FLUX FLEET — INTEL BRIEFING №4
Period: 31 Aug–1 Sep 2026 (24h, day 4 of operations)
Sources: 3 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East)
Confidence: High (direct observation; 4-day baselines populated)
Related: Briefing №3 (docs/intel/flux-fleet-intel-briefing-2026-08-31.md); digest medina:/data/flux-logs/reports/flux-digest-2026-09-01.md
BLUF
The fleet's defining pattern solidified: every prior campaign returned on schedule with rotated or identical infrastructure, and the NightAgent intrusion chain is no longer single-operator — two additional residential IPs (Office National des Postes, Morocco) ran the byte-identical journey alongside the original DELTA Fiber actor, while a new Techoff/SoloRDP pairing opened with the same phpunit→git→.DS_Store sequence, indicating the chain's tooling has propagated beyond its originator. canary-farm-1 became the fleet's hottest node (+224%, 10.4K events) as the XMLRPC brute-force relocated there with a volume-identical 8,146 POSTs from a fresh Google IP; the MALWARE-DICT replay returned from the same IP with the same 12,707-path count — automation on a daily schedule, not opportunistic scanning. A new 93-trap-family config-harvest sweep (RMP Protection, BG) hit both EU nodes within hours of each other. 45 more canaries minted (fleet ~185), zero failures — and three harvesters collected /.env mints directly, putting live tripwires in hostile hands.
Key Judgements
- The NightAgent chain has escaped its originator. Three residential IPs (81.172.241.94 DELTA Fiber NL + 196.77.107.174 and 105.138.220.253 Office National des Postes MA) now run the full journey — identical 38-path/27-POST shape within the same hours — and signature
5126216e04e5(new 09-01) opens with the exact phpunit→git→.DS_Store prefix before diverging, run by Techoff Srv (BG) and SoloRDP (US) infrastructure. Briefing №3's single-operator judgement is superseded: this is a shared/distributed intrusion kit, likely residential-proxy-routed. (High confidence — journey and signature evidence) - Replay campaigns run on automation, not impulse. MALWARE-DICT returned from the same IP (169.150.201.29) with an identical 12,707-path dictionary; XMLRPC-BRUTE returned with an identical 8,146-POST volume from a new Google IP, simply re-targeted from aidev to farm. Identical volume day-over-day = scheduled feed replay / cron'd tooling. Expect both again tomorrow. (High confidence)
- Credential-file harvesting is the fleet's dominant economy. Config-trap result tags spiked across both EU nodes simultaneously (aidev: app-config-php 21×, app-config-python 27×, wp-batch 15×; farm: wp-config/env-production/phpinfo all 3–5×+) with a 93-family 734-path sweep executed in under a minute (RMP Protection, BG — both EU nodes) and a Microsoft-hosted 32-family git/env harvester on farm. Access-broker tooling treats our surfaces as a standing harvest target. (High confidence)
- The aidev cooling is rotation, not retreat. aidev −50% while farm +224%: the xmlrpc brute moved nodes, but the registry-hunt, config sweeps, and NightAgent descendants still cover both EU boxes. The day-2 "AI surface draws disproportionate fire" judgement should be held loosely — the fleet's EU pair is now uniformly contested. (Moderate confidence)
Active Campaigns (day 4 status)
⚠ NEW: CONFIG-SWEEP (industrial credential-file harvest) — hostile, industrial
- Actor: 93.152.223.194 — RMP Protection Limited (BG), both EU nodes within ~10h (1,098 aidev / 750 farm events, 93 trap families, 734+743 paths, executed in ~1 minute per node)
- TTPs: exhaustive dev-ops config census in a single burst —
docker-compose.yaml,wp-config.php.bak,configuration.php,composer.json,Gemfile.lock,config.json,/.aws/credentials,/.circleci/config.yml,settings.py,.htpasswd, ~30.envvariants, plusyarn.lock/package-lock.json/composer.lockerror probes - Assessment: the most comprehensive single-IP config harvest observed; broadest trap-family coverage in fleet history (93, beating METADATA-HUNT's 130-path burst on family diversity). Supply-chain-adjacent tooling mapping full CI/CD and secret surfaces
⚠ NEW: GIT-VAULT (Microsoft-hosted secret harvester) — hostile, notable
- Actor: 20.168.94.17 (Microsoft Corporation, US) — 32 trap families on farm
- TTPs: full git-internals walk (HEAD/config/logs/refs on both
masterandmain) interleaved with.env,.env.local,.env.production,database.yml,secrets.yml— collected a/.envcanary mint in passing - Assessment: Azure-hosted credential harvester; the Microsoft ASN does not confer legitimacy — treat as hostile. Tracebit callback watch: this IP holds a live aws canary
⚠ NEW: PHPSWEEP-PAIR (Techoff × SoloRDP coordinated chain) — hostile, high interest
- Actors: 93.123.109.163 (Techoff Srv, BG) + 103.215.74.185 (SoloRDP, US) on farm, 103.215.74.26 (SoloRDP) on aidev — 78 POSTs each, identical 12-path journeys, signature
5126216e04e5(first seen 09-01) - TTPs: opens with the NightAgent prefix (phpunit eval-stdin →
/.git/config→/.git/index→.DS_Store) then POST-bearing follow-ups — an RCE-verify-then-exploit chain run from two ASNs in lockstep - Assessment: two infra providers executing one tooling chain is the strongest signal yet that the NightAgent kit is commoditized. Watch for their POST targets — 78 POSTs is active exploitation traffic, not recon
⟳ NIGHTAGENT — day 4, now multi-operator residential
- All three residential IPs returned: 81.172.241.94 (NL, 242+74 events across both EU nodes), 196.77.107.174 (MA, 242+237), 105.138.220.253 (MA, 74) — byte-identical 38-path journeys (phpunit → cPanel brute → wp-batch SQLi → tarpit engagement). The wp-batch component now clusters independently fleet-wide (signature
1de56f9af5ba, 328 events). No new capability; the roster growth is the story
⟳ XMLRPC-BRUTE — day 4, node-hopped
- 136.119.157.160 (Google LLC, US) — 8,153 events, 8,146 POSTs, 5 paths in 24 min against farm (aidev this time was the day-3 target). Identical volume to 34.63.40.186's run: same tooling, fresh Google IP, target rotated
⟳ MALWARE-DICT — day 4, exact replay
- 169.150.201.29 (Datacamp, DE, ipsum:1) — 12,707 events, 12,707 unique paths, 60-second burst against control, identical to day 3's count. Feed replay confirmed as scheduled infrastructure
⟳ REGISTRY-HUNT — day 4, fourth IP set
- 8 DigitalOcean IPs (4 per EU node signature, both variants), byte-identical 12-step journey, 164 events each. Four days, four IP sets, same tooling. Internal Docker-registry enumeration unchanged; still control-averse
⟳ RCE-SWARM — day 4, fleet-wide
- 5 IPs across all 3 nodes (245 events, signature
7e61a9500d8b, first seen 08-29) — the phpunit/CGI chain's fourth consecutive day. A second tarpit-heavy cluster (38 IPs,3e1c5eb879e7) rides the same/-entry pattern
Standing actors (persistence check)
- Pfcloud UG (204.76.203.18, ipsum:2) — day 4 of unbroken low-and-slow control recon (2,176 more events, 580 paths). Longest-tenured actor in fleet history
- SS-Net (80.94.95.211, RO) — farm again (168 events); collected a
/.envmint during its.env-variant walk - TechTies (91.92.47.201, NL) — 20-family config sweep on farm, also collected a
/.envmint - Censys/Palo Alto + new
osint-scanner/1.0UA — benign research cadence unchanged
Fleet Observations
- Canary economics day 4: 45 mints (farm 22 — aws/ssh/http types, aidev 20, control 3), zero mint failures for the second consecutive day. Fleet total distributed: ~185 tripwires. Three mints went directly into hostile hands this window — the kill-chain journeys show
/.env [issued]served to GIT-VAULT, SS-Net, and TechTies. The callback era may open within days - Volume rebalanced to farm: farm 10.4K (+224%), aidev 2.6K (−50%), control 15.4K (+57%). Fleet total ~28.4K events, the second-largest day, but aidev's concentration phase (day 3) has normalized
- XFF forgery gone quiet: 728 requests with single-entry XFF, zero multi-entry forged chains and zero empty-clientIp events — the WP-BATCH log-evasion tradecraft from day 2 has not recurred in 48h
- Control ramp continues: 39 → 70 → 88 → 107 unique IPs over four days, all volume IP-literal (
38.54.2.209) — the contested-baseline judgement stands; per-IP normalization in spike detection remains needed - TLS steady: farm ~2% https (CT-cert traffic), aidev ~13% (
inference.fapthropic.com585 events), control certless. Cert-scanner draw unchanged
Gaps / Next Collection
- Tracebit callbacks are now the single highest-value watch item — three live aws/ssh/http canaries were handed to harvesters today (GIT-VAULT, SS-Net, TechTies) on top of the ~185 in circulation. Any callback fuses honeypot observation with operator infrastructure
- Cross-node IP-reuse flagging in the digest fleet overview (carried from Briefing №3) — today produced another instance (93.152.223.194, plus all three residential IPs); the digest still doesn't surface it automatically
- Per-IP normalization for spike detection (carried) — control's burst-dominated baseline keeps distorting raw-count differentials
- The PHPSWEEP-PAIR's 78 POSTs per actor deserve body-hash comparison against NightAgent's day-3 POSTs — if
bodySha256values match, the kit-sharing judgement upgrades to proof