๐Ÿ”ด META-ANALYSIS โ€” Operation Shadow Nexus Part H ยท The Feedback Loop ยท When Dossiers Create Reactions ยท All Roads Lead to the Same Network

TI-2026-019H โ€” "The Feedback Loop" โ€” How 18 Investigations Reveal One Interconnected Criminal Ecosystem, a P2P Botnet Named "sshd", and the Observable Consequences of Publishing Intelligence

TI-2026-019H ยท Published June 9, 2026 ยท Part H of Operation Shadow Nexus ยท Confidence: HIGH

๐Ÿ“‹ When You Watch the Watchers, They Watch Back

This dossier presents findings that were never asked for. They emerged from cross-referencing all 18 previous investigations โ€” and they reveal something unexpected: the actors from separate dossiers are connected. They share credentials, infrastructure, breach data, and most tellingly โ€” they react to our publications.

Since the publication of DOSSIER-011 ("The Personal Touch"), our MikroTik router's cooling fans have been running at full speed. While prerouting rules block all non-honeypot traffic, the volume of blocked connection attempts has visibly increased. This is the feedback loop: publish intelligence โ†’ attackers escalate โ†’ generate more intelligence โ†’ publish again.

Additionally, we've discovered a previously undocumented P2P botnet that replaces the SSH daemon itself with a worm that knows 299 peer IP addresses, and a network of credential validators logging in 16,061 times just to disconnect โ€” monitoring our honeypot without triggering alarm bells.

๐Ÿ•ธ๏ธ SEGMENT 1: The Cross-Dossier Connection Map

Every previous dossier was treated as an independent investigation. When we cross-reference their actors, a different picture emerges:

ActorFirst AppearedAlso Appears InCurrent Status
Proton66 (Russia)011 Campaign A, Wave 1019F Bulletproof hostingActive, 6 IPs, 197 silent logins
SPARKED HOST (US)011 Campaign A (30.8% of attacks)019 dataset (7 IPs)Active, threat 100, still attacking
OMEGATECH (Seychelles)010 GPU Hunter019 silent logins (560x)Evolved: GPU profiling โ†’ passive monitoring
Private Layer (Panama)014 Phase Layer019 silent logins (5,751x!)12+ IPs, massive monitoring campaign
Baidu Cloud (China)003 Weaponized Infra019 P2P sshd botnet (peer node!)Compromised by P2P worm, threat 100
Grameen (Bangladesh)011 "The Grameen Operator"019 Gโ€ขโ€ขโ€ขโ€ขโ€ขโ€ข86. distributionStill active, same unique HASSH
FranTech/BuyVM (US)019F Bulletproof (121 IPs)Uses Gโ€ขโ€ขโ€ขโ€ขโ€ขโ€ข86. credentialActive, hosting Tor nodes + attack infra
Viettel (Vietnam)016 Phantom Pipes019B Military cluster92 IPs (AsyncSSH), proxy + offensive ops
๐Ÿ”‘ THE "GOOGLE1986." DISTRIBUTION NETWORK

The breached credential Gโ€ขโ€ขโ€ขโ€ขโ€ขโ€ข86. โ€” first documented in DOSSIER-011 as the primary weapon against our infrastructure โ€” is now observed across 26 unique IPs from 15 different organizations:

  • ๐Ÿ‡ง๐Ÿ‡ฉ Grameen Communications (Bangladesh) โ€” dossier-011 primary actor
  • ๐Ÿ‡ช๐Ÿ‡น Ethio Telecom (Ethiopia) โ€” dossier-011 OSINT operator
  • ๐Ÿ‡ฐ๐Ÿ‡ญ CamGSM/Cellcard (Cambodia) โ€” tried "lsn" username
  • ๐Ÿ‡บ๐Ÿ‡ธ FranTech/BuyVM โ€” bulletproof hosting (dossier-019F)
  • ๐Ÿ‡บ๐Ÿ‡ธ PureVoltage Hosting โ€” 3 IPs
  • ๐Ÿ‡ฉ๐Ÿ‡ช Hetzner โ€” 2 IPs
  • ๐Ÿ‡บ๐Ÿ‡ธ DigitalOcean โ€” 2 IPs
  • ๐Ÿ‡ช๐Ÿ‡ช EENet (Estonian Ministry of Education!) โ€” 1 IP
  • ๐Ÿ‡ต๐Ÿ‡ฑ Mevspace โ€” 2 IPs
  • ๐Ÿ‡ต๐Ÿ‡พ Red Paraguaya โ€” 1 IP

Interpretation: Different SSH client libraries (paramiko, libssh2, Go) across these IPs proves multiple operators purchased or received this credential from a shared source. This is not one actor using 26 proxies โ€” this is a credential marketplace where breached data about specific targets is sold to multiple buyers.

๐Ÿ‘ป SEGMENT 2: The Silent Army โ€” 16,061 Login-and-Disconnect Operations

Of 17,044 successful honeypot logins, 16,061 (94%) execute zero commands. These are not failed attacks โ€” they're deliberate login-and-disconnect operations. The top operators:

ActorCountrySilent LoginsCredential UsedAssessment
Private Layer INC (Panama)๐Ÿ‡ต๐Ÿ‡ฆ PA5,751admin:adminHoneypot monitoring / intelligence
w1n ltd (UKโ†’Sweden)๐Ÿ‡ฌ๐Ÿ‡ง GB/SE4,496admin:admin + 0:0Monitoring + router credential testing
ISAEV Igor (Kazakhstan)๐Ÿ‡ฐ๐Ÿ‡ฟโ†’๐Ÿ‡ต๐Ÿ‡ฑ/๐Ÿ‡ท๐Ÿ‡บ3,670admin:admin + support credsResidential proxy network builder
OMEGATECH (Seychelles)๐Ÿ‡ธ๐Ÿ‡จโ†’๐Ÿ‡บ๐Ÿ‡ฆ/๐Ÿ‡น๐Ÿ‡ท686VariousEvolved from GPU profiling (Dossier-010)
SOLDATOV ALEXEY (80.66.66.x)๐Ÿ‡ฐ๐Ÿ‡ฟโ†’๐Ÿ‡ท๐Ÿ‡บ198admin:adminKnown Russian cybercrime range
Proton66 OOO (Russia)๐Ÿ‡ท๐Ÿ‡บ197VariousBulletproof hoster (also in Dossier-011)
๐Ÿงฎ WHAT ARE THEY DOING?

Three distinct purposes for silent logins:

  1. Honeypot Monitoring: Private Layer (5,751x) and w1n (4,496x) log in repeatedly with admin:admin โ€” they KNOW it's a honeypot. They're tracking uptime, response changes, and whether the honeypot adds new fingerprinting. This is counter-intelligence.
  2. Credential Validation: Testing if passwords still work. Log in โ†’ success โ†’ log out โ†’ credential confirmed valid โ†’ sell access or return later.
  3. Proxy Suitability Assessment: ISAEV's one command execution checks for SSH tunneling capability (socat, chisel, gost), router OS (MikroTik, OpenWrt, Ubnt), and TCP forwarding config. He's building a residential proxy network โ€” same business model as DOSSIER-016 "Phantom Pipes".

๐Ÿ› SEGMENT 3: The Undocumented P2P "sshd" Botnet

A previously undocumented botnet has been operating in our data, disguised by naming its binary sshd โ€” the same name as the legitimate SSH daemon. Its behavior is unlike anything in our previous dossiers:

INFECTION SEQUENCE: 1. Compromise target via SSH brute-force 2. Create hidden directory: ./{random_19_digit_number}/ Examples: .1015026083002449969, .3659982939581713256, .8789527882976412579 3. Download binary named "sshd" (SHA256: 94f2e4d8d4436874...da4c00) 4. chmod +x ./{id}/sshd 5. Launch with peer list: nohup ./{id}/sshd [IP1] [IP2] [IP3] ... [IP50+] & PEER LIST ANALYSIS: โ”œโ”€โ”€ 299 unique IP addresses observed across 11 infection sessions โ”œโ”€โ”€ Each launch receives 50+ peer IPs as command-line arguments โ”œโ”€โ”€ Peers span: China (dominant), US, GB, Vietnam, Indonesia, India โ”œโ”€โ”€ 11 peer IPs confirmed in our honeypot database (attacking us too) โ”œโ”€โ”€ Includes: Baidu Cloud, ChinaNet, China Mobile, DigitalOcean, UK hosting โ””โ”€โ”€ Binary SHA256 is POLYMORPHIC โ€” 24 unique hashes observed (recompiled per victim?) NOTABLE PEERS (confirmed in our database): 180.76.175.142 โ€” Baidu Cloud (Dossier-003!) โ€” threat 100 49.72.111.25 โ€” ChinaNet โ€” threat 100 159.203.120.106 โ€” DigitalOcean โ€” threat 100 36.137.79.219 โ€” China Mobile โ€” threat 100 46.101.107.202 โ€” DigitalOcean โ€” threat 100
โš ๏ธ WHY THIS BOTNET IS DIFFERENT
  • P2P architecture: Unlike Outlaw (central C2), this botnet passes peer lists to each node. No single point of failure. Takedown requires simultaneous action against 299+ nodes.
  • Binary polymorphism: 24 unique SHA256 hashes for "sshd" across 36 downloads. Either recompiled per victim (unique build ID) or uses packing/encryption.
  • Naming camouflage: The binary is literally named "sshd" โ€” on a compromised server running SSH, this is INVISIBLE to casual process listing. ps aux | grep sshd shows the real sshd AND the malware identically.
  • Hidden directory obfuscation: 19-digit random numbers as directory names, with leading dot (hidden). ls won't show them; ls -la will, but the 19-digit name looks like a legitimate process artifact.
  • China-dominant peer mesh: 60%+ of peer IPs are Chinese residential/cloud (Baidu, ChinaNet, China Mobile, China Unicom). This is either a Chinese-operated botnet or one that primarily targets Chinese infrastructure.
  • Cross-campaign victim: Baidu IP 180.76.175.142 is BOTH a peer in this botnet AND was documented in DOSSIER-003 as weaponized Baidu infrastructure. The same server compromised by multiple botnets.

๐ŸŽฏ SEGMENT 4: ISAEV Igor โ€” The Proxy Network Builder

ISAEV Igor (AS number registered in Kazakhstan, operating from Poland and Russia) runs a single comprehensive command on successful login that reveals their exact business model:

ISAEV's probe command checks (in order): โ”œโ”€โ”€ System info: uname, hostname, arch, user ID โ”œโ”€โ”€ SSH config: AllowTcpForwarding, PermitTunnel, GatewayPorts โ”‚ โ†’ Can this host be used as an SSH tunnel proxy? โ”œโ”€โ”€ Network: IP addresses, listening services โ”œโ”€โ”€ Resources: uptime, memory, CPU count, disk space โ”œโ”€โ”€ Tunnel tools: socat, curl, wget, python3, ncat, chisel, gost โ”‚ โ†’ Are proxy tools already installed? โ”œโ”€โ”€ Write test: touch /tmp/.sshprobe (can we write files?) โ”œโ”€โ”€ Package manager: apt, yum, apk, opkg, dnf, pacman, zypper โ”‚ โ†’ Can we INSTALL proxy tools? โ”œโ”€โ”€ Sudo: sudo -n true โ†’ can we escalate privileges? โ”œโ”€โ”€ Device type detection: โ”‚ โ”œโ”€โ”€ /system resource print โ†’ MikroTik router? โ”‚ โ”œโ”€โ”€ /etc/openwrt_release โ†’ OpenWrt router? โ”‚ โ””โ”€โ”€ /etc/version โ†’ Ubiquiti device? โ””โ”€โ”€ Goal: Build inventory of devices suitable for SSH tunnel proxying
๐Ÿ’ฐ THE BUSINESS MODEL

ISAEV operates the same business documented in DOSSIER-016 "Phantom Pipes" โ€” a residential proxy network. The infrastructure:

  • 8 IPs in 87.251.64.x (all threat score 100), registered to an individual in Kazakhstan, operating from Poland/Russia
  • 3,670 silent logins + 8 support-credential attempts โ€” testing for ISP equipment defaults
  • Revenue model: Residential proxies sell for $5-15/GB. A network of 1,000 compromised home routers generating 10GB/day = $50K-150K/month
  • Why check for MikroTik/OpenWrt/Ubnt? These are HOME ROUTERS โ€” the most valuable proxy endpoints because their IP addresses appear "residential" to anti-fraud systems

This is the SAME operation as Viettel's 102 compromised home routers in DOSSIER-016, but run by a different operator targeting different geography. The residential proxy market is large enough to support multiple competing criminal enterprises.

๐Ÿ”„ SEGMENT 5: The Observable Feedback Loop

Since publishing dossiers on shuffle-on.com, observable changes in attacker behavior:

Observable ChangeEvidenceInterpretation
MikroTik CPU load increaseCooling fans at maximum since dossier publicationDDoS or scanning surge against edge router (blocked at prerouting)
248 IPs targeting "shuffleon" userDomain-specific credential generation (Shuffleon2026@)Increased targeting after domain gained visibility
16,061 silent monitoring logins94% of successful logins do nothingCounter-intelligence: tracking honeypot behavior changes
CYBEROLOGY honeypot fingerprinting20+ IPs checking /proc/1/mounts, container detectionMapping whether honeypot infrastructure changed after publications
Gโ€ขโ€ขโ€ขโ€ขโ€ขโ€ข86. spread to 26 IPsWas 3-4 IPs in original dossier-011, now 26Credential was RESOLD after publication confirmed it was known
The paradox of transparency: Publishing intelligence about attacks creates a feedback loop. Attackers read the publications (our analytics confirm traffic from IP ranges matching attacker infrastructure). They learn what we know. They adapt. But adaptation creates NEW observable signatures. The 16,061 silent logins wouldn't exist if they weren't specifically trying to understand our capabilities. Their caution IS the signal.

๐Ÿงฉ SEGMENT 6: The Unified Theory โ€” One Ecosystem, Many Operators

These 18+ investigations, when viewed together, reveal not separate campaigns but one criminal ecosystem with specialized roles:

THE ECOSYSTEM (roles, not individuals): โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”‚ LAYER 1: INFRASTRUCTURE PROVIDERS (enabling layer) โ”‚ โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค โ”‚ โ€ข Proton66 (RU) โ€” Bulletproof hosting, zero abuse response โ”‚ โ”‚ โ€ข FranTech/BuyVM (US) โ€” "Privacy" hosting, Tor exit nodes โ”‚ โ”‚ โ€ข YISU Cloud (HK/SC) โ€” Shell company, offshore routing โ”‚ โ”‚ โ€ข Private Layer (PA) โ€” Intelligence-grade hosting โ”‚ โ”‚ โ€ข SPARKED HOST (US) โ€” Budget attack infrastructure โ”‚ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ”‚ provides infrastructure to โ–ผ โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”‚ LAYER 2: BREACH DATA MARKET (intelligence layer) โ”‚ โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค โ”‚ โ€ข Credential databases (Gโ€ขโ€ขโ€ขโ€ขโ€ขโ€ข86. sold to 26+ buyers) โ”‚ โ”‚ โ€ข Domain OSINT packages (shuffleon service enumeration) โ”‚ โ”‚ โ€ข Vulnerability feeds (exposed Portainer, SSH keys) โ”‚ โ”‚ โ€ข Target dossiers (family names, personal details) โ”‚ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ”‚ purchased by โ–ผ โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”‚ LAYER 3: OPERATORS (action layer) โ”‚ โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค โ”‚ โ€ข Grameen/UIH cluster โ€” Targeted credential stuffing (011) โ”‚ โ”‚ โ€ข Outlaw botnet โ€” Mass SSH worm, crypto-mining (019A-C) โ”‚ โ”‚ โ€ข P2P sshd botnet โ€” Sophisticated China-focused worm (NEW) โ”‚ โ”‚ โ€ข ISAEV network โ€” Residential proxy recruitment โ”‚ โ”‚ โ€ข OMEGATECH โ€” GPU profiling โ†’ access brokering (010โ†’019) โ”‚ โ”‚ โ€ข Viettel cluster โ€” State-adjacent offensive ops (016, 019B) โ”‚ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ”‚ monetized by โ–ผ โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”‚ LAYER 4: REVENUE (extraction layer) โ”‚ โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค โ”‚ โ€ข Crypto mining โ€” $450K-930K/year (Outlaw, 019C) โ”‚ โ”‚ โ€ข Residential proxies โ€” $50K-150K/month (ISAEV, Phantom Pipes) โ”‚ โ”‚ โ€ข Access brokering โ€” $5-50 per validated credential โ”‚ โ”‚ โ€ข Data exfiltration โ€” Priceless (AI models, student records) โ”‚ โ”‚ โ€ข State intelligence โ€” No price tag (Viettel, Afghan gov) โ”‚ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ COUNTER-INTELLIGENCE (watching it all): โ”œโ”€โ”€ CYBEROLOGY (NL) โ€” Active honeypot fingerprinting โ”œโ”€โ”€ Private Layer (PA) โ€” Passive availability monitoring โ”œโ”€โ”€ w1n ltd (UK) โ€” Passive availability monitoring โ””โ”€โ”€ OMEGATECH (SC) โ€” Evolved from profiling to monitoring

๐Ÿ“Ž Sources (Part H)

๐Ÿ“„ Cross-reference of all 18 previous dossier investigations (001-019G)
๐Ÿ“„ Direct honeypot observation โ€” 16,061 silent logins, P2P sshd botnet (299 peers), credential distribution
๐Ÿ“„ DOSSIER-011 "The Personal Touch" โ€” original Gโ€ขโ€ขโ€ขโ€ขโ€ขโ€ข86. documentation (3-4 IPs โ†’ now 26)
๐Ÿ“„ DOSSIER-010 "The GPU Hunter" โ€” OMEGATECH evolution from profiling to monitoring
๐Ÿ“„ DOSSIER-014 "Phase Layer" โ€” Private Layer INC (Panama) first identified
๐Ÿ“„ DOSSIER-003 "Baidu Cloud" โ€” Same Baidu IP now in P2P sshd botnet peer list
๐Ÿ“„ DOSSIER-016 "Phantom Pipes" โ€” Residential proxy model (Viettel) now replicated by ISAEV
๐Ÿ“„ MikroTik router diagnostics โ€” cooling fan speed increase post-publication
๐Ÿงญ Operation Shadow Nexus โ€” Complete Series:
A: Core ยท B: Ugly Machinery ยท C: Follow The Money ยท D: Open Doors ยท E: Web Between ยท F: Ghost in the Machine ยท G: Broken Window ยท H: The Feedback Loop (Meta-Analysis)
Methodology: Cross-dossier correlation ยท Passive SSH honeypot ยท Credential distribution tracking ยท P2P peer list analysis ยท Behavioral pattern classification ยท No active scanning performed
โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous Operation Shadow Nexus โ€” 8 / 13 Next โ†’