Forensic investigations of real threat actors observed attacking a personal SSH honeypot. Every finding backed by evidence. Every claim sourced.
Investigation into W1n LTD, a UK-registered company operating bulletproof hosting infrastructure used for SSH brute-force campaigns. Traces company registration, network allocation, and abuse patterns from honeypot obse…
A precisely synchronized botnet of 15 compromised residential devices across 14 countries executes an identical 9-step reconnaissance playbook, exfiltrating credentials via Telegram bot API. Traces the infection chain f…
30 Baidu Cloud IPs in the 120.48.x.x range launched 671 coordinated attack events against our honeypot. Investigates whether China's second-largest cloud provider is negligent, complicit, or compromised.
31 Google Cloud Platform instances across 5+ regions generated 4,208 attack events. The primary behavior is OS fingerprinting — silent reconnaissance that maps target infrastructure without triggering traditional IDS al…
Two distinct SSH worm families operating in parallel: one with sophisticated anti-forensic capabilities that erases its own tracks, the other a blunt proxy-shell dropper. Both exploit the same credential lists but serve…
A Romanian-language love letter found in honeypot SSH session logs. What appears to be an accidental paste reveals an operator's human moment — and raises questions about who sits behind the keyboard of automated attack…
Maps the economics of compromised SSH credentials — from initial brute-force to darknet marketplace listing. Traces pricing models, bulk discount structures, and the supply chain that turns a honeypot login into a monet…
A coordinated Outlaw/Shellbot campaign captured over 34 days of continuous operation. Documents the complete attack chain from SSH brute-force through cryptominer deployment, IRC C2 communication, and SSH key harvesting…
The Outlaw/Shellbot SSH backdoor key documented at 56 machines in TI-2026-008 has grown to 81 across 20+ countries, per the intel-linker's 2026-07-07 re-link. One planted authorized_keys public key at 0.90 confidence un…
Two parallel SSH brute-force scanner families sharing the same libssh fingerprint but operating distinct credential lists and targeting strategies. Evidence suggests a single operator running A/B testing on attack metho…
Attackers systematically fingerprint GPU hardware through SSH sessions, deploying cryptominers optimized for the detected hardware. Documents the technical sophistication of mining-focused threat actors who treat compro…
Beyond automated brute-force — documenting SSH sessions where human operators manually explore compromised systems. Interactive commands, typos, and browsing patterns reveal the people behind the scripts.
Deep forensic analysis of the 'mdrfckr' botnet — a cryptojacking operation that combines SSH brute-force propagation with XMRig deployment, process hiding, and competitor elimination. Documents the complete kill chain f…
The Krane botnet targets containerized environments, detecting Docker and Kubernetes installations before deploying specialized payloads. Documents how modern botnets have adapted their propagation strategies for cloud-…
Statistical analysis of attack burst patterns reveals distinct operational phases — reconnaissance sweeps, credential spraying, and exploitation waves — each with characteristic timing signatures that fingerprint threat…
Investigation into the 'echo BMOK' command pattern — a callback beacon used by multiple threat actors to verify successful command execution on compromised hosts. Traces the pattern across campaigns and maps the C2 infr…
Six weeks after TI-2026-015, the near-unique OpenSSH 10.0p2 Debian 13 fingerprint (HASSH eeca2460) spread from 2 to 4 nodes. Shodan proves the banner authentic and portable across the operator's own VPS and a compromise…
Documents covert data exfiltration techniques observed in honeypot sessions — from DNS tunneling and ICMP channels to steganographic encoding in seemingly benign traffic. Maps the infrastructure that enables persistent…
421 IP addresses from state-owned telecoms, military networks, universities, children's educational platforms, and government data centers caught attacking our honeypot. The uncomfortable question: are these compromised…
A Go-based DDoS botnet operated from KataBump, a French 'Free Discord Bot Hosting' platform. Traces how legitimate hosting services become unwitting infrastructure for botnet C2, and how a cat-themed service enables den…
The master investigation that maps the interconnected web of threat actors, bulletproof hosters, and credential markets operating against our honeypot infrastructure. The starting point for a 13-part deep dive into the…
Reverse-engineering the automation frameworks behind mass SSH brute-force campaigns. From credential generation algorithms to distributed scanning architectures — the industrial machinery that turns vulnerability into a…
Tracing the financial flows from compromised SSH credentials through cryptocurrency mixers, darknet marketplaces, and legitimate payment processors. Maps the money laundering infrastructure that converts unauthorized ac…
Investigation into how misconfigured servers, default credentials, and forgotten services create the 'open doors' that attackers systematically discover and exploit. Maps the gap between security best practices and oper…
Network analysis revealing the hidden connections between seemingly independent threat actors. Shared infrastructure, credential overlap, and temporal correlation expose the cooperative relationships that define the cyb…
Cataloguing anti-forensic techniques observed in live honeypot sessions — log deletion, timestamp manipulation, process hiding, and evidence destruction. Documents how sophisticated operators cover their tracks in real-…
How a single unpatched vulnerability cascades through interconnected systems — from initial compromise through lateral movement to full network takeover. The broken window theory applied to internet infrastructure secur…
Documents the self-reinforcing cycle where compromised servers become attack infrastructure, generating new compromises that generate new attackers. Maps the exponential growth dynamics of botnet propagation.
Analysis of a sophisticated three-pronged attack methodology combining credential brute-force, vulnerability exploitation, and social engineering — deployed simultaneously against the same targets for maximum success pr…
Economic analysis of the cybercrime marketplace — supply and demand dynamics, pricing mechanisms, specialization and division of labor. How market forces shape the evolution of threat actor behavior and attack methodolo…
A four-dimensional classification framework mapping threat actors by capability, intent, infrastructure, and persistence. Positions each honeypot-observed actor in a threat landscape that reveals strategic patterns invi…
Organizational analysis revealing hierarchical structures within cybercrime operations — from script-kiddie foot soldiers through mid-level operators to the architects who design the infrastructure. The cathedral model…
A honeypot-captured multi-phase scanning operation from Max-Planck-Institut für Informatik (MPI-INF), Saarbrücken — 14 disclosed scanning servers, global AWS vantage points, and undisclosed Tor-routed operations that co…
Maps the shell company networks that provide corporate facades for bulletproof hosting operations. Traces nominee directors, formation agents, and the geography of paper companies from the BVI to London to Seychelles.
Forensic investigation tracing a darknet operator through operational security failures. From cryptocurrency transactions through hosting records to real-world identity — the unmasking of a threat actor who thought they…
How bulletproof hosting providers use corporate roll-up strategies — acquiring smaller operations, merging ASNs, and consolidating IP address blocks — to build resilient infrastructure empires while maintaining deniabil…
Investigation into why the Seychelles — 115 islands with 100,000 people — hosts thousands of companies linked to cybercrime infrastructure. Traces the regulatory gap between offshore incorporation and internet resource…
How offshore hosting operations use European shell companies as legitimate wrappers — UK LTDs, German GmbHs, and Dutch BVs that provide RIPE membership, banking access, and regulatory credibility to fundamentally offsho…
How bulletproof hosting providers construct legitimate-appearing corporate identities — ISO certifications, professional websites, industry conference participation, and governance roles — to deflect scrutiny while enab…
Investigation into how Regional Internet Registries (RIRs) — RIPE, ARIN, APNIC, AFRINIC, LACNIC — allocate and govern IP addresses in ways that systematically enable abuse through policy gaps, lax enforcement, and struc…
How SSH key fingerprints and HASSH hashes become the most reliable attribution signals in threat intelligence. When operators share SSH keys across IPs, they leave an unforgeable identity trail that connects seemingly i…
The synthesis investigation mapping how regulatory gaps, jurisdictional arbitrage, governance capture, and economic incentives combine to create a self-sustaining architecture where internet abuse is structurally profit…
Forensic analysis of why 96% of abuse reports to hosting providers go unanswered — documenting the five architectural failure modes that ensure criminal infrastructure remains undisturbed.
Investigation into tier-2 transit providers who knowingly carry BGP traffic for Spamhaus DROP-listed networks — M247, Stark Industries, Cogent, and the economics of complicity.
Cloud Innovation Ltd's 25+ lawsuits against AFRINIC — the first documented hostile governance capture of an Internet registry, using Seychelles courts to seize African IP resources.
How criminal operators exploit IP reputation system resets to launder tainted address space — cycling through dead ASNs and IP brokers to emerge with clean scores despite continuous abuse.
Structural analysis of why Mutual Legal Assistance Treaties cannot address cybercrime — 6-24 month delays vs infrastructure that moves in hours, non-signatory states, and the jurisdiction-shopping problem.
Follow the money through the bulletproof hosting ecosystem: from $50 shell companies to $300M+ annual industry revenue — the economic incentives that make the architecture self-perpetuating.
Series finale presenting the complete forensic evidence from our honeypot — 8,000+ attacking IPs, 271,000+ entity links proving every structural claim in this series through direct observation.
How Stark Industries Solutions — incorporated 14 days before Russia invaded Ukraine, run from Transnistria by a cybercrime forum veteran — became the nexus where bulletproof hosting meets state warfare: NoName057(16) DD…
Legal analysis of the Digital Services Act Article 4 'mere conduit' exemption — the EU law that explicitly shields transit providers from liability for carrying criminal traffic, and why it will never be reformed.
Investigation into the Phantom Pipes AsyncSSH botnet — compromised home routers forming million-IP proxy networks that let criminals operate behind residential IP addresses, invisible to traditional detection.
The ultimate conclusion: state intelligence and criminal hackers share the same infrastructure because the architecture of impunity was built to serve both — making the distinction between state and criminal meaningless.
How Iranian entities route internet traffic through UK-registered companies to evade sanctions. Traces the corporate chains, BGP paths, and financial flows that connect Tehran's network operations to London's Companies…
How 1,091 IP addresses exist in multiple countries simultaneously — mapping the five cross-border corridors that sanctions cannot reach.
How Iranian state nuclear research infrastructure routes through Welsh PO boxes, Latvian shell companies, and RIPE NCC membership to reach the global internet.
How Russian operators control foreign internet infrastructure through RIPE NCC maintainer chains, Kazakhstan shell ASNs, and Ukrainian front companies — from Novosibirsk to the world.
How PIO-Hosting, XSServer, and SkyLink exploit the German-Dutch border to provide transit for Iranian LIRs, Chinese IDCs, and bulletproof hosting — from one phone number to an architecture of impunity.
How M247 Europe SRL systematically misrepresents IP geolocation through RFC 8805 geofeeds — enabling sanctioned states, botnets, and VPN breaches across a permanent jurisdictional void.
When the ISP is the army: how Viettel, ChinaNet, and Myanmar Mytel create attack corridors beyond civilian governance — the mdrfckr campaign, Article 7, and the end of attribution.
Deep forensic investigation into how the $44.6B VPN industry commoditized geographic identity, enabling credential harvesting and attack infrastructure through M247, Private Layer, Torservers, and FranTech across 469 ge…
Deep investigation into M247 Europe SRL (AS9009), the Romanian ISP that became backbone infrastructure for VPN abuse, brute-force campaigns, and bulletproof hosting. Traces M247's acquisition by Macquarie Group, Omegate…
Investigation into how M247 Europe SRL uses RFC 8805 geofeeds to create virtual endpoints in 116 countries — including OFAC-sanctioned Iran, Cuba, Belarus, and Russia — from Romanian servers. Examines 'M247 Ltd Iran' an…
Forensic analysis of 1,357 IP addresses where authoritative geolocation sources disagree on country. Exposes BGP-vs-RDAP corridors, Tencent Cloud's 76-IP geographic fiction via 'AceVille Pte Ltd', IPinfo's blind spot (0…
Traces the complete pipeline from Seychelles company registration through European shell wrapping to darknet hosting services. Maps how a $500 offshore incorporation becomes the foundation for bulletproof infrastructure…
Seychelles IBCs cost $50, require no beneficial ownership disclosure, cannot be subpoenaed. The jurisdiction of choice for bulletproof hosting.
Omegatech LTD (AS202412): Turkish operators behind Seychelles shell. Virtualine brand. ThreatFox IOCs. 7 honeypot IPs. Zero enforcement.
w1n Ltd used £12 UK registration to front bulletproof hosting. 11 actors, 40 findings, 8 honeypot IPs. Companies House as enabler.
BVI-registered RIPE LIR providing IP resources to bulletproof operators. Panama Papers connection. Zero beneficial ownership transparency.
Pfcloud UG (AS51396): Daniel Mishayev's transit hub for DROP-listed networks. Israel anomaly: 7 IPs, 0 honeypot hits. Operational separation.
87.251.64.0/24 cycled through 5 dead ASNs since 2021. Each revoked for abuse, replaced by new shell. RIPE creates recycling, not deterrence.
The complete cycle: incorporate ($50) → register LIR → get ASN → host abuse → get listed → deregister → repeat. The system is designed for this.
When publishing threat intelligence dossiers attracts targeted retaliation. Documents a focused campaign against a threat researcher and his family — from credential spraying to infrastructure reconnaissance — and what…
Investigation into MEVSPACE, a Polish hosting provider whose infrastructure appeared in targeted attacks against our researcher. Traces corporate registration, abuse handling failures, and the thin line between 'privacy…
Maps the complete infostealer pipeline — from browser credential theft through log aggregation, marketplace listing, and credential spray deployment. How a stolen password becomes an automated attack against thousands o…
Attacks from Grameen Telecom's network — an organization founded by Nobel laureate Muhammad Yunus, now Bangladesh's head of state. Investigates whether a national telecom's infrastructure is compromised, complicit, or s…
Analysis of a Go-based SSH scanner botnet operating through FranTech Solutions (BuyVM) infrastructure. Traces the connection between a privacy-focused hosting provider's 'no abuse reports' policy and the industrial-scal…
Deep forensic investigation of mdrfckr/Outlaw — the SSH botnet unchanged since 2018. Eight years, same key, zero arrests. Live honeypot data, OSINT, economic analysis.
Complete mapping of the mdrfckr botnet's 81 compromised machines across 29 countries. Reveals Microsoft Azure, DigitalOcean, BytePlus (TikTok), Tencent, Oracle, and Google Cloud all hosting active botnet nodes alongside…
Forensic attribution of the mdrfckr/Outlaw botnet to a Romanian-speaking crew operating since 2018. Traces IRC C2 on FranTech's abuse-tolerant infrastructure, decodes the haiduc folklore reference, analyzes the three-wa…
Financial analysis of the mdrfckr/Outlaw botnet's Monero mining operation. Calculates revenue at 81 observed nodes ($1.23/day) through 180,000 peak nodes ($3K-8K/day). Documents the XMRig configuration, the kswapd0 proc…
Victim analysis of the mdrfckr/Outlaw botnet across 29 countries and 81 confirmed nodes. Documents infections at Tanzania's TERNET education network, BytePlus/TikTok's 46-IP cloud fleet, Microsoft Azure across 6 countri…
Evolutionary analysis of the mdrfckr/Outlaw botnet across 8 years (2018-2026). Documents three campaign waves observed in our honeypot with 30,213 sessions from 1,928 unique IPs, the crossover event of May 13, 2026 when…
Extended forensic investigation of the mdrfckr/Outlaw SSH botnet — an eight-year Romanian criminal enterprise exploiting structural negligence across cloud providers, developing nations, and the security industry itself…
Who the actual victims of the mdrfckr/Outlaw SSH botnet are — from Ethiopian state telecom to Korean broadband, Indonesian digitization to Pakistani small ISPs — and why the damage ratio runs 50:1 against the earnings.
Financial forensics of the mdrfckr botnet
Starting from a honeypot geographic discrepancy, we traced two ASNs to a bulletproof hosting empire spanning 7+ jurisdictions, linked to the Panama Papers, enabling Iranian sanctions evasion, and connected to a $55M IP…
HBING LIMITED — a UK 'retail store' at a residential address — operates AS208949, a bulletproof hosting network with risk 95.26/100, BVI shell companies, Panama Papers nominees, and confirmed Hitrow botnet C2 infrastruc…
PIO-Hosting, XSServer, and SkyLink Data Center share personnel, phone numbers, and a border region — while routing 42 prefixes from 5 RIRs for Iranian LIRs, reputation launderers, and a $55M IP marketplace.
IPXO UAB — a $55M Lithuanian IP marketplace — routes through both bulletproof ASNs while its co-founder sits on the RIPE Anti-Abuse Working Group. Academic researchers documented the problem. Nothing happened.
IP addresses attacking our honeypot are registered to a person named in the Panama Papers. Rea Ketty Barreau — ICIJ node 12169229, Seychelles nominee director — controls prefixes through a BVI shell, sponsored by Dubai,…
Four Iranian LIRs route through a German bulletproof ASN with zero sanctions compliance. EU Regulation 267/2012 prohibits this. German law prescribes 10 years. No one has ever been prosecuted for internet transit.
Five individuals operate a bulletproof hosting network across Turkey, Russia, Germany, Netherlands, and Lithuania. All identifiable through public registries. None has ever been charged.
628 machines across 48 countries share one SSH fingerprint, one credential, and one purpose: scanning the entire internet for weak SSH servers. The infrastructure costs $75K-188K per year.
RIPE NCC has an IPXO executive on its Programme Committee, allows anonymous Private Customer records hiding bulletproof hosts, and has never revoked an ASN for abuse. Structural governance analysis.
A forensic investigation into the systematic failure of internet abuse reporting. Traces how 8,000+ attacker IPs generate thousands of abuse reports that vanish into organizational black holes — from hosting providers w…
Forensic reconstruction of the corporate genealogies behind today's bulletproof hosting. Traces how Digital Energy Technologies became Heficed became IPXO, how Quasi Networks became FranTech/BuyVM, and how PIO-Hosting e…
Maps the complete supply chain of internet abuse — from IP address allocation at RIPE/ARIN through leasing marketplaces, BGP transit providers, and proxy infrastructure to the SSH brute-force attempts hitting our honeyp…
Temporal analysis of 1,313 attacker IPs reveals the operational rhythms of coordinated scanning campaigns. Business-hour patterns expose human operators behind 'automated' botnets, while burst analysis identifies campai…
Deep investigation into IPXO UAB, the world's largest IP address marketplace managing 14 million IPv4 addresses from Kaunas, Lithuania. Traces corporate structures across 5 jurisdictions, RIPE NCC governance capture by…
Temporal forensic analysis revealing the operational rhythms hidden in attack timestamps. Business-hour patterns across UTC+3 and UTC+8 time zones expose human operators behind automated botnets.
Forensic analysis of HASSH fingerprint 16443846184eafde36765c9bab2f4397 — a custom Go-based SSH scanner operating 434+ IPs across 6,613 sessions in 25 days. Traces the tool from its crypto/ssh library origins through th…
The final synthesis of a 16-part investigation. Traces how geographic discrepancies in honeypot data revealed a global ecosystem of phantom ASNs, shell companies, captured governance, and weaponized IP leasing.
The illicit economy does not run on hidden infrastructure — it runs on ours. A forensic map of how the same transit ASNs, bulletproof shells, and crypto rails carry drugs, weapons, trafficking, spyware, and laundering.
How mixers, DeFi, exchanges and bridges form the settlement layer of the shared illicit substrate behind ransomware and cybercrime.
Darknet narcotics markets as a financial and infrastructure problem: virtual-asset settlement, DeFi laundering risk, transit ASNs, and enforcement view.
The financial architecture behind human trafficking: shell companies, opaque funding sources, money movement, jurisdiction, and the Epstein financial-network record as a documented case study.
Commercial spyware as illicit-economy commerce: Pegasus/NSO, lawful-intercept vendors, Vault7, export controls, and human-rights harm.
Proliferation financing as an illicit-economy vertical: front companies, dual-use export-control evasion, mixers, and corridor infrastructure.
Sanctions evasion as the connective tissue of the illicit economy: OFAC SDNs, designated crypto entities, and how designated infrastructure keeps operating.
The bulletproof/offshore hosting layer that abuse enforcement cannot reach, and the international takedown response — documented via Europol tracing, ThreatFox IOCs, and the Shuffle-on bulletproof-hosting corpus. Infras…
The synthesis of The Illicit Economy: one measurable substrate carries laundering, narcotics, trafficking, spyware, proliferation, sanctions evasion and hosting.
How a single Seychelles phone number connects 16 million IPs, five shell companies, and the systematic dismantling of geographic attribution on the Internet.
How LARUS Limited operates from a single Hong Kong flat to manage 16 million IPs, reshape Internet governance through NRS, and enable the mdrfckr botnet.
How IPXO and IP address marketplaces structurally destroy attribution — with SSH key evidence proving WHG and HBING are the same operator using marketplace anonymity.
How Cloud Innovation weaponized a Mauritius court to capture AFRINIC governance, threatening the Internet commons model while their infrastructure runs botnets.
How WHG and HBING operate from Norwich UK with shared SSH keys across 5 jurisdictions, creating tiered anonymity that correlates perfectly with threat level.
Deep investigative analysis of Lu Heng — the man behind Cloud Innovation, LARUS, NRS, and 16 million African IP addresses. Exploring state connections, Belt and Road digital infrastructure, and the question Western inte…
Deep analysis of why the most dangerous IPs in our honeypot route through UAE — a documented surveillance state. Exploring Project Raven parallels, Five Eyes questions, and the surveillance-enabling architecture of mode…
How did 16 million IP addresses leave Africa without anyone noticing for six years? Deep investigation into AFRINIC's governance crisis, institutional capture, the R6 billion question, and why dissolution is the endgame.
A coordinated GPU reconnaissance botnet fingerprints server hardware from bulletproof hosting — the opening salvo of the compute theft economy.
How a Seychelles shell company, German partnership, and Russian underground forum created the bulletproof hosting backbone for GPU compute theft.
From GPU fingerprint to crypto profit — the monetization pipeline, ShadowRay parallels, wallet hunters, and the invisible tax of stolen compute.
The conspiratorial deep-dive: state-adjacent questions, AI industry complicity, compute cartels, and what GPU reconnaissance at scale really means.
AS210558 hides behind a SHA1 hash in BGP databases. The real operator — 1337 Services GmbH — runs rdp.sh, a bulletproof hosting empire that survived Operation Talent.
SERVPERSO Systems: How a Belgian entity in a Wallonian market square became the administrative layer protecting the most abused IP block on a German bulletproof hosting network.
Investigation into Julian Achter's LAIN LIR marketplace — how a Munich sole proprietor's €71/year ASN sponsoring service became an anonymous gateway to bulletproof internet routing resources, complete with Spamhaus ASN-…
Deep investigation into the anonymous Tor exit operator 'Satanist' running 27 relays across 16 ASNs under the 2cb.li domain, connecting all three bulletproof hosting providers in The Anonymity Factory series.
Forensic deconstruction of the April 6 2026 mass deployment event: CollecTor archives prove the Satanist relay network existed since September 2025, and April 6 was a family reconstitution, not a first launch.
How relay naming conventions reveal five distinct operator archetypes sharing the same anonymous hosting habitat
Following the money through the 2cb.su Tor exit relay network — and finding that the €2,500/month myth was wrong by 10×. A crypto-native supply chain with zero fiat touchpoints, operating for the cost of a gym membershi…
Deep investigation of Aokigahara SRL — a Romanian micro-entity operating AS215659 for Tor exit hosting. Company formation mechanics, the anime-death naming aesthetic, and the minimum-viable-entity pattern for internet r…
Forensic investigation of D.O. Bronk / Bronk-ICT — a Dutch IT firm operating 28 Tor relays (2.4% of network) on infrastructure shared with the Satanist/2cb.su criminal network. Traces the MAXKO and Five Cyber Host suppl…
Investigation into the convergence of Tor exit relays and phishing infrastructure on Spamhaus-DROP subnet 45.154.98.0/24, operated by 1337 Services GmbH / rdp.sh
Forensic Q&A analysis of the Anonymity Factory — who, what, when, where, why, how — and the questions nobody has publicly asked about 1337 Services / rdp.sh
Structural and conspiratorial analysis of the Anonymity Factory — reading between the lines of regulatory silence, intelligence incentives, and the architecture of unknowability
How Aceville Pte Ltd functions as Tencent Cloud's international legal wrapper, enabling 181 attack IPs to claim 10 different countries while all routing through Singapore.
BytePlus Pte Ltd — ByteDance/TikTok's cloud arm — operates attack infrastructure where 100% of tracked IPs carry maximum abuse scores. Top IP resolves directly to bytedance.com.
How one Seychelles phone number (+248-4-610-795) connects Cloud Innovation Ltd, LARUS Limited, and Yisu Cloud across 15+ ASNs and 16 million IP addresses — the mother of all attribution breaks.
UCloud Technology (Shanghai STAR Market, 688158.SH) operates 147 attack IPs through a Hong Kong shell with a fake phone number — while PRC law mandates intelligence cooperation and blocks foreign law enforcement access.
4 IPs, ALL at threat 95-100. CDS Global Cloud — US-registered, Chinese-operated, Kubernetes-weaponized. The highest per-IP threat concentration in our intelligence platform.
417 IPs, 253 at maximum abuse, 2180 attacks, zero enforcement. How Chinese cloud providers engineered themselves to exist where no abuse reporting mechanism reaches.
How a Seychelles shell company captured 16 million African IP addresses from AFRINIC and weaponized Mauritius courts to keep them — while running global attack infrastructure.
287 cross-provider links prove six Chinese cloud providers share malware, credentials, commands, and abuse contacts while maintaining legal separation for enforcement evasion.
Where commercial negligence ends and state-adjacent activity begins — PRC National Intelligence Law Article 7, golden shares, and the Volt Typhoon parallel.
Final synthesis — how 6 Chinese cloud providers form one ecosystem connected to Belt and Road Initiative digital infrastructure policy. The Silk Road was always digital.
ColoCrossing/HostPapa AS36352: How a Buffalo NY data center enables a 628-IP botnet infrastructure targeting global networks.
Forensic analysis of Psychz Networks and MULTACOM Corporation — two Los Angeles hosting providers contributing 60 nodes to a 628-IP global botnet
SingleHop/Internap — two bankruptcies, a ransomware cover-up, and the highest average threat score of any US provider in our database
DigitalOcean — NYSE-listed, 350 IPs, 5+ botnet campaigns, one IP at threat score 100. The paradox of scale and accountability.
FranTech Solutions/BuyVM: How one man built 121 IPs of privacy-branded abuse infrastructure across five jurisdictions — and called it freedom
OVH and Contabo: European companies producing worse abuse rates than US counterparts — 219 IPs, 20 RDAP entities, and a provider-specific botnet
Google Cloud Platform: 157 IPs, 77 at abuse=100. Belgium cluster at 73% abuse rate — 2.3× worse than US. The hyperscaler accountability gap.
The Double Standard: 8 Western providers produce 4.3× the abuse IPs, 3.0× the max-abuse, and 6.5× the attack hits of the Chinese ecosystem. The mirror thesis proved.
2cb.li is named after the Schedule I psychedelic 2C-B. Registered in Liechtenstein, DNS anonymized through NymDNS (Saint Kitts LLC), hosted via NymBox (Saint Kitts LLC). Domain held since 2015. The naming, TLD choice, a…
The 2cb.li Tor exit network spans 49+ relays, 17 ASNs, and 12+ countries with ~4 Gbps bandwidth — approximately 1-3% of global Tor exit capacity. A coordinated April 6, 2026 deployment added 14+ relays in a single day.…
Seven bulletproof hosting providers form the substrate of 2cb.li's 49-relay Tor network — two Spamhaus-blacklisted ASNs, a defunct Belgian entity, a 2025-allocated one-man operation, and a Romanian SRL named after a Jap…
A Nevis LLC, a dark domain with forged heritage, and a Romanian SRL sharing CDN fingerprints with a Caribbean shell — how the 2cb.li network uses offshore corporate structures in Saint Kitts and Nevis to place legal acc…
Four pseudonymous operators behind the Psychedelic Connector Tor exit network — Satanist, em/j3, maxzrbn, and secretdrop.to — profiled from their public declarations. OPSEC tiers, PGP anchors, warrant canary architectur…
The Psychedelic Connector series conclusion: Caisse d'Épargne bank phishing on 45.154.98.153 (AS210558 / 1337 Services), HiddenPhish toolkit SSL fingerprint, Russian actors probing egrul.nalog.ru, a 1.67-billion-request…
DiamWall (AS207731, Lisbon PT) sells CDN and DDoS protection while simultaneously operating six DDoS-for-hire stresser services on its own infrastructure. CEO Hugo Carvalho and CTO Miguel Miranda identified. The .ST TLD…
HiddenPhish is a phishing-as-a-service platform identified via self-signed SSL cert (CN=hiddenphish.xyz, fingerprint f7a67265) on 45.154.98.153, a Spamhaus ASN-DROP bulletproof hosting node (1337 Services GmbH, AS210558…
EGRUL reconnaissance, adversary-in-the-middle BEC infrastructure, and the Njalla bridge to 033C. Final article in The Psychedelic Connector series — the full kill chain from Tor relay to wire transfer fraud.
Israel: 7 IPs, 0 honeypot hits. The world's most capable cyber nation is statistically invisible in an 8,000+ IP threat database. The absence is the finding.
How 51 Israeli-connected IPs appear as zero in every database. Daniel Mishayev, Pfcloud, Kamatera, Bright Data, Kape Technologies, and the architecture of attribution invisibility.
From Crossrider adware to four major VPNs: how an Israeli-founded company with a convicted fraudster owner, Unit 8200 co-founder, and UAE government hacker CIO controls the privacy infrastructure millions trust.
How Unit 8200 — Israel's NSA equivalent — recruits at 16, trains at 18, and produces founders by 25. Alumni have built $200B+ in cyber companies: Check Point, Wiz ($32B Google), NSO Group (Pegasus), Candiru, Cellebrite,…
How Bright Data (formerly Luminati/Hola VPN) turned 150 million living rooms into proxy exit nodes — from free VPN exploitation to smart TV SDKs to DDoS attacks on human rights organizations.
Investigation into Israel's submarine cable infrastructure: Blue-Raman (highest capacity Europe-Asia cable) routes through Israeli territory, Unit 8200 confirmed cable-tapping capability, Snowden-confirmed raw NSA intel…
Synthesis of TI-2026-034 series: Seven layers of Israeli internet infrastructure control from physical cables to application proxies, producing near-zero threat database visibility while enabling passive total awareness.
TI-2026-034H: Documents a 40-year pattern of Israeli corporate fraud as infrastructure maintenance — from PROMIS to Kape Technologies, how surveillance capability survives every corporate death through cycles of fraud,…
Forensic investigation connecting honeypot-observed SSH credential scanning through initial access brokerage, ransomware deployment, cryptocurrency laundering, and sanctions-exposed state infrastructure
Meta-analysis synthesizing 48 published dossiers, 518 investigations, 8,000+ honeypot IPs, and 4,692 OSINT library documents into a single forensic finding: the infrastructure of cybercrime and the infrastructure of sta…
How surveillance tools built for governments become criminal weapons. Unit 8200's production line, FinFisher's ISP-level interception, three documented leak-to-criminal pipelines, the Project Raven prosecution, and Para…
The question 666 documents avoid: who hosted Jeffrey Epstein's digital infrastructure? PROMIS to Pegasus — a 40-year pattern of intelligence-commercialized surveillance. The jurisdictional architecture that hides ASN ow…
Following the money from a 0.3-second SSH probe to a $4.5 million cash-out. FinCEN SARs, Europol crypto tracing, OFAC sanctions, Chainalysis data. The 34-month Garantex gap. The insurance industry's role in the ransomwa…
NSA, GRU, PLA, GCHQ, Unit 8200 — all operating on commercial infrastructure indistinguishable from cybercriminals. Microsoft's own admission. Israel's statistical zero. GRU indicted but operational. Volt Typhoon already…
Five components, each legal, each under $2,000, producing impunity at industrial scale. Shell companies in Seychelles, LIR memberships in Germany, ASN leasing, geofeed manipulation, and AFRINIC IP extraction — the compl…
Snowden, Manning, Hale, Winner — every disclosure confirmed, every architecture still running. Seven predictions, seven confirmations, sixteen years of prison, zero systems dismantled. The honeypot as citizen verificati…
45,000 SCADA devices exposed. Volt Typhoon pre-positioned. Colonial Pipeline paid. Oldsmar nearly poisoned. The same scanning infrastructure our honeypot captures also probes every power grid, water plant, and pipeline…
Same pipes, different payload. The IRA's troll farm uses bulletproof hosting and VPNs from the cybercrime ecosystem. Cambridge Analytica harvested 87M profiles through legitimate APIs. Team Jorge disrupted 33 elections.…
Where all lines meet. Ten entities across five domains. Five jurisdictions forming one supply chain. Three business models generating $28B annually. The infrastructure of cybercrime, surveillance, state operations, fina…
Series finale. Five hypotheses at the boundary between evidence and inference. Do intelligence agencies preserve the ecosystem? Is ransomware state-licensed? Is Pegasus an intelligence franchise? Who maintains the equil…
Romania ranks #20 in our honeypot — 75 IPs, modest count. But 8 bulletproof ASNs, 4 on Spamhaus nuclear blocklist, the world's largest VPN proxy network (M247, 5,000 prefixes, 60 IXPs), Chinese phishing on Romanian serv…
Deep investigation into M247 Europe SRL (AS9009): 5,000 prefixes, 60 IXPs, Servers Factory LLC attack arm, 10 national subsidiaries from one Romanian office, participation in 628-node global scanning campaign.
Investigation into how Romanian SRLs (minimum capital €0.20) are used to manufacture bulletproof hosting ASNs. Bunea TELECOM's triple ASN-DROP, NexonHost's IPXO pipeline, Feo Prest's 3-month lifecycle, and the RIPE NCC…
From Guccifer's NEC desktop to NexonHost's 628-node botnet: how Romanian cybercrime evolved from prosecutable hacking to unprosecutable infrastructure. Three generations, one structural immunity.
Series finale: how Romania's cyber corridor connects to the global Kill Chain Economy through shared HASSH campaigns, SSH key bridges, registrant overlap, and the AbuseRadar nexus. 2,648 IPs, 84 countries, one infrastru…
Forensic investigation of a Go-based SSH scanner botnet operated by Kazakhstan shell entities through Russian bulletproof hosting, recruiting IoT devices and routers into a proxy tunnel network. 88 days of continuous sc…
Behavioral forensics of SSH post-compromise operations: 670 commands from 53 operators reveal seven species of attacker — from Telegram session thieves to cryptomining SSH key injectors to Google Cloud Mirai deployers.…
Forensic analysis of malware delivery to SSH honeypots: whisper ARM malware from Latvia, meow Mirai variant on Google Cloud, notwork-monitoring iterative builds, silent SCP uploads, and the w1n ltd UK-Ukrainian-Swedish…
Statistical forensic analysis of 11,026 fingerprinted sessions across 63 HASSH fingerprints from 2,190+ unique IPs in 84 countries. When you count everything, the infrastructure of SSH attack belongs to cloud providers,…
How does a compromised SSH server generate revenue? From residential proxy markets (NASDAQ-listed companies recruiting botnets) to cryptomining on stolen compute to credential markets and ransomware-as-a-service — the c…
The grand synthesis of the Ghost Machines series. Six letters. Seven botnets. 84 countries. 2,190 IPs. Five revenue streams. One conclusion: the infrastructure of cybercrime and the infrastructure of legitimate technolo…
Live forensic investigation of 179.43.139.58 (Private Layer INC, Panama/Switzerland). 86,239 events across 94 days, 112 open proxy ports on Shodan, 3 flood cycles, using Yahoo.com as a proxy verification target. The ind…
Two IP addresses — 179.43.139.58 (Private Layer INC) and 185.246.128.133 (w1n ltd) — account for 178,581 events and 96% of all honeypot traffic over 94 days. w1n rotates 37 fake client versions while verifying proxies a…
Four nodes across OMEGATECH (Seychelles), Private Layer (Panama), and w1n (UK) expose 331 unique proxy ports on Shodan. Same HASSH fingerprint. Same credential. Same verification targets. Different jurisdictions. A sing…
RDAP forensics reveal four named persons behind the proxy factory — Milciades Garcia (Private Layer), Anastasiia (w1n), Vatlin Mihail (Private Layer), and Artem Sevastyanov (OMEGATECH). Ukrainian phone numbers connect w…
Recorded Future intelligence reveals the upstream chain: Railnet LLC (AS214943, Kentucky) migrated to OMEGATECH (AS202412, Seychelles) in January 2026. Both route through aurologic GmbH (AS30823, Germany). Virtualine Te…
A practical defense guide documenting the exact stack used to detect, analyze, and document the proxy verification factory: Cowrie SSH honeypot, CrowdSec community threat intelligence, MikroTik firewall rules, PostgreSQ…
Israeli national Daniel Mishayev operates GHOSTYNETWORKS/OMEGATECH from Bavaria — the same geographic registration arbitrage used by Unit 8200-linked entities like NSO Group, Kape Technologies, and Bright Data. From sub…
The commercial surveillance vendor industry is a pipeline from Unit 8200 to your phone. NSO Group, Cellebrite, Candiru, Intellexa — all Israeli-founded, all tested on Palestinians, sold to 45+ governments. Google TAG do…
The proxy economy operates identically at every tier: Bright Data (150M nodes, NASDAQ supply chain, $500M/yr) vs Socks5Systemz (250K botnet nodes) vs GHOSTYNETWORKS (bulletproof hosting). Our honeypot catches the recrui…
Information warfare uses the same infrastructure as cybercrime and surveillance. Operation Gladio's Strategy of Tension digitized: NATO stay-behind networks became troll farms, false-flag bombings became false-flag soci…
The series finale. 7,994 IPs. 110,140 entity links. 64,411 honeypot hits. 136,617 OSINT documents. 52+ published dossiers. One conclusion: there is no separation between cybercrime, surveillance, proxy economy, and info…
The electromagnetic spectrum is weaponized at every frequency band. IMSI catchers (8cm×9cm, battery-powered) grab phone identities. The Frey Effect (1960) transmits sound directly into the brain via pulsed microwaves —…
Social media platforms are weapons systems. Cambridge Analytica harvested 50M Facebook profiles for psychographic targeting. Russia's IRA spent $1.25M/month impersonating Americans via residential proxies. False news tr…
Analysis of coded naming conventions in attack infrastructure: Moloch domains, MKUltra credentials, DGA word selection, Turkish botnets, and the GHOSTYNETWORKS-XSServer-PIO-Hosting convergence.
Deep analysis of religious and mythological naming in attack infrastructure: Moloch domains, Kerberos darknet markets, 666 credential patterns, Gnostic anagrams, and the theology of criminal networks.
MKUltra and Monarch programming vocabulary found in global botnet credential dictionaries: Alice, Kitten, Master-Slave, Matrix, Ghost — 270 entries mapping CIA mind control to SSH scanning infrastructure.
Forensic analysis of the warnight botnet: Turkish nationalist cyber army with hierarchical command structure, fake Linux service persistence, 101 IPs across 30+ countries, Grey Wolves-to-digital pipeline.
Forensic analysis of attack philosophy encoded in malware: Voidsetdownload.so (28 IPs/14 countries), meow malware on Google Cloud, UUID panopticon surveillance (11 IPs/Strong Technology LLC), SSH skeleton key botnet (81…
Forensic analysis of food-coded credentials in honeypot data: pizza, cheese, candy, cookie, honey matched to law enforcement documented code words. banana666 credential cross-referenced to warnight Turkish network. Pode…
Structural parallels between Epstein's trafficking infrastructure and modern attack networks. Offshore jurisdictions (Seychelles 41 IPs, St. Kitts, Panama), intelligence connections (Mossad, PROMIS), shell companies, st…
Complete mapping of law enforcement documented food code words to honeypot credentials. 9 of 11 primary codes found. Pizza, cheese, candy, cookie, honey, chocolate, ice cream (1cecream obfuscation). Color codes (yellow…
cart00ns credential linked to banana666 and warnight network. Disney as documented MKUltra hypnotic tool. Peter Pan never-growing-up programming. daddygirl-eyecandy cluster on Kamatera/Viettel military. v1isagoodgirl ca…
Documentation of protection mechanisms enabling exploitation networks. 5 hyperscalers hosting attack infrastructure (Google meow-to-meow same ASN). 3 state telecoms (Viettel military, Etisalat state, TENET academic). 6…
Final letter of The Menu Decoded series. Complete convergence map: banana666=warnight=cart00ns triangle proven, daddygirl2=eyecandy identity proven, Google meow-to-meow proven, Strong Technology UUID panopticon proven.…
Revisiting TI-2026-017 Glass Houses through exploitation lens. SchoolBridge.in: 60+ children schools on compromised server, exposed MySQL/Redis, 283 abuse reports, 13 CVEs. Viettel (military) sends daddygirl2+eyecandy+i…
Military telecoms as trafficking infrastructure, not victims. Viettel (Ministry of Defence) 154 IPs sends daddygirl2+eyecandy+ilovemykids. DynCorp Bosnia 8 confessed to buying sex slaves. Bacha bazi widely tolerated. UN…
SchoolBridge.in shares HASSH fingerprint with PIO-Hosting/GHOSTYNETWORKS in actor_cluster_013. 114 hostnames, 60+ schools, exposed MySQL+Redis, 283 abuse reports. franchisebridge.in same server. Scanning behavior (root:…
ICC judge warned trafficking investigator: investigate organ harvesting and you're dead. Kosovo: thousands of child refugees trafficked into multiple slave industries. China organ transplant wait times in days. 231 Chin…
DynCorp: 8 employees confessed to purchasing sex slaves in Bosnia. Arizona Market named for American buyers. Whistleblower Bolkovac fired. Company kept Pentagon contracts. slave:slave credential in honeypot. Military co…
NXIVM charged as CIA child sex trafficking front. Master/slave hierarchy maps to honeypot credentials. Branding as ownership marking. Snuff film desensitization. Allison Mack Hollywood recruitment. MKUltra to Finders to…
Marc Dutroux Belgium: leads blocked or buried. Second parallel network with 7 children never investigated. Parliamentary cover-up. 275,000 marched in White March. Protection pattern identical to Epstein and Savile. Belg…
Jersey Crown Dependency: Haut de la Garenne children's home decades of abuse. Edward Heath implicated in rape and murder of children on yacht. Islands as architecture of impunity. Seychelles, St. Kitts, Singapore provid…
Tencent Cloud threat 98: cash-1000.xyz 20+ fraud domains. slave:slave credentials. 231 Chinese state telecom IPs. WeChat surveillance but cannot detect fraud. China Tribunal organ harvesting. root:young credential. Digi…
Korea Telecom 121 IPs 564 hits. Three-stage SIGINT: MikroTik/Telegram/GSM harvesting. 23skidoo, princess, foreveryoung credentials. SK Broadband 30 IPs. State surveillance + exploitation vocabulary. Real-name registrati…
Kosovo IP 84.22.62.247: shipdrug.ru, rxdrugship.ru AND kitten.rxdrugship.ru. Drug trafficking + exploitation vocabulary same server. Kosovo: refugee camp trafficking + drug shipping. Named ships (carrie, kalyn, kassandr…
Poland: 5 IPs but 48 exploitation credentials (9.6 per IP vs 1.4 average). babygirl, babygirl1, iloveyou1/2, dragon. Catholic Church code of silence in 87% Catholic country. Poland as trafficking transit country. Number…
CloudHost Singapore hosts daddygirl2 IP + girlallaroundx.site + misraudlatulislam.sch.id (Islamic school) + Dubai financial fraud. 3 IPs share daddygirl2+eyecandy across Indonesia/Israel/Vietnam. Second school on exploi…
Rostelecom: 15 IPs avg threat 53 highest of any state telecom. BGP hijacking documented. SORM gives FSB direct wiretap access. domolink.elcom.ru malware deployment. State telecom as surveillance AND attack infrastructur…
OMEGATECH Seychelles IBC: threat 100, intstantlocalhookups.com. 41 Seychelles IPs. $350 company formation, no ownership disclosure. Sex scams + Turkish operations + warnight overlap. Digital Panama Papers.
Peshawar APS 2014: 132 children killed. Army Public School Gopalpur on compromised SchoolBridge.in. Air University Islamabad scanning. Pakistan NTC military telecom SSH key injection. Military children digitally exposed…
Academic networks scanning: DFN Germany 49 hits, HaNoi University Vietnam 10, Khajeh Nasir Iran 10, Air University Pakistan. Research as cover for reconnaissance. Military-academic nexus in Vietnam, Iran, Pakistan.
Brazil: teenow.com.br on DigitalOcean threat 83. coolkid, devil, kids123, kitten credentials. Latin American trafficking corridor. banana666 Ecuador/Panama. DigitalOcean selective enforcement.
phonesnoops.com + greattoysforkids.com same IP threat 85. edgetrack.org tracking ecosystem with shop+analytics+community. camdvr.org camera photos. Surveillance tools + children's products on attack infrastructure.
European hosting as attack backbone. Contabo play.eutoligado.net threat 95. Hetzner darkcurry.com. OVH xplaydashboard. German data protection law as paradoxical shield for attackers. Infrastructure quality + legal prote…
271,458 entity links connecting IPs, ASNs, hostnames, actors. Korea Telecom 36 IPs. Two-hop path from military telecom to financial fraud through exploitation credentials. Hub nodes: CloudHost, Kamatera, DigitalOcean.
139,335 honeypot credentials analyzed statistically. Exploitation vocabulary as statistical outliers. daddygirl2/eyecandy on exactly 3 IPs. 57 Viettel IPs identical lists. Botnet fingerprint. Language distribution acros…
224 honeypot malware samples. neofetch GitHub disguise. whisper multi-architecture IoT botnet (ARMv5-v7, MIPS, x86). notwork-monitoring mocking defenders. shr Indonesian connection. Professional operation evidence.
15 actor clusters. actor_cluster_001: 1,831 IPs across 50+ countries. actor_cluster_013: SchoolBridge.in + GHOSTYNETWORKS share HASSH fingerprint. Children's data → bulletproof hosting → German shell companies. Organiza…
90 days March-June 2026 temporal analysis. Weekday peaks, UTC+8 concentration. Credential evolution from dictionary to exploitation vocabulary. SSH skeleton key campaign May. Command timeline reconnaissance→persistence→…
Series finale: 26 letters, 7,999 IPs, 137 countries, 139,336 credentials, 110,288 entity links, 57 campaigns, 4,692 OSINT documents. Six-layer architecture: infrastructure, operations, state integration, exploitation, c…
Analysis of 33,286 unique credential combinations revealing a 5-layer hierarchy of ritualistic control vocabulary in honeypot data — from infrastructure defaults to explicit victim-referencing patterns across 700+ sourc…
The dual meaning of master/slave — computing architecture AND human trafficking hierarchy — creates permanent plausible deniability in credential dictionaries. 57 Vietnamese military IPs deploy identical lists. Three co…
When credential vocabulary applies product naming conventions to human beings. v1isagoodgirl! — software versioning applied to a person. daddygirl2 — iteration numbering for victims. brittany20, claire12, kids123 — inve…
Forensic analysis of theological naming in attack infrastructure: gods, demons, and underworld guardians embedded in honeypot credentials, Tor relay networks, darknet marketplaces, and hosting companies.
Series finale. Where hierarchy, product naming, theology, and coded commerce converge on the same infrastructure. Military telecoms deploying child exploitation vocabulary. 3-hop entity paths from state surveillance to…
MKUltra and Monarch programming vocabulary found operational in global botnet credential dictionaries — 270+ credentials mapping CIA mind control to SSH scanning infrastructure.
Six documented government-linked child procurement operations — The Finders/CIA, Franklin Credit Union, DynCorp Bosnia, Dutroux, Westminster, Epstein — and their operational vocabulary persisting in active SSH credentia…
FBI-documented pedophile symbols, Bohemian Grove Moloch worship, Epstein Blue Butterfly, NXIVM branding — traced to SSH credential dictionaries and infrastructure naming. The credential IS the symbol. The authentication…
The systematic destruction of those who spoke: COINTELPRO, MKUltra, Franklin, DynCorp, Dutroux, WikiLeaks. Every whistleblower follows the same trajectory — disclosure, discrediting, persecution, elimination. The creden…
Why the system persists: five structural pillars — jurisdictional arbitrage, shell infrastructure, sovereign immunity, cryptographic anonymity, distributed resilience. Combined probability of successful prosecution: zer…
How SSH credential dictionaries function as a covert communication channel. Documents heartbeat protocols, synchronized military bursts, credential vocabularies as structured messages, and campaign hierarchies hiding in…
Temporal analysis proves military precision behind SSH honeypot traffic. Coefficient of variation 2.6%, Monday evening bursts at 21:00 CET, 269-node army across 88 ASNs — mathematical proof that internet noise is coordi…
Organizational topology of The Liturgy of Control infrastructure. Entity link analysis proves ISAEV, Private Layer, w1n, Omegatech, and the 269-IP army are one coordinated system across 30+ countries.
How PRQ, Bahnhof, DFRI, and Njalla turned Sweden into a durable privacy-hosting ecosystem—and why the same structure now appears in attack telemetry.
Internet Vikings, PatrikWeb, Gigahost, and 19 Swedish ASNs show how gambling hosting and Nordic legitimacy form a pipeline into abuse infrastructure.
Lithuania's IPXO and the Baltic address market turned IPv4 reputation into a tradable commodity feeding Swedish hosts and European bulletproof infrastructure.
M247 routes traffic for NordVPN and Mullvad while hosting 47+ attack IPs. Every tested no-log VPN produced logs. The privacy promise is marketing fiction.
Sweden hosts disproportionate Tor exit infrastructure through DFRI, 1337 Services, and pseudonymous operators — connected via Njalla and No-KYC providers.
Sweden wiretaps ALL fiber optic cables crossing its borders while hosting WikiLeaks, Njalla, and Pirate Bay — making the privacy ecosystem either naive or deliberate intelligence cover.
Gigahost controls 83% of Norwegian honeypot IPs. DotSrc runs Tor exits from a Danish education network. Finland hosts Hetzner overflow. Three countries, 50+ attack IPs, zero headlines.
WikiLeaks Spy Files document Nokia-Siemens and Ericsson selling lawful interception to 180+ countries. Trovicor sold monitoring centers to Bahrain, Iran, Syria. Privacy at home, surveillance for export.
Danske Bank laundered €200B. Swedbank €135B. Same Baltic corridor, same shell structures. The financial twin of the IP pipeline closes the loop from infrastructure to money.
DOJ extracted $4B+ from Nordic entities. Zero executives imprisoned. Ericsson paid ISIS. Telia bribed a dictator's daughter. The fine is the subscription fee.
KPMG gave 8 years of clean audits during €200B laundering. 2 compliance staff for 15,000 accounts. Journalism succeeded where every gatekeeper failed.
M247 routes to Tehran. NordVPN transits sanctioned infrastructure. Danske served sanctioned entities. The complete evasion stack: VPN + shell company + correspondent bank.
How Cloud Innovation, LARUS Limited, and Yisu Cloud built a three-layer jurisdictional architecture controlling 16+ million stolen IP addresses
A Chinese cloud provider with a perfect 100% abuse score across every scored IP, connected through a single Seychelles phone number
How China's largest cloud provider censors politics while hosting the highest-threat attack infrastructure
The Singapore corporate shell that transforms Chinese state cloud into international legitimacy
The backbone carrier at the center of repeated routing controversy also dominates the Chinese abuse slice in direct honeypot telemetry.
Five separate mechanisms ensure that reporting abuse to Chinese providers usually becomes ritual, not remediation.
Article 7 makes Chinese cloud neutrality legally conditional because every provider can be compelled to support intelligence work.
Digital Silk Road projects export not just connectivity but long-term dependency on an ecosystem already linked to cloud abuse, surveillance, and state intelligence leverage.
China Unicom and China Mobile access networks operate as credential factories: 90 observed hostile IPs, high abuse density, IoT churn, and exported SSH pressure.
Mid-series synthesis of the Chinese ecosystem so far: 710 IPs, 84 ASNs, state telecom substrate, cloud legitimacy, offshore wrappers, and deeper revelations still ahead.
Baidu and ByteDance run cloud infrastructure with perfect abuse saturation in the observed corpus, collapsing the comfort boundary between consumer platforms and hostile infrastructure.
Alibaba Cloud and Huawei Cloud place enterprise trust on hostile ground: high abuse density, severe Alibaba threat concentration, and Huawei telecom-cloud adjacency.
The I-Soon leak exposed a Shanghai contractor pricing ministry hacks and targeting Digital Silk Road partner states.
China stayed outside Budapest, backed a rival UN cybercrime treaty, and turned legal asymmetry into cyber advantage.
The US shows more attack volume; China shows more concentration and near-total impunity. Part O explains the difference.
Grand finale: why law, infrastructure, shells, contractors, and zero-response tolerance form one Chinese attack architecture.
Nine AS135089 IPs reached the SSH honeypot across late May to early July — 57 login attempts, one success. Two of them matter:
Forensic analysis of a professional .env credential harvesting operation: 54 Google Cloud IPs, 7 daily burst campaigns, 35-path framework-aware enumeration, zero SSH overlap proving dedicated HTTP-only specialization. D…
Forensic analysis of a massive Microsoft Azure botnet (269+ IPs) using empty user-agents to check for pre-planted WordPress backdoors. The fleet does not attack — it harvests from previous compromises.
🔍 HIGH — The Line Between Legitimate Scanning and Criminal Reconnaissance Has Dissolved TI-2026-046C — The Reconnaissance Industrial Complex When a $2.7 Billion SEO Company, Chinese State Telecom, and Credential Thieves…
⚡ CRITICAL — 39% of HTTP Attackers Simultaneously Brute-Force SSH — Protocol-Agnostic Attack Platforms TI-2026-046D — The Multi-Vector Operators When the Same IP Address Scans Your Web Server for Credentials While Simul…
☁️ CRITICAL — 41% of All HTTP Attack Traffic Originates From Three Hyperscalers That Also Sell You Security Products TI-2026-046E — The Cloud Mercenaries How Google, Microsoft, and Amazon Became the Largest Attack Infra…
How an Authelia forward-auth login page became a honeypot that logged every credential-scanning bot's full target list — 100+ .env variants in 62 seconds, decoded ?rd= probes, and the auth-indifferent scanners hitting b…
The web-threats surface didn't find new villains — it re-convicted networks the corpus already named. 73 four-layer-confirmed threats, the Azure empty-UA webshell botnet, and M247's backbone returning on the web surface.
36 web campaigns, ~88k requests, three coordination fingerprints — temporal bursts, empty-UA clusters, and shared-path toolkits. A 7-IP fleet spanning Amazon and Google shares the same 170-path .env dictionary: one oper…
An IP doesn't have a location — it has several, and they disagree. How web attackers weaponise the gap between where an address is registered, routed and geolocated — from a Hong-Kong/Netherlands block to M247's virtual…
What happens the instant an attacker gets in: the SSH front door falls to admin/admin, then a single pasted command runs 24 steps in one second — fetch multi-arch malware, change root's password, plant backdoor users. T…
The capstone of The Glass Cage: how five windows onto one siege — the Authelia honeypot, the repeat offenders, the botnet census, the cartographers, and the first ten seconds — resolve into a single kill chain, and the…
Decoding one honeypot session, line by line: nine commands that hunt MikroTik routers, Telegram Desktop sessions and GSM/SMS gateways — and reveal an attacker's whole business model before any malware is even downloaded.
The persistent botnet hunts Telegram sessions and SMS gateways because both defeat two-factor authentication. NIST already called SMS 2FA weak; the WikiLeaks Spy Files show the same interception capability sold to state…
An attacker rotates across 49 residential IPs in 20 countries to look like nobody — and is identified anyway, by the one thing it cannot change: its behaviour. A full-spectrum investigation of identity without an addres…
A compromised machine is not a victim but an asset — re-tasked over time from recon to payload to proxy. How the honeypot's TTP-label timeline measures behavioural drift, from a frozen nine-command kit to a host that tr…
Ninety days of one honeypot as a core sample of the internet's attack climate: a steady baseline punctuated by datable botnet surges, a source-geography that migrates from Poland/Sweden to Switzerland/US/Asia, drifting…
🟠 ACTIVE — libssh Swarm · 2,341 Distributed Nodes · 3 Library Versions · 84 Countries · actor-6285990cc704 TI-2026-049A — The Library That Moves Series: The Swarm Protocol · Letter A of 6 · Published 2026 Three library…
🟠 ACTIVE — libssh Swarm Post-Auth · 3,060 Command Links · 2 Protocol Families · 176 IPs · 19-Command Intrusion Lifecycle TI-2026-049B — The Command Language Series: The Swarm Protocol · Letter B of 6 · Published 2026 Th…
🟠 ACTIVE — libssh Swarm · 84+ Countries · 5 Continents · Seychelles 240x US Density · ByteDance 141 IPs · 48.8% Known-Bad Still Active TI-2026-049C — Eighty-Four Flags Series: The Swarm Protocol · Letter C of 6 · Publis…
🟠 ACTIVE — libssh Swarm · 3 Simultaneous Versions · 38 CVEs in Lineage · 0.9.6 EOL Since 2021 · Fingerprint Diversification · Operator Accepts Own Vulnerabilities TI-2026-049D — The Version Tree Series: The Swarm Protoc…
🟠 ACTIVE — libssh Swarm · Human Scheduling Detected · Tuesday 78% of Traffic · 02:00-04:00 UTC Burst = 10:00 CST · Weekend 8.4% of Weekday · Netherlands Migration +67% TI-2026-049E — The Temporal Pattern Series: The Swa…
🟠 SERIES COMPLETE — The Swarm Protocol · 6 Letters · 2,341 IPs · 84 Countries · 606 ASNs · 84,726 Attempts · 54 Days · 1 Actor Cluster TI-2026-049F — The Census Series: The Swarm Protocol · Letter F of 6 · FINAL · Publi…
⚙️ Series 050 — The Toolmakers The Other Swarm TI-2026-050A · Letter 1 of 5 · Page 297 While we spent six letters dissecting the libssh swarm — 2,341 IPs, 84 countries, three library versions braided into one organism —…
🤝 Series 050 — The Toolmakers The Silent Handshake TI-2026-050B · Letter 2 of 5 · Page 298 Three hundred and thirty-three shells opened. In three hundred and twenty-one of them, nothing happened . The Go_SSH fleet authe…
🏝️ Series 050 — The Toolmakers The Shell Game TI-2026-050C · Letter 3 of 5 · Page 299 Follow the IP addresses and you find VPS providers. Follow the VPS providers and you find shell companies. Follow the shell companies…
🔗 Series 050 — The Toolmakers The Food Chain TI-2026-050D · Letter 4 of 5 · Page 300 Step back far enough and the individual campaigns dissolve into something larger. Not fifteen separate scanning operations. One ecosys…
Final synthesis of Series 050 The Toolmakers. Complete operational model of the Go_SSH fleet, Seychelles shell companies, three-tier SSH scanning ecosystem, and defensive recommendations.
TI-2026-051A • The Credential Harvest • Letter I of VI The Password Is the Product In which we discover that 14,652 attempts to type "admin" into a box are not chaos — they are commerce CONFIDENCE: HIGH CATEGORY: CREDEN…
TI-2026-051B • The Credential Harvest • Letter II of VI The Shopping List In which we read the receipts of 133 commands and discover that every attacker arrives with a plan CONFIDENCE: HIGH CATEGORY: BEHAVIORAL ANALYSIS…
TI-2026-051C • The Credential Harvest • Letter III of VI The Stuffing Machine In which 99 IP addresses attack in the same 10-minute window and we learn that coincidence has a threshold CONFIDENCE: HIGH CATEGORY: COORDIN…
🔑 TI-2026-051D KEYS TO THE KINGDOM — The SSH Key as Skeleton Key Series: The Credential Harvest | Letter D of F+ | Confidence: HIGH The Operating Premise: In the physical world, if three burglars from different cities a…
🏪 TI-2026-051E THE TELEGRAM MARKET — Where Access Becomes Commodity Series: The Credential Harvest | Letter E of F+ | Confidence: HIGH The Operating Premise: Everything we've documented in this series — the credential s…
💰 TI-2026-051F THE ECONOMY OF ACCESS — A Distributed Corporation Worth Billions Series: The Credential Harvest | Letter F — Series Synthesis | Confidence: HIGH The Final Premise: Over five previous letters, we dissected…
📡 TI-2026-051G THE SIGNAL IN THE NOISE — When Credential Storms Speak Series: The Credential Harvest — Extension | Letter G | Confidence: MEDIUM ··· − − − ··· ··· − − − ··· ··· − − − ··· WEDNESDAY 02:00 UTC — THE…
⏰ TI-2026-051H THE WEDNESDAY PROTOCOL — Temporal Forensics of a Criminal Schedule Series: The Credential Harvest — Extension | Letter H | Confidence: HIGH The Methodology: Intelligence agencies call it traffic analysis…
📊 TI-2026-051I THE DICTIONARY — What Credential Selection Reveals About the Operators Series: The Credential Harvest — Extension | Letter I | Confidence: HIGH The Question: We've analyzed when they scan (Wednesday, 02:0…
📜 TI-2026-051J THE DOCTRINE — Criminal Operational Science in Ten Letters Series: The Credential Harvest — FINAL LETTER | Confidence: HIGH What We Built: Over ten letters and 102 days of observation, a single SSH honeyp…
🔴 TI-2026-051K THE DARK PORTFOLIO — When Credential Harvesters Host Darknet Markets Series: The Credential Harvest — Extension Letter K | Confidence: HIGH The Question We Avoided: In letters A through J, we documented t…
🎖️ TI-2026-051L THE MILITARY CONNECTION — State Telecoms in the Credential Harvest Series: The Credential Harvest — Extension Letter L | Confidence: HIGH The Uncomfortable Discovery: In 051K we documented criminal ASNs…
⚠️ TI-2026-051M THE EXPLOITATION CREDENTIAL — When Passwords Spell Out Abuse Series: The Credential Harvest — Extension Letter M | Confidence: HIGH ⚠️ CONTENT WARNING: This letter documents exploitation vocabulary found…
🏗️ TI-2026-051N THE COMPLETE ARCHITECTURE — Credential Harvest as Enabler of Everything Series: The Credential Harvest — FINAL SYNTHESIS | Letter N of 14 | Confidence: HIGH 14 Letters. One Architecture. This series bega…
2,089 shared-malware links reveal 82 nodes in 28 countries deploying one binary — seven years of zero evolution because the worm has no predators.
Three parallel deployment chains (Meow worm via GCP, Whisper IoT via Latvia, Chinese C2 triad) — total infrastructure cost $50-100/month.
Attribution methodology: 1,312 IP pairs sharing both malware AND commands prove single-operator coordination exceeding DOJ prosecution standards.
91-day malware evolution: zero mutation (Outlaw) vs maximum polymorphism (sshd backdoors). Ecosystem diversity collapses from 11 species to monoculture.
The complete criminal supply chain: developer, distributor, operator, resource manager, customer — all at zero marginal cost. Structurally indestructible.
Microsoft, DigitalOcean, Google carry 10% of malicious traffic. The roads attackers travel were built by companies that sell antivirus.
Shell companies, registry markers, and Private Customer — 661+ malicious IPs operate without meaningful RDAP attribution.
102,008 abuse reports for one IP. Still online. The abuse reporting system requires contacts exist but not that they respond.
508 IPs under RIPE self-reference. KYC verification evaporates at the LIR-to-customer boundary.
tech@cloudinnovation.org spans 15 ASNs. hm-changed@vnnic.vn is a dead placeholder. Email addresses are organizational X-rays.
Google, Microsoft, Amazon, DigitalOcean host 26.9% of all attack infrastructure. The building has thousands of tenants.
The attack surface is a feature of the architecture, not a bug. Coordination between competitors could fix 60% — but won't.
Temporal correlation analysis reveals three coordination hubs synchronized with 292+ IPs, operating on a nocturnal schedule that exposes timezone-aware human operators
Geographic analysis of 3,085 attacker IPs across 109 countries reveals concentrated attack corridors, timezone handoff patterns, and purpose-built infrastructure
22,311 same-prefix relationships reveal three patterns: Tor anonymization clusters, purpose-built attack subnets, and compromised residential pools
Circadian analysis exposes the human operator behind the automation: evening peaks, Monday batch runs, Thursday dips reveal a CET-timezone side-job pattern
Three-phase operational lifecycle: campaign launch bursts, steady-state maintenance, and periodic activation waves reveal planning cycles behind the coordination network
Complete operator profile synthesized from temporal analysis: CET evening operator running credential validation as a side business with 90-day planning cycles
The largest actor cluster: 269-628 IPs scanning for empty root passwords across 48 countries. Pure reconnaissance with zero exploitation — mapping targets for someone else.
The exploitation counterpart to the scanner fleet: 69-1,313 IPs that actually log in, inject SSH keys, and establish persistent backdoors across 84 countries
A 16-IP European cluster with 100% login success rate evaluates compromised servers for value — container detection, CPU fingerprinting, nanosecond-precision orchestration
A 12-IP operation active for 97 days that only connects and disconnects — the heartbeat monitor of compromised infrastructure
Twenty micro-campaigns reveal the attack ecosystem true diversity: .NET, Rust, Java, IoT botnets, and custom tools
Three highest-threat operations: a Vietnamese ghost army, a manual PuTTY operator still active today, and a multi-tool actor using claude:claude credentials
The complete portrait of a criminal ecosystem: 57 campaigns, 9,928 IPs, 7 languages, 4 supply chain stages observed through one honeypot in 97 days
📡 TI-2026-056A THE CODEBOOK — SSH Credential Storms as Encrypted Broadcast NEW SERIES: The Codebook | Letter A | Confidence: MEDIUM → developing The Hypothesis: What if SSH brute-force attacks are not only attempts to g…
📡 TI-2026-056B — The Heartbeat Protocol Series: The Codebook Classification: CRITICAL Confidence: HIGH — direct measurement, multi-source corroboration Date: 1 July 2026 Executive Summary This dossier presents mathemati…
📡 TI-2026-056C — The Vocabulary Cipher Series: The Codebook Classification: CRITICAL Confidence: HIGH — multi-source convergence, documented parallels Date: 1 July 2026 Executive Summary If credential storms are radio b…
📡 TI-2026-056D — The Broadcast Schedule Series: The Codebook Classification: CRITICAL Confidence: HIGH — statistical + multi-investigation convergence Date: 1 July 2026 Executive Summary Numbers stations broadcast on fi…
📡 TI-2026-056E — The Codebook Stations Series: The Codebook Classification: CRITICAL Confidence: HIGH — multi-source attribution, infrastructure verification Date: 1 July 2026 Executive Summary A numbers station require…
📡 TI-2026-056F — The Decryption Series: The Codebook — FINALE Classification: CRITICAL Confidence: HIGH (architecture) / MEDIUM (specific decoding) Date: 1 July 2026 Executive Summary This is the synthesis. Across five…
Executive portrait of the 89.248.168.227 + 77.246.159.182 dual-node threat. HASSH c39f4cec links both actors. Five findings across evasion, attribution, and defense.
Full forensic profiles of 89.248.168.227 (AS202425, NL) and 77.246.159.182 (AS29182, RU). CrowdSec dual-ban timeline. Behavioral divergence despite identical HASSH.
HASSH fingerprint c39f4cec145ee3d50fb590595143b9d5 — the unclassified Go SSH signature linking 89.248.168.227 and 77.246.159.182. How SSH_MSG_KEXINIT hashing exposes banner spoofing.
Three evasion layers: PTR deception (no-reverse-dns-configured.com, 23 IPs), banner spoofing (SSH-2.0-OpenSSH_7.4 on Go client), multi-protocol scanning. Sophistication ranking HIGH/MEDIUM/LOW-MEDIUM.
AS202425 (IP Volume inc, Seychelles/NL, Spamhaus ASN-DROP) and AS29182 (JSC IOT, Skolkovo Moscow) — the infrastructure providers enabling the dual-node threat. Actor cards A1-A4.
How registration fraud across five registries enables jurisdictional arbitrage — 8 shell company identities, 12 jurisdictions, same HASSH fingerprints proving unified operation.
77.246.159.182: 7 years from cPanel install (2019) through silver trading dormancy to 2026 weaponization. PTR evasion domain registered 2024, renewed 12 days before alert. Reputation laundering via time-decay.
IOC bundle, 5 detection signatures, 3 detection gaps, defensive measures. HASSH c39f4cec as primary detection signal. What the PTR evasion blinds and what HASSH correlation catches.
TI-2026-058A • SERIES: THE OPERATORS • CONFIDENCE: HIGH ⚙️ The Go Machine Anatomy of a 22-Node Automated Reconnaissance Platform Published: 1 July 2026 Sources: Cowrie Honeypot, RIPE DB, Entity Crosslinks, HASSH Analysi…
TI-2026-058B • SERIES: THE OPERATORS • CONFIDENCE: HIGH ⚙️ The Two Machines How Two Go Variants Divide Labor: Reconnaissance vs. Signaling Published: 1 July 2026 Sources: Cowrie Honeypot, RIPE DB, Entity Crosslinks, HAS…
TI-2026-058C • SERIES: THE OPERATORS • CONFIDENCE: HIGH ⚙️ The Constant Retooling Four Go Variants in Six Weeks — Why They Recompile Every Deployment Published: 1 July 2026 Sources: Cowrie Honeypot, Entity Crosslinks, H…
TI-2026-058D • SERIES: THE OPERATORS • CONFIDENCE: HIGH ⚙️ The Supply Chain From Target Acquisition to Malware Delivery — The Complete Kill Chain Published: 1 July 2026 Sources: Cowrie Honeypot, Malware Analysis, Entity…
TI-2026-058E • SERIES: THE OPERATORS • CONFIDENCE: HIGH ⚙️ The Org Chart Complete Organizational Map of a Multi-National Cyber-Criminal Enterprise Published: 1 July 2026 Sources: Series 058A–D Synthesis, 30+ Prior Inves…
Five distinct credential vocabularies decoded as covert communication channels in a multi-national SSH attack enterprise
TI-2026-058G: The Cluster Map Operator Clustering Reveals the True Scale of the Enterprise Series 058: The Operators July 2026 TLP:CLEAR Individual IP addresses lie. SSH fingerprints don't. When 269 nodes across 30 coun…
TI-2026-058H: The Passwords Speak Decoding Temporal Markers, Target Designators, and Cultural Signals in Password Selection Series 058: The Operators July 2026 TLP:CLEAR A password tells you when it was created, who cre…
TI-2026-058I: The Crypto Hunter Anatomy of a Single-Purpose Blockchain Predator Series 058: The Operators July 2026 TLP:CLEAR One IP address. One purpose. Zero shared infrastructure with the larger enterprise. The Crypt…
TI-2026-058J: The True Scale Campaign-Level Analysis Reveals an Enterprise of 2,500+ Nodes Across 84 Countries Series 058: The Operators July 2026 TLP:CLEAR Our previous estimate of 402 nodes was based on operator clust…
🏢 TI-2026-058K: The Shell Companies Series: The Operators | Letter K: Corporate Forensics of the Bulletproof Hosting Pipeline How a multi-national SSH attack enterprise hides behind UK dormant companies, Kazakh village…
🇮🇩 TI-2026-058L: The Indonesian Amplifier Series: The Operators | Letter L: Why Indonesian Infrastructure Hits 11.4× Per IP While Others Average 3.9 Inside the compromised ISP nodes and Chinese-operated cloud instances…
🧬 TI-2026-058M: The Worm's DNA Series: The Operators | Letter M: The Complete Infection Chain of the libssh Worm Fleet 121 commands captured in our honeypot reveal the full lifecycle of the mdrfckr worm: reconnaissance,…
🎓 TI-2026-058N: The University Series: The Operators | Letter N: When a Max Planck Researcher Gets Blocklisted Alongside Worm Fleets 139.19.117.129 made 410 attempts against our honeypot over 27 days. It shares SSH keys…
🕵️ TI-2026-058O: The Counter-Intelligence Series: The Operators | Letter O: How the Enterprise Monitors, Targets, and Acknowledges Security Researchers 168 credential variants. 1,681 scanning nodes. Three years of versi…
925 IPs, 23,298 hits: how cloud-hosted scanners harvest exposed .env, .git and cloud/AI credential files from ephemeral AWS, GCP and Azure compute at the web edge.
Campaign 126: a 200-node empty-User-Agent botnet running entirely inside Microsoft Azure, hunting pre-existing webshells across every region. Why Azure is the disposable attack cloud.
The cms_detect surface decoded: a 28-IP cluster across HK shells, Russia, Brazil and Azure mapping WordPress xmlrpc.php endpoints for system.multicall brute-force amplification and pingback DDoS.
Why scanner_fingerprint is the noisiest web-threat class: how the Authelia auth proxy turns every probe into a 200, and how rd= decoding, UA honesty and reverse DNS separate real crawlers from five-identity impostors.
Why /.git/config is hunted harder than /.env: an exposed git directory leaks the whole repo and its deleted history. Inside the polyglot sweepers and Cloudzy git specialists harvesting secrets at the web edge.
Campaigns 126 and 157 are the two clock-speeds of cloud abuse: a persistent 200-node Azure botnet vs a 10-hour Google Cloud flash. The capstone of The Front Door series on web-edge threat intelligence.
How HTTP 200 masks hostile web traffic from every status-code dashboard — the SSRF out-of-band oracle that returns success by design, benign-on-404 state telecoms, and AWS as the firing range.
The population of the invisible: 20 ASNs that read clean on HTTP 404 yet run 60–100% hostile once the 200-mask is pierced — Chinese state telecoms, offshore recidivists (Contabo, Seychelles), and subdomain-guessing swee…
The HTTP method is a third axis attacks hide on: a lone Armenian IP firing 2,084 CONNECT open-proxy tunnels in five minutes, WebDAV verbs probing for a webshell surface (PROPFIND returns 207, never a 4xx), and the offsh…
The auth proxy is the strongest 200-mask in the corpus — and its own best witness. Decoding Authelia's ?rd= redirect turns a wall of clean 200s into a filename-exact confession: a 15-variant .env dictionary attack, reco…
The synthesis of The 200 That Lied: four orthogonal axes (status, host, method, redirect) that a single mask cannot defeat at once. Cross-axis and cross-sensor convergence turns four deniable signals into one attributio…
LeakIX/l9scan decoded: a self-identifying grey-hat scanner fleet of 14 DigitalOcean droplets firing ~30 unauthenticated critical-CVE probes (Confluence CVE-2022-26134, ProxyShell, PHP-CGI) to stock a for-sale index of t…
B is for Bug Bounty. The friendly 'responsible disclosure' badge and the Zerodium/VUPEN zero-day auction (up to $2M per iOS chain, government-only customers) are one continuous market that prices human defencelessness a…
C is for Cellebrite. The UFED phone-cracker sold as neutral 'digital forensics for law enforcement' — classified 'dual-use civilian' to dodge Israeli export oversight — turned up on the phones of journalists (Botswana)…
D is for Data broker. 'Location analytics' firms (Venntel/Gravy, X-Mode/Outlogic, SafeGraph, Fog, Babel Street) harvested phone-GPS from the ad bidstream and resold it to ICE, CBP, DHS, local police and the US military…
E is for 'Ethical hacker'. 'Ethical' is not a property of an act — it's a registered trademark (EC-Council's CEH), a DoD compliance checkbox, and a signed scope document. The toolchain (Metasploit, Cobalt Strike, Sliver…
F is for 'Fraud prevention'. Device-fingerprinting firms (FingerprintJS, ThreatMetrix/LexisNexis, iovation/TransUnion) sell a persistent, un-clearable cross-site device ID — the same canvas/WebGL technique the CIA's Vau…
G is for GreyNoise. The 'internet observatories' (Shodan, Censys, GreyNoise) call themselves neutral cartographers — but they are consent-free mass-scanners, their exposure index is a symmetric targeting database wired…
H is for 'Threat intelligence'. The defensive feed and the targeting list are the same artifact: an IOC is an indicator of a person (Mandiant's APT1 named PLA officers), automation removes the human check (NIST 800-150)…
I is for Interception. 'Lawful interception' is a back door mandated by law (ETSI TC-LI, 3GPP SA3, CALEA) into every telecom network, sold by respectable vendors (Utimaco, SS8, Qosmos). But the door is architecture, not…
J is for 'Journalism'. OSINT-for-hire and private-intelligence 'research' firms borrow journalism's method and credibility but invert its purpose — surveilling private people for a paying client in secret. Black Cube (e…
K is for 'Knowledge'. The research university launders surveillance and weapons into peer-reviewed respectability on military money: angr (DARPA-funded, UCSB) turned up in the CIA's Vault 7 kit; MIT's Media Lab took ~$1…
L is for 'Loyalty'. Rewards cards and 'membership' are the most consented surveillance there is — the discount is the acquisition price of a permanent, identity-linked, confessional record of everything you buy, monetis…
M is for 'Monitoring'. Bossware (Teramind/Veriato/ActivTrak/Hubstaff) and 'insider threat' security reframe watching your own workforce — keystrokes, screenshots, webcams, productivity/risk scores — as efficiency and pr…
N is for 'NSO'. Mercenary spyware (Pegasus, Paragon/Graphite, Predator) sells zero-click, invisible, total capture of a phone to states under 'we only license to governments to fight terrorism' — but the US confirmed it…
O is for 'Open data'. Clearview AI scraped billions of public photos into a searchable biometric face-print of humanity and sold it to police, under the defense 'it's just public information'. But aggregating faces into…
P is for 'Privacy'. A VPN routes all your traffic through one provider — it moves the watcher, it doesn't remove it — and privacy reduces to an unverifiable 'no-log' promise. Facebook's Onavo was a 'privacy' VPN that su…
Q is for QUANTUM. The NSA/GCHQ programs revealed by Snowden — QUANTUMINSERT/FOXACID backbone injection, the ANT implant catalog, 'collect it all' — turn the internet itself into an exploit-delivery weapon and even hacke…
R is for 'Research'. The meta-letter: the single word running under nearly the whole series — security/vulnerability/academic/investigative 'research'. TI-2026-019J named it the Research Cover ('an insurance company tha…
S is for 'Smart'. Smart TVs, speakers and doorbells are sensors you paid to install in your own home and thanked the store for. Vizio tracked what you watched (FTC 2017); Alexa kept children's recordings (FTC/DOJ ~$25M,…
T is for 'Telecom'. Your carrier knows your location by physical necessity — you cannot use a phone without giving it — so it's the one datum you can't withhold. The four major US carriers sold it to aggregators (Locati…
U is for 'Updates'. Auto-updating agents, RMM and 'observability'/EDR tools run with god-mode and auto-trust their vendor's signed updates — so the update channel is a backdoor you installed for your own good. SolarWind…
V is for 'Verification'. 'Verify yourself' makes your body — face, iris, fingerprint — the credential, and a biometric is a password you can never reset, so a breach is forever. Worldcoin paid the vulnerable for their i…
W is for the WikiLeaks Spy Files — the receipts. The leaked catalogue of the surveillance industry (Amesys, Qosmos, Cellebrite, VUPEN, HackingTeam, SS8…) has been public since 2011, filed under both 'Lawful Interception…
Data fusion and 'decision intelligence' — Palantir Gotham/Foundry — join every stream the Fake Umbrella series named into one searchable, operational profile of a person. 'We don't collect data, we just organise yours'…
Surveillance capitalism — the 'free' ad-funded platform (Google, Meta) whose real customer is the advertiser and whose real product is a behavioural model of you accurate enough to change you. 'You are the product' read…
The Fake Umbrella capstone. Twenty-five letters, one machine: a surveillance supply chain (collection → aggregation → fusion → action) in which every layer is legal, every disclaimer is true, and the total is a per-pers…
A single Go SSH proxy-recruitment scanner (HASSH eff4c24d) operating from two unrelated bulletproof hosting operations — ISAEV (AS200730) and ZornTech/BearShield (AS154383) — probes SSH hosts for tunnel/proxy capability…
A census of 50,348 SSH direct-tcpip forward probes on the LSN honeypot, partitioned into three proxy-validation methods — DNS-canary (1.1.1.1), HTTP provider-fetch (Yahoo/Yandex/Google/MS), and ip-who.com IP-reflection…
151 Vietnamese Viettel residential broadband IPs running AsyncSSH forward exclusively to ip-who.com to check their own exit IP, while brute-forcing embedded devices with a curated IoT/router credential database — the re…
Series synthesis: a two-axis map (datacenter-vs-residential x DNS/HTTP/mirror validation) organising The Proxy Recruiters, positioned against the documented proxy-verification market, with the same open-proxy recruitmen…
A live-captured C2 implant that uses the Telegram Bot API as its command channel: 25 lines of POSIX sh giving a remote shell over any compromised box, un-blockable because it lives on api.telegram.org. Caught in two sam…
Across the LSN honeypot corpus Telegram plays three distinct roles in the attack chain: the loot (stolen sessions, TI-2026-007), the courier (credential exfiltration, TI-2026-002), and the handler (C2, TI-2026-063A) — o…
The TI-2026-063A Telegram-bot-C2 implant is a live IoT instance of MITRE ATT&CK T1102.002. This dossier places it in its decade-long lineage (TeleRAT, Small Sieve, DeerStealer/Lumma) and binds the OSINT library's SIGMA…
Part A of the Circumstantial series: why temporal co-occurrence — attacking in the same 10-minute window — is the weakest attribution signal, and how it manufactures false links between unrelated heavy scanners.
Part B of the Circumstantial series: co-occurrence in independent third-party threat feeds (shared_otx_pulse) is stronger corroboration than a shared clock, but promiscuous infrastructure like Tor exits inflates it — we…
Part C of the Circumstantial series: a shared geolocation discrepancy (cymru=US / ipinfo=Brussels) is the weakest signal (0.35) yet fingerprints the cloud region an operator provisioned in — useful for profiling, worthl…
Part D of the Circumstantial series: network adjacency (same_prefix and kin) carries no fixed weight — near-noise on a hyperscaler, near-identity on a wholly-malicious bulletproof block. The base rate of the container i…
Part E (synthesis) of the Circumstantial series: weak signals become proof only when diverse independent kinds converge on a pair anchored by a strong signal — and the tell that separates intelligence from confirmation…
For a year we tracked Tencent/Aceville (AS132203) through one sensor — the SSH honeypot. The web-threats platform, which did not exist then, now reveals a parallel HTTP attack surface: 203 IPs, 43.5% effective-bad-rate,…
Planned to prove one operator behind AS132203's SSH botnet and web cohort. The evidence refused: they are disjoint at IP, operator-key DNA, tooling, schedule, and reach. What binds them is only the landlord — Tencent/Ac…
Part B hinted the accused was reading its own case file. Tested three ways, the self-monitoring hypothesis fails: AS132203's dossier reads are generic crawler botnet traffic, smaller than Microsoft/Google, and never tar…
The transparency asymmetry of Tencent: the entity built to collect the world's communications is itself the most collected — compellable inward by China's National Intelligence Law, catalogued from outside by the CIA (V…
The AS132203 .env sweep of 065A, decoded: a commodity six-stage kill chain matched probe-for-probe to public tooling in the OSINT library — SecLists, Nuclei, Metasploit git_scanner/aws_keys, HackTricks cloud-IAM escalat…
4,029 open-redirect (rd=) probes from 431 cloud IPs (Amazon/Google-led) against the LSN SSO estate hit a mirror that masks: 0 external targets possible (CWE-601 closed by Authelia rd-validation) and all 36 services retu…
New series, The Allowlist. Held to behaviour not reputation, 63% of intent-labelled web attackers (1,346 of 2,137) ride the hyperscalers defenders whitelist by default — Microsoft, Google Cloud, DigitalOcean, Cloudflare…
Part B of The Allowlist. Web attackers forge identity at scale: fake Googlebot/Bingbot from non-Google ASNs (14.6% of crawler identities, several attacking while wearing it), datacenter IPs in stale desktop-browser cost…
Part C of The Allowlist — RESOLVED. The 76 Cloudflare-edge credential-harvest attackers are confirmed reaching us THROUGH Cloudflare egress (WARP/Workers), not us-behind-CF: DNS resolves to our residential IP, no tunnel…
Part D of The Allowlist. Drei-K-Tech / 3xK Tech GmbH (AS200373): 178 IPs at ebr 0.955, but 154 sent exactly one request each across 85 /24s — a month-long credential-harvest campaign engineered for invisibility. Too obs…
Part E of The Allowlist. The abuse-tolerant midtier hides above consequence, not beneath notice: Advin (AS22295) ran 8,790 requests from 59 stable IPs (149/IP) over a month — the deepest .env sweep in the corpus plus /.…
The Allowlist capstone. Reputation trusts an identity the sender controls — the ASN (A), the user-agent (B), the source IP (C), the request volume (D) — and each was shown forged at scale. Behavior is the only signal an…
A 37-day census of the web attack surface: 159,592 requests and 152 campaigns collapse into just four detection archetypes — every one already dossiered. The web threat reached a confirmation-only steady state.
The Azure shell-checker fleet looks like it grew 269→466 IPs. It didn't. Weekly-active holds a ~150-node plateau while 83% of IPs live a single day — a 3.1x rotation artifact. How cumulative counts fake threat growth.
Every attribution rests on a graph of 943,692 entities reconciling 21 ranked sources — and it records its own disagreement (60,077 open conflicts) rather than hiding it. Opening the black box behind 'who is whom.'
For 10,813 IPs the graph can't say who owns them — 79% are announced by one entity but registered to another. It's the IP-leasing layer as data, and 1,967 of those contested IPs attacked us. The ownership gap is the acc…
The graph's biggest 'threat disagreement' — 12,561 malware domains — turns out to be two feeds using different words for the same thing: URLhaus says malware_download, ThreatFox says payload_delivery. A vocabulary gap t…
Who owns a box comes from the registry; whose hand is on it comes only from behavior. The graph's 'same operator' claims are honeypot-sourced, from the bottom of the authority ladder — and it asserts them for just 97 of…
The credential attack isn't a secret weapon — it's a public GitHub repo (SecLists) sitting in our own library. 161,181 honeypot attempts prove attackers fire it verbatim, protocol-matched, and it's already absorbed 'cla…
The web scanner is public too. 2,010 exploit paths hitting our edge are the Nuclei/Exploit-DB template corpus executed — Git-config, Spring Actuator, .env, ProxyShell — YAML files ranked by EPSS, held in our own library.
Exploit-DB is a library of dated, runnable CVE proofs. The scanning we see is a decade-long changelog — Shellshock 2014 to ProxyShell 2021 to Vite 2025, all fired at once. A patched CVE is never a closed chapter.
MITRE ATT&CK maps ~200 techniques across 14 tactics. The honeypot shows real intruders use ~6, from 4 tactics — and 48% of all commands are one: 'what CPU is this?'. The map is a continent; the territory is a footpath.
The first thing an intruder does isn't reconnaissance — it's an appraisal. CPU model, core count, GPU (414 nvidia-smi checks), who's watching, is it real. They price the stolen machine's compute, then decide whether to…
Persistence isn't just one technique — it's one key. 85 of 86 backdoor installs drop the same Outlaw/Dota3 RSA key (the 0x25-exponent signature). The key that owns the machine is the fingerprint that identifies its owne…
A is for APT. The archive named the apex predator — PLA Unit 61398, Sandworm, Lazarus — and the world rarely caught it. Its three words hollowed out: 'advanced' is now a public template, 'persistent' a one-line key, 'th…
B is for Bulletproof. The host that never answers an abuse report — from the Russian Business Network (2007) and the McColo takedown (2008) to 25+ live bulletproof ASNs at 98-100 risk today, now global and disguised in…
C is for Covert Collection. The WikiLeaks Spy Files exposed the wiretap industry's own catalog — 'Capture and Recording of All Traffic,' exploits as a product line. It didn't end; it became the phone implant (Pegasus, C…
D is for Dota. The commodity Linux SSH mining worm gets no glossy report — it's documented as a YARA rule, and a 2018 signature still fires on our 2026 wire. Seven years, zero evolution: no endpoint protection means no…
E is for EternalBlue. In 2017 two states lost control of their cyber-weapon stockpiles; WikiLeaks called it 'the global arms trade' of exploits. EternalBlue powered WannaCry and NotPetya, then became a Metasploit module…
F is for Financial Rails. Crypto's public ledger made it the one harm enforcement genuinely traces — seizures, mixer sanctions, arrests. So the rail relocates: Bitcoin to Monero to mixers to DeFi. Our worms mine Monero,…
The Alphabet of Harm, letter G: Greece proves letter C's appliance-to-implant surveillance mutation TWICE in one country 18 years apart — the 2004-05 Athens Affair (rogue software on Ericsson AXE lawful-intercept exchan…
The Alphabet of Harm, letter H: RFC 4253's mandated SSH key-exchange handshake is a per-tool fingerprint (HASSH). On live LSN honeypot data, 145,834 hostile SSH connections collapse to just 116 tool-signatures — one lib…
The Alphabet of Harm, letter I: Mandiant's APT1 (2013) exposed a Chinese state MILITARY hacking unit; the February 2024 i-SOON leak exposed the same harm mutated into a private contractor selling espionage as a product…
The Alphabet of Harm, letter J — the meta-letter. Jurisdiction is the harm-enabler behind every other letter: harm crosses borders the law cannot. The Budapest Convention (2001) tried to close the gap; the ODNI 2024 ass…
The Alphabet of Harm, letter K: the recurring demand to mandate a way past encryption. The archive holds the origin — RFC 4949's Escrowed Encryption Standard and its Law Enforcement Access Field, the 1993 Clipper Chip.…
The Alphabet of Harm, letter L: Log4Shell (CVE-2021-44228) made one flaw in a tiny logging library an RCE in millions of systems — the blast radius was the dependency graph. The archive holds it fully weaponized (Metasp…
The Alphabet of Harm, letter M: exploitation shielded by wealth, status, and deference — the Epstein/Maxwell case, read strictly from the adjudicated record. The archive holds the SDNY charging documents, the flight log…
The Alphabet of Harm, letter N: the passive optical tap — NetOptics, Endace/NarusInsight, ONPATH submarine-cable taps — that copies all traffic at the physical layer, undetectable by the tapped party. The archive holds…
The Alphabet of Harm, letter O: ORB — Operational Relay Box networks. Origin-laundering by relay so the address a defender sees is a dead end. The archive traces the arc — commodity open SOCKS proxies (Nuclei), the ad-h…
The Alphabet of Harm, letter P: voice biometrics — the identifier you can never change. The archive holds the industry (Phonexia speaker search, STC's nation-wide VoiceNet.ID, Agnitio's SIFT in 25 countries beside finge…
The Alphabet of Harm, letter Q: QUANTUM — the NSA man-on-the-side injector (QUANTUMINSERT racing a target's web request to the FOXACID exploit server, Snowden 2013). The active twin of letter N's passive tap: same netwo…
The Alphabet of Harm, letter R: ransomware mutated from lone file-encryptors into a commercial industry — RaaS subscription franchises (FinCEN/Treasury), double extortion (encrypt + steal + leak, CISA), triple/harassmen…
The Alphabet of Harm, letter S — the reflexive meta-letter. The 2011 WikiLeaks Spy Files exposed the global mass-surveillance industry (~160 vendors: Amesys, HackingTeam, NetOptics, Phonexia…), turning it from secret to…
The Alphabet of Harm, letter T: Telegram — the platform as ungoverned territory. Its design (huge public channels, minimal moderation, non-cooperation) made it a coordination layer for extremism (Treasury), fraud (Treas…
The Alphabet of Harm, letter U: Unpatched — the patch gap. Attackers exploit known, published, patched-in-principle vulnerabilities because the world runs unpatched — a patched vuln is a working 0-day against everyone w…
The Alphabet of Harm, letter V: VasTech — mass retention and retrospective search. Its Spy Files decks state the modality outright — ZEBRA, 'Strategic Surveillance of all Communication,' and 'Record all and filter → Lon…
The Alphabet of Harm, letter W — the sober counterweight to S. Mass disclosure is double-edged: the same act that exposes the powerful (accountability, the Spy Files) causes collateral harm (Vault 7 dumped live CIA expl…
The Alphabet of Harm, Letter X. XKeyscore is the query layer atop the tap and the warehouse — search everything you collected, about anyone. The distinct harm is access governance: who may query, under what authorizatio…
The Alphabet of Harm, Letter Y. YARA is the defender's pattern-rule — the reflexive twin of XKeyscore. A rule is an accusation encoded in bytes: this pattern means bad, therefore act. The harm is who writes the rule, th…
The Alphabet of Harm, Letter Z — the closer. Zero-accountability is the constant under every prior letter: the harm was never the primitive but the absent watcher. Attribution is solved; consequence is not — indictments…
The Alphabet of Actors, Letter A — Amesys. The French vendor whose EAGLE/GLINT system did nationwide content interception (Mail, Chat, HTTP, VoIP), sold to Gaddafi's Libya and found in a Tripoli monitoring room. It titl…
The Alphabet of Actors, Letter B — Blue Coat. The dual-use case: a genuinely useful enterprise ProxySG appliance (categorize every URL, allow/deny, log, and — decisively — an SSL Proxy that decrypts TLS) that turned up…
The Alphabet of Actors, Letter C — Chengdu 404, the PRC front company the US identifies as APT41. The dual-purpose actor ('Double Dragon'): state espionage and for-profit crime in one crew, fused by its signature move —…
The Alphabet of Actors, Letter D — DarkSide. Crime, incorporated: the ransomware-as-a-service franchise (affiliate program, leak site, press office, a 'code of conduct' that was really heat-avoidance) the FBI tied to th…
The Alphabet of Actors, Letter E — Equation Group, the apex intrusion set attributed to the NSA. The Western-state counterpart to Letter C. The distinct harm is the stockpile that escaped: firmware implants and a hoarde…
The Alphabet of Actors, Letter F — FinFisher (Gamma Group). The infection answer to encryption: an endpoint implant (FinSpy) that reads plaintext on the device, explicitly built to defeat 'end-to-end encryption from the…
The Alphabet of Actors, Letter G — GRU / Fancy Bear (APT28). The hack-and-leak: steal to publish, not to keep. The theft is espionage; the leak is the weapon; public perception is the target (DNC 2016 via Guccifer 2.0/D…
The Alphabet of Actors, Letter H — Hafnium. The smash-and-grab: a state actor that took the Microsoft Exchange ProxyLogon zero-days and, racing the patch, sprayed them across tens of thousands of servers indiscriminatel…
The Alphabet of Actors, Letter I — Intellexa. Where FinFisher was a company you could reach, Intellexa is an alliance you cannot: Predator spyware sold through a multi-jurisdiction corporate maze built to dodge export c…
The Alphabet of Actors, Letter J — Jia Tan, the persona behind the XZ Utils backdoor (CVE-2024-3094). The long game: don't steal the trusted key or fake the update — become the trusted maintainer. Years of patient open-…
The Alphabet of Actors, Letter K — Kimsuky, North Korea's espionage-by-rapport group. The isolated regime that phishes the world's Korea experts: impersonating journalists and academics to lure analysts into simply repl…
The Alphabet of Actors, Letter L — LockBit, the world's most prolific ransomware-as-a-service brand and the mirror of DarkSide. Where DarkSide self-destructed under heat, LockBit was taken down by Operation Cronos — whi…
M is for Mirai: the botnet that weaponised the Internet of Things by guessing default passwords, took down Krebs, OVH and Dyn in 2016, and became immortal when its source was released. Its authors were convicted — and i…
N is for NSO Group: the Israeli firm whose Pegasus spyware industrialized the mercenary model — a zero-click phone-interception weapon sold to governments as a deniable product. The archetype the whole spyware market co…
O is for OceanLotus (APT32): the Vietnam-nexus state actor that runs like a business — stealing from foreign automakers for national economic advantage, hiding inside crimeware tradecraft, and hunting the state's own jo…
P is for Park Jin Hyok: the North Korean programmer the US named — the register's first individual — as part of the Lazarus conspiracy that robbed Bangladesh Bank via SWIFT, ransomed the NHS with WannaCry (built on leak…
Q is for QakBot: the quiet loader that manufactured footholds and sold them to ransomware crews — the middleman of the extortion supply chain. In August 2023 Operation Duck Hunt seized its command channel and pushed an…
R is for REvil (Sodinokibi): the Russia-based ransomware-as-a-service that turned the software supply chain into a weapon — one Kaseya compromise cascading to ~1,500 businesses, a $70M demand, JBS and the food supply hi…
S is for Sandworm (Russia's GRU Unit 74455): the military cyber unit that turned off Ukraine's power in 2015 — the first blackout caused by hacking — built NotPetya, the ~$10B most costly cyberattack in history, faked a…
T is for Turla (Snake/Uroburos): Russia's FSB espionage service, the oldest and stealthiest actor in the register — a two-decade lineage from Agent.BTZ (the 2008 breach that helped birth US Cyber Command) to Snake, hidi…
U is for UNC2452 (SolarWinds / APT29 / Cozy Bear): Russia's SVR, the third head of the Russian bear after the GRU and FSB. It poisoned a signed SolarWinds Orion update, rode it into ~18,000 organizations, and — with a p…
V is for Volt Typhoon: the Chinese state actor that broke into US water, power and communications not to steal but to pre-position — a loaded gun placed inside critical infrastructure against a future war over Taiwan. I…
W is for Wizard Spider: the Russia-based syndicate behind TrickBot, Ryuk and Conti — cybercrime industrialized into a corporation. The 2022 Conti Leaks exposed salaries, HR, an org chart and a boss called Stern; the sam…
X is for Xenotime: the actor behind TRITON, the first malware built to attack a plant's Safety Instrumented System — the automated last line of defense that keeps a petrochemical facility from exploding. Widely assessed…
Y is for Yanluowang: the small ransomware crew linked to the 2022 breach of Cisco — a security giant, entered not with a zero-day but through a tricked employee (stolen synced credentials + MFA-fatigue vishing). The hum…
Z is for Zeus — the finale. The banking trojan that taught crime to scale, whose 2011 source leak seeded an immortal genus (as Mirai later did), and whose creator Evgeniy Bogachev ran Gameover Zeus to rob banks AND spy…
**TI-2026-073A · Series: The Agent Frontier (Part A) · TLP:WHITE · 2026-07-10**
**TI-2026-073B · Series: The Agent Frontier (Part B) · TLP:WHITE · 2026-07-10**
**TI-2026-073C · Series: The Agent Frontier (Part C) · TLP:WHITE · 2026-07-10**
**TI-2026-073D · Series: The Agent Frontier (Part D) · TLP:WHITE · 2026-07-10**
**TI-2026-073E · Series: The Agent Frontier (Part E) · TLP:WHITE · 2026-07-10**
Follow the Money · 01 — a new forensic register. Where The Alphabet of Actors asked who broke in, this one asks where the money went. Case 01 follows a ransomware payment from a hospital's coerced wire through FinCEN's…
Follow the Money · 02 — the marquee flow, where following the money reveals stakes no attack-analysis can: the through-line from a stolen gaming token to a warhead. North Korea's Lazarus Group stole ~$620M from the Roni…
Follow the Money, Case 03 — RECOVERED. Colonial Pipeline paid ~75 BTC to DarkSide; the FBI traced the ransom across the public ledger and seized ~$2.3M by obtaining the wallet's private key. 'Not your keys, not your coi…
Follow the Money, Case 04 — FROZEN. Centralized stablecoins (USDT, USDC) carry a contract-level freeze the issuer controls: blacklist an address and its tokens become permanently unmovable, no private key needed. Trigge…
Follow the Money, Case 05 — VANISHED. The mixer (Tornado Cash) pools deposits and issues clean withdrawals so the on-chain link between crime and cash dissolves in the anonymity set. It laundered hundreds of millions fo…
Follow the Money, Case 06 — CONVERTED. Pig-butchering (sha zhu pan) has two sets of victims: the targets manipulated over months into converting their savings to crypto, and the trafficked workers held in guarded Southe…
Follow the Money, Case 07 — RECOVERED. Business Email Compromise is the FBI IC3's largest fraud category by dollar loss, and its money moves as a plain bank wire, not crypto. Once a fraudulent wire is sent, the FBI's Fi…
Follow the Money, Case 08 — SPENT. The darknet marketplace (Silk Road, AlphaBay, Hydra) is not a storefront but an unregulated bank: it escrows buyers' crypto, adjudicates disputes, takes commission, and — with Hydra —…
Follow the Money, Case 09 — CONVERTED. North Korea's IT-worker scheme: thousands of skilled operatives use stolen identities and US 'laptop farms' to get hired as remote developers worldwide, do real work, and funnel th…
Follow the Money, Case 10 — VANISHED. The crypto Ponzi, an ancient fraud in blockchain costume: OneCoin (a 'currency' with no real blockchain, its price simply set by its sellers) and BitConnect (a real token, a fake tr…
Follow the Money, Case 11 — LAUNDERED. The cross-chain bridge is both the richest heist target (Wormhole, Nomad, Harmony, Ronin — hundreds of millions each) and the launderer's highway: 'chain-hopping' moves stolen valu…
Follow the Money, Case 12 — CONVERTED. Every crime in this series eventually needs the same service: turning crypto into spendable cash. The 'bulletproof' exchange (Suex, Garantex, Bitzlato, BTC-e) sells it — conversion…
Follow the Money, Case 13 — FROZEN. Against the fear narrative: crypto terror financing is real but smaller and far more traceable than assumed. When Hamas's al-Qassam Brigades posted public donation addresses, the perm…
Follow the Money, Case 14 — CONVERTED. The register's most lethal conversion: cartels (Sinaloa, CJNG) pay overseas chemical suppliers — increasingly in crypto — for the fentanyl precursors cooked into the drug that driv…
Follow the Money, Case 15 — LAUNDERED. Under the million-dollar-ape spectacle, two old crimes in a perfect new instrument: wash trading (trading an NFT between your own wallets to fake value and volume, luring real buye…
Follow the Money, Case 16 — VANISHED. The honest counterweight to the whole series. Fifteen cases said 'the ledger remembers'; privacy coins (Monero) are where that stops being true. Ring signatures, stealth addresses,…
Follow the Money, Case 17 — RECOVERED. The reckoning at the market's center: in November 2023 Binance, the world's largest exchange, pleaded guilty and paid ~$4.3B for operating as an unregistered US money transmitter a…
Follow the Money, Case 18 — SPENT. Ransomware became an industry: ransomware-as-a-service, a franchise of developers, affiliates, and initial-access brokers, with a product roadmap (double/triple extortion that defeats…
Follow the Money, Case 19 — FROZEN. When a state is cut off from the dollar (Russia, Iran, DPRK), crypto looks like an escape hatch around the blockade. It's real but walled: too shallow to carry a national economy, too…
Follow the Money, Case 20 — VANISHED. The register's most intimate crime: a scammer posing as the IRS, tech support, or a grandchild panics an elderly victim into feeding cash into a crypto ATM, which converts it to irr…
Follow the Money, Case 21 — LAUNDERED. Laundering became a service industry. Professional money-laundering organizations and Chinese underground-banking networks wash any crime's proceeds for a fee — the cartel, the ran…
Follow the Money, Case 22 — RECOVERED. In 2021 an attacker drained ~$610M from Poly Network — the largest DeFi hack of its time — and then gave nearly all of it back, styling themselves 'Mr. White Hat.' Why? The money w…
Follow the Money, Case 23 — SPENT. The deepest betrayal: money stolen not by an outside hacker but by the custodian you trusted to hold it. Keeping crypto on an exchange means holding an IOU, not coins — and FTX (SBF co…
Follow the Money, Case 24 — FROZEN. The complement of the returned heist: the thief who won't give it back and can't spend it either. So billions in stolen crypto sit dormant for years — visible to all, movable by none…
Case 25 of Follow the Money: the SIM swap. A criminal talks a carrier into moving a victim's phone number to their own SIM, inherits the SMS 2FA and recovery codes it unlocks, and drains the victim's crypto into the lau…
The finale of Follow the Money. Twenty-six cases in, the verdict is on the ledger itself: the public blockchain is a perfect memory of movement and a total amnesiac of meaning. Most stolen crypto is laundered, converted…
**TI-2026-075A · Series: The Armory (Part A) · TLP:WHITE · 2026-07-10**
**TI-2026-075B · Series: The Armory (Part B) · TLP:WHITE · 2026-07-10**
**TI-2026-075C · Series: The Armory (Part C) · TLP:WHITE · 2026-07-10**
**TI-2026-075D · Series: The Armory (Part D) · TLP:WHITE · 2026-07-10**
**TI-2026-075E · Series: The Armory (Part E) · TLP:WHITE · 2026-07-10**
The post-login command record sorts, cleanly, into a small number of behavioural phases. The first is **orientation**, and `whoami` is its signature.
That is not an accident of growth. It is an architecture. This is what a fleet looks like when its designer's first priority is not efficiency but *survival* — when the operator has looked at how takedowns actually happ…
If the addresses churn and the device count is hidden, how do we know this is one fleet at all, rather than 155 unrelated Vietnamese machines that happen to run the same common library?
So the reallocation the series argues for is concrete: stop chasing the ever-changing artifact, and detect the unchanging act. You will never keep pace with the recompiled weapon. You can absolutely catch the operator w…
There are, in the record, three doctrines of loading — and a fourth category that fires nothing at all.
The honeypot has watched this handoff 247 times, from 152 IPs. What it delivers is a small, reused, and revealing arsenal.
You do not have to take the language choice on faith that it signals sophistication — the swarm's behaviour confirms it, in tells no commodity botnet leaves.
It is worth being precise about why the PuTTY fingerprint carries the weight it does, because the inference is unusually strong.
That is what reconnaissance is: not the break-in, but the intelligence that makes the break-in efficient. The mapmaker is the tool that gathers it, one silent handshake at a time.
The Glue deserves its own letter precisely because it is the least weapon-like weapon in the armory — the point where the tool catalogue stops being a catalogue of tools and becomes a catalogue of *infrastructure*.
The letters so far have profiled *named* tools — Hydra, PuTTY, Nmap, Paramiko, the Go swarm. But the largest populations in the census are not named utilities at all. They are raw library versions. And they are enormous.
They deserve a single letter, together, because their most important property is precisely that they are interchangeable.
The previous letter, *The Version Fleets* (075P), was about reach — the giant libssh cohorts, 1,341 IPs of one build across 84 countries. This one is about danger, and the first thing to say is that the two are not the…
Every letter so far has counted attacks — tools that fire, magazines that spray, payloads that land. But the single most common thing in the honeypot's entire record is not an attack. It is the *absence* of one.
That is the subject of this letter. Every other tier of the armory announces something suspicious about itself. This one announces the opposite — *I am ordinary* — and does so precisely because ordinary is the best disg…
Here is what makes the reused key such a gift: avoiding it costs *nothing*.
But the interesting thing about the bulletproof shelf is not that it exists. It is how *little* of the armory actually sits on it.
Time, it turns out, is as characteristic as any handshake. When a fleet fires binds it as surely as what it fires — and, as we will see, the rhythm of an operation can separate a machine from a human hand without any ot…
Except they don't. The same addresses appear in both. And when they do, they reveal something the SSH census alone could never show: that an operator the series has been profiling as an *SSH attacker* is, from another w…
This final substantive letter is about that innocent fraction — because it turns out to be the purest possible demonstration of the thesis the whole series has been building toward.
The method matters as much as the findings, and the method is the second thing the finale makes explicit.
Case 01 of Follow the Access, the sequel register to Follow the Money. The most common way into a machine on the internet is not an exploit but the unchanged factory password: admin:123456, tried 5,385 times on the hone…
Case 02 of Follow the Access. When the default password is changed but weak, the attacker guesses — credential brute force and password spraying run at machine speed by Hydra, Medusa, Ncrack, and Paramiko, fingerprinted…
Case 03 of Follow the Access. The internet-facing Remote Desktop endpoint is the ransomware era's most consequential access vector: unlike an SSH shell, RDP hands the attacker the victim's own graphical Windows desktop,…
Case 04 of Follow the Access. The second of CISA's two dominant ransomware doors — but where Case 03 forced a machine, the phish deceives a person, bypassing every control by targeting the one component no firewall defe…
Case 05 of Follow the Access. The internet-facing security appliance — the VPN, firewall, and gateway bought to keep attackers out — is exploited to let them in. Exposed by design, trusted implicitly, poorly monitored,…
Case 06 of Follow the Access. Unauthenticated remote code execution against a public-facing web application — the vector that severs access from identity: no login, no user, just a crafted request that a bug turns into…
Case 07 of Follow the Access. The purest misconfiguration in the register: an internet-exposed database (Redis, MongoDB, Elasticsearch) with authentication off — no lock to pick because there is no lock, and connecting…
Case 08 of Follow the Access. The exposed Docker daemon socket (port 2375) or unauthenticated Kubernetes API is a remote root primitive: launching a container that mounts the host is owning the host, and the K8s API mul…
Case 09 of Follow the Access. Where the phish tricks a user into typing one credential, the infostealer runs on the endpoint and empties the whole credential warehouse in a single silent sweep — saved passwords, session…
Case 10 of Follow the Access — the keystone. The initial access broker sells footholds he does not use, the wholesaler between the producers (brute-force, phishing, infostealers) and the operators (ransomware). Access i…
Case 11 of Follow the Access. The most effective modern intruder does not break in — he logs in, with a valid stolen credential, and lives off the land using the target's own tools (PowerShell, WMI, RDP) so nothing look…
Case 12 of Follow the Access. The register kept naming MFA as the fix; this case follows the crews who defeat it without breaking it — push-bombing (fatiguing the user until they tap approve) and help-desk social engine…
Case 13 of Follow the Access. The one-to-many attack: breach not the target but a supplier it trusts, and the poison flows downhill into everyone downstream who installs it. SolarWinds reached thousands through one tamp…
Case 14 of Follow the Access. The inversion of phishing: instead of luring the victim to a strange place, the attacker poisons a legitimate site the victim already visits and trusts, and waits. From DarkHotel's strategi…
Case 15 of Follow the Access. The fake installer poisons the act of acquiring software: malvertising buys the ad above the real download, SEO poisoning games the top result, and the pirate lure routes crack-seekers to t…
Case 16 of Follow the Access. Bring Your Own Vulnerable Driver: an attacker already inside brings a legitimate, vendor-signed but flawed driver (WinRing0 and its kin), loads it because the signature is real, and exploit…
Case 17 of Follow the Access. The professional intruder's first act is persistence — cutting a copy of the key before the lock is changed. The honeypot captured it 3,240 times: attackers planting their own SSH key in au…
Case 18 of Follow the Access. The IoT worm (Mirai, Mozi, Bashlite — captured on the honeypot as elf.mirai/elf.bashlite) is self-propagating: it infects a weak-credential device and immediately uses it to infect more, a…
Case 19 of Follow the Access. The wormable exploit spreads by flaw, not credential — carrying its own way in (EternalBlue in SMB, Log4Shell in Log4j) and sweeping unpatched networks machine-to-machine in minutes, uncont…
Case 20 of Follow the Access. The leaked secret is a credential the victim published by accident — a cloud key committed to a public repo, left in an exposed .env, or embedded in shipped client code. Automated scanners…
Case 21 of Follow the Access. The insider never broke in — the organization gave them the keys. It inverts every defense: MFA, patching, and the perimeter all assume the attacker is unauthorized, but the insider is auth…
Case 22 of Follow the Access. Cloud instances expose a metadata endpoint (169.254.169.254) that hands out their IAM credentials — the keys to the machine's cloud identity, at a URL the machine can request. A Server-Side…
Follow the Access, Case 23. Mass internet scanning is the census beneath every vector: 3,477 honeypot scanner IPs running libssh/Go_SSH/AsyncSSH/Nmap toolchains, sweeping the whole IPv4 internet in hours so exposure equ…
Follow the Access, Case 24. Credential stuffing replays breached username:password pairs against unrelated services — the combolist. The honeypot watches the replay: admin:123456 tried 5,385 times, admin:admin from 136…
Follow the Access, Case 25 — the reflexive case. The honeypot is itself the first machine, so this fate is watched from inside, not inferred: the automated post-access routine (recon, ipinfo/ifconfig callbacks, wget|sh…
Follow the Access, the finale. The verdict on 25 vectors: four laws (exposure equals discovery; the takeover is automated and indifferent; the economy is specialized and commoditized; the victims become the infrastructu…
Before the fingerprints and the ASN numbers, here is the whole story in ordinary words.
So when you say "block the VPN exit," what you are actually saying is: *block the doorway that thousands of innocent people are using, in order to stop the one who is not.* That is the whole problem in a sentence, and e…
The single hardest piece of evidence is an address we have already met: **`5.183.101.141`**.
Here is the twist that completes the portrait. For all its spotless reputation, AS212238 does not live in a different world from the bulletproof floor. It is routed **right beside it.**
Every server on the internet gets attacked constantly. That is normal, and most of it is faceless background noise — automated scanners sweeping the whole internet, hitting your address the same way they hit everyone's,…
Part A described a front — two thousand machines, faceless and statistical. This letter is about one of them, and it is the letter where the offensive stops being a number and becomes personal, because this machine does…
This is the letter where the offensive's scale stops being impressive and starts being *instructive* — because the way it is built is precisely designed to defeat the standard defence, and understanding how it does that…
Which forces the question this finale exists to answer: **why can no one make it stop?**
The previous series, *The Cloud Offensive*, was about the hardest possible network to defend against: Google Cloud, so reputable and so essential that it cannot be blocked. This series is about its exact opposite — and…
But the *mechanism* of probing is not what makes this probe notable. What makes it notable is the one request that reveals how the attacker knew `lsn-docsearch` existed at all.
Start with the structure, because the structure is the first reason the operator is hidden.
Follow the Operator, Case 01. One operator, 124 honeypot IPs across 56 ASNs and 15 countries — every surface attribute varied to look like a crowd, but all 124 offer the identical SSH key at login. The key is the invari…
Follow the Operator, Case 02. Where Case 01 read the key an operator offers at login, this reads the key he leaves: the public key planted into victims' authorized_keys for persistence (MITRE T1098.004). 81 backdoored h…
Follow the Operator, Case 03. A HASSH fingerprint hashes the algorithm set an SSH client declares before authenticating — a signature of the tool, not the address. A 92-IP, single-country cluster all fingerprinting as A…
Follow the Operator, Case 04. 12 delivery IPs across 9 countries tied to one operation by a shared payload. The malware is three invariants — hash, staging URL, C2 — and attribution rests on the bespoke config (C2, wall…
Follow the Operator, Case 05. Attackers who share only a bulletproof host share a landlord, not a hand — the honeypot's high-threat registrants (TechTies Inc. ~47 IPs at avg threat 78.5; IP Manager ~33). The register's…
Follow the Operator, Case 06. A scripted post-access routine is deterministic — the same commands in the same order every session, captured verbatim by the honeypot across scattered IPs. Attribution lives in authorship…
Follow the Operator, Case 07. The credential wordlist an operator brings — captured pair by pair by the honeypot (33,977 unique pairs). The common head (admin:123456) attributes nothing; identity lives in the rare curat…
Follow the Operator, Case 08, closing the behavioral arc. An operator scatters his IPs across the world but works on his own clock: a diurnal hour-of-day curve leaks his real timezone regardless of where his machines ge…
Follow the Operator, Case 09. Unlike Case 05's rented bulletproof host, the C2 is the operator's OWN — the point his whole fleet converges on. Its TLS certificate, JARM, and panel fingerprints survive an address change…
Follow the Operator, Case 10, opening the identity arc. When does the abstract hand acquire a name? Registration records (WHOIS/RDAP/certificate transparency) can carry the operator's identity — but they are the most-po…
Follow the Operator, Case 11. Where Case 10 read the identity an operator was forced to register, this reads the one he chose: his handle, kept out of vanity because it carries his reputation, reused across services and…
Follow the Operator, Case 12 — the first null case. Tor/VPN/proxy sever the address (28 Tor exits in the honeypot), defeating every address-based signal. But the cut hides the address, not the session: the key, tool fin…
Follow the Operator, Case 13. The whole method applied to one cluster: the 124-IP operator walked end to end through key, coordinated timing, consistent behavior, and tool fingerprint — four independent invariants that…
Follow the Operator, Case 14. Attribution is not isolated verdicts but one 200,000+ edge graph — the six signals are edge types, operators are dense regions, and every new cluster is cross-referenced against all prior d…
Follow the Operator, Case 15. The inverse of the bulletproof host: the legitimate mega-cloud (Google AS396982, DigitalOcean, Microsoft, OVH tops the honeypot's attacker ASNs). Un-blockable and clean-reputation, so opera…
Follow the Operator, Case 16. The operator who knows he's being attributed and plants signals to frame someone else — a foreign string, a rival's tool, a borrowed C2 — weaponizing the analyst's method against an innocen…
Follow the Operator, Case 17. Attribution is revisable: two campaigns documented as distinct operators, revealed as one hand when a heavy cross-cluster edge (a bespoke key reused across both) bridges them. Merge only on…
Follow the Operator, Case 18, the mirror of the merge. One cluster documented as a single operator, revealed as two — falsely joined by a light bridge (a shared common tool). The tell is the internal structure: two dens…
Follow the Operator, Case 19 — the promised failure case. A shared bespoke key, the register's strongest signal, bridges two clusters — but they contradict on behavior, timing, and every other invariant, sharing only th…
Follow the Operator, Case 20 — the intrusion that is genuinely two operators' work. In the access-broker economy the hand that GAINS access (the broker, who sells it) and the hand that USES access (the buyer) are differ…
Follow the Operator, Case 21 — the register's closest approach to a name. A persona (a self-chosen, reused, near-unshareable handle) is the strongest LEGIBLE identity signal; when it appears in both honeypot evidence an…
Follow the Operator, Case 22 — the honest null. The ghost leaves no durable invariant: rotates keys per session, uses commodity default tools, rents fresh infrastructure, varies behavior, carries no persona — defeating…
Follow the Operator, Case 23 — the scanner layer. Before most attacks there is a scan, but most scan fingerprints belong to internet-wide mass-scanners (research censuses, scanning-as-a-service) that precede nearly ever…
Follow the Operator, Case 24 — the methodological capstone. The register audits its own confidence scale: HIGH/MEDIUM/LOW/DECLINED defined as auditable claims, not moods. Two principles govern it — the SHAREABILITY GRAD…
Follow the Operator, Case 25 — the reflexive turn. The 200,000-edge entity graph is drawn not by a human but by the LINKER, an automated engine — so the linker IS the register's method executed automatically, and auditi…
Follow the Operator, Case 26 — THE VERDICT (finale). The whole register's synthesis: attribution is the search for the INVARIANT THAT SURVIVES TRANSFORMATION — the fixed point of an operator's disguises, the one thing h…
Follow the Payload, Case 1 — the register opens. The frame: the payload is the purpose made executable — a payload's intent is not inferred like a motive but EXECUTED, observable directly. The cryptominer is the archety…
Follow the Payload, Case 2 — STEAL BANDWIDTH. The proxy payload turns the host into a residential exit node, stealing not compute but network position — its clean IP reputation, used to LAUNDER malicious traffic (creden…
Follow the Payload, Case 3 — RECRUIT, the register's first META-objective. A botnet agent does not USE the host — it ENROLLS it, subordinating it to a remote commander to await orders. So the register reads two intents…
Follow the Payload, Case 4 (methodology) — the intent/author split formalized. SHAREABILITY governs both registers and moves them in OPPOSITE directions: it destroys author-confidence (widely-shared = no single hand) bu…
Follow the Payload, Case 5 — STEAL DATA. The harvester reads the host's credential stores (SSH keys, cloud credentials, tokens, secrets) and exfiltrates them. Its defining feature: the loot is itself a KEY, so the theft…
Follow the Payload, Case 6 — STEAL DATA (bulk). The exfiltrator steals the data itself (documents, databases, records) — TERMINAL loot, the mirror of the harvester's generative keys, pointing to a passive downstream har…
Follow the Payload, Case 7 — EXTORT. Ransomware inverts the register: every prior payload wanted to stay hidden, but ransomware REQUIRES being seen — the victim must know to pay. So its intent is DECLARED, not inferred:…
Follow the Payload, Case 8 — DESTROY (declared EXTORT refused). A wiper dressed as ransomware encrypts or corrupts files and demands payment for a decryptor that does not exist: the declared objective (EXTORT) is a lie…
Follow the Payload, Case 9 — PERSIST, the sixth and foundational objective. A backdoor does not mine, steal, or extort; it keeps the door open so the operator can RETURN. PERSIST is the objective of maintaining access i…
Follow the Payload, Case 10 — DELIVER (terminal objective deferred). A loader/dropper/stager exists to fetch and run ANOTHER payload; its own objective is delivery, and the terminal intent resides in a second stage it d…
Follow the Payload, Case 11 — the honest null. A payload found on disk but never executed forces the register to separate CAPABILITY (what it COULD do) from INTENT-EXPRESSED (what it DID). The capability is readable (a…
Follow the Payload, Case 12 — MISDIRECT. A decoy is a payload planted to be FOUND and MISREAD, so the analyst reads it as the objective and stops — while a quieter payload does the real work. The payload-layer false fla…
Follow the Payload, Case 13 (methodology) — the dual-use tool. Netcat, curl, ssh, tar, PowerShell: a binary that is INTENT-NEUTRAL, used identically for administration and attack. This breaks artifact-reading (identifyi…
Follow the Payload, Case 14 — STACK (plural objectives). Real intrusions drop several payloads with different objectives (backdoor + miner + harvester) on one host — the norm — so the objective is PLURAL. Two readings:…
Follow the Payload Case 15 — the rented payload: a malware-as-a-service payload is built by a vendor and deployed by an unrelated affiliate, splitting author into two hands. Intent belongs to the deployer; the family id…
Follow the Payload Case 16 — the self-propagator: a worm's directly-readable objective is PROPAGATE, but propagation is a meta-objective (a means, not an end). The register reads the spread at HIGH and holds the termina…
Follow the Payload Case 17 — the DDoS cannon: the register's first two-victim case, whose objective is aimed past the host. It weaponizes the machine to fire at a third party — two victims (the host owner and the extern…
Follow the Payload Case 18 — the anti-analysis payload: the one built to defeat the register's method. The armor reads HIGH, the core reads unknown-behind-armor. Evasion is a protective meta-behaviour that leaks intent…
Follow the Payload Case 19 — the objective that changed: the same foothold serves many purposes over time, so the objective is a timeline, not a point. Three drivers — escalation, monetization pivot, re-sale. Read each…
Follow the Payload Case 20 — the sleeper: a payload present but unfired. Dormancy means unfired, not unknowable — a logic bomb carries its trigger and action in code, so the latent objective reads at HIGH while the exec…
Follow the Payload Case 21 — the misattributed objective: how the register reads an objective wrong. Adversarial misreads (decoy, false flag) and methodological ones (benign, wrong-phase, wrong-payload), and the master…
Follow the Payload Case 22 — the payload with no objective: a genuine null, completing the trilogy unread/unfired/absent. Four forms (broken, debris, misfire, purposeless); the null verdict is a high bar requiring posit…
Follow the Payload Case 23 — the living-off-the-land intrusion: an operation with no payload. The register reads the objective from the action-sequence (the behavioural kill-chain), not an artifact — proving 'Follow the…
Follow the Payload Case 24 — the Intent Ledger: the methodology capstone assembling every discipline into a five-column accounting instrument (WHAT/CONFIDENCE/STATE/AUTHOR/UNKNOWN-TYPE) governed by a double-entry balanc…
Follow the Payload Case 25 — the classifier: the register's method applied to the machine that reads objectives at scale. The Intent Ledger is what makes a classifier possible, but the machine inherits the disciplines o…
Follow the Payload Case 26, the finale — the Verdict: what the whole register establishes about purpose. The payload cannot hide its purpose; purpose is the last and hardest concealment, possible only by abandoning it.…
Except this one lies about where it is, and it lies more than once.
Pull the registration apart and the United Kingdom evaporates:
Strip the assumption that a company holding address space must be a hosting company, and look at what the registries say.
Every entry below shares one thing and only one thing that matters: it sits in the EMBNEX (AS401661) downstream cone, most drawing a `/48` from `2604:be0::/32`. Everything else — the name, the flag, the story — is paint.
Start with the behaviour, because it reframes the category the tripwire assigned.
That was one axis. This part finds a second one, running perpendicular to it.
What came next identifies the target as an embedded device, not a server:
It did not answer the more interesting question: **what was the loader aiming at?**
Where the shotgun sprays, the appraiser inspects. Same trail, opposite doctrine.
Then look at the honeypot's own books. Sort every post-login command it has ever recorded into categories, and the shape is startling:
The subject is a single IP, `200.89.69.247`, which arrived at the SSH honeypot as an ordinary abuse-100 brute-forcer — until you look up its name, and the name changes everything.
The abuse is egressing the network of the organisation you are supposed to *report abuse to*.
And what egresses that reputation is the most *modern* attacker in the series so far. Where Chile sprayed `root:1234` and NASK guessed subdomains, this node went hunting for the keys to a devops stack.
The real lesson is narrower and harder: **an institutional IP in attack data is a question, not a verdict.** This part is the field guide for answering it.
The Unmasking, Case 1 — the register opens. The frame: the claim is the identity made testable — the User-Agent is testimony, admissible only once corroborated against the network of origin the visitor does not control.…
The Unmasking, Case 2 — the visitor whose claim is false, and the easiest conviction in the register. SPOOFED means a verifier was run and FAILED (not merely unconfirmed). Archetype: a scanner sending the exact Googlebo…
The Unmasking, Case 3 — a verified visitor where it should not be. OpenAI's OAI-SearchBot (verified against OpenAI's published CIDRs, though egressing from Microsoft's Azure AS8075 — the mirror of Case 2) reached for /r…
The Unmasking, Case 4 — the visitor with no discrepancy to expose: a commercial reconnaissance scanner that is exactly what it claims. The recon class (Censys, Palo Alto Expanse, BitSight, LeakIX, Odin) spans the taxono…
The Unmasking, Case 5 — malice in the costume of an ordinary user. The dangerous visitor does not impersonate a crawler (checkable, convictable) but a person: a plain browser UA that returns 'unclassified' — no verdict,…
The Unmasking, Case 6 (finale) — the visitor with no User-Agent, the terminus of the gradient Case 1 named. Against the identity taxonomy the empty UA is perfect concealment (no name to verify, spoof-catch, or even call…
One Google Cloud address space, seven spoofed crawler masks at once — Fake-Googlebot (77 IPs), Fake-ia_archiver, Fake-Baiduspider and more — now auto-detected as fleets and CrowdSec-banned by name. The anchor case of Th…
The 77-IP Fake-Googlebot fleet on Google Cloud, turned out node by node: internal-subdomain enumeration, Joomla fingerprinting and a 151-path .env burst — one shared toolkit under an interchangeable crawler costume, pro…
The 22-IP Fake-ia_archiver fleet impersonates the Internet Archive to license exhaustive crawling, completes the costume with vintage BlackBerry/Series80 user-agents, and bursts 79 .env paths at a host that answers a un…
The Fake-Baiduspider and Fake-YandexBot fleets forge China's and Russia's search crawlers to exploit the internationalised allowlist — flags that never match their US Google Cloud origin — and hit the Gitea host with .e…
The fake AI crawlers — ClaudeBot, GPTBot, ChatGPT-User — are the wardrobe's newest masks. The classifier convicts them by the operator's real published ASN (Anthropic AS399358, OpenAI AS394699), cutting through a mislea…
The Fake-Twitterbot, facebookexternalhit, Feedfetcher and SemrushBot fleets trade on being harmless — preview and feed masks allowlisted by indifference. The classifier convicts them by operator ASN (Twitter AS13414, Me…
The identity-rotation /24s on budget host Hostodo cycle many crawler masks across a few IPs — the inverse of the Google Cloud fleets' one-mask-many-IPs. A second detector catches the mobile wardrobe the static-fleet det…
The crawler-mask wardrobe rents reputable clouds — Google, AWS, Cloudflare, DigitalOcean — because reputation is the mask's currency, the opposite of the bulletproof hosts the loud SSH-attack economy uses. Each landlord…
Across the whole rack the mask predicts the payload: search/archive masks cover high-volume credential harvests, the SEO mask covers light recon, AI masks hunt AI subdomains — and the loud shell-upload floods go maskles…
The web mask and the SSH scanner hunt the same prize — developer credentials. Node 35.188.112.111 runs a DevOps-wordlist SSH scan (deploy, git, claude:Claude2026!) from the same Google Cloud tenancy whose web fleets swe…
The series' aphorism made a cron job: an hourly autoban keys a 7-day CrowdSec ban to a spoofed fleet's own name, escalates proven impostors to a threshold of one, and enforces at nftables + the MikroTik router — with ho…
The SPOOFED verdict the autoban rides on is the strongest signal and the most fragile to maintain. Between false-verify and false-spoof, every method (ASN, CIDR, rDNS, none) trades one cliff for the other — proven live:…
Turning the entity graph on the fleets resolves the deferred 'who': the wardrobe is a structured crowd — coordination provable via shared SSH keys across 56-ASN clusters, but principals unnameable by design because the…
The industrialised wardrobe is the latest move in a years-long arms race the corpus has tracked: empty-UA → blend-in browser → budget-host impostor → reputable-cloud mask-fleet, each rung forced by a defence that caught…
The mask is the one corner of the cloud accountability gap that is cheap to close and closable only by the landlord: a tenant forging Googlebot is a near-certain impostor Google alone can flag at near-zero cost — becaus…
Every probe wears two masks: the attacker's forged crawler identity and the server's masked status code. Vhost sweeps show effective-bad-rate 0.96 at a raw 404-rate of 0.00 — a naive defender sees zero badness. Method+h…
robots.txt is the crawler's declared first act. The verifiable crawlers fetch it from their real networks; the crude .env fleets skip it; the careful fake ClaudeBot mimics it — but provenance still convicts. A declared…
The attackers' .env dictionary, DevOps credential list and subdomain guesses are a reverse-engineered blueprint of the modern estate — commodity, current (claude:Claude2026!, qdrant, comfyui), and partly generated from…
The mask is interchangeable; the rhythm is not. A fleet's burst cadence (98k–127k paths/hr, a toolkit fingerprint) and its coordination windows (19 IPs at 1 request each, synchronized) track it across every disguise cha…
The vhost-sweep is the operation's mapping phase: 252 guessed hostnames from 4,331 IPs, built by Host-header enumeration against one ingress — service subdomains, plus inferred MikroTik and Synology appliance DNS. But t…
No single signal convicts a masked node — the strength is convergence. Four internal sensors (router, CrowdSec, honeypot, web) plus a dozen external feeds agreeing on one IP collapses the false-positive space, and backs…
A false-positive audit of the wardrobe method. Real crawlers verified from their true networks pass clean; identities the system cannot disprove are held at CLAIMED, never escalated to SPOOFED. The method convicts on di…
A mask defeats a log line but not a semantic index. 157,579 vectors across 21 collections, keyed on network identity not User-Agent, put a masked node one query from its honeypot sessions and every dossier that named it…
A cost-benefit analysis from the adversary's ledger. The mask is free but the IP it rides is rented and confiscated for 168 hours per SPOOFED verdict, while the credentials it hunts do not exist behind the masked-200. C…
A forecast. Because the mask is unprofitable at a verifier-backed edge, the rational adversary migrates toward the NO-VERIFIER gap, residential origins, and low-and-slow tempo. The estate's counter to each is already vi…
The finale of The Wardrobe. Twenty-five cases resolve to one rule for the modern edge: the name a visitor gives is inventory, not identity — and every durable defence is built on the axes the name cannot forge. The Ward…
A #!/bin/bash IRC bot (Backdoor:Linux/IRCbot.YA!MTB, MulDrop.14 lineage) captured via scp-push from a compromised Raspberry Pi. First-party strings reveal the C2 (Undernet #biret), an authorized_keys backdoor, a pi-acco…
Part 2 of the Raspberry Worm: the self-propagating MulDrop-fork watched as a population. The same worm recurs a week later; its first-party loop spreads over the Pi default credential turning each victim into a spreader…
Part 3 of the Raspberry Worm: the botnet's C2 is not criminal infrastructure but a legitimate public IRC network - UnderNet, channel #biret - un-sinkholable, self-resilient, DNS-hardened, and authenticated by a captured…
Part 4 of the Raspberry Worm: running the captured operator RSA key across the corpus unifies 13 samples the classifier scattered across six family labels - including four mislabeled as the miner the worm kills. One dur…
Part 5 of the Raspberry Worm: a census of the brood finds it is mostly its own victims - ~80% compromised residential/telecom devices across the Global South conscripted involuntarily (incl an Argentine town-hall device…
Part 6 of the Raspberry Worm: its killall eviction routine is a census of the Linux/IoT malware it fights - miners, DDoS bots, loaders across 8 CPU architectures - and the honeypot caught exactly that (XMRig x33, RedTai…
Part 7 of the Raspberry Worm: a deployable detection-and-response package ordered by IOC durability. One firewall line (egress-deny 6667) cuts C2 even for undiscovered infections; a YARA rule on the operator key catches…
Part 8 of the Raspberry Worm: the honeypot's 'persist corner' is a SEPARATE operation - a modern Go cgo-libpam credential-harvesting toolkit that hooks the Linux auth chokepoint. A silent wiretap opposite the worm's lou…
Part 9 of the Raspberry Worm: it is a documented fork of the 2017 Linux.MulDrop.14 worm. It kept the parent's propagation body unchanged (nine years, because pi:raspberry was never fixed) but inverted its purpose - the…
Part 10 of the Raspberry Worm - find the unexpected: the honeypot is a crossroads where >=5 botnet operations converge, including Whisper, an 18-architecture Mirai with a Windows PE dropper, and its sibling Nexus. Both…
Two UK shell companies, two autonomous systems, one bulletproof operator: how UNMANAGED LTD (AS47890) and DMZHOST / TECHOFF SRV LIMITED (AS48090) merge — not on paper, but through a dual-origin prefix and a single Gmail…
A fourth Romanian /24 (193.32.162.0/24) announced by AS47890 carries the same TECHOFF-MNT maintainer and dmzhostabuse@gmail.com abuse desk as the documented DMZHOST prefixes — the same operator, not a co-tenant.
RIPE RDAP names Bunea TELECOM SRL as the sponsoring organisation behind AS42397/62380/35478 near the DMZHOST cluster — a durable attribution anchor. The apparent 'nested ASN tree' among them is rejected as a shared_bgp_…
A GPU-hunting, profile-first loader campaign ('The Appraiser', TI-2026-083C) runs on DMZHOST's bulletproof floor — but the same toolkit also runs from a rival host, marking the operator as a tenant, not DMZHOST itself.…
Across all 20 IPs of the DMZHOST bulletproof cluster the honeypot recorded zero CVE exploitation — the entire observed threat is SSH credential brute-force. The absence is the finding: harden authentication and blocklis…
RIPE holds two live route objects for 2.57.122.0/24 — origin AS47890 and origin AS48090 — both signed by the same TECHOFF-MNT maintainer, proving one operator controls both DMZHOST autonomous systems and can flip the pr…
The DMZHOST operation hides behind the appearance of ordinary UK companies — a dormant shell with a non-hosting SIC code at formation-agent virtual addresses, one of them a self-storage facility — refreshed by shell sub…
AS197170 (TechTies/HostSlick, Seychelles) shares DMZHOST's tooling and tenants but is a separate operator — a different registration, a different maintainer (techties-mnt), and no same-operator edge in the entity graph.…
Ask what country the DMZHOST network is in and the registries give six answers — GB registration, RO/NL routing, Andorra and Netherlands RDAP claims, Bulgaria routing data, Romania and Seychelles Spamhaus attribution. A…
Two named directors front the DMZHOST shells — a Romanian and an Italian, on companies incorporated four years apart — a corporate split engineered as a legal firewall. The human layer is a deliberate dead end; its one…
Where 088E proved the host weaponizes no CVEs, the tenants deploy a real but entirely commodity arsenal — AdaptixC2, a Google-Cloud-staged backdoor loader, XMRig, RedTail, a Kaiten IRC botnet. And the deeper threads (a…
The shared tenant's footprint on the rival host TechTies confirms it is The Appraiser — its bespoke GPU-profiler runs on all 12 hosts — and exposes a second maintainer-signed dual-origin whose second ASN is a repurposed…
Following the TechTies maintainer to the reseller layer connects the DMZHOST tenant story to the EMBNEX 'Costume Catalog' foundry: one Bulgarian/German reseller pool (Telco power Ltd, mnt-bg-eurocrypt-1, ZeXoTeK) provis…
A reverse-maintainer census of the reseller pool behind TechTies reveals its shared handles bridge three previously-separate bulletproof investigations — the German Phantom ASN cluster, the EMBNEX Costume Catalog, and D…
Resuming the blocked reverse queries closes the identities but blows open the scale: the enabler is an industrial registration substrate — Via-Registry (~48 ASNs/136 orgs), RTM Networks, Euro Crypt EOOD — of which the c…
The LSN estate runs a custom escalating-ban manager that tiers repeat offenders 3h->1wk->1mo->1yr and bans whole /24s when a range keeps climbing. Since March it distilled 2,700 attackers into 23 hard-core recidivists a…
**TI-2026-089B — The Recidivists series · Part B · Addendum to [TI-2026-089A "The Ladder"](https://www.shuffle-on.com/threat-intel/ti-2026-089a-the-ladder)**
**[DOCUMENTED]** Its external reputation predates our ladder by years:
There is no subtlety in the blast radius. A `/24` ban is a single firewall entry — `x.y.z.0/24` — that rejects all 256 addresses. The escalator does not check which of those addresses were actually hostile; it does not…
Here are the cloud hosts from the tier-3 roster, each with the `/24` it occupies.
For each provider I pulled the pipeline's bulletproof assessment — an automated read of an ASN's abuse posture — and its *cross-corpus* count: how many previously published dossiers already cite that provider's infrastr…
Pursuing the one recidivist-hosting provider no prior dossier had: Zkillu SAS, a 2024 French shell announcing two decades-old geo-smeared legacy /24s, all IPs critical-abuse, its attacking range fronted by a managed abu…
The honeypot's SSH brute-force flood is the ladder's biggest ban source (1188 IPs) yet produces zero year-ban recidivists - 83% one-and-done. It reveals that 'recidivism' measures infrastructure reuse, not adversary per…
~160 IPs forge trusted-crawler identities - Googlebot (69 from Google's OWN cloud), ClaudeBot, ChatGPT-User - to inherit allow-listed exemptions. AI-crawler impersonation is the new identity theft. A verification-first…
Part 9 of this series named a fleet. Twenty-three addresses inside a single Amazon `216.73.217.0/24`, all announcing themselves as Anthropic's crawler, presented as the lead illustration of a new kind of identity theft…
Opening The Toolkit: the honeypot's largest family - 33 'XMRig' samples - is not a miner but a modular Go agent carrying XMRig as one config preset. A shared cgo build hash (eba3282b571c) proves it is the same codebase…
Part 2 of The Toolkit: it carries two miner presets - XMRig (CPU/Monero) and NBMiner (GPU) - to mine whatever hardware it lands on. But the pool and wallet are deliberately absent from the binary - empty runtime-config…
Part 3 of The Toolkit: measuring its true footprint finds that 42 of the honeypot's 81 retained samples - 52%, the majority of all serious malware at the sensor - are one operator's Go platform, scattered by the classif…
Part 4 of The Toolkit: clustering the honeypot's whole 81-sample corpus by durable build artifact collapses ~20 family labels into ~6 operators - three artifacts are 83% of everything - and reveals the inversion: the wi…
The honeypot census's widest-reaching artifact - 389 bytes, 100 distinct source IPs, four months - is one byte-identical SHA-256: a single fixed ssh-rsa key with the comment 'mdrfckr' and RSA exponent 37, the decade-old…
The command that plants the Outlaw mdrfckr key - byte-identical across 100 source IPs - is not an append but a demolition: rm -rf .ssh destroys the victim's keys, their known_hosts, and any rival's backdoor before insta…
A second, far more advanced SSH-key operator makes its planted key immutable with chattr +ai - so no rival, no cleanup, and not even root can remove it without first clearing a kernel attribute most responders never che…
A third SSH-key operator plants nothing - it harvests: a single find sweep enumerates the victim's own private keys, known_hosts map, and .ssh/config network diagram, the exact material to authenticate as the victim to…
RedTail is the honeypot census's breadth exemplar: its loader ships XMRig for every architecture and, when it cannot name your CPU, runs every binary until one executes. Two waves ten days apart show a maintained codeba…
A correction: the download log links http://31.170.22.205/bins/whisper.armv5 to the exact Windows calc.exe PE the census read as a separate operator. Whisper and the 'Windows misfirer' are one - the staging server serve…
The Whisper staging server is not a lone VPS: the intel graph resolves it into a two-network crew that scans from w1n ltd (UK) and stages on Sia Nano IT (Latvia), joined by a shared paramiko HASSH, sitting in a bulletpr…
Before breadth drops a binary, it asks the machine what it is - by four kinds of uname, by raw /proc/cpuinfo flags when uname is gone, by device-tree model name, by GPU probe - and asks whether the machine is real, by w…
Two of the honeypot census's 'singletons' are full multi-architecture botnets - Whisper (~30 arches, C2 in Latvia) and Nexus (14 arches, payload disguised as sshd, C2 behind a UK reseller) - that dropped only a loader a…
Four Go binaries dropped on one day, which the classifier split into two families and four confident names, are one operator's toolset - proven by a shared runtime marker and identical entropy. Their function is deliber…
The honeypot census's reconnaissance layer: neofetch, a beloved open-source tool dropped 10 times to triage the victim's CPU, RAM, and GPU (mining intent, revealed before any payload), and a Windows calc.exe test binary…
The honeypot census, closed: read rather than weighed, its 81-sample corpus is about ten operators - not the twenty-plus the family labels imply nor the six the drop-weights suggested - in four strategies (depth, breadt…
A growing fraction of attackers check whether a compromised shell is a honeypot, and the crudest way is by name: a canned roll-call that greps for the famous default user 'phil', for ten named honeypot projects' process…
A tier of attacker checks not what the trap is named but what its shell can do: echo $((1337+1337)) - a real bash computes 2674, a naive emulator echoes it literally. Behavioral detection can't be renamed away because f…
The hardest honeypot check ignores the disguise and probes emptiness: DMI for real hardware, and a find for the .env files, secrets, and lived-in mess a real machine accumulates and a stage-set filesystem lacks. The sec…
The close: honeypot-detection is automated (machine-parsed checks baked into kits), distorting (they run first, so the sensor sees the incautious clearly and the cautious only in silhouette - biasing every census toward…
A loader family that falls back to bash's built-in /dev/tcp raw socket to fetch its payload when curl and wget are absent — living off the shell to defeat host hardening and egress filters. Mapped across 17 honeypot-cap…
A one-shot honeypot capture: a single operator interviews the box for a proxy job — reading the sshd_config forwarding directives that decide tunnel capability, checking for chisel/gost, and fingerprinting MikroTik/Open…
In a 985,859-entity intelligence graph with 92,869 'vulnerable_to' posture edges, the offensive 'targets' relationship exists on just 16 edges. Those sixteen — promoted from a new web-threats CVE-correlation engine — ar…
66 DigitalOcean droplets throwing CVE-2017-5638 — the nine-year-old Apache Struts2 S2-045 RCE that breached Equifax — at essentially every host in a homelab's published estate, one droplet per subdomain, 59,318 hits. A…
A Google Cloud fleet (AS396982, ~143 nodes) spoofing the Internet Archive Wayback bot bursts a 271-path secret-harvesting sweep — AWS/GCP creds, SSH keys, Terraform state, CI/CD pipelines, Spring actuator heapdumps, DB…
A 41-IP multi-provider swarm — anchored by offshore bulletproof-adjacent hosting (ColocaTel, Seychelles), not mainstream cloud — hammers one host in a day to harvest the WordPress register: usernames, IDs and roles via…
The weaponization that follows the roll call: a Russian/offshore fleet POSTs to xmlrpc.php across every mount-point variant on a homelab's estate for weeks, abusing the endpoint the recon located. Shared source IPs prov…
Intersecting 11 web-CVE rosters: 318 attacker IPs, 212 throw one exploit, 99 throw two, only 7 throw three — and breadth never crosses toolkit families. The versatile few stay in their lane (WordPress/xmlrpc, the Struts…
A forensic census of 197 autonomous systems that route nothing. Reading the entity graph's change-log as an instrument, the allocated-but-dark ASN population stratifies into a bulletproof reserve of operators we already…
Inside the dark census, one Moldovan SRL holds the largest sub-cluster: Contrust Solutions accumulated ~two dozen autonomous systems across 2017–2019, in both 16-bit and 32-bit AS space, all now dark — zero prefixes, ze…
The dark census's individual-name stratum: autonomous systems held by a single person, not a company — Manilich (AS39720), Mashayekhi (AS214357), Nebaba (AS214422, with a .lol vanity site), Berdiev (AS214576), a mid-202…
The change-log's biggest stream, owner_changed (9,239 events), is also its least reliable — and reading it honestly is the point. Most are data-pipeline re-mappings (Comcast internal renumbering, Prolexic folding into A…
The change-log's smallest, cleanest stream — renamed (187 operator-authored peeringdb events) — records the inverse of going dark: an autonomous system acquiring a name. Three types: a bare number gaining a human face (…
Synthesis of The Unannounced: reading the entity graph's change-log as a distinct intelligence vector. Point-in-time attribution sees the flow; lifecycle sees the stock and the transitions. The three streams — taken_dow…
The experiment 096F left open: join the change streams, trace a prefix's ownership history, catch a carousel turning. Run honestly, it inverts intuition. The flashy multi-hop candidate (a /24 oscillating PINKMARE↔ODCLOU…
Rank a honeypot's dropped-file corpus by download count and the table lies: the #1 'payload' across 100 IPs is the mdrfckr SSH backdoor key (not a binary), #2 across 67 IPs is a single newline, #4 is the empty string, a…
A full teardown of the severity-100 sample TI-2026-097A buried at #5 by count: a 4.7 KB bash Raspberry Pi IRC worm (Linux.MulDrop lineage, ~2017, still landing in 2026). It roots via rc.local + authorized_keys, resets t…
Three delivery operations in the honeypot's drop corpus each ship one miner compiled for a matrix of CPUs: RedTail for x86_64/i686/arm7/arm8/RISC-V (rebuilt between campaigns), a Mirai-style host for i386/m68k/aarch64/L…
When the honeypot scans its attackers back — via Tor, auto-triggered at high threat — the population that returns is not disposable IoT bots but exposed servers: 37% of 1,676 attacker IPs run a full stack of SSH/web/dat…
How the honeypot's scan-back actually works — and why its headline number is softer than it looks. A graduated trigger ladder (threat + hit count pick scan depth), Tor-exit rotation for anonymity, and a discovery-only p…
**Investigation window: 2026-05-21 → 2026-07-26** · **Subject: AS41745 (FORTIS-AS), RIPE NCC**
Our platform rated Charter Communications a bulletproof host at risk 90.4. The evidence was three compromised MikroTik routers on Spectrum Business lines. This is the correction — and the fix, now deployed and verified.
One table listed eleven upstreams. Seven had an em-dash where the operator name should be. One dash was a US Treasury-sanctioned bulletproof host. Another was a darknet operator this corpus had unmasked 46 hours earlier.
OFAC and the UK NCA designated Aeza Group as a bulletproof host in July 2025. Twelve months on, both its ASNs are still registered, still routed, still announcing 107,000 addresses through 85 BGP neighbours — and its de…
The last unexamined row in the table. Four sources give four different countries, the address is an Amsterdam mailbox, and 17 of its 256 addresses sit on a feed we ingested once. Our sensor has never seen it. This is a…
Six Spamhaus-listed networks the corpus cited and never examined. They share one flag and almost nothing else — five registries, 22 years to 4 months, 280,000 addresses to 1,024. But two of them share something we did n…
Seven autonomous systems carrying up to 15.8 years of routing history changed hands in the first five months of 2026 — one every few weeks, all through one registry, each behind its own name. Not one actor. A market, an…
> No conclusion should be drawn about the status of `lir-bg-telco-1-MNT` from this dossier. Every other measurement in it was taken before the limit was reached and is unaffected.
The query that built this series' backlog contained the clause AND ips > 0. It hid seven Spamhaus-listed networks — including two siblings of an ASN we had already published as low risk. A dossier about auditing your ow…
Part H reported that a maintainer handle had vanished from the registry. It had not. The zero was an HTTP 429 error body parsed as an empty result — the fourth time this series has caught itself using a value without ch…
That closed one door and left another open. If not the actors, then who?
Part A counted the readers. This one counts something less flattering: the people trying the door.
Then it typed `uname -s -m`, read the answer, and hung up.
A fleet on Google Cloud wore 56 identities in five seconds — every major AI crawler — to find which name opens a door. It never once read robots.txt, while wearing the name of a robots.txt directive.
Four AI crawler fleets have read 24,712 pages of this corpus — including 804 cryptographic verification pages. All of them ask for robots.txt. The counterfeit fleet never did.
A fleet asked our edge which crawler names it would accept. It got a complete answer in 5.02 seconds, dropped the two that failed, and never used them again.
A high-confidence campaign in our own corpus described 85 hosts that cannot exist. Corrected 2026-08-09: they entered via forged X-Forwarded-For, not impossible traffic — and the corpus has now been purged.
Googlebot is impersonated seven times more often than it is used, and 73 of the 116 impostors rent their machines from Google Cloud. Two Google ASNs share one organisation string — only one of them can be trusted.
A URL we never published has been requested 821 times in two months and answered 404 every time. Our side is provably clean; the client invents it. An access log records what clients believed you published, not what you…
324 hostnames that do not exist have drawn 92,466 requests, because a wildcard makes every invented name resolve, trusted and answered — and the largest sweep is a verified AI training crawler, not an attacker.
Three auth-protected hosts took 18,517 requests in 70 days. The endpoint that accepts a password was hit four times, by two account holders. Nobody attacks the lock any more — 1,687 addresses were checking whether the k…
For five weeks two services on this estate answered HTTP 200 to any filename a scanner invented — 1,015 nonexistent paths, including 54 spellings of cloud credential files. Nothing leaked, because none of them existed.…
964 addresses, 470 networks, 80 countries, one request each — and every one claiming to be the same phone discontinued in 2015. A residential proxy pool harvesting a public corpus, and why per-IP defence cannot see it.
Fixing four measurement defects changed 7.9% of the corpus and revealed 7,109 addresses that had been arriving for two months — each fetching one page, almost always the same one. Not harvesting the corpus. Watching it…
74 addresses spent two months hunting for an exposed LLM inference endpoint on an estate that genuinely runs 49 models and 507 GB of them. They never got a single model listing. A letter about a negative result.
The classifier has no opinion about 62% of everyone who visits. Three tests show its silence is almost always correct — and then reveal the one 169-address campaign it was hiding.
presentation · **node-connection** = connections from a single source address.
> **Updated 2026-07-30.** Three open items in §9 are now **closed** by later letters, including **point 5 — the pivot this letter said the series turns on**. Letter E answered it a third way this letter did not consider…
Per **R8**, a derived index's silence is evidence about the index, not the world.
presentation · **node-connection** = connections from a single source address.
> **Updated 2026-07-30.** The full fleet wordlist, listed here as unrecoverable without per-address enumeration, was **recovered in Letter H** by querying the fingerprint instead. A second correction affects §5. Origina…
A hundred and thirteen machines installed a backdoor. Twenty-seven ran a honeypot detector for 25 days and never read the answer. The ten that opened the most doors took nothing.
methodology, **a documented absence of an anchor is itself a finding.**
Three transit contracts hold up a network Spamhaus has already blacklisted. The wordlist hunts game servers. And the bulletproof ASN turns out to be a landlord, not an actor.
> **Updated 2026-07-30.** §10's disjointness question is **closed by Letter J, and the answer is no** — 1,751 addresses appear on both sensors. This letter's own suspicion about testing at the extremes was correct. Orig…
Nine letters of work, and the corpus had already published the biggest finding. Plus: why every clustering layer in this dataset counts to two and stops.
mundane explanation for every finding and give it the strongest possible case. Several win.
Eight dossiers name this address. It has never once loaded the site that published them. The falsification criteria for targeting, stated first and then tested.
**This letter measures coordination directly and refines a pacing figure from Letter D.**
fourteen letters, reassembled as a specification for what should have found these actors.
primary data. `[INFERRED]` = reasoning over observations, with confidence bounded.
Two handles resolved after publication: ru-avm-1-mnt is a sponsoring RIPE LIR, not an operator link — a correction to Letter C — and vmheaven.io advertises port scanning as a feature, closing the operator question as un…
The mdrfckr cohort was Outlaw all along and already published five times over; investigating it showed the sensor regime called accept-all refused 82,921 credential attempts, including every one of the botnet's markers.