The Invisible Infrastructure
How 51 Israeli-Connected IPs Appear as Zero in Every Database
Executive Summary
In 034A โ The Empty Column, we documented a statistical anomaly: Israel โ a nation of 10 million people with the world's highest per-capita cyber capability โ appeared in our 8,000+ IP threat intelligence database with exactly 7 IPs and 0 honeypot hits.
This letter reveals what happens when you stop searching by country field and start tracing by operator nationality.
The Revised Israeli Footprint
| Layer | IPs | Hits | Registration |
|---|---|---|---|
| Israeli ISPs (country=IL) | 7 | 0 | Israel |
| Kamatera (Israeli-founded) | 7 | 31 | US, NL, ES |
| Mishayev/Pfcloud (Israeli national) | 37 | 930 | SC, US, DE, NL, TR, LU |
| TRUE TOTAL | 51 | 961 | Never "Israel" |
Seven IPs. Zero hits. That was the visible column. The invisible infrastructure is 7.3ร larger with infinite times more attacks.
This is not a coincidence. It is the most sophisticated geographic registration arbitrage we have documented in 31 prior investigations. An Israeli national operates from Bavaria. His companies register in Seychelles. His ASNs host in Netherlands. His bulletproof clients attack from Luxembourg. Every layer of indirection removes one more trace of origin.
And beyond this measurable infrastructure, two additional invisible layers โ Bright Data's 150 million residential proxy IPs and Kape Technologies' VPN empire โ create attack surfaces that are structurally impossible to attribute.
The Three Layers of Israeli Infrastructure
We discovered the true footprint through three progressive searches, each revealing infrastructure invisible to the previous method:
Layer 1: Country Field Search
country = "IL" โ 7 IPs, 0 hits
What every threat platform shows you
Layer 3: Operator Nationality Trace
Daniel Mishayev (ORG-DM262-RIPE, IL) โ 37 IPs, 930 hits
7+ Spamhaus DROP-listed ASNs, all Seychelles/US shells
Layer 1: The Visible Seven
Seven Israeli IPs exist in our database. All belong to consumer ISPs โ Partner Communications, Pelephone, Cellcom. None has a single honeypot interaction.
| IP | ASN | Organization | Threat | Hits |
|---|---|---|---|---|
82.102.188.117 | 12400 | Partner Communications | 69 | 0 |
37.25.36.197 | 16116 | Pelephone Communications | 53 | 0 |
80.250.155.76 | 1680 | Cellcom Fixed Line | 52 | 0 |
130.185.96.125 | 16116 | Pelephone | 10 | 0 |
2.55.70.124 | 12400 | Partner | 10 | 0 |
185.181.10.136 | 204548 | Kamatera IL | 10 | 0 |
185.191.204.254 | 35758 | HQServ / Eli Twito | 8 | 0 |
This is what 034A documented. A conspicuous absence from a nation that produces more cyber tools per capita than any other country on Earth. The question was: where is the infrastructure?
The answer is: everywhere except Israel.
Layer 2: The Kamatera Shell Game
Kamatera Inc. was founded in Israel (Tel Aviv headquarters). Today it operates under at least 8 different entity names across 5 ASNs in 3 regional internet registries:
| ASN | Entity Name | Registry | Registration |
|---|---|---|---|
| 36007 | KAMATERA | ARIN | 315 Madison Ave, NYC |
| 396948 | CLOUDWEBMANAGE-SC | ARIN | US (virtual office) |
| 396949 | CLOUDWEBMANAGE | ARIN | US |
| 41436 | CloudWebManage-EU | RIPE | Netherlands |
| 204548 | CLOUDWEBMANAGE-IL-FR | RIPE | IL/FR |
Additional names include: Global Cloud Infrastructure LLC, Cloud Web Manage, IRT-KAMATERAINC-AP. The same Israeli company uses different legal wrappers in every jurisdiction. 315 Madison Avenue, NYC โ their ARIN registration address โ is a virtual office service.
DNS reveals a deeper layer: omc.co.il โ OMC Group, an Israeli cloud services provider โ resolves on Kamatera's Spain and Netherlands infrastructure. The Israeli connection is there, but you have to read DNS records to find it.
Seven Kamatera IPs appear in our database. One is an active attacker:
209.182.218.187 (CloudWebManage-SC, AS396948): Threat score 93, 31 honeypot hits, abuse score 100. Registered as a US company. Founded in Tel Aviv.
Layer 3: The Mishayev Ecosystem
This is where the investigation transforms from a statistical curiosity into a forensic case study.
Daniel Mishayev
- RIPE Record: ORG-DM262-RIPE, country: IL (Israel)
- Physical Address: Lilienstraรe 5, 94051 Hauzenberg, Bavaria, Germany
- Phone: +49 17640385000
- Company: Pfcloud UG (HRB 12249, District Court Passau), Waning 1, 94136 Thyrnau
- Service: whitelabel.sh โ turnkey ASN provisioning
- Direct ASN: AS215460 FELCLOUD, registered to "Daniel Mishayev, IL"
An Israeli national, operating from a Bavarian village, provides a service called whitelabel.sh โ literally a turnkey system for creating branded autonomous systems. His clients are uniformly Spamhaus DROP-listed:
| ASN | Entity | Registration | IPs | Hits | Max Threat | Status |
|---|---|---|---|---|---|---|
| 202412 | Omegatech LTD | Seychelles | 7 | 789 | 100 | Spamhaus DROP |
| 197170 | TechTies Inc. | Seychelles | 17 | 128 | 62 | Spamhaus DROP |
| 51396 | Pfcloud UG | Germany | 8 | 1 | 45 | Spamhaus DROP |
| 205759 | GhostyNetworks LLC | US (Kentucky) | 2 | 12 | 56 | Spamhaus DROP |
| 44382 | WhiteLabel/Fiba Cloud | US | 3 | 0 | 46 | Spamhaus DROP |
Note the registration countries: Seychelles, Germany, United States. Never Israel. Yet the operator โ the single individual whose RIPE record says country=IL โ controls all of them.
The Top Attacker: 94.154.35.215
- ASN: 202412 (Omegatech LTD) โ Seychelles IBC
- Location: Netherlands
- Threat Score: 100 (maximum)
- Honeypot Hits: 560
- Abuse Score: 100 (AbuseIPDB)
- GreyNoise: MALICIOUS
- Shodan: 30+ open ports (10004-17780 range โ C2 infrastructure)
- Campaign: hassh-a7a87fbe86774c2e (4-node coordinated cluster)
- RIPE Route Origin: SKAYVIN-BROADBAND-UA (Ukrainian ISP space)
This IP โ threat score 100, abuse score 100, 560 honeypot hits, GreyNoise classification MALICIOUS โ is operated by an Israeli national, registered as a Seychelles company, hosted in the Netherlands, announcing Ukrainian IP space. Four countries in the provenance chain. Israel appears in none of the lookup fields.
Campaign Coordination Across ASNs
HASSH fingerprint analysis reveals that the nominally separate ASNs share operational tooling:
- hassh-a7a87fbe86774c2e: Links Omegatech IPs (94.154.35.215, 178.16.54.226) with Private Layer Switzerland (179.43.x.x) โ a 4-node coordinated attack cluster
- hassh-2ec37a7cc8daf20b: 12-node cluster spanning Omegatech (Turkey, Germany, Netherlands), TechTies (Netherlands), and external providers (DigitalOcean, Scaleway, FranTech)
- hassh-63ae64767f334c6a: Includes 91.92.243.49 (Omegatech, Netherlands)
These shared SSH client fingerprints prove that the "separate" ASNs operated under separate Seychelles IBCs are running identical attack toolkits. The corporate separation is cosmetic. The operational infrastructure is unified.
Third-Party Validation: GBHackers / Intrinsec
Our honeypot data (930 hits from the Mishayev ecosystem) is independently confirmed โ and dramatically exceeded โ by third-party research.
Intrinsec Report via GBHackers (May 28, 2026)
- 642,001 hits from Omegatech IPs in March 2026 alone (Intrinsec honeypots)
- 30,244 attacks from GhostyNetworks in the same period
- 67 C2 servers on a single Omegatech subnet
- 16 malware families hosted simultaneously
- GhostyNetworks linked to defunct OPTIBOUNCE / AnonRDP โ "front companies registered under organizer Daniel Mishayev"
- TeamPCP group used GhostyNetworks for PUREHVNC RAT + malicious LiteLLM PyPI package
- JS malspam campaigns targeting energy companies, finance ministries (Transnistria)
- Targets include: Ukraine, Russia, Poland, Germany
Our 930 hits represent 0.14% of the attack volume documented by Intrinsec in a single month. This is not a small-time operation. This is industrial-scale malware infrastructure operated by an Israeli national through a chain of shell companies that makes the origin invisible.
The Layers You Cannot See
The three measurable layers โ Israeli ISPs, Kamatera, Mishayev/Pfcloud โ account for 51 IPs and 961 hits. But Israel's cyber footprint extends into infrastructure that is structurally impossible to detect with honeypots.
Bright Data: 150 Million Exit Nodes
Bright Data Ltd. (formerly Luminati Networks), headquartered in Netanya, Israel, operates what they describe as the world's largest residential proxy network: 72 million to 150+ million IP addresses across 195 countries.
The company grew from Hola VPN โ which was caught in 2015 selling its users' bandwidth as commercial proxy exit nodes without consent. Rather than shutting down, the proxy business was spun out as Luminati, then rebranded as Bright Data.
June 2026 Discovery: Smart TVs as Proxy Nodes
Security firm Include Security revealed that Bright Data's SDK is embedded in free apps on Samsung, LG, and Roku smart TVs, turning them into residential proxy exit nodes:
- 200 GB/month bandwidth per device
- SDK config:
ignore_screen_on: true,ignore_on_call: trueโ operates while TV is "off" - Partners: PlayWorks Digital (250M TV households), CloudTV (125+ TV brands), Viber (250-820M MAU)
- Bypasses user VPNs via
NWParameters.requiredInterface - TLS certificates still show
*.luminatinet.comโ the old Luminati domain
This means an Israeli company can route traffic through a TV in your living room, and it will appear to any threat analyst as your home IP address, attributed to your local ISP, in your country. Zero trace of Israeli origin.
Bright Data's annual revenue is estimated at $500 million+. Their client list reportedly includes Fortune 500 companies, but also โ as documented by the Swedish digital rights organization Qurium โ entities that used their infrastructure to DDoS Philippine human rights organizations.
Zero Bright Data IPs appear in our honeypot. That is not because they're not involved in our traffic โ it's because residential proxy IPs are attributed to the home user's ISP. If an attacker routes through Bright Data's network, our database records it as Comcast, AT&T, or Deutsche Telekom. The Israeli infrastructure is structurally invisible.
Kape Technologies: The Privacy Empire
If Bright Data controls the proxy layer, Kape Technologies controls the VPN layer โ and the review ecosystem that recommends VPNs.
The Kape Timeline
| Year | Event |
|---|---|
| 1996 | Teddy Sagi convicted of securities fraud in Israel |
| 2011 | Sagi funds Crossrider โ adware/malware injection platform |
| 2014 | Crossrider goes public on London AIM market |
| 2018 | Rebrand: Crossrider โ Kape Technologies |
| 2017-19 | Acquires CyberGhost ($10.4M), ZenMate ($5.5M), PIA ($95.5M) |
| 2019 | Co-founder Koby Menachemi (Unit 8200 alumnus) joins leadership |
| 2021 | Acquires ExpressVPN for $936 million |
| 2021 | Acquires vpnMentor and Wizcase (VPN review sites) |
| 2023 | Taken private for $1.6 billion โ removed from public oversight |
Read that timeline again. A company founded by a convicted fraudster, evolved from an adware platform, co-led by a Unit 8200 alumnus, now controls four of the world's most popular VPN services AND two of the largest VPN review sites that recommend them. Then it was taken private, removing all public reporting obligations.
This is documented extensively in our prior investigations (TI-2026-023D: The Trust Chain). What's new here is the pattern match: Kape is another Israeli-founded company where the origin is systematically obscured. ExpressVPN appears to customers as a British Virgin Islands company. CyberGhost appears Romanian. PIA appears American. The Israeli founding origin appears nowhere in the consumer-facing brand.
The Unit 8200 Pipeline
Unit 8200 is the Israeli Defense Forces' signals intelligence unit โ the equivalent of the NSA, but with a unique characteristic: its alumni systematically found private-sector companies.
Documented Unit 8200 Alumni Companies
| Company | Founder(s) | Product |
|---|---|---|
| Check Point Software | Gil Shwed, Marius Nacht | Enterprise firewalls |
| Palo Alto Networks | Nir Zuk | Next-gen firewalls |
| CyberArk | Udi Mokady | Privileged access security |
| NSO Group | Shalev Hulio, Omri Lavie | Pegasus spyware (45+ countries) |
| Cellebrite | โ | Phone data extraction (police) |
| Candiru | โ | Offensive spyware |
| Verint | โ | Surveillance systems |
| Kape Technologies | Koby Menachemi | VPN empire (ExpressVPN et al.) |
According to DropSite News, hundreds of former Unit 8200 operatives now work at Microsoft, Google, Amazon, and other major technology companies. Bismarck Analysis documented that the unit's alumni have "founded hundreds of cybersecurity companies."
This pipeline explains WHY Israel doesn't need visible hosting infrastructure:
- NSO's Pegasus runs on target phones โ the customer's infrastructure
- Cellebrite's UFED runs in police stations โ the customer's infrastructure
- Check Point firewalls run in enterprise networks โ the customer's infrastructure
- Kape's VPNs run on user devices โ the customer's infrastructure
The Israeli model is fundamentally different from Chinese or Russian cyber infrastructure. China builds the cloud. Russia hosts the botnet. Israel builds the tool and sells it. The tool runs everywhere, but its origin appears nowhere.
The Physical Chokepoint: Submarine Cables
Israel's cyber capability is not only digital โ it is physically positioned at a critical junction of global internet infrastructure.
Blue-Raman Cable System (Google, Operational 2025)
Route: Italy โ Israel โ Jordan โ Saudi Arabia โ India
- Blue segment: Palermo, Italy to Tel-Aviv, Israel (16 fiber pairs)
- Raman segment: Jordan to Mumbai, India (16 fiber pairs)
- Israel is the land bridge โ the physical interconnection between Mediterranean and Indian Ocean fiber
Source: European Investment Bank project documentation, Wikipedia
Wikipedia records โ citing French press sources โ that Unit 8200 "reportedly taps undersea cables." Middle East Eye reported that Red Sea submarine cable landing points enable surveillance by US, UK, and allied intelligence agencies.
A nation that controls both the physical chokepoint (Blue-Raman cable) and the tool ecosystem (NSO, Cellebrite, Check Point) and the proxy network (Bright Data, 150M+ IPs) and the VPN infrastructure (Kape, 4 major VPNs) does not need to appear in honeypot databases. The honeypot sees the exit nodes. The cables carry the backbone. The tools run on the targets. Everything is everywhere, and origin is nowhere.
Synthesis: The Architecture of Invisibility
Seven layers of invisibility, documented and cross-referenced:
| # | Layer | Mechanism | Effect |
|---|---|---|---|
| 1 | Geographic Registration Arbitrage | Israeli operators register in Seychelles, US, UK, Germany | countryโ IL in all databases |
| 2 | LIR Sponsor / whitelabel.sh | Turnkey ASN creation without beneficial ownership verification | Unlimited clean ASNs on demand |
| 3 | Multi-Entity Fragmentation | Kamatera uses 5 ASNs, 8+ names for one company | Appears as multiple unrelated companies |
| 4 | Residential Proxy Network | Bright Data: 150M+ IPs through home devices and smart TVs | Traffic attributed to consumer ISPs |
| 5 | VPN Control | Kape owns 4 VPNs + 2 review sites | Controls both the product and the narrative |
| 6 | Tool-as-Product Model | Sell Pegasus/Cellebrite/UFED โ tool runs on customer infra | Zero hosting footprint |
| 7 | Physical Cable Position | Blue-Raman: ItalyโIsraelโIndia land bridge | Structural access to Europe-Asia traffic |
The Comparison: How Nations Hide
| Nation | Pattern | Visibility in Our Data |
|---|---|---|
| China | BytePlus (SG) masks ByteDance (CN) | 300+ IPs visible as CN |
| Russia | Seychelles shells, NL hosting | 400+ IPs visible as RU |
| Vietnam | State telecom (Viettel) visible | 38+ IPs visible as VN |
| Iran | Routes through NL/DE via LIRs | 20+ IPs visible as IR |
| Israel | Operator=IL, company=SC/US/DE/UK, host=NL | 7 IPs as IL, 0 hits |
Every other nation leaks. China's country field reveals 300+ IPs. Russia's 400+. Vietnam's 38+. Even Iran, routing through European LIRs, shows 20+ IPs with country=IR. Israel shows 7 IPs and zero hits. The architecture of invisibility is complete.
Investigative Q&A
Q: Is Daniel Mishayev knowingly operating bulletproof infrastructure?
A: Confidence: HIGH. Every ASN he sponsors is Spamhaus DROP-listed. GBHackers/Intrinsec explicitly link his name to GhostyNetworks and the AnonRDP operation. His whitelabel.sh service automates ASN provisioning โ its entire business model is enabling others to create branded autonomous systems. When 100% of your known customers are on the Spamhaus blocklist, plausible deniability evaporates.
Q: Why does an Israeli national operate from Bavaria?
A: Germany provides EU jurisdiction (RIPE access, banking, legal stability) without Israeli regulatory oversight. Hauzenberg, Bavaria โ his listed address โ is a village of 12,000 people near the Austrian border. Thyrnau โ where Pfcloud UG is registered โ is even smaller. This is not where you locate a legitimate hosting company. It IS where you locate a company that wants minimal attention.
Q: How does Kamatera justify 8 entity names for one company?
A: In isolation, each entity name has a plausible explanation โ regional subsidiary, service brand, legacy acquisition. Together, they create attribution fragmentation. A threat analyst searching for "Kamatera" will not find "CloudWebManage-SC" or "Global Cloud Infrastructure LLC." This may be administrative convenience. It also may be deliberate obscuration. The effect is identical regardless of intent.
Q: Is the Israeli government directing these operations?
A: Confidence: LOW for Mishayev, MEDIUM for institutional pattern. No evidence links Mishayev to Israeli state operations. However, the Unit 8200 โ private sector pipeline is institutionally documented. Kape Technologies' co-founder is a Unit 8200 alumnus. The question is not whether the state directs individual companies, but whether the state training apparatus systematically produces the capability that makes this infrastructure possible. The answer to that is documented: yes.
Q: Why do we have zero Bright Data IPs in our honeypot?
A: Bright Data's residential proxy network operates through consumer devices โ home routers, mobile phones, and as of June 2026, smart TVs. When traffic exits through these devices, it carries the IP address of a Comcast subscriber in Ohio or a Deutsche Telekom user in Hamburg. Our honeypot records it as American or German consumer traffic. The Israeli origin is structurally invisible because the attribution follows the exit node, not the proxy operator. This is not evasion โ it's architectural invisibility.
Reading Between the Lines
Q: If you can tap the cables, control the VPNs, own the proxy network, and build the hacking tools โ what CAN'T you see?
A: This is the question that makes intelligence analysts uncomfortable. Blue-Raman carries Europe-to-Asia traffic through Israel. Bright Data routes through 150 million exit nodes in 195 countries. Kape controls 4 major VPN providers. NSO's Pegasus has been deployed in 45+ countries. Check Point firewalls sit in enterprise networks globally. Consider the combined access surface: the physical cables, the residential proxies, the VPN infrastructure, the enterprise firewalls, the phone extraction tools, and the offensive spyware โ all with Israeli origin, all structurally invisible. The answer to "what can't you see?" may be: nothing. And the answer to "who can see everything?" may be: the nation with 7 IPs and 0 hits.
Q: Is the statistical absence itself a form of capability demonstration?
A: We documented 31 prior investigations. China appears. Russia appears. Vietnam appears. Iran appears. Every nation with significant cyber activity leaves traces. Israel โ home to NSO, Cellebrite, Candiru, Unit 8200, Bright Data, Kape โ appears as 7 consumer IPs with zero interactions. If zero visibility is the goal, this is a perfect score. In intelligence terms, the absence of intelligence is itself intelligence. A nation whose entire cyber export industry is built on SIGINT expertise would presumably know how to avoid appearing in honeypot databases. The question is not whether they're capable of it. The question is whether this is what capability looks like from the outside.
Q: Mishayev operates from Bavaria. Kape is registered in the Isle of Man. Bright Data's parent is in the UK. Why does everything Israeli end up everywhere EXCEPT Israel?
A: There is a benign explanation: Israel is a small market, and internationalization requires foreign entities. There is also a structural explanation: if your founders trained in signals intelligence, they understand attribution chains. They know that every database query starts with country=IL. They know that not appearing in that query is worth more than any firewall. Hauzenberg. Isle of Man. British Virgin Islands. Seychelles. These are not random choices โ they are the jurisdictions where oversight is minimal and questions are expensive. The same jurisdictions we documented in TI-2026-024: Offshore Bulletproof, used by Russian and Chinese operators. The nationality of the operator changes. The jurisdictional arbitrage is identical.
Q: The geographic position โ what's REALLY there?
A: Look at a map. Israel sits at the junction of three continents: Europe (Mediterranean coast), Asia (bordering Jordan and Syria), Africa (bordering Egypt via Sinai). Every submarine cable from Europe to Asia that doesn't go through the Suez Canal goes through Israel (Blue-Raman). Every intelligence agency with Middle East operations routes through Israeli SIGINT partnerships. Every tech company expanding to the Gulf or India benefits from Israeli expertise. This is not a nation with cyber capability. This is the geographic chokepoint WHERE cyber capability has maximum leverage. The fiber runs through here. The intelligence runs through here. The tools were built here. And in our database: 7 IPs. Zero hits. The most capable nation in the most strategic position is the most invisible. This is either the world's largest coincidence or the world's most impressive demonstration of what visibility control actually looks like.
Methodology
Data Sources
- LSN Honeypot Database: 8,000+ attacker IPs with enrichment from 12+ OSINT sources
- LSN Intelligence Platform: 277K+ entity links across 17 relationship types
- Dossier Vector Store: Cross-referenced against 31 published investigations
- RIPE Database: ORG-DM262-RIPE, corporate records, LIR sponsorship data
- German Corporate Registry: HRB 12249 (Pfcloud UG), District Court Passau
- Spamhaus: ASN-DROP classifications for all Mishayev-sponsored networks
- GBHackers / Intrinsec: Third-party validation report (May 28, 2026)
- Include Security: Bright Data SDK analysis (June 2026)
- European Investment Bank: Blue-Raman cable project documentation
- DropSite News: Unit 8200 alumni in private sector investigation
- Qurium Media Foundation: Bright Data enabling Philippines DDoS documentation
Search Methodology
- Country field search:
SELECT * FROM ips WHERE country='IL'โ yielded 7 IPs - Organization search: Searched all known Israeli cyber companies (Check Point, NSO, Cellebrite, Candiru, Radware, CyberArk) โ zero matches
- RDAP registration search: Searched for ", IL" suffix in RDAP org fields โ 6 consumer ISP IPs
- Founding origin trace: Identified Israeli-founded cloud providers (Kamatera) โ 7 IPs across 5 ASNs
- Operator nationality trace: Searched RIPE for Israeli nationals operating German/EU companies โ discovered Daniel Mishayev (ORG-DM262-RIPE, IL) โ 37 IPs, 930 hits
- Vector cross-reference: Searched all 31 prior dossier investigations โ found extensive existing coverage of Mishayev ecosystem across 5+ investigations
- BGP upstream analysis: Traced transit relationships between Pfcloud and co-located ASNs
- Open-source intelligence: GBHackers, Include Security, Qurium, DropSite News, Wikipedia, EIB documents
Confidence Assessment
- Mishayev โ Pfcloud โ bulletproof ASNs: HIGH (RIPE records, corporate filings, Spamhaus data, third-party reporting)
- Kamatera identity fragmentation: HIGH (5 ASNs in 3 RIRs under 8+ names โ all publicly verifiable)
- Bright Data residential proxy scale: HIGH (company's own claims + June 2026 SDK analysis)
- Kape โ Unit 8200 connection: HIGH (documented co-founder biography)
- Submarine cable tapping: MEDIUM (Wikipedia citing French press; no primary source available)
- Israeli state direction of Mishayev operations: LOW (no evidence; pattern is private sector)
Cross-References
- TI-2026-034A: The Empty Column โ Statistical anomaly analysis
- TI-2026-024: Offshore Bulletproof โ Seychelles pipeline (documents Omegatech)
- TI-2026-023D: The Trust Chain โ Kape Technologies investigation
- TI-2026-023B: BACKBONE โ Documents Mishayev as "The German Gatekeeper"
- TI-2026-029: Omegatech+TechTies=Same Pfcloud Pipeline