FLUX FLEET — INTEL BRIEFING №1
Period: 28–29 Aug 2026 (first ~36h of operations)
Sources: 3 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East)
Confidence: High (direct observation; low data volume)
Related: docs/plans/2026-08-29-002-feat-flux-fleet-digest-plan.md, medina /data/flux-logs/reports/
BLUF
The fleet was discovered and is under active multi-campaign attack within 36 hours of going live — including the deliberately "fresh" control node. Activity splits into two hostile organized campaigns (an RCE-exploitation swarm and a supply-chain registry hunt), one high-volume credential sweeper, pervasive opportunistic credential-file scanning, and distinguishable benign research traffic. Source-IP rotation between nodes defeats IP-based campaign tracking — all campaign correlation must be TTP/journey-based. First canary tripwires have been minted and are awaiting callback.
Key Judgements
- Discovery velocity is hours, not weeks. The control node (no DNS, no CT cert, fresh ASN) absorbed 2,052 events / 39 unique IPs in its first day. A fresh cloud IP is indexed by range-sweep infrastructure almost immediately. (High confidence)
- At least two campaigns rotate source IPs per target. The same 12-step tooling hit both EU nodes from four different DigitalOcean IPs within the same 3-minute window. IP-reputation blocking would not have caught the second node. (High confidence)
- Attacker infrastructure is ~entirely cloud-hosted (GCP, DO, Oracle, OVH, Contabo, Timeweb, Tencent) plus bulletproof-adjacent ASNs (Feo Prest DE, SS-Net RO, "State Cyber Protection" UA). No residential sources observed. (High confidence)
Active Campaigns
CAMPAIGN RCE-SWARM (phpunit/CGI chain) — Hostile, active
- Actors: 4 cloud IPs (Oracle 129.121.128.70, Contabo 169.58.184.188, OVH 212.100.171.242, Timeweb 216.57.110.81), 2 per EU node, identical choreography
- TTPs: PHP-CGI RCE chain (
/bin/shtraversal →cmd-injection-apache-cgi-shell→/hello.world+/test.helloexecution probes) followed by a 35-prefix CVE-2017-9841 (phpunit eval-stdin.php) wordlist sweep. POST bodies present — active exploitation attempts, not recon - Assessment: commodity exploitation kit harvesting PHP fleets
CAMPAIGN REGISTRY-HUNT (supply-chain recon) — Hostile, active, most sophisticated
- Actors: 4 DigitalOcean IPs (46.101.111.185, 157.245.113.227 farm; 167.71.175.236, 165.22.34.189 aidev), distributed, <3-min per-node execution
- TTPs: WebLogic console → Confluence login → WHM/cPanel proxy-subdomain probes → Docker Registry API enumeration against internal service names (
/v2/internal/api-gateway/tags/list,/v2/internal/auth-service/manifests/latest). Targeted hunting for exposed internal container registries — pre-positioning for image-tampering/supply-chain compromise - Assessment: actor has a profile of k8s/microservice orgs; 130-family coverage on the GCP variant suggests nuclei-style template automation
CAMPAIGN CREDSWEEP (credential-file harvesting) — Hostile, persistent, highest volume
- Actors: 213.209.159.175 (Feo Prest SRL, DE; ipsum:3 + firehol2-listed) — 1,002 events/6h/532 paths, rotating consumer-device UAs (Android vivo / iPad / IE9); 80.94.95.211 (SS-Net, RO); 87.120.104.29 (Sino Worldwide Trading, NO — hit only the control node)
- TTPs: exhaustive
.envvariant enumeration (~30 filenames incl./prod/.env,/.env.stage), SSH private keys,.aws/credentials,tfstate,firebase.json, SQL dumps - Assessment: bulk credential-harvesting to feed access markets; volume validates the canary-farm thesis
CAMPAIGN METADATA-HUNT (cloud SSRF/IMDS) — Hostile, sophisticated
- Actor: 35.245.230.215 (Google Cloud-hosted) — 130 trap families, 533 paths in a ~1-minute burst, 12 POSTs
- TTPs: SSRF-proxy discovery (
/fetch,/proxy→ trippedssrf-relay-aws-role-list×8,ssrf-relay-gcp-token×2), cloud-metadata credential paths (/.aws/credentials,/.azure/credentials), Vite@fstraversals,.mcp.jsonprobe - Assessment: cloud-workload-targeted tooling seeking SSRF→IMDS pivots — the exact threat the aws-canary menu was built for
AI-surface signal
Infrawatch/1.0 POSTing structured bodies to /mcp, /api/mcp, /mcp/messages — MCP-endpoint discovery tooling found the AI node's fake surface within 36h
Benign (do not treat as hostile)
Censys, Palo Alto research scans, zgrab/zmap, OAI-SearchBot, crawler traffic. Distinguishable by honest UAs and shallow journeys.
Fleet Observations
- Canary tripwires live: 6 mints issued (aws/ssh/gitlab types) post-key-fix; callbacks pending — any use of a minted credential converts these campaigns into attribution-grade intel
- TLS front producing: ~6% of farm/aidev traffic arrives via the CT-logged certs (
sso.rightabouteverything.show,inference.fapthropic.com); cert-scrapers expected to add targeted traffic; control stays certless as clean baseline - Fleet-wide IP uniqueness: 0 of ~150 source IPs appeared on 2+ nodes. Cross-node campaign detection must fingerprint on TTP sequences and tooling artifacts (body hashes, wordlist sets), never on IPs alone
Gaps / Next Collection
- POST body capture is hash-only (
bodySha256) — payload reuse clustering possible, content not; acceptable - Journey-shape hashing (campaign signatures) added to the daily digest — recurring campaigns will now be tracked across days regardless of IP rotation
- Awaiting first Tracebit callback to fuse honeypot observation with upstream attribution