TI-2026-034B โ€ข THE INVISIBLE NATION SERIES

The Invisible Infrastructure

How 51 Israeli-Connected IPs Appear as Zero in Every Database

Series: The Invisible Nation (034) Published: June 2026 Classification: OSINT โ€ข Honeypot Forensics โ€ข Attribution

Executive Summary

In 034A โ€” The Empty Column, we documented a statistical anomaly: Israel โ€” a nation of 10 million people with the world's highest per-capita cyber capability โ€” appeared in our 8,000+ IP threat intelligence database with exactly 7 IPs and 0 honeypot hits.

This letter reveals what happens when you stop searching by country field and start tracing by operator nationality.

The Revised Israeli Footprint

LayerIPsHitsRegistration
Israeli ISPs (country=IL)70Israel
Kamatera (Israeli-founded)731US, NL, ES
Mishayev/Pfcloud (Israeli national)37930SC, US, DE, NL, TR, LU
TRUE TOTAL51961Never "Israel"

Seven IPs. Zero hits. That was the visible column. The invisible infrastructure is 7.3ร— larger with infinite times more attacks.

This is not a coincidence. It is the most sophisticated geographic registration arbitrage we have documented in 31 prior investigations. An Israeli national operates from Bavaria. His companies register in Seychelles. His ASNs host in Netherlands. His bulletproof clients attack from Luxembourg. Every layer of indirection removes one more trace of origin.

And beyond this measurable infrastructure, two additional invisible layers โ€” Bright Data's 150 million residential proxy IPs and Kape Technologies' VPN empire โ€” create attack surfaces that are structurally impossible to attribute.

The Three Layers of Israeli Infrastructure

We discovered the true footprint through three progressive searches, each revealing infrastructure invisible to the previous method:

Layer 1: Country Field Search

country = "IL" โ†’ 7 IPs, 0 hits

What every threat platform shows you

Layer 3: Operator Nationality Trace

Daniel Mishayev (ORG-DM262-RIPE, IL) โ†’ 37 IPs, 930 hits

7+ Spamhaus DROP-listed ASNs, all Seychelles/US shells

Layer 1: The Visible Seven

Seven Israeli IPs exist in our database. All belong to consumer ISPs โ€” Partner Communications, Pelephone, Cellcom. None has a single honeypot interaction.

IPASNOrganizationThreatHits
82.102.188.11712400Partner Communications690
37.25.36.19716116Pelephone Communications530
80.250.155.761680Cellcom Fixed Line520
130.185.96.12516116Pelephone100
2.55.70.12412400Partner100
185.181.10.136204548Kamatera IL100
185.191.204.25435758HQServ / Eli Twito80

This is what 034A documented. A conspicuous absence from a nation that produces more cyber tools per capita than any other country on Earth. The question was: where is the infrastructure?

The answer is: everywhere except Israel.

Layer 2: The Kamatera Shell Game

Kamatera Inc. was founded in Israel (Tel Aviv headquarters). Today it operates under at least 8 different entity names across 5 ASNs in 3 regional internet registries:

ASNEntity NameRegistryRegistration
36007KAMATERAARIN315 Madison Ave, NYC
396948CLOUDWEBMANAGE-SCARINUS (virtual office)
396949CLOUDWEBMANAGEARINUS
41436CloudWebManage-EURIPENetherlands
204548CLOUDWEBMANAGE-IL-FRRIPEIL/FR

Additional names include: Global Cloud Infrastructure LLC, Cloud Web Manage, IRT-KAMATERAINC-AP. The same Israeli company uses different legal wrappers in every jurisdiction. 315 Madison Avenue, NYC โ€” their ARIN registration address โ€” is a virtual office service.

DNS reveals a deeper layer: omc.co.il โ€” OMC Group, an Israeli cloud services provider โ€” resolves on Kamatera's Spain and Netherlands infrastructure. The Israeli connection is there, but you have to read DNS records to find it.

Seven Kamatera IPs appear in our database. One is an active attacker:

209.182.218.187 (CloudWebManage-SC, AS396948): Threat score 93, 31 honeypot hits, abuse score 100. Registered as a US company. Founded in Tel Aviv.

Layer 3: The Mishayev Ecosystem

This is where the investigation transforms from a statistical curiosity into a forensic case study.

Daniel Mishayev

  • RIPE Record: ORG-DM262-RIPE, country: IL (Israel)
  • Physical Address: LilienstraรŸe 5, 94051 Hauzenberg, Bavaria, Germany
  • Phone: +49 17640385000
  • Company: Pfcloud UG (HRB 12249, District Court Passau), Waning 1, 94136 Thyrnau
  • Service: whitelabel.sh โ€” turnkey ASN provisioning
  • Direct ASN: AS215460 FELCLOUD, registered to "Daniel Mishayev, IL"

An Israeli national, operating from a Bavarian village, provides a service called whitelabel.sh โ€” literally a turnkey system for creating branded autonomous systems. His clients are uniformly Spamhaus DROP-listed:

ASNEntityRegistrationIPsHitsMax ThreatStatus
202412Omegatech LTDSeychelles7789100Spamhaus DROP
197170TechTies Inc.Seychelles1712862Spamhaus DROP
51396Pfcloud UGGermany8145Spamhaus DROP
205759GhostyNetworks LLCUS (Kentucky)21256Spamhaus DROP
44382WhiteLabel/Fiba CloudUS3046Spamhaus DROP

Note the registration countries: Seychelles, Germany, United States. Never Israel. Yet the operator โ€” the single individual whose RIPE record says country=IL โ€” controls all of them.

The Top Attacker: 94.154.35.215

  • ASN: 202412 (Omegatech LTD) โ€” Seychelles IBC
  • Location: Netherlands
  • Threat Score: 100 (maximum)
  • Honeypot Hits: 560
  • Abuse Score: 100 (AbuseIPDB)
  • GreyNoise: MALICIOUS
  • Shodan: 30+ open ports (10004-17780 range โ€” C2 infrastructure)
  • Campaign: hassh-a7a87fbe86774c2e (4-node coordinated cluster)
  • RIPE Route Origin: SKAYVIN-BROADBAND-UA (Ukrainian ISP space)

This IP โ€” threat score 100, abuse score 100, 560 honeypot hits, GreyNoise classification MALICIOUS โ€” is operated by an Israeli national, registered as a Seychelles company, hosted in the Netherlands, announcing Ukrainian IP space. Four countries in the provenance chain. Israel appears in none of the lookup fields.

Campaign Coordination Across ASNs

HASSH fingerprint analysis reveals that the nominally separate ASNs share operational tooling:

  • hassh-a7a87fbe86774c2e: Links Omegatech IPs (94.154.35.215, 178.16.54.226) with Private Layer Switzerland (179.43.x.x) โ€” a 4-node coordinated attack cluster
  • hassh-2ec37a7cc8daf20b: 12-node cluster spanning Omegatech (Turkey, Germany, Netherlands), TechTies (Netherlands), and external providers (DigitalOcean, Scaleway, FranTech)
  • hassh-63ae64767f334c6a: Includes 91.92.243.49 (Omegatech, Netherlands)

These shared SSH client fingerprints prove that the "separate" ASNs operated under separate Seychelles IBCs are running identical attack toolkits. The corporate separation is cosmetic. The operational infrastructure is unified.

Third-Party Validation: GBHackers / Intrinsec

Our honeypot data (930 hits from the Mishayev ecosystem) is independently confirmed โ€” and dramatically exceeded โ€” by third-party research.

Intrinsec Report via GBHackers (May 28, 2026)

  • 642,001 hits from Omegatech IPs in March 2026 alone (Intrinsec honeypots)
  • 30,244 attacks from GhostyNetworks in the same period
  • 67 C2 servers on a single Omegatech subnet
  • 16 malware families hosted simultaneously
  • GhostyNetworks linked to defunct OPTIBOUNCE / AnonRDP โ€” "front companies registered under organizer Daniel Mishayev"
  • TeamPCP group used GhostyNetworks for PUREHVNC RAT + malicious LiteLLM PyPI package
  • JS malspam campaigns targeting energy companies, finance ministries (Transnistria)
  • Targets include: Ukraine, Russia, Poland, Germany

Source: gbhackers.com/ghostynetworks-and-omegatech/

Our 930 hits represent 0.14% of the attack volume documented by Intrinsec in a single month. This is not a small-time operation. This is industrial-scale malware infrastructure operated by an Israeli national through a chain of shell companies that makes the origin invisible.

The Layers You Cannot See

The three measurable layers โ€” Israeli ISPs, Kamatera, Mishayev/Pfcloud โ€” account for 51 IPs and 961 hits. But Israel's cyber footprint extends into infrastructure that is structurally impossible to detect with honeypots.

Bright Data: 150 Million Exit Nodes

Bright Data Ltd. (formerly Luminati Networks), headquartered in Netanya, Israel, operates what they describe as the world's largest residential proxy network: 72 million to 150+ million IP addresses across 195 countries.

The company grew from Hola VPN โ€” which was caught in 2015 selling its users' bandwidth as commercial proxy exit nodes without consent. Rather than shutting down, the proxy business was spun out as Luminati, then rebranded as Bright Data.

June 2026 Discovery: Smart TVs as Proxy Nodes

Security firm Include Security revealed that Bright Data's SDK is embedded in free apps on Samsung, LG, and Roku smart TVs, turning them into residential proxy exit nodes:

  • 200 GB/month bandwidth per device
  • SDK config: ignore_screen_on: true, ignore_on_call: true โ€” operates while TV is "off"
  • Partners: PlayWorks Digital (250M TV households), CloudTV (125+ TV brands), Viber (250-820M MAU)
  • Bypasses user VPNs via NWParameters.requiredInterface
  • TLS certificates still show *.luminatinet.com โ€” the old Luminati domain

This means an Israeli company can route traffic through a TV in your living room, and it will appear to any threat analyst as your home IP address, attributed to your local ISP, in your country. Zero trace of Israeli origin.

Bright Data's annual revenue is estimated at $500 million+. Their client list reportedly includes Fortune 500 companies, but also โ€” as documented by the Swedish digital rights organization Qurium โ€” entities that used their infrastructure to DDoS Philippine human rights organizations.

Zero Bright Data IPs appear in our honeypot. That is not because they're not involved in our traffic โ€” it's because residential proxy IPs are attributed to the home user's ISP. If an attacker routes through Bright Data's network, our database records it as Comcast, AT&T, or Deutsche Telekom. The Israeli infrastructure is structurally invisible.

Kape Technologies: The Privacy Empire

If Bright Data controls the proxy layer, Kape Technologies controls the VPN layer โ€” and the review ecosystem that recommends VPNs.

The Kape Timeline

YearEvent
1996Teddy Sagi convicted of securities fraud in Israel
2011Sagi funds Crossrider โ€” adware/malware injection platform
2014Crossrider goes public on London AIM market
2018Rebrand: Crossrider โ†’ Kape Technologies
2017-19Acquires CyberGhost ($10.4M), ZenMate ($5.5M), PIA ($95.5M)
2019Co-founder Koby Menachemi (Unit 8200 alumnus) joins leadership
2021Acquires ExpressVPN for $936 million
2021Acquires vpnMentor and Wizcase (VPN review sites)
2023Taken private for $1.6 billion โ€” removed from public oversight

Read that timeline again. A company founded by a convicted fraudster, evolved from an adware platform, co-led by a Unit 8200 alumnus, now controls four of the world's most popular VPN services AND two of the largest VPN review sites that recommend them. Then it was taken private, removing all public reporting obligations.

This is documented extensively in our prior investigations (TI-2026-023D: The Trust Chain). What's new here is the pattern match: Kape is another Israeli-founded company where the origin is systematically obscured. ExpressVPN appears to customers as a British Virgin Islands company. CyberGhost appears Romanian. PIA appears American. The Israeli founding origin appears nowhere in the consumer-facing brand.

The Unit 8200 Pipeline

Unit 8200 is the Israeli Defense Forces' signals intelligence unit โ€” the equivalent of the NSA, but with a unique characteristic: its alumni systematically found private-sector companies.

Documented Unit 8200 Alumni Companies

CompanyFounder(s)Product
Check Point SoftwareGil Shwed, Marius NachtEnterprise firewalls
Palo Alto NetworksNir ZukNext-gen firewalls
CyberArkUdi MokadyPrivileged access security
NSO GroupShalev Hulio, Omri LaviePegasus spyware (45+ countries)
Cellebriteโ€”Phone data extraction (police)
Candiruโ€”Offensive spyware
Verintโ€”Surveillance systems
Kape TechnologiesKoby MenachemiVPN empire (ExpressVPN et al.)

According to DropSite News, hundreds of former Unit 8200 operatives now work at Microsoft, Google, Amazon, and other major technology companies. Bismarck Analysis documented that the unit's alumni have "founded hundreds of cybersecurity companies."

This pipeline explains WHY Israel doesn't need visible hosting infrastructure:

  • NSO's Pegasus runs on target phones โ€” the customer's infrastructure
  • Cellebrite's UFED runs in police stations โ€” the customer's infrastructure
  • Check Point firewalls run in enterprise networks โ€” the customer's infrastructure
  • Kape's VPNs run on user devices โ€” the customer's infrastructure

The Israeli model is fundamentally different from Chinese or Russian cyber infrastructure. China builds the cloud. Russia hosts the botnet. Israel builds the tool and sells it. The tool runs everywhere, but its origin appears nowhere.

The Physical Chokepoint: Submarine Cables

Israel's cyber capability is not only digital โ€” it is physically positioned at a critical junction of global internet infrastructure.

Blue-Raman Cable System (Google, Operational 2025)

Route: Italy โ†’ Israel โ†’ Jordan โ†’ Saudi Arabia โ†’ India

  • Blue segment: Palermo, Italy to Tel-Aviv, Israel (16 fiber pairs)
  • Raman segment: Jordan to Mumbai, India (16 fiber pairs)
  • Israel is the land bridge โ€” the physical interconnection between Mediterranean and Indian Ocean fiber

Source: European Investment Bank project documentation, Wikipedia

Wikipedia records โ€” citing French press sources โ€” that Unit 8200 "reportedly taps undersea cables." Middle East Eye reported that Red Sea submarine cable landing points enable surveillance by US, UK, and allied intelligence agencies.

A nation that controls both the physical chokepoint (Blue-Raman cable) and the tool ecosystem (NSO, Cellebrite, Check Point) and the proxy network (Bright Data, 150M+ IPs) and the VPN infrastructure (Kape, 4 major VPNs) does not need to appear in honeypot databases. The honeypot sees the exit nodes. The cables carry the backbone. The tools run on the targets. Everything is everywhere, and origin is nowhere.

Synthesis: The Architecture of Invisibility

Seven layers of invisibility, documented and cross-referenced:

#LayerMechanismEffect
1Geographic Registration ArbitrageIsraeli operators register in Seychelles, US, UK, Germanycountryโ‰ IL in all databases
2LIR Sponsor / whitelabel.shTurnkey ASN creation without beneficial ownership verificationUnlimited clean ASNs on demand
3Multi-Entity FragmentationKamatera uses 5 ASNs, 8+ names for one companyAppears as multiple unrelated companies
4Residential Proxy NetworkBright Data: 150M+ IPs through home devices and smart TVsTraffic attributed to consumer ISPs
5VPN ControlKape owns 4 VPNs + 2 review sitesControls both the product and the narrative
6Tool-as-Product ModelSell Pegasus/Cellebrite/UFED โ€” tool runs on customer infraZero hosting footprint
7Physical Cable PositionBlue-Raman: Italyโ†’Israelโ†’India land bridgeStructural access to Europe-Asia traffic

The Comparison: How Nations Hide

NationPatternVisibility in Our Data
ChinaBytePlus (SG) masks ByteDance (CN)300+ IPs visible as CN
RussiaSeychelles shells, NL hosting400+ IPs visible as RU
VietnamState telecom (Viettel) visible38+ IPs visible as VN
IranRoutes through NL/DE via LIRs20+ IPs visible as IR
IsraelOperator=IL, company=SC/US/DE/UK, host=NL7 IPs as IL, 0 hits

Every other nation leaks. China's country field reveals 300+ IPs. Russia's 400+. Vietnam's 38+. Even Iran, routing through European LIRs, shows 20+ IPs with country=IR. Israel shows 7 IPs and zero hits. The architecture of invisibility is complete.

Investigative Q&A

Q: Is Daniel Mishayev knowingly operating bulletproof infrastructure?

A: Confidence: HIGH. Every ASN he sponsors is Spamhaus DROP-listed. GBHackers/Intrinsec explicitly link his name to GhostyNetworks and the AnonRDP operation. His whitelabel.sh service automates ASN provisioning โ€” its entire business model is enabling others to create branded autonomous systems. When 100% of your known customers are on the Spamhaus blocklist, plausible deniability evaporates.

Q: Why does an Israeli national operate from Bavaria?

A: Germany provides EU jurisdiction (RIPE access, banking, legal stability) without Israeli regulatory oversight. Hauzenberg, Bavaria โ€” his listed address โ€” is a village of 12,000 people near the Austrian border. Thyrnau โ€” where Pfcloud UG is registered โ€” is even smaller. This is not where you locate a legitimate hosting company. It IS where you locate a company that wants minimal attention.

Q: How does Kamatera justify 8 entity names for one company?

A: In isolation, each entity name has a plausible explanation โ€” regional subsidiary, service brand, legacy acquisition. Together, they create attribution fragmentation. A threat analyst searching for "Kamatera" will not find "CloudWebManage-SC" or "Global Cloud Infrastructure LLC." This may be administrative convenience. It also may be deliberate obscuration. The effect is identical regardless of intent.

Q: Is the Israeli government directing these operations?

A: Confidence: LOW for Mishayev, MEDIUM for institutional pattern. No evidence links Mishayev to Israeli state operations. However, the Unit 8200 โ†’ private sector pipeline is institutionally documented. Kape Technologies' co-founder is a Unit 8200 alumnus. The question is not whether the state directs individual companies, but whether the state training apparatus systematically produces the capability that makes this infrastructure possible. The answer to that is documented: yes.

Q: Why do we have zero Bright Data IPs in our honeypot?

A: Bright Data's residential proxy network operates through consumer devices โ€” home routers, mobile phones, and as of June 2026, smart TVs. When traffic exits through these devices, it carries the IP address of a Comcast subscriber in Ohio or a Deutsche Telekom user in Hamburg. Our honeypot records it as American or German consumer traffic. The Israeli origin is structurally invisible because the attribution follows the exit node, not the proxy operator. This is not evasion โ€” it's architectural invisibility.

Reading Between the Lines

Q: If you can tap the cables, control the VPNs, own the proxy network, and build the hacking tools โ€” what CAN'T you see?

A: This is the question that makes intelligence analysts uncomfortable. Blue-Raman carries Europe-to-Asia traffic through Israel. Bright Data routes through 150 million exit nodes in 195 countries. Kape controls 4 major VPN providers. NSO's Pegasus has been deployed in 45+ countries. Check Point firewalls sit in enterprise networks globally. Consider the combined access surface: the physical cables, the residential proxies, the VPN infrastructure, the enterprise firewalls, the phone extraction tools, and the offensive spyware โ€” all with Israeli origin, all structurally invisible. The answer to "what can't you see?" may be: nothing. And the answer to "who can see everything?" may be: the nation with 7 IPs and 0 hits.

Q: Is the statistical absence itself a form of capability demonstration?

A: We documented 31 prior investigations. China appears. Russia appears. Vietnam appears. Iran appears. Every nation with significant cyber activity leaves traces. Israel โ€” home to NSO, Cellebrite, Candiru, Unit 8200, Bright Data, Kape โ€” appears as 7 consumer IPs with zero interactions. If zero visibility is the goal, this is a perfect score. In intelligence terms, the absence of intelligence is itself intelligence. A nation whose entire cyber export industry is built on SIGINT expertise would presumably know how to avoid appearing in honeypot databases. The question is not whether they're capable of it. The question is whether this is what capability looks like from the outside.

Q: Mishayev operates from Bavaria. Kape is registered in the Isle of Man. Bright Data's parent is in the UK. Why does everything Israeli end up everywhere EXCEPT Israel?

A: There is a benign explanation: Israel is a small market, and internationalization requires foreign entities. There is also a structural explanation: if your founders trained in signals intelligence, they understand attribution chains. They know that every database query starts with country=IL. They know that not appearing in that query is worth more than any firewall. Hauzenberg. Isle of Man. British Virgin Islands. Seychelles. These are not random choices โ€” they are the jurisdictions where oversight is minimal and questions are expensive. The same jurisdictions we documented in TI-2026-024: Offshore Bulletproof, used by Russian and Chinese operators. The nationality of the operator changes. The jurisdictional arbitrage is identical.

Q: The geographic position โ€” what's REALLY there?

A: Look at a map. Israel sits at the junction of three continents: Europe (Mediterranean coast), Asia (bordering Jordan and Syria), Africa (bordering Egypt via Sinai). Every submarine cable from Europe to Asia that doesn't go through the Suez Canal goes through Israel (Blue-Raman). Every intelligence agency with Middle East operations routes through Israeli SIGINT partnerships. Every tech company expanding to the Gulf or India benefits from Israeli expertise. This is not a nation with cyber capability. This is the geographic chokepoint WHERE cyber capability has maximum leverage. The fiber runs through here. The intelligence runs through here. The tools were built here. And in our database: 7 IPs. Zero hits. The most capable nation in the most strategic position is the most invisible. This is either the world's largest coincidence or the world's most impressive demonstration of what visibility control actually looks like.

Methodology

Data Sources

  • LSN Honeypot Database: 8,000+ attacker IPs with enrichment from 12+ OSINT sources
  • LSN Intelligence Platform: 277K+ entity links across 17 relationship types
  • Dossier Vector Store: Cross-referenced against 31 published investigations
  • RIPE Database: ORG-DM262-RIPE, corporate records, LIR sponsorship data
  • German Corporate Registry: HRB 12249 (Pfcloud UG), District Court Passau
  • Spamhaus: ASN-DROP classifications for all Mishayev-sponsored networks
  • GBHackers / Intrinsec: Third-party validation report (May 28, 2026)
  • Include Security: Bright Data SDK analysis (June 2026)
  • European Investment Bank: Blue-Raman cable project documentation
  • DropSite News: Unit 8200 alumni in private sector investigation
  • Qurium Media Foundation: Bright Data enabling Philippines DDoS documentation

Search Methodology

  1. Country field search: SELECT * FROM ips WHERE country='IL' โ€” yielded 7 IPs
  2. Organization search: Searched all known Israeli cyber companies (Check Point, NSO, Cellebrite, Candiru, Radware, CyberArk) โ€” zero matches
  3. RDAP registration search: Searched for ", IL" suffix in RDAP org fields โ€” 6 consumer ISP IPs
  4. Founding origin trace: Identified Israeli-founded cloud providers (Kamatera) โ€” 7 IPs across 5 ASNs
  5. Operator nationality trace: Searched RIPE for Israeli nationals operating German/EU companies โ€” discovered Daniel Mishayev (ORG-DM262-RIPE, IL) โ€” 37 IPs, 930 hits
  6. Vector cross-reference: Searched all 31 prior dossier investigations โ€” found extensive existing coverage of Mishayev ecosystem across 5+ investigations
  7. BGP upstream analysis: Traced transit relationships between Pfcloud and co-located ASNs
  8. Open-source intelligence: GBHackers, Include Security, Qurium, DropSite News, Wikipedia, EIB documents

Confidence Assessment

  • Mishayev โ†’ Pfcloud โ†’ bulletproof ASNs: HIGH (RIPE records, corporate filings, Spamhaus data, third-party reporting)
  • Kamatera identity fragmentation: HIGH (5 ASNs in 3 RIRs under 8+ names โ€” all publicly verifiable)
  • Bright Data residential proxy scale: HIGH (company's own claims + June 2026 SDK analysis)
  • Kape โ†’ Unit 8200 connection: HIGH (documented co-founder biography)
  • Submarine cable tapping: MEDIUM (Wikipedia citing French press; no primary source available)
  • Israeli state direction of Mishayev operations: LOW (no evidence; pattern is private sector)

Cross-References

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Invisible Nation โ€” 2 / 8 Next โ†’