FLUX FLEET — INTEL BRIEFING №1

Period: 28–29 Aug 2026 (first ~36h of operations) Sources: 3 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East) Confidence: High (direct observation; low data volume) Related: docs/plans/2026-08-29-002-feat-flux-fleet-digest-plan.md, medina /data/flux-logs/reports/

BLUF

The fleet was discovered and is under active multi-campaign attack within 36 hours of going live — including the deliberately "fresh" control node. Activity splits into two hostile organized campaigns (an RCE-exploitation swarm and a supply-chain registry hunt), one high-volume credential sweeper, pervasive opportunistic credential-file scanning, and distinguishable benign research traffic. Source-IP rotation between nodes defeats IP-based campaign tracking — all campaign correlation must be TTP/journey-based. First canary tripwires have been minted and are awaiting callback.

Key Judgements

  1. Discovery velocity is hours, not weeks. The control node (no DNS, no CT cert, fresh ASN) absorbed 2,052 events / 39 unique IPs in its first day. A fresh cloud IP is indexed by range-sweep infrastructure almost immediately. (High confidence)
  2. At least two campaigns rotate source IPs per target. The same 12-step tooling hit both EU nodes from four different DigitalOcean IPs within the same 3-minute window. IP-reputation blocking would not have caught the second node. (High confidence)
  3. Attacker infrastructure is ~entirely cloud-hosted (GCP, DO, Oracle, OVH, Contabo, Timeweb, Tencent) plus bulletproof-adjacent ASNs (Feo Prest DE, SS-Net RO, "State Cyber Protection" UA). No residential sources observed. (High confidence)

Active Campaigns

CAMPAIGN RCE-SWARM (phpunit/CGI chain) — Hostile, active

  • Actors: 4 cloud IPs (Oracle 129.121.128.70, Contabo 169.58.184.188, OVH 212.100.171.242, Timeweb 216.57.110.81), 2 per EU node, identical choreography
  • TTPs: PHP-CGI RCE chain (/bin/sh traversal → cmd-injection-apache-cgi-shell/hello.world + /test.hello execution probes) followed by a 35-prefix CVE-2017-9841 (phpunit eval-stdin.php) wordlist sweep. POST bodies present — active exploitation attempts, not recon
  • Assessment: commodity exploitation kit harvesting PHP fleets

CAMPAIGN REGISTRY-HUNT (supply-chain recon) — Hostile, active, most sophisticated

  • Actors: 4 DigitalOcean IPs (46.101.111.185, 157.245.113.227 farm; 167.71.175.236, 165.22.34.189 aidev), distributed, <3-min per-node execution
  • TTPs: WebLogic console → Confluence login → WHM/cPanel proxy-subdomain probes → Docker Registry API enumeration against internal service names (/v2/internal/api-gateway/tags/list, /v2/internal/auth-service/manifests/latest). Targeted hunting for exposed internal container registries — pre-positioning for image-tampering/supply-chain compromise
  • Assessment: actor has a profile of k8s/microservice orgs; 130-family coverage on the GCP variant suggests nuclei-style template automation

CAMPAIGN CREDSWEEP (credential-file harvesting) — Hostile, persistent, highest volume

  • Actors: 213.209.159.175 (Feo Prest SRL, DE; ipsum:3 + firehol2-listed) — 1,002 events/6h/532 paths, rotating consumer-device UAs (Android vivo / iPad / IE9); 80.94.95.211 (SS-Net, RO); 87.120.104.29 (Sino Worldwide Trading, NO — hit only the control node)
  • TTPs: exhaustive .env variant enumeration (~30 filenames incl. /prod/.env, /.env.stage), SSH private keys, .aws/credentials, tfstate, firebase.json, SQL dumps
  • Assessment: bulk credential-harvesting to feed access markets; volume validates the canary-farm thesis

CAMPAIGN METADATA-HUNT (cloud SSRF/IMDS) — Hostile, sophisticated

  • Actor: 35.245.230.215 (Google Cloud-hosted) — 130 trap families, 533 paths in a ~1-minute burst, 12 POSTs
  • TTPs: SSRF-proxy discovery (/fetch, /proxy → tripped ssrf-relay-aws-role-list ×8, ssrf-relay-gcp-token ×2), cloud-metadata credential paths (/.aws/credentials, /.azure/credentials), Vite @fs traversals, .mcp.json probe
  • Assessment: cloud-workload-targeted tooling seeking SSRF→IMDS pivots — the exact threat the aws-canary menu was built for

AI-surface signal

Infrawatch/1.0 POSTing structured bodies to /mcp, /api/mcp, /mcp/messages — MCP-endpoint discovery tooling found the AI node's fake surface within 36h

Benign (do not treat as hostile)

Censys, Palo Alto research scans, zgrab/zmap, OAI-SearchBot, crawler traffic. Distinguishable by honest UAs and shallow journeys.

Fleet Observations

  • Canary tripwires live: 6 mints issued (aws/ssh/gitlab types) post-key-fix; callbacks pending — any use of a minted credential converts these campaigns into attribution-grade intel
  • TLS front producing: ~6% of farm/aidev traffic arrives via the CT-logged certs (sso.rightabouteverything.show, inference.fapthropic.com); cert-scrapers expected to add targeted traffic; control stays certless as clean baseline
  • Fleet-wide IP uniqueness: 0 of ~150 source IPs appeared on 2+ nodes. Cross-node campaign detection must fingerprint on TTP sequences and tooling artifacts (body hashes, wordlist sets), never on IPs alone

Gaps / Next Collection

  1. POST body capture is hash-only (bodySha256) — payload reuse clustering possible, content not; acceptable
  2. Journey-shape hashing (campaign signatures) added to the daily digest — recurring campaigns will now be tracked across days regardless of IP rotation
  3. Awaiting first Tracebit callback to fuse honeypot observation with upstream attribution