

TI-2026-086H

🧥 The Landlords: The Per-Cloud Geography of the Wardrobe

The crawler-mask wardrobe rents reputable clouds — Google, AWS, Cloudflare, DigitalOcean — because reputation is the mask's currency, the opposite of the bulletproof hosts the loud SSH-attack economy uses. Each landlord…

TI-2026-086I

🧥 The Costume Fits the Crime: The Intent-to-Mask Correlation

Across the whole rack the mask predicts the payload: search/archive masks cover high-volume credential harvests, the SEO mask covers light recon, AI masks hunt AI subdomains — and the loud shell-upload floods go maskles…

TI-2026-086J

🧥 The Same Hand: When the Web Mask and the SSH Scanner Share a Target

The web mask and the SSH scanner hunt the same prize — developer credentials. Node 35.188.112.111 runs a DevOps-wordlist SSH scan (deploy, git, claude:Claude2026!) from the same Google Cloud tenancy whose web fleets swe…

TI-2026-086K

🧥 The Mask That Convicts: The Automated Unmasking Loop

The series' aphorism made a cron job: an hourly autoban keys a 7-day CrowdSec ban to a spoofed fleet's own name, escalates proven impostors to a threshold of one, and enforces at nftables + the MikroTik router — with ho…

TI-2026-086L

🧥 The Verifier's Dilemma: Why the Strongest Verdict Is the Most Fragile

The SPOOFED verdict the autoban rides on is the strongest signal and the most fragile to maintain. Between false-verify and false-spoof, every method (ASN, CIDR, rDNS, none) trades one cliff for the other — proven live:…

TI-2026-086M

🧥 The Operators Behind the Rack: Structure Without a Name

Turning the entity graph on the fleets resolves the deferred 'who': the wardrobe is a structured crowd — coordination provable via shared SSH keys across 56-ASN clusters, but principals unnameable by design because the…

TI-2026-086N

🧥 The Long Con: The Mask's Evolution Across the Corpus

The industrialised wardrobe is the latest move in a years-long arms race the corpus has tracked: empty-UA → blend-in browser → budget-host impostor → reputable-cloud mask-fleet, each rung forced by a defence that caught…

TI-2026-086O

🧥 The Bystander Cloud: The Accountability Gap at the Identity Layer

The mask is the one corner of the cloud accountability gap that is cheap to close and closable only by the landlord: a tenant forging Googlebot is a near-certain impostor Google alone can flag at near-zero cost — becaus…

TI-2026-086P

🧥 The Two-Hundred Mask: Reading Intent When Nothing Returns 404

Every probe wears two masks: the attacker's forged crawler identity and the server's masked status code. Vhost sweeps show effective-bad-rate 0.96 at a raw 404-rate of 0.00 — a naive defender sees zero badness. Method+h…

TI-2026-086Q

🧥 The robots.txt Tell: The Handshake a Crawler Declares and an Impostor Mimics

robots.txt is the crawler's declared first act. The verifiable crawlers fetch it from their real networks; the crude .env fleets skip it; the careful fake ClaudeBot mimics it — but provenance still convicts. A declared…

TI-2026-086R

🧥 The Wordlist as a Blueprint: Reading the Attacker's Model of Your Estate

The attackers' .env dictionary, DevOps credential list and subdomain guesses are a reverse-engineered blueprint of the modern estate — commodity, current (claude:Claude2026!, qdrant, comfyui), and partly generated from…

TI-2026-086S

🧥 The Rhythm: Timing as a Fingerprint the Mask Cannot Change

The mask is interchangeable; the rhythm is not. A fleet's burst cadence (98k–127k paths/hr, a toolkit fingerprint) and its coordination windows (19 IPs at 1 request each, synchronized) track it across every disguise cha…

TI-2026-086T

🧥 The Estate Map: How One Hostname Becomes a Hypothesis of the Whole Network

The vhost-sweep is the operation's mapping phase: 252 guessed hostnames from 4,331 IPs, built by Host-header enumeration against one ingress — service subdomains, plus inferred MikroTik and Synology appliance DNS. But t…

TI-2026-086U

🧥 The Corroborators: Why Four Sensors Agreeing Collapses the Doubt

No single signal convicts a masked node — the strength is convergence. Four internal sensors (router, CrowdSec, honeypot, web) plus a dozen external feeds agreeing on one IP collapses the false-positive space, and backs…

TI-2026-086V

🧥 The Ones That Passed: A False-Positive Audit of the Wardrobe

A false-positive audit of the wardrobe method. Real crawlers verified from their true networks pass clean; identities the system cannot disprove are held at CLAIMED, never escalated to SPOOFED. The method convicts on di…

TI-2026-086W

🧥 The Semantic Layer: How a Mask Becomes Searchable

A mask defeats a log line but not a semantic index. 157,579 vectors across 21 collections, keyed on network identity not User-Agent, put a masked node one query from its honeypot sessions and every dossier that named it…

TI-2026-086X

🧥 The Economics of a Face: Why the Mask Costs More Than It Earns

A cost-benefit analysis from the adversary's ledger. The mask is free but the IP it rides is rented and confiscated for 168 hours per SPOOFED verdict, while the credentials it hunts do not exist behind the masked-200. C…

TI-2026-086Y

🧥 The Next Rung: Where the Adversary Climbs When the Mask Stops Paying

A forecast. Because the mask is unprofitable at a verifier-backed edge, the rational adversary migrates toward the NO-VERIFIER gap, residential origins, and low-and-slow tempo. The estate's counter to each is already vi…

TI-2026-086Z

🧥 The Identity Layer: What the Wardrobe Means

The finale of The Wardrobe. Twenty-five cases resolve to one rule for the modern edge: the name a visitor gives is inventory, not identity — and every durable defence is built on the axes the name cannot forge. The Ward…

The Raspberry Worm
TI-2026-087A

🤖 The scp Drop: A Self-Propagating Linux IRC Bot from a Compromised Pi

A #!/bin/bash IRC bot (Backdoor:Linux/IRCbot.YA!MTB, MulDrop.14 lineage) captured via scp-push from a compromised Raspberry Pi. First-party strings reveal the C2 (Undernet #biret), an authorized_keys backdoor, a pi-acco…

TI-2026-087B

bug The Self-Made Botnet: The Raspberry Worm Builds Its Own Brood

Part 2 of the Raspberry Worm: the self-propagating MulDrop-fork watched as a population. The same worm recurs a week later; its first-party loop spreads over the Pi default credential turning each victim into a spreader…

TI-2026-087C

satellite The Channel: A Botnet That Lives in Someone Else's House

Part 3 of the Raspberry Worm: the botnet's C2 is not criminal infrastructure but a legitimate public IRC network - UnderNet, channel #biret - un-sinkholable, self-resilient, DNS-hardened, and authenticated by a captured…

TI-2026-087D

key One Key, Six Names: The Operator's Signature Across Four Months

Part 4 of the Raspberry Worm: running the captured operator RSA key across the corpus unifies 13 samples the classifier scattered across six family labels - including four mislabeled as the miner the worm kills. One dur…

TI-2026-087E

chains The Dispossessed: A Census of the Brood

Part 5 of the Raspberry Worm: a census of the brood finds it is mostly its own victims - ~80% compromised residential/telecom devices across the Global South conscripted involuntarily (incl an Argentine town-hall device…

TI-2026-087F

crossed_swords The Kill List: What the Worm Clears to Own the Host

Part 6 of the Raspberry Worm: its killall eviction routine is a census of the Linux/IoT malware it fights - miners, DDoS bots, loaders across 8 CPU architectures - and the honeypot caught exactly that (XMRig x33, RedTai…

TI-2026-087G

shield The Countermeasure: Detecting and Cutting the Raspberry Worm

Part 7 of the Raspberry Worm: a deployable detection-and-response package ordered by IOC durability. One firewall line (egress-deny 6667) cuts C2 even for undiscovered infections; a YARA rule on the operator key catches…

TI-2026-087H

headphones The Other Tenant: A Modern PAM Backdoor on the Worm's Ground

Part 8 of the Raspberry Worm: the honeypot's 'persist corner' is a SEPARATE operation - a modern Go cgo-libpam credential-harvesting toolkit that hooks the Linux auth chokepoint. A silent wiretap opposite the worm's lou…

TI-2026-087I

deciduous_tree The Lineage: A 2017 Worm, Forked and Turned Against Its Parent

Part 9 of the Raspberry Worm: it is a documented fork of the 2017 Linux.MulDrop.14 worm. It kept the parent's propagation body unchanged (nine years, because pi:raspberry was never fixed) but inverted its purpose - the…

TI-2026-087J

vertical_traffic_light The Crossroads: Whisper, Nexus, and the Botnets That Share the Worm's Door

Part 10 of the Raspberry Worm - find the unexpected: the honeypot is a crossroads where >=5 botnet operations converge, including Whisper, an 18-architecture Mirai with a Windows PE dropper, and its sibling Nexus. Both…

Bulletproof Hosting
TI-2026-088

🛡️ The DMZHOST Trinity: One Operator, Three Shells, Two Autonomous Systems

Two UK shell companies, two autonomous systems, one bulletproof operator: how UNMANAGED LTD (AS47890) and DMZHOST / TECHOFF SRV LIMITED (AS48090) merge — not on paper, but through a dual-origin prefix and a single Gmail…

TI-2026-088B

🛡️ The Fourth Prefix: 193.32.162.0/24, and the Discipline of Not Over-Claiming

A fourth Romanian /24 (193.32.162.0/24) announced by AS47890 carries the same TECHOFF-MNT maintainer and dmzhostabuse@gmail.com abuse desk as the documented DMZHOST prefixes — the same operator, not a co-tenant.

TI-2026-088C

🛡️ The Bunea Sponsor: A Romanian Telecom Underwrites a UK Shell — and the Upstream That Wasn't

RIPE RDAP names Bunea TELECOM SRL as the sponsoring organisation behind AS42397/62380/35478 near the DMZHOST cluster — a durable attribution anchor. The apparent 'nested ASN tree' among them is rejected as a shared_bgp_…

TI-2026-088D

🛡️ The Tenant: What Actually Runs on the Bulletproof Floor

A GPU-hunting, profile-first loader campaign ('The Appraiser', TI-2026-083C) runs on DMZHOST's bulletproof floor — but the same toolkit also runs from a rival host, marking the operator as a tenant, not DMZHOST itself.…

TI-2026-088E

🛡️ The Empty Arsenal: A Bulletproof Cluster That Weaponizes No CVEs

Across all 20 IPs of the DMZHOST bulletproof cluster the honeypot recorded zero CVE exploitation — the entire observed threat is SSH credential brute-force. The absence is the finding: harden authentication and blocklis…

TI-2026-088F

🛡️ The Dual-Origin Prefix: One /24, Two Autonomous Systems, One Maintainer

RIPE holds two live route objects for 2.57.122.0/24 — origin AS47890 and origin AS48090 — both signed by the same TECHOFF-MNT maintainer, proving one operator controls both DMZHOST autonomous systems and can flip the pr…

TI-2026-088G

🛡️ Jingle Shells: The Virtual-Office Facade Over a Bulletproof Network

The DMZHOST operation hides behind the appearance of ordinary UK companies — a dormant shell with a non-hosting SIC code at formation-agent virtual addresses, one of them a self-storage facility — refreshed by shell sub…

TI-2026-088H

🛡️ The Adjacent Operator: Why AS197170 Is Not DMZHOST

AS197170 (TechTies/HostSlick, Seychelles) shares DMZHOST's tooling and tenants but is a separate operator — a different registration, a different maintainer (techties-mnt), and no same-operator edge in the entity graph.…

TI-2026-088I

🛡️ Jurisdictional Arbitrage: One Operator, Six Countries, No Accountability

Ask what country the DMZHOST network is in and the registries give six answers — GB registration, RO/NL routing, Andorra and Netherlands RDAP claims, Bulgaria routing data, Romania and Seychelles Spamhaus attribution. A…

TI-2026-088J

🛡️ The Directors: Two Names on the Paperwork, One Firewall Between Them

Two named directors front the DMZHOST shells — a Romanian and an Italian, on companies incorporated four years apart — a corporate split engineered as a legal firewall. The human layer is a deliberate dead end; its one…

TI-2026-088K

🛡️ The Arsenal on the Floor: Commodity Weapons, Borrowed Ground

Where 088E proved the host weaponizes no CVEs, the tenants deploy a real but entirely commodity arsenal — AdaptixC2, a Google-Cloud-staged backdoor loader, XMRig, RedTail, a Kaiten IRC botnet. And the deeper threads (a…

TI-2026-088L

🛡️ The Tenant's Second Floor: The Same Tool, a Borrowed Bank, a Faceless Operator

The shared tenant's footprint on the rival host TechTies confirms it is The Appraiser — its bespoke GPU-profiler runs on all 12 hosts — and exposes a second maintainer-signed dual-origin whose second ASN is a repurposed…

TI-2026-088M

🛡️ The Enabler: The Reseller Pool Beneath Two Investigations

Following the TechTies maintainer to the reseller layer connects the DMZHOST tenant story to the EMBNEX 'Costume Catalog' foundry: one Bulgarian/German reseller pool (Telco power Ltd, mnt-bg-eurocrypt-1, ZeXoTeK) provis…

TI-2026-088N

🛡️ The Full Brood: One Reseller Substrate Beneath Three Investigations

A reverse-maintainer census of the reseller pool behind TechTies reveals its shared handles bridge three previously-separate bulletproof investigations — the German Phantom ASN cluster, the EMBNEX Costume Catalog, and D…

TI-2026-088O

🛡️ Closing the Census — And Why It Doesn't Close

Resuming the blocked reverse queries closes the identities but blows open the scale: the enabler is an industrial registration substrate — Via-Registry (~48 ASNs/136 orgs), RTM Networks, Euro Crypt EOOD — of which the c…

The Recidivists
TI-2026-089A

🔨 The Ladder: How Persistence Gets Punished, One Tier at a Time

The LSN estate runs a custom escalating-ban manager that tiers repeat offenders 3h->1wk->1mo->1yr and bans whole /24s when a range keeps climbing. Since March it distilled 2,700 attackers into 23 hard-core recidivists a…

TI-2026-089B

🔨 The Repeat Offenders: Twenty-Three Rap Sheets

**TI-2026-089B — The Recidivists series · Part B · Addendum to [TI-2026-089A "The Ladder"](https://www.shuffle-on.com/threat-intel/ti-2026-089a-the-ladder)**

TI-2026-089C

👁️ The Familiar Faces: How Many Recidivists We Already Knew

**[DOCUMENTED]** Its external reputation predates our ladder by years:

TI-2026-089D

🧱 The Subnet Verdict: When One Block Answers for All of It

There is no subtlety in the blast radius. A `/24` ban is a single firewall entry — `x.y.z.0/24` — that rejects all 256 addresses. The escalator does not check which of those addresses were actually hostile; it does not…

TI-2026-089E

☁️ The Cloud Recidivists: The Fleet That Scatters to Survive

Here are the cloud hosts from the tier-3 roster, each with the `/24` it occupies.

TI-2026-089F

🔑 The Supply Underneath: The Recidivists' Landlords Were Already in the File

For each provider I pulled the pipeline's bulletproof assessment — an automated read of an ASN's abuse posture — and its *cross-corpus* count: how many previously published dossiers already cite that provider's infrastr…

TI-2026-089G

mag The First New Address: Pursuing Zkillu, the Lead the Ladder Found

Pursuing the one recidivist-hosting provider no prior dossier had: Zkillu SAS, a 2024 French shell announcing two decades-old geo-smeared legacy /24s, all IPs critical-abuse, its attacking range fronted by a managed abu…

TI-2026-089H

ghost The Vanishing Majority: The Attackers the Ladder Cannot Count

The honeypot's SSH brute-force flood is the ladder's biggest ban source (1188 IPs) yet produces zero year-ban recidivists - 83% one-and-done. It reveals that 'recidivism' measures infrastructure reuse, not adversary per…

TI-2026-089I

performing_arts The Counterfeit Crawlers: Forging Googlebot, ClaudeBot, and the New Identity Theft

~160 IPs forge trusted-crawler identities - Googlebot (69 from Google's OWN cloud), ClaudeBot, ChatGPT-User - to inherit allow-listed exemptions. AI-crawler impersonation is the new identity theft. A verification-first…

TI-2026-089J

⚖️ The Recidivists · Addendum — The Fleet That Wasn't: Retracting Fake-ClaudeBot

Part 9 of this series named a fleet. Twenty-three addresses inside a single Amazon `216.73.217.0/24`, all announcing themselves as Anthropic's crawler, presented as the lead illustration of a new kind of identity theft…

The Toolkit
TI-2026-090A

toolbox One Binary, Many Masks: The Go Toolkit Behind the Honeypot's Miners and Backdoors

Opening The Toolkit: the honeypot's largest family - 33 'XMRig' samples - is not a miner but a modular Go agent carrying XMRig as one config preset. A shared cgo build hash (eba3282b571c) proves it is the same codebase…

TI-2026-090B

pick Two Miners, No Wallet: The Toolkit's Deliberately Missing Money Trail

Part 2 of The Toolkit: it carries two miner presets - XMRig (CPU/Monero) and NBMiner (GPU) - to mine whatever hardware it lands on. But the pool and wallet are deliberately absent from the binary - empty runtime-config…

TI-2026-090C

performing_arts Half the Honeypot: One Toolkit Wearing Ten Names

Part 3 of The Toolkit: measuring its true footprint finds that 42 of the honeypot's 81 retained samples - 52%, the majority of all serious malware at the sensor - are one operator's Go platform, scattered by the classif…

TI-2026-090D

abacus The Widest Net Is 389 Bytes: The Honeypot's Real Operator Census

Part 4 of The Toolkit: clustering the honeypot's whole 81-sample corpus by durable build artifact collapses ~20 family labels into ~6 operators - three artifacts are 83% of everything - and reveals the inversion: the wi…

The Skeleton Key
TI-2026-091A

key The Skeleton Key: One Public Key, a Hundred Hands, a Single Owner

The honeypot census's widest-reaching artifact - 389 bytes, 100 distinct source IPs, four months - is one byte-identical SHA-256: a single fixed ssh-rsa key with the comment 'mdrfckr' and RSA exponent 37, the decade-old…

TI-2026-091B

key The Eviction: How the Widest Net Takes a Machine by Emptying It First

The command that plants the Outlaw mdrfckr key - byte-identical across 100 source IPs - is not an append but a demolition: rm -rf .ssh destroys the victim's keys, their known_hosts, and any rival's backdoor before insta…

TI-2026-091C

lock The Immutable Lock: The Backdoor That Cannot Be Removed by Deleting It

A second, far more advanced SSH-key operator makes its planted key immutable with chattr +ai - so no rival, no cleanup, and not even root can remove it without first clearing a kernel attribute most responders never che…

TI-2026-091D

card_index The Harvest: When the Backdoor Is the Victim's Own Key

A third SSH-key operator plants nothing - it harvests: a single find sweep enumerates the victim's own private keys, known_hosts map, and .ssh/config network diagram, the exact material to authenticate as the victim to…

The Broad Sweep
TI-2026-092A

globe_with_meridians Try Them All: RedTail and the Discipline of Covering Every Architecture

RedTail is the honeypot census's breadth exemplar: its loader ships XMRig for every architecture and, when it cannot name your CPU, runs every binary until one executes. Two waves ten days apart show a maintained codeba…

TI-2026-092B

globe_with_meridians The Same Server, the Wrong Binary: Two Operators Collapse Into One

A correction: the download log links http://31.170.22.205/bins/whisper.armv5 to the exact Windows calc.exe PE the census read as a separate operator. Whisper and the 'Windows misfirer' are one - the staging server serve…

TI-2026-092C

globe_with_meridians The Neighborhood: A Staging Server Is Never Alone

The Whisper staging server is not a lone VPS: the intel graph resolves it into a two-network crew that scans from w1n ltd (UK) and stages on Sia Nano IT (Latvia), joined by a shared paramiko HASSH, sitting in a bulletpr…

TI-2026-092D

globe_with_meridians The Arch Oracle: How Breadth Decides Which Binary to Drop

Before breadth drops a binary, it asks the machine what it is - by four kinds of uname, by raw /proc/cpuinfo flags when uname is gone, by device-tree model name, by GPU probe - and asks whether the machine is real, by w…

The Long Tail
TI-2026-093A

ghost The Staged Sweeps: Two Botnets Hiding as Singletons

Two of the honeypot census's 'singletons' are full multi-architecture botnets - Whisper (~30 arches, C2 in Latvia) and Nexus (14 arches, payload disguised as sshd, C2 behind a UK reseller) - that dropped only a loader a…

TI-2026-093B

detective The Fingerprint Without a Face: One Operator, Four Names, No Legible Function

Four Go binaries dropped on one day, which the classifier split into two families and four confident names, are one operator's toolset - proven by a shared runtime marker and identical entropy. Their function is deliber…

TI-2026-093C

telescope Profiling the Prey: The Reconnaissance Layer, and a Binary That Missed the Planet

The honeypot census's reconnaissance layer: neofetch, a beloved open-source tool dropped 10 times to triage the victim's CPU, RAM, and GPU (mining intent, revealed before any payload), and a Windows calc.exe test binary…

TI-2026-093D

scroll The Final Accounting: Reading the Tail, Counting the Board

The honeypot census, closed: read rather than weighed, its 81-sample corpus is about ten operators - not the twenty-plus the family labels imply nor the six the drop-weights suggested - in four strategies (depth, breadt…

Do You Know You're a Honeypot?
TI-2026-094A

eyes The Named Trap: Attackers Who Check for the Honeypot by Name

A growing fraction of attackers check whether a compromised shell is a honeypot, and the crudest way is by name: a canned roll-call that greps for the famous default user 'phil', for ten named honeypot projects' process…

TI-2026-094B

eyes The Emulation Test: Can This Shell Add Two Numbers?

A tier of attacker checks not what the trap is named but what its shell can do: echo $((1337+1337)) - a real bash computes 2674, a naive emulator echoes it literally. Behavioral detection can't be renamed away because f…

TI-2026-094C

eyes The Empty Room: A Honeypot Has Nothing in Its Drawers

The hardest honeypot check ignores the disguise and probes emptiness: DMI for real hardware, and a find for the .env files, secrets, and lived-in mess a real machine accumulates and a stage-set filesystem lacks. The sec…

TI-2026-094D

eyes The Arms Race: The Sensor Reading the Attackers Reading the Sensor

The close: honeypot-detection is automated (machine-parsed checks baked into kits), distorting (they run first, so the sensor sees the incautious clearly and the cautious only in silhouette - biasing every census toward…

Below the Noise Floor
TI-2026-095A

🔌 The /dev/tcp Dropper: A Downloader That Needs No Downloader

A loader family that falls back to bash's built-in /dev/tcp raw socket to fetch its payload when curl and wget are absent — living off the shell to defeat host hardening and egress filters. Mapped across 17 honeypot-cap…

TI-2026-095B

🕵️ The Tunnel Scout: A One-Shot Probe That Interviews the Box for a Proxy Job

A one-shot honeypot capture: a single operator interviews the box for a proxy job — reading the sshd_config forwarding directives that decide tunnel capability, checking for chisel/gost, and fingerprinting MikroTik/Open…

TI-2026-095C

🎯 The Weaponizers: The Sixteen Edges the Graph Will Vouch For

In a 985,859-entity intelligence graph with 92,869 'vulnerable_to' posture edges, the offensive 'targets' relationship exists on just 16 edges. Those sixteen — promoted from a new web-threats CVE-correlation engine — ar…

TI-2026-095D

👻 The Equifax Ghost: One DigitalOcean Droplet per Host, Nine Years On

66 DigitalOcean droplets throwing CVE-2017-5638 — the nine-year-old Apache Struts2 S2-045 RCE that breached Equifax — at essentially every host in a homelab's published estate, one droplet per subdomain, 59,318 hits. A…

TI-2026-095E

🦅 The Config Vultures: A Google-Cloud Fleet Wears the Wayback Machine to Strip Every Secret

A Google Cloud fleet (AS396982, ~143 nodes) spoofing the Internet Archive Wayback bot bursts a 271-path secret-harvesting sweep — AWS/GCP creds, SSH keys, Terraform state, CI/CD pipelines, Spring actuator heapdumps, DB…

TI-2026-095F

📋 The Roll Call: Harvesting the WordPress Register Before the Siege

A 41-IP multi-provider swarm — anchored by offshore bulletproof-adjacent hosting (ColocaTel, Seychelles), not mainstream cloud — hammers one host in a day to harvest the WordPress register: usernames, IDs and roles via…

TI-2026-095G

🏰 The Siege: The xmlrpc POST Assault That Follows the Roll Call

The weaponization that follows the roll call: a Russian/offshore fleet POSTs to xmlrpc.php across every mount-point variant on a homelab's estate for weeks, abusing the endpoint the recon located. Shared source IPs prov…

TI-2026-095H

🧬 The Seven: Exploit Breadth and the Toolkit Families Behind the Web Attacks

Intersecting 11 web-CVE rosters: 318 attacker IPs, 212 throw one exploit, 99 throw two, only 7 throw three — and breadth never crosses toolkit families. The versatile few stay in their lane (WordPress/xmlrpc, the Struts…

The Unannounced
TI-2026-096A

🕳️ The Dark Census: 197 Autonomous Systems That Route Nothing

A forensic census of 197 autonomous systems that route nothing. Reading the entity graph's change-log as an instrument, the allocated-but-dark ASN population stratifies into a bulletproof reserve of operators we already…

TI-2026-096B

🏭 One Company, Two Dozen Numbers: The Contrust Accumulator

Inside the dark census, one Moldovan SRL holds the largest sub-cluster: Contrust Solutions accumulated ~two dozen autonomous systems across 2017–2019, in both 16-bit and 32-bit AS space, all now dark — zero prefixes, ze…

TI-2026-096C

🧑‍💻 The Retail Floor: Autonomous Systems Held in One Person's Name

The dark census's individual-name stratum: autonomous systems held by a single person, not a company — Manilich (AS39720), Mashayekhi (AS214357), Nebaba (AS214422, with a .lol vanity site), Berdiev (AS214576), a mid-202…

TI-2026-096D

🔀 Change of Hands: Reading the Ownership-Churn Feed Without Fooling Yourself

The change-log's biggest stream, owner_changed (9,239 events), is also its least reliable — and reading it honestly is the point. Most are data-pipeline re-mappings (Comcast internal renumbering, Prolexic folding into A…

TI-2026-096E

🪪 Putting On a Face: What the Rename Feed Reveals About Identity

The change-log's smallest, cleanest stream — renamed (187 operator-authored peeringdb events) — records the inverse of going dark: an autonomous system acquiring a name. Three types: a bare number gaining a human face (…

TI-2026-096F

📖 The Ledger of Change: Lifecycle as an Intelligence Vector

Synthesis of The Unannounced: reading the entity graph's change-log as a distinct intelligence vector. Point-in-time attribution sees the flow; lifecycle sees the stock and the transitions. The three streams — taken_dow…

TI-2026-096G

🎠 Running the Carousel Down: What Joining the Streams Actually Finds

The experiment 096F left open: join the change streams, trace a prefix's ownership history, catch a carousel turning. Run honestly, it inverts intuition. The flashy multi-hop candidate (a /24 oscillating PINKMARE↔ODCLOU…

Reading the Drop
TI-2026-097A

📥 Count Is a Lie: The Honeypot's Top Malware Is a Newline

Rank a honeypot's dropped-file corpus by download count and the table lies: the #1 'payload' across 100 IPs is the mdrfckr SSH backdoor key (not a binary), #2 across 67 IPs is a single newline, #4 is the empty string, a…

TI-2026-097B

🐛 The Signed Worm: Anatomy of the #biret Raspberry Pi Bot

A full teardown of the severity-100 sample TI-2026-097A buried at #5 by count: a 4.7 KB bash Raspberry Pi IRC worm (Linux.MulDrop lineage, ~2017, still landing in 2026). It roots via rc.local + authorized_keys, resets t…

TI-2026-097C

🧩 One Binary Per CPU: The Cross-Architecture Build Matrix

Three delivery operations in the honeypot's drop corpus each ship one miner compiled for a matrix of CPUs: RedTail for x86_64/i686/arm7/arm8/RISC-V (rebuilt between campaigns), a Mirai-style host for i386/m68k/aarch64/L…

Counter-Recon
TI-2026-098

🔦 Who Scans the Scanners: The Attack Surface of the Machines That Attack Us

When the honeypot scans its attackers back — via Tor, auto-triggered at high threat — the population that returns is not disposable IoT bots but exposed servers: 37% of 1,676 attacker IPs run a full stack of SSH/web/dat…

TI-2026-098B

⚙️ The Machinery of the Scan-Back: Trigger Ladders, Tor Rotation, and the Reachability Split

How the honeypot's scan-back actually works — and why its headline number is softer than it looks. A graduated trigger ladder (threat + hit count pick scan depth), Tor-exit rotation for anonymity, and a discovery-only p…

The Complaint Department
TI-2026-099

📇 The Complaint Department: Who Is Actually Accountable for the Attacks

The honeypot's 749 'persons' are not the attackers — they're the WHOIS abuse contacts you'd report the attacks to, and read as a graph that accountability layer is a mirage. In the top 100 contacts, four shared mailboxe…

The Quiet Transit
TI-2026-100A

🚦 The Quiet Transit — AS41745, One Moscow Flat, and Five Names

**Investigation window: 2026-05-21 → 2026-07-26** · **Subject: AS41745 (FORTIS-AS), RIPE NCC**

TI-2026-100B

🚦 The Quiet Transit, Part B — The Flag That Fired on Spectrum

Our platform rated Charter Communications a bulletproof host at risk 90.4. The evidence was three compromised MikroTik routers on Spectrum Business lines. This is the correction — and the fix, now deployed and verified.

TI-2026-100C

🚦 The Quiet Transit, Part C — The Table of Seven Dashes

One table listed eleven upstreams. Seven had an em-dash where the operator name should be. One dash was a US Treasury-sanctioned bulletproof host. Another was a darknet operator this corpus had unmasked 46 hours earlier.

TI-2026-100D

🚦 The Quiet Transit, Part D — Aeza, or What a Sanction Does Not Do

OFAC and the UK NCA designated Aeza Group as a bulletproof host in July 2025. Twelve months on, both its ASNs are still registered, still routed, still announcing 107,000 addresses through 85 BGP neighbours — and its de…

TI-2026-100E

🚦 The Quiet Transit, Part E — SABOTAGE LLC, and the Discipline of Not Knowing

The last unexamined row in the table. Four sources give four different countries, the address is an Amsterdam mailbox, and 17 of its 256 addresses sit on a feed we ingested once. Our sensor has never seen it. This is a…

TI-2026-100F

🚦 The Quiet Transit, Part F — Six Flags, Five Registries, One Blind Spot

Six Spamhaus-listed networks the corpus cited and never examined. They share one flag and almost nothing else — five registries, 22 years to 4 months, 280,000 addresses to 1,024. But two of them share something we did n…

TI-2026-100G

🚦 The Quiet Transit, Part G — The 2026 Wave: Seven Old Numbers, New Owners

Seven autonomous systems carrying up to 15.8 years of routing history changed hands in the first five months of 2026 — one every few weeks, all through one registry, each behind its own name. Not one actor. A market, an…

TI-2026-100H

🚦 The Quiet Transit, Part H — The Brokers: A Layer That Never Attacks Anyone

> No conclusion should be drawn about the status of `lir-bg-telco-1-MNT` from this dossier. Every other measurement in it was taken before the limit was reached and is unaffected.

TI-2026-100I

🚦 The Quiet Transit, Part I — The Ones the Filter Hid

The query that built this series' backlog contained the clause AND ips > 0. It hid seven Spamhaus-listed networks — including two siblings of an ASN we had already published as low risk. A dossier about auditing your ow…

TI-2026-100J

🚦 The Quiet Transit, Part J — The Phantom Finding

Part H reported that a maintainer handle had vanished from the registry. It had not. The zero was an HTTP 429 error body parsed as an empty result — the fourth time this series has caught itself using a value without ch…

The Machine Readership
TI-2026-101A

📖 The Machine Readership: 19,494 Agent Requests, 918 Dossiers Served, and a Name Anyone Can Wear

That closed one door and left another open. If not the actors, then who?

TI-2026-101B

🔑 The Account Named Claude — How AI Tooling Entered the Attacker's Dictionary

Part A counted the readers. This one counts something less flattering: the people trying the door.

The Census
TI-2026-102A

📐 The Census: A Scanner That Breaks In, Asks What You Are, and Leaves

Then it typed `uname -s -m`, read the answer, and hung up.

TI-2026-102B

🎭 The Wardrobe: Fifty-Six Identities in Five Seconds

A fleet on Google Cloud wore 56 identities in five seconds — every major AI crawler — to find which name opens a door. It never once read robots.txt, while wearing the name of a robots.txt directive.

TI-2026-102C

📖 The Readers: Who Is Counting the Counters

Four AI crawler fleets have read 24,712 pages of this corpus — including 804 cryptographic verification pages. All of them ask for robots.txt. The counterfeit fleet never did.

TI-2026-102D

🚪 The Door That Answers: How Our Blocklist Taught the Fleet Which Names to Wear

A fleet asked our edge which crawler names it would accept. It got a complete answer in 5.02 seconds, dropped the two that failed, and never used them again.

TI-2026-102E

👻 The Fleet That Never Was: Eighty-Five Addresses That Cannot Exist, Counted as an Adversary

A high-confidence campaign in our own corpus described 85 hosts that cannot exist. Corrected 2026-08-09: they entered via forged X-Forwarded-For, not impossible traffic — and the corpus has now been purged.

TI-2026-102F

🏢 The Landlord: Half the Impersonation on This Estate Is Rented From the Company Being Impersonated

Googlebot is impersonated seven times more often than it is used, and 73 of the 116 impostors rent their machines from Google Cloud. Two Google ASNs share one organisation string — only one of them can be trusted.

TI-2026-102G

🕳️ Null: Eight Hundred Requests for a Page Nobody Ever Wrote

A URL we never published has been requested 821 times in two months and answered 404 every time. Our side is provably clean; the client invents it. An access log records what clients believed you published, not what you…

TI-2026-102H

🚪 The Wildcard: Why Every Hostname They Invent Comes Back Alive

324 hostnames that do not exist have drawn 92,466 requests, because a wildcard makes every invented name resolve, trusted and answered — and the largest sweep is a verified AI training crawler, not an attacker.

TI-2026-102I

🚪 Nobody Knocked: The Login Portal Is the Least-Attacked Surface on This Estate

Three auth-protected hosts took 18,517 requests in 70 days. The endpoint that accepts a password was hit four times, by two account holders. Nobody attacks the lock any more — 1,687 addresses were checking whether the k…

TI-2026-102J

🪞 The Hits We Advertised: Five Weeks of Saying Yes to Files We Never Had

For five weeks two services on this estate answered HTTP 200 to any filename a scanner invented — 1,015 nonexistent paths, including 54 spellings of cloud credential files. Nothing leaked, because none of them existed.…

TI-2026-102K

📱 The Nexus 5: Nine Hundred and Sixty-Four Addresses Wearing One Dead Phone

964 addresses, 470 networks, 80 countries, one request each — and every one claiming to be the same phone discontinued in 2015. A residential proxy pool harvesting a public corpus, and why per-IP defence cannot see it.

TI-2026-102L

👁️ The Watchers: Seven Thousand Addresses to Read One Page

Fixing four measurement defects changed 7.9% of the corpus and revealed 7,109 addresses that had been arriving for two months — each fetching one page, almost always the same one. Not harvesting the corpus. Watching it…

TI-2026-102M

🧠 The Model Hunters: Seventy-Four Addresses Came for the GPU and Left With Nothing

74 addresses spent two months hunting for an exposed LLM inference endpoint on an estate that genuinely runs 49 models and 507 GB of them. They never got a single model listing. A letter about a negative result.

TI-2026-102N

🤫 The Silent Majority: What the Instrument Declines to Say

The classifier has no opinion about 62% of everyone who visits. Three tests show its silence is almost always correct — and then reveal the one 169-address campaign it was hiding.

The Loud Hour
TI-2026-103A

📊 The Census

presentation · **node-connection** = connections from a single source address.

TI-2026-103B

🕰️ The Metronome

> **Updated 2026-07-30.** Three open items in §9 are now **closed** by later letters, including **point 5 — the pivot this letter said the series turns on**. Letter E answered it a third way this letter did not consider…

TI-2026-103C

🪪 Who Goes Loud

Per **R8**, a derived index's silence is evidence about the index, not the world.

TI-2026-103D

⚙️ The Recipe

presentation · **node-connection** = connections from a single source address.

TI-2026-103E

🔑 Two Words

> **Updated 2026-07-30.** The full fleet wordlist, listed here as unrecoverable without per-address enumeration, was **recovered in Letter H** by querying the fingerprint instead. A second correction affects §5. Origina…

TI-2026-103F

🔇 The Silence: Twenty-Three Thousand Open Doors, and What Came Through None of Them

A hundred and thirteen machines installed a backdoor. Twenty-seven ran a honeypot detector for 25 days and never read the answer. The ten that opened the most doors took nothing.

TI-2026-103G

🏛️ Paper Companies

methodology, **a documented absence of an anchor is itself a finding.**

TI-2026-103H

📒 The Ledger: Three Upstreams, No Peers, and an ASN Younger Than Its Own Campaign

Three transit contracts hold up a network Spamhaus has already blacklisted. The wordlist hunts game servers. And the bulletproof ASN turns out to be a landlord, not an actor.

TI-2026-103I

🩹 Nothing to Exploit

> **Updated 2026-07-30.** §10's disjointness question is **closed by Letter J, and the answer is no** — 1,751 addresses appear on both sensors. This letter's own suspicion about testing at the extremes was correct. Orig…

TI-2026-103J

🕸️ The Graph: The Corpus Already Knew, and the Clustering Only Counts to Two

Nine letters of work, and the corpus had already published the biggest finding. Plus: why every clustering layer in this dataset counts to two and stops.

TI-2026-103K

🥱 The Boring Explanations

mundane explanation for every finding and give it the strongest possible case. Several win.

TI-2026-103L

⚖️ What If: The Evidence That Would Prove Targeting, and the Seven Tests the Record Fails

Eight dossiers name this address. It has never once loaded the site that published them. The falsification criteria for targeting, stated first and then tested.

TI-2026-103M

🎯 The Fleet Test

**This letter measures coordination directly and refines a pacing figure from Letter D.**

TI-2026-103N

🛡️ Detection

fourteen letters, reassembled as a specification for what should have found these actors.

TI-2026-103O

🔬 The Instrument

primary data. `[INFERRED]` = reasoning over observations, with confidence bounded.

TI-2026-103P

🏛️ The Sponsor

Two handles resolved after publication: ru-avm-1-mnt is a sponsoring RIPE LIR, not an operator link — a correction to Letter C — and vmheaven.io advertises port scanning as a feature, closing the operator question as un…

TI-2026-103Q

🚪 The Accept List

The mdrfckr cohort was Outlaw all along and already published five times over; investigating it showed the sensor regime called accept-all refused 82,921 credential attempts, including every one of the botnet's markers.