FLUX FLEET — INTEL BRIEFING №4

Period: 31 Aug–1 Sep 2026 (24h, day 4 of operations) Sources: 3 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East) Confidence: High (direct observation; 4-day baselines populated) Related: Briefing №3 (docs/intel/flux-fleet-intel-briefing-2026-08-31.md); digest medina:/data/flux-logs/reports/flux-digest-2026-09-01.md

BLUF

The fleet's defining pattern solidified: every prior campaign returned on schedule with rotated or identical infrastructure, and the NightAgent intrusion chain is no longer single-operator — two additional residential IPs (Office National des Postes, Morocco) ran the byte-identical journey alongside the original DELTA Fiber actor, while a new Techoff/SoloRDP pairing opened with the same phpunit→git→.DS_Store sequence, indicating the chain's tooling has propagated beyond its originator. canary-farm-1 became the fleet's hottest node (+224%, 10.4K events) as the XMLRPC brute-force relocated there with a volume-identical 8,146 POSTs from a fresh Google IP; the MALWARE-DICT replay returned from the same IP with the same 12,707-path count — automation on a daily schedule, not opportunistic scanning. A new 93-trap-family config-harvest sweep (RMP Protection, BG) hit both EU nodes within hours of each other. 45 more canaries minted (fleet ~185), zero failures — and three harvesters collected /.env mints directly, putting live tripwires in hostile hands.

Key Judgements

  1. The NightAgent chain has escaped its originator. Three residential IPs (81.172.241.94 DELTA Fiber NL + 196.77.107.174 and 105.138.220.253 Office National des Postes MA) now run the full journey — identical 38-path/27-POST shape within the same hours — and signature 5126216e04e5 (new 09-01) opens with the exact phpunit→git→.DS_Store prefix before diverging, run by Techoff Srv (BG) and SoloRDP (US) infrastructure. Briefing №3's single-operator judgement is superseded: this is a shared/distributed intrusion kit, likely residential-proxy-routed. (High confidence — journey and signature evidence)
  2. Replay campaigns run on automation, not impulse. MALWARE-DICT returned from the same IP (169.150.201.29) with an identical 12,707-path dictionary; XMLRPC-BRUTE returned with an identical 8,146-POST volume from a new Google IP, simply re-targeted from aidev to farm. Identical volume day-over-day = scheduled feed replay / cron'd tooling. Expect both again tomorrow. (High confidence)
  3. Credential-file harvesting is the fleet's dominant economy. Config-trap result tags spiked across both EU nodes simultaneously (aidev: app-config-php 21×, app-config-python 27×, wp-batch 15×; farm: wp-config/env-production/phpinfo all 3–5×+) with a 93-family 734-path sweep executed in under a minute (RMP Protection, BG — both EU nodes) and a Microsoft-hosted 32-family git/env harvester on farm. Access-broker tooling treats our surfaces as a standing harvest target. (High confidence)
  4. The aidev cooling is rotation, not retreat. aidev −50% while farm +224%: the xmlrpc brute moved nodes, but the registry-hunt, config sweeps, and NightAgent descendants still cover both EU boxes. The day-2 "AI surface draws disproportionate fire" judgement should be held loosely — the fleet's EU pair is now uniformly contested. (Moderate confidence)

Active Campaigns (day 4 status)

⚠ NEW: CONFIG-SWEEP (industrial credential-file harvest) — hostile, industrial

  • Actor: 93.152.223.194 — RMP Protection Limited (BG), both EU nodes within ~10h (1,098 aidev / 750 farm events, 93 trap families, 734+743 paths, executed in ~1 minute per node)
  • TTPs: exhaustive dev-ops config census in a single burst — docker-compose.yaml, wp-config.php.bak, configuration.php, composer.json, Gemfile.lock, config.json, /.aws/credentials, /.circleci/config.yml, settings.py, .htpasswd, ~30 .env variants, plus yarn.lock/package-lock.json/composer.lock error probes
  • Assessment: the most comprehensive single-IP config harvest observed; broadest trap-family coverage in fleet history (93, beating METADATA-HUNT's 130-path burst on family diversity). Supply-chain-adjacent tooling mapping full CI/CD and secret surfaces

⚠ NEW: GIT-VAULT (Microsoft-hosted secret harvester) — hostile, notable

  • Actor: 20.168.94.17 (Microsoft Corporation, US) — 32 trap families on farm
  • TTPs: full git-internals walk (HEAD/config/logs/refs on both master and main) interleaved with .env, .env.local, .env.production, database.yml, secrets.yml — collected a /.env canary mint in passing
  • Assessment: Azure-hosted credential harvester; the Microsoft ASN does not confer legitimacy — treat as hostile. Tracebit callback watch: this IP holds a live aws canary

⚠ NEW: PHPSWEEP-PAIR (Techoff × SoloRDP coordinated chain) — hostile, high interest

  • Actors: 93.123.109.163 (Techoff Srv, BG) + 103.215.74.185 (SoloRDP, US) on farm, 103.215.74.26 (SoloRDP) on aidev — 78 POSTs each, identical 12-path journeys, signature 5126216e04e5 (first seen 09-01)
  • TTPs: opens with the NightAgent prefix (phpunit eval-stdin → /.git/config/.git/index.DS_Store) then POST-bearing follow-ups — an RCE-verify-then-exploit chain run from two ASNs in lockstep
  • Assessment: two infra providers executing one tooling chain is the strongest signal yet that the NightAgent kit is commoditized. Watch for their POST targets — 78 POSTs is active exploitation traffic, not recon

⟳ NIGHTAGENT — day 4, now multi-operator residential

  • All three residential IPs returned: 81.172.241.94 (NL, 242+74 events across both EU nodes), 196.77.107.174 (MA, 242+237), 105.138.220.253 (MA, 74) — byte-identical 38-path journeys (phpunit → cPanel brute → wp-batch SQLi → tarpit engagement). The wp-batch component now clusters independently fleet-wide (signature 1de56f9af5ba, 328 events). No new capability; the roster growth is the story

⟳ XMLRPC-BRUTE — day 4, node-hopped

  • 136.119.157.160 (Google LLC, US) — 8,153 events, 8,146 POSTs, 5 paths in 24 min against farm (aidev this time was the day-3 target). Identical volume to 34.63.40.186's run: same tooling, fresh Google IP, target rotated

⟳ MALWARE-DICT — day 4, exact replay

  • 169.150.201.29 (Datacamp, DE, ipsum:1) — 12,707 events, 12,707 unique paths, 60-second burst against control, identical to day 3's count. Feed replay confirmed as scheduled infrastructure

⟳ REGISTRY-HUNT — day 4, fourth IP set

  • 8 DigitalOcean IPs (4 per EU node signature, both variants), byte-identical 12-step journey, 164 events each. Four days, four IP sets, same tooling. Internal Docker-registry enumeration unchanged; still control-averse

⟳ RCE-SWARM — day 4, fleet-wide

  • 5 IPs across all 3 nodes (245 events, signature 7e61a9500d8b, first seen 08-29) — the phpunit/CGI chain's fourth consecutive day. A second tarpit-heavy cluster (38 IPs, 3e1c5eb879e7) rides the same /-entry pattern

Standing actors (persistence check)

  • Pfcloud UG (204.76.203.18, ipsum:2) — day 4 of unbroken low-and-slow control recon (2,176 more events, 580 paths). Longest-tenured actor in fleet history
  • SS-Net (80.94.95.211, RO) — farm again (168 events); collected a /.env mint during its .env-variant walk
  • TechTies (91.92.47.201, NL) — 20-family config sweep on farm, also collected a /.env mint
  • Censys/Palo Alto + new osint-scanner/1.0 UA — benign research cadence unchanged

Fleet Observations

  • Canary economics day 4: 45 mints (farm 22 — aws/ssh/http types, aidev 20, control 3), zero mint failures for the second consecutive day. Fleet total distributed: ~185 tripwires. Three mints went directly into hostile hands this window — the kill-chain journeys show /.env [issued] served to GIT-VAULT, SS-Net, and TechTies. The callback era may open within days
  • Volume rebalanced to farm: farm 10.4K (+224%), aidev 2.6K (−50%), control 15.4K (+57%). Fleet total ~28.4K events, the second-largest day, but aidev's concentration phase (day 3) has normalized
  • XFF forgery gone quiet: 728 requests with single-entry XFF, zero multi-entry forged chains and zero empty-clientIp events — the WP-BATCH log-evasion tradecraft from day 2 has not recurred in 48h
  • Control ramp continues: 39 → 70 → 88 → 107 unique IPs over four days, all volume IP-literal (38.54.2.209) — the contested-baseline judgement stands; per-IP normalization in spike detection remains needed
  • TLS steady: farm ~2% https (CT-cert traffic), aidev ~13% (inference.fapthropic.com 585 events), control certless. Cert-scanner draw unchanged

Gaps / Next Collection

  1. Tracebit callbacks are now the single highest-value watch item — three live aws/ssh/http canaries were handed to harvesters today (GIT-VAULT, SS-Net, TechTies) on top of the ~185 in circulation. Any callback fuses honeypot observation with operator infrastructure
  2. Cross-node IP-reuse flagging in the digest fleet overview (carried from Briefing №3) — today produced another instance (93.152.223.194, plus all three residential IPs); the digest still doesn't surface it automatically
  3. Per-IP normalization for spike detection (carried) — control's burst-dominated baseline keeps distorting raw-count differentials
  4. The PHPSWEEP-PAIR's 78 POSTs per actor deserve body-hash comparison against NightAgent's day-3 POSTs — if bodySha256 values match, the kit-sharing judgement upgrades to proof