shared_malware graph, which is retention-limited: the shared_malware graph was later corrected to exclude junk/trivial hashes that had inflated these counts (the raw download data is fully retained since March 2026), so the malware-download figures cited here (downloaded-sample counts, shared_malware edge counts) are a point-in-time snapshot and are not live-reproducible (the current shared_malware graph holds ~68 links / ~16 IPs). The findings hold as of the capture window; the live graph will not match. Session, command, credential, HASSH and SSH-key evidence in this dossier is unaffected.
๐ TI-2026-026L โ The Supply Chain: From SSH Scan to Ransomware Attack โ How 333 Logins Become a $5 Million Extortion
Executive Summary: The modern cybercrime economy is not a collection of lone hackers. It is a vertically integrated supply chain with specialized actors at every stage: scanners who find open doors, brokers who verify and price the access, ransomware affiliates who weaponize it, and bulletproof hosting providers who protect the infrastructure from law enforcement. Our honeypot sat at Stage 1 of this pipeline for 30 days and recorded the raw mechanics: 5 distinct scanning campaigns operating across 2,600+ IPs in 84 countries, achieving 333 successful SSH logins from the Go_SSH campaign alone. Each login is a product. Each product has a price. Each price leads to a victim.
This dossier traces the complete economic pipeline: from the $5/month VPS that runs a scanner, through the $50-$5,000 Initial Access Broker listing on Exploit or XSS forums, to the $5 million ransomware demand that closes the loop. We map the specific campaigns, identify the operator clusters, analyze the shared malware payloads that prove cross-campaign coordination, and calculate the ROI at every stage. The numbers are not theoretical. They come from our honeypot's session logs, from court filings in ransomware cases, from dark web marketplace monitoring, and from the insurance claims that document the final cost.
Along the way we ask the questions that the cybersecurity industry prefers to avoid: Why do DigitalOcean, Google Cloud, and Microsoft Azure โ whose platforms host more attack infrastructure than any "bulletproof" provider โ face zero consequences? What if the real supply chain isn't criminal at all, but a natural market response to the internet's architectural flaws? And what does it mean that dismantling any single stage of this pipeline has never once reduced the total volume of attacks?
Chapter 1: The Assembly Line โ Three Stages of Digital Extortion
Every ransomware attack that makes headlines โ every hospital locked out, every school district paying millions, every pipeline shut down โ begins the same way: someone, somewhere, runs a scanner. The scanner finds a door. The door opens. What happens next follows a supply chain as structured as any legitimate industry, with specialization, pricing tiers, quality assurance, and customer service.
Our honeypot sat at Stage 1 for 30 days. It pretended to be a vulnerable SSH server. It recorded everything. What it captured was not chaos โ it was manufacturing.
โ What If This Isn't a "Chain" at All โ But an Ecosystem?
The term "supply chain" implies linearity: A sells to B who sells to C. But our honeypot data shows something more complex. The same IPs appear in multiple campaigns. The same malware payloads are downloaded by IPs belonging to different operator clusters. Credentials are shared laterally, not just vertically.
The better metaphor is a marketplace ecosystem โ like Amazon. There are sellers (scanners), wholesalers (IABs), retailers (ransomware affiliates), and a platform infrastructure that enables all of them. No single entity controls the chain. No takedown disrupts the market for more than weeks. When LockBit was seized in February 2024 (Operation Cronos), the affiliates simply moved to other RaaS platforms. When ALPHV/BlackCat exit-scammed after the $22M Change Healthcare payment, its operators launched a new brand within months. The chain is resilient precisely because it isn't a chain โ it's a decentralized marketplace where every participant is replaceable.
Sources: Europol Operation Cronos press release (Feb 2024); Reuters โ ALPHV/BlackCat exit scam analysis; BleepingComputer โ LockBit restoration after seizure
โ Why Does Nobody Talk About Stage 0?
The entire cybersecurity industry focuses on Stages 1-3: detect the scanner, block the credential, stop the ransomware. Billions are spent on endpoint detection, threat intelligence, incident response. But Stage 0 โ the infrastructure that makes everything possible โ is barely discussed.
Because Stage 0 implicates the cybersecurity industry's own customers. DigitalOcean hosts 171 campaign IPs in our dataset โ more than any bulletproof provider. Google Cloud hosts 79. Microsoft Azure hosts 108. OVH hosts 86. These are not "bulletproof" hosters. These are Fortune 500 companies whose platforms are the primary infrastructure for scanning campaigns. Talking about Stage 0 means talking about platform liability. Platform liability means regulation. Regulation means reduced revenue. So the industry talks about "advanced persistent threats" and "zero-day vulnerabilities" instead of the $5/month DigitalOcean droplet that scanned 50,000 SSH servers last Tuesday.
Sources: Honeypot ASN analysis โ top campaign ASNs by IP count; DigitalOcean Terms of Service (prohibit scanning, rarely enforce for short-lived instances)
๐ Reading Between the Lines
- The supply chain model has a built-in redundancy at every stage. When one scanner is taken down, another takes its place because the VPS costs $5/month. When one IAB is arrested, another surfaces because the forum infrastructure (Tor-hosted) persists. When one RaaS platform is seized, affiliates migrate because the ransomware code is fungible.
- The only stage where disruption has lasting effect is Stage 0 โ infrastructure. Physical servers cannot be respawned. Peering agreements cannot be rebuilt in days. This is why CyberBunker's physical seizure in 2019 actually worked, while every software-level takedown has failed within weeks.
- The cybercrime supply chain is not an aberration. It is the internet's immune system working in reverse โ using the same distributed, resilient architecture that makes the internet survivable, but pointing it at extraction instead of communication.
Chapter 2: Stage 1 โ The Five Campaigns We Watched
Over 30 days, our honeypot recorded five distinct scanning campaigns. Each represents a different operational model, a different level of sophistication, and a different position in the supply chain.
| Campaign | IPs | Attempts | Successes | Rate | Countries | Strategy |
|---|---|---|---|---|---|---|
| libssh_0.11.x | 1,313 | 44,341 | 38 | 0.09% | 84 | Mass botnet โ volume over precision |
| Go_SSH | 320 | ~7,100 | 333 | 4.68% | 43 | VPS-based precision scanner |
| libssh_0.9.6 | 421 | ~35,000 | 24 | 0.07% | 60+ | Legacy botnet โ older infrastructure |
| go_scanner | 6 | 3,518 | 3,518 | 100% | 4 | Targeted โ pre-identified hosts |
| paramiko_script | 3 | 3,200 | 3,200 | 100% | 2 | Targeted โ known credentials |
The success rates tell the story. The mass botnets (libssh variants) spray credentials at everything โ 0.07-0.09% success. The precision scanners (Go_SSH) select targets โ 4.68% success. The targeted operators (go_scanner, paramiko) already know what they're hitting โ 100% success.
These are not three versions of the same thing. They are three different business models operating in the same market.
โ How Does a Campaign Achieve 100% Success Rate?
The go_scanner (6 IPs, 3,518 attempts, 100% success) and paramiko_script (3 IPs, 3,200 attempts, 100% success) campaigns show something that should be impossible in brute-force scanning: every single attempt succeeds.
100% success means they are not scanning โ they are replaying known-good credentials. These operators already possess a list of valid username:password combinations for specific targets. Where did the list come from? Three possibilities: (1) They purchased it from a Stage 1 scanner who already validated these credentials. (2) They obtained it from a credential dump โ a breach of another service where the same passwords were reused. (3) They are the scanner, returning to previously compromised hosts to install persistence or deploy payloads. In all three cases, this is Stage 2 activity masquerading as Stage 1 โ the supply chain has already processed these credentials before our honeypot saw them.
Sources: Honeypot session analysis โ go_scanner campaign; paramiko_script credential correlation
โ Why 1,313 IPs for 38 Successes? Is the libssh Botnet Incompetent โ or Something Else?
The libssh_0.11.x campaign deployed 1,313 IPs across 84 countries and achieved only 38 successful logins โ a 0.09% success rate. At face value, this looks like spectacular inefficiency. Why rent 1,313 cloud instances if you're going to fail 99.91% of the time?
Because the botnet isn't measuring success by our honeypot's standards. Our honeypot is one server. The internet has approximately 20 million SSH-accessible servers (Shodan, 2024). At 0.09% against 20 million, the libssh_0.11.x campaign would yield 18,000 valid credentials. At $50-$200 each on the IAB market, that's $900,000 to $3.6 million in potential revenue from a single 30-day campaign. The 1,313 VPS instances cost approximately $6,500/month on cheap providers. That's a minimum 138ร ROI. The "incompetence" is actually a cold economic calculation. They don't need a high success rate. They need volume. And 1,313 IPs deliver volume.
Sources: Shodan SSH service count (2024); VPS pricing on Contabo/Hetzner (~$5/mo); IAB pricing โ Group-IB Hi-Tech Crime Trends 2024
โ What If the 84 Countries Are the Product, Not Just the Method?
The libssh_0.11.x botnet operates from 84 countries. Go_SSH from 43. These aren't accidents of infrastructure availability โ VPS providers exist in every country. So why specifically 84?
Geographic diversity has value beyond evasion. An IAB selling SSH access to a corporate network in Germany will command a higher price if the access was obtained from a German IP address โ because German IPs are less likely to trigger geographic anomaly alerts on the target network. A scanner in 84 countries can offer geographically localized access โ scanning Brazilian targets from Brazilian IPs, Japanese targets from Japanese IPs. This isn't just operational security. It's a premium feature. "We provide access that won't trigger your target's geo-fencing" is a selling point. The 84 countries are inventory diversity, not operational overhead.
Sources: Honeypot campaign geographic analysis; IAB market research โ geographic pricing premiums
โ What Is the Go_SSH Campaign's Actual Hit Rate Against the Real Internet?
Against our honeypot โ a deliberately vulnerable target โ Go_SSH achieved 4.68%. But our honeypot accepts everything by design. What's the real-world success rate against actual servers?
Against properly configured servers: essentially zero. Against the estimated 3-5% of SSH servers with default or weak credentials (based on Rapid7's National Exposure Index), Go_SSH's 4.68% rate is almost perfectly calibrated. It means the campaign's wordlist is well-tuned to default credential patterns (root:root, admin:admin, ubuntu:ubuntu, pi:raspberry). Against the 20 million SSH servers on the internet, the campaign's 320 IPs could realistically scan ~500,000 hosts per day (at conservative rates), find ~23,500 with weak credentials in one month, and validate ~1,100 at Go_SSH's observed success rate. Each valid credential: a product for sale.
Sources: Rapid7 National Exposure Index; Honeypot credential analysis โ top Go_SSH attempts: root:root, admin:admin, ubuntu:ubuntu
๐ Reading Between the Lines
- The five campaigns we observed are not competing with each other. They occupy different market segments. The mass botnet (libssh) finds everything. The precision scanner (Go_SSH) finds the easy targets. The targeted operators (go_scanner, paramiko) exploit previously discovered access. This is market segmentation, not competition.
- The campaigns share infrastructure. Our entity link analysis found 4,462 IP pairs sharing identical HASSH fingerprints across campaigns. This means different campaigns are using the same SSH client software โ either from a shared toolkit, a shared operator, or a shared malware distribution network.
- One IP โ 87.251.64.176 (Poland, AS200730, ISAEV Igor KZ) โ achieved a 92.7% success rate across 4,132 attempts. This IP is not scanning. It is systematically harvesting previously compromised hosts. It knows what it's hitting before it connects. This is Stage 2 operating under Stage 1 cover.
Chapter 3: Behind the IPs โ The Operator Clusters
IPs are disposable. VPS instances are created and destroyed in minutes. But the operators behind them leave fingerprints. Our intelligence platform identified operator clusters by correlating shared SSH keys, shared malware downloads, shared HASSH fingerprints, and temporal correlation across the 30-day observation window.
| Operator Cluster | Member IPs | ASNs | Countries | Avg Threat | Honeypot Hits | Identity Signal |
|---|---|---|---|---|---|---|
| actor-0d9fdff8bb3d | 269 | 89 | 30 | 72 | 5,387 | Shared SSH keys |
| actor-6285990cc704 | 1,313 | โ | 84 | โ | 44,341 | Shared HASSH (libssh_0.11.x) |
| HASSH-03a80b21afa81068 | 1,058 | โ | 39 | โ | โ | Shared SSH algo set |
| HASSH-acaa53e0a7d7ac7d | 757 | โ | 42 | โ | โ | Shared SSH algo set |
| HASSH-14b2ddda386a4d10 | 619 | โ | 43+ | โ | โ | Shared SSH algo set |
The largest single-identity operator we identified โ actor-0d9fdff8bb3d โ controls 269 IPs across 89 different ASNs in 30 countries. That's not a script kiddie. That's an enterprise. At $5-10/month per VPS, this operator spends $1,345-$2,690/month on infrastructure. For that investment, they generated 5,387 honeypot interactions in 30 days โ and our honeypot is one server among 20 million.
โ Who Is actor-0d9fdff8bb3d? A Person, a Group, or an Organization?
269 IPs. 89 ASNs. 30 countries. Shared SSH keys across all nodes. This cluster has the operational footprint of a small company, not an individual.
Three hypotheses: (1) Criminal service provider. An entity that operates scanning infrastructure as-a-service, renting out access to campaign operators who don't want to manage their own VPS fleet. Revenue model: monthly subscription or per-credential fee. (2) Organized crime group. A structured criminal organization with multiple operators managing different geographic regions, sharing a central SSH key for coordination. (3) State-adjacent operation. A scanning operation tolerated or sponsored by a government for intelligence collection, using commercial VPS to maintain deniability. The 89-ASN diversity suggests option 1 โ a service provider distributing across many providers to avoid single-provider takedowns. A state actor would more likely concentrate in domestic infrastructure.
Sources: Honeypot operator cluster analysis; SSH key correlation engine; ASN diversity analysis
โ What If the Operator Clusters ARE the Initial Access Brokers?
The traditional supply chain model assumes separation: scanners sell to IABs who sell to ransomware affiliates. But what if the boundary between Stage 1 and Stage 2 doesn't exist?
Our data supports vertical integration. IPs in actor-0d9fdff8bb3d both scan for credentials (Stage 1) and execute post-exploitation commands (Stage 2 activity). They don't just find open doors โ they walk in, run reconnaissance (uname -a, whoami), check for writable directories, and inject SSH keys for persistence. This is not a scanner handing off to a broker. This is an operation that discovers, validates, and prepares access for sale in a single automated pipeline. The IAB isn't a separate actor โ the IAB is the scanner's afternoon shift.
Sources: Honeypot session analysis โ post-login command sequences in actor-0d9fdff8bb3d cluster
โ 89 ASNs โ Is This Diversity by Design or by Necessity?
Why would one operator spread across 89 different hosting providers when concentrating on one would be simpler to manage?
Takedown resilience. When a single provider receives an abuse complaint and suspends 10 VPS instances, the operator loses 10 out of 269 nodes โ a 3.7% reduction. The scanning continues from the other 259. If the operator concentrated on one provider, a single abuse complaint could eliminate the entire fleet. 89 ASNs means 89 separate abuse teams, 89 separate legal jurisdictions, 89 separate decision-making processes. The probability that all 89 will act simultaneously approaches zero. This is the same resilience principle that makes the internet itself hard to shut down โ and the operator is weaponizing it.
Sources: ASN diversity analysis of actor-0d9fdff8bb3d; VPS provider abuse response time studies (avg 48-72h per Shadowserver Foundation)
Chapter 4: Post-Compromise โ What Happens After the Door Opens
Finding an open door is Stage 1. What happens inside determines the value of the product. Our honeypot recorded every command executed by attackers after successful login. The most common:
| Command | Count | Unique IPs | Purpose |
|---|---|---|---|
echo BMOK | 278 | 200+ | Heartbeat โ confirms active session |
uname -a / uname -s -v -n -r -m | 374 | 300+ | System reconnaissance โ OS, kernel, architecture |
Writable directory test (/var/tmp, /tmp, /dev/shm) | 130 | 100+ | Payload staging โ find where to drop malware |
whoami | 106 | 80+ | Privilege check โ root or user? |
SSH key injection (authorized_keys) | 85 | 70+ | Persistence โ backdoor for future access |
| Crontab enumeration | 84 | 70+ | Persistence + privilege escalation path |
| History clearing | 53 | 40+ | Anti-forensics โ cover tracks |
/ip cloud print | 52 | 40+ | MikroTik detection โ IoT/router targeting |
The sequence is standardized: heartbeat โ reconnaissance โ staging โ persistence โ cleanup. This isn't improvisation. It's a playbook. The same commands, in the same order, from hundreds of different IPs. The botnet operators have documented their procedures like a franchise operation.
โ What Is "BMOK" and Why Do 200+ IPs Send It?
The command echo BMOK appears in 278 sessions from over 200 distinct IPs. It is always the first command executed after login. It produces no useful output for the attacker. So why is it there?
BMOK is a heartbeat protocol. The scanner's control infrastructure sends echo BMOK as a connection verification โ if it receives "BMOK" back, it knows: (1) the SSH session is live, (2) command execution works, (3) the target is responsive. If BMOK doesn't come back, the credential is marked as dead and removed from the inventory. The string "BMOK" itself is likely an acronym or identifier for a specific botnet family. Its presence across 200+ IPs confirms that all those IPs are running the same command-and-control software โ same operator, or same malware framework.
Sources: Honeypot command analysis; botnet C2 protocol research; BMOK pattern identified in TI-2026-015 "Echo BMOK"
โ Why Does the Botnet Check for MikroTik Routers?
52 sessions included the command /ip cloud print โ a MikroTik RouterOS command that returns the router's cloud DNS hostname. This command does nothing on a Linux server. So why do the bots send it?
Because MikroTik routers are the most valuable targets in the IoT scanning economy. A compromised MikroTik router provides: (1) Persistent access to a network that is never patched (most home/SMB routers are never updated). (2) Network-level control โ the ability to intercept, redirect, or tunnel traffic for the entire network behind the router. (3) VPN infrastructure โ MikroTik supports L2TP, PPTP, IPsec, and WireGuard, allowing the compromised router to become a proxy endpoint. (4) Botnet node โ MikroTik's CPU can run cryptominers, DDoS packets, or scanning payloads. The /ip cloud print check is a target identification command. If it returns a result, the bot knows it has hit a MikroTik โ and escalates the session to a different handler optimized for router exploitation. See TI-2026-002: MikroTik Recon & Telegram Stealer Botnet for our full analysis.
Sources: Honeypot command analysis; TI-2026-002; MikroTik RouterOS command reference
โ What Does the SSH Key Injection Actually Look Like?
85 sessions included SSH key injection into ~/.ssh/authorized_keys. This is the most dangerous post-compromise action because it creates permanent access that survives password changes.
The injected key allows the attacker to return at any time โ even if the victim discovers the breach and changes all passwords. The key works independently of the authentication system. It is the digital equivalent of copying a physical key to a building: changing the locks on one door doesn't help if the copy opens a side entrance. Crucially, authorized_keys files are rarely audited. Most sysadmins check /var/log/auth.log for suspicious logins but never inspect the authorized_keys file for entries they didn't add. The injected key can sit there for months or years before detection โ if it's ever detected at all. This transforms a $50 credential into persistent, undetectable access worth $500-$5,000 on the IAB market.
Sources: Honeypot session analysis โ SSH key injection patterns; IAB market pricing tiers
๐ Reading Between the Lines
- The standardized command sequence (BMOK โ uname โ staging โ persistence โ cleanup) across 200+ IPs means this is not individual hackers. This is software executing a programmed workflow. The operator writes the playbook once. The bot executes it thousands of times.
- The anti-forensics step (history clearing, 53 sessions) tells us the operators know their sessions may be monitored. They are aware of honeypots. They clear history anyway because the cost of clearing is zero and the cost of being fingerprinted is loss of infrastructure.
- The MikroTik check (52 sessions) reveals target prioritization. The same bot that sprays credentials at everything has a built-in branch for high-value targets. This is not a dumb scanner โ it's a scanner with a triage system.
Chapter 5: The Shared Payload โ Cross-Campaign Malware Distribution
If the five campaigns were truly independent operations, they would use different malware. They don't. Our entity link analysis reveals 2,077 IP pairs sharing identical malware downloads โ and two payloads dominate:
| Payload SHA256 | Distributing IPs | Campaigns | Distribution Window | Classification |
|---|---|---|---|---|
a8460f446be5...f8f2 | 81 | Go_SSH, libssh2, multi-campaign | May 20 โ Jun 13, 2026 | Botnet variant / worm |
01ba4719c80b...546b | 55 | Go_SSH, libssh, multi-campaign | Same window | Botnet variant |
136 IPs across multiple independent campaigns download the same two payloads. The confidence score for these links: 0.9 (highest tier). This is not coincidence. This is a shared distribution network.
โ Who Operates the Payload Server?
81 IPs from different campaigns download the same binary. Someone hosts it. Someone maintains it. Someone controls the distribution URL. Who?
We identified payload distribution through GCP (35.237.91.38), AWS (34.181.210.37), and ISP infrastructure (31.170.22.205). The use of legitimate cloud providers for payload hosting is deliberate: these domains pass reputation filters, aren't on blocklists, and blend into normal traffic. The payload provider is likely a Malware-as-a-Service (MaaS) operator โ someone who develops and maintains the botnet software and distributes it to campaign operators in exchange for a cut of revenues or a flat licensing fee. This is the hidden fourth stage of the supply chain: the arms manufacturer who sells to all sides.
Sources: Honeypot download analysis; Cloud IP attribution โ GCP/AWS hosting; MaaS business model research
โ What If the Two Payloads Are Versions of the Same Framework?
Payload A (81 IPs) and Payload B (55 IPs) have different SHA256 hashes but appear in the same campaigns during the same time window. Are they competitors or collaborators?
More likely they are different builds of the same framework โ compiled for different architectures (x86 vs ARM), different OS versions, or different functionality modules. This is standard practice in botnet development: a modular codebase compiled into target-specific binaries. The operator tests both payloads, finds that Payload A works on 81 targets and Payload B works on 55 โ together covering the maximum number of compromised architectures. The two hashes are not two products. They are one product in two packages.
Sources: Malware reverse engineering patterns; Honeypot download correlation analysis
โ Why Are Legitimate Cloud Providers Hosting Attack Payloads?
The malware distribution servers sit on Google Cloud Platform (35.237.91.38) and Amazon Web Services (34.181.210.37). How do malware binaries persist on platforms with sophisticated abuse detection?
Speed and expendability. A GCP instance costs $0.01/hour. The attacker spins up an instance, uploads the payload, distributes it to 81 bots over 2-4 hours, and destroys the instance before any abuse team notices. Total cost: $0.04. Google's abuse detection pipeline runs on a cycle of hours to days. The payload distribution completes in minutes. By the time Google's systems flag the content, the instance is already gone and a new one is serving from a different IP. This is cloud abuse by design โ exploiting the gap between provisioning speed and enforcement speed. And it's why cloud providers will never fully solve this problem without fundamentally changing how quickly instances can be created.
Sources: GCP pricing calculator; Cloud abuse response time analysis; Honeypot download timestamps (burst patterns)
Chapter 6: The Market โ What a Stolen SSH Login Is Worth
Every successful login our honeypot recorded has a market value. The price depends on the target: who it belongs to, what network it's on, what access it provides. The cybercrime economy has developed a sophisticated pricing model for stolen access:
| Access Type | Price Range | Buyer | End Use |
|---|---|---|---|
| SSH โ unknown target | $10โ$100 | Bulk buyers, botnet operators | Proxy, cryptomining, further scanning |
| SSH โ corporate network | $500โ$3,000 | IABs, ransomware affiliates | Lateral movement, data theft |
| SSH โ healthcare/education | $1,000โ$30,000 | Ransomware affiliates directly | Encryption + extortion |
| VPN + domain admin | $5,000โ$50,000 | APT groups, ransomware affiliates | Full network compromise |
| RDP โ basic | $10โ$100 | Automated shops (Russian Market) | Identity theft, fraud |
| Citrix/VPN credentials | $200โ$2,000 | IABs for resale | Corporate network entry |
Sources: CIS โ Initial Access Brokers; Group-IB Hi-Tech Crime Trends 2024; Chainalysis 2024 Crypto Crime Report
The forums where this trade happens are well-known but practically impossible to shut down permanently:
| Forum | Type | Status (2025) | Specialty |
|---|---|---|---|
| Exploit | Russian-language forum | Active (Tor) | Enterprise access, high-value targets |
| XSS | Russian-language forum | Active (Tor) | Initial access, zero-days |
| RAMP | Russian-language forum | Active (Tor) | Ransomware affiliate recruitment |
| BreachForums | English-language forum | Seized/Reborn (cycle) | Data dumps, credential leaks |
| Russian Market | Automated shop | Active | RDP/SSH/cookies โ automated purchasing |
โ How Much Revenue Did Our Honeypot's 333 Logins Generate for the Attackers?
333 successful SSH logins from the Go_SSH campaign alone. If each was a real server instead of a honeypot, what's the economic output?
Conservative estimate: 333 valid SSH credentials ร $50 (minimum, unknown target) = $16,650 in IAB market value. But that's the floor. If even 10% of those targets were corporate networks (33 servers), the value jumps: 300 ร $50 + 33 ร $1,000 = $48,000. And if even one of those corporate targets led to a ransomware deployment, the return explodes: the average ransomware payment in 2024 was $2.73 million (Sophos State of Ransomware 2024). One payment exceeds the entire scanning campaign's operational cost by 1,700ร. The Go_SSH campaign cost approximately $1,600/month to operate (320 VPS ร $5). Its potential revenue from one month of scanning: $16,650 to $2.73 million. The ROI ranges from 10ร to 1,700ร.
Sources: Honeypot success count; IAB pricing models; Sophos State of Ransomware 2024 โ average ransom payment $2.73M
โ What If the Real Money Isn't in the Credentials โ But in the Data?
IABs sell access for $50-$5,000. Ransomware operators demand millions. But what if neither is the most valuable output of a successful SSH login?
Consider what a root-level SSH login provides: complete filesystem access. On a real server, that means databases, configuration files, API keys, private keys, customer data, source code. A database dump from a healthcare provider doesn't just enable ransomware โ it enables insurance fraud, identity theft, medical extortion, regulatory blackmail. The credential is the door. The data behind it is worth orders of magnitude more than the door itself. This is why the post-compromise playbook always includes directory enumeration and file harvesting โ the operators know that the real product isn't access, it's information.
Sources: IBM Cost of a Data Breach 2024 โ avg breach cost $4.88M; healthcare sector avg $9.77M
โ Is the IAB Market Shrinking or Growing?
Group-IB reported a 15% decrease in IAB offers in late 2024 compared to 2023. Does this mean the supply chain is weakening?
No โ it means the supply chain is maturing. Fewer public IAB listings doesn't mean less access trading. It means the market is moving from public forums to private channels โ direct Telegram groups, encrypted peer-to-peer deals, invite-only markets. This is the natural evolution of any underground market: as law enforcement infiltrates public forums (Genesis Market seized in 2023, BreachForums seized twice), sellers migrate to less visible channels. The total volume of access sales is likely increasing even as visible forum listings decrease. We're seeing the market go dark โ which makes it more dangerous, not less.
Sources: Group-IB Hi-Tech Crime Trends 2024; Genesis Market seizure (Operation Cookie Monster, April 2023); BreachForums seizure timeline
Chapter 7: Documented Cases โ When the Supply Chain Delivers
The supply chain we've traced isn't theoretical. It has produced documented, catastrophic outcomes. Here are three cases where the exact pipeline we observe โ scan โ compromise โ broker โ ransomware โ resulted in real-world devastation:
Case 1: Change Healthcare (February 2024)
The chain: Citrix remote access credentials (no MFA) โ ALPHV/BlackCat affiliate login โ 9 days undetected lateral movement โ data exfiltration of 100 million Americans' records โ encryption โ $22 million ransom paid (350 BTC)
The aftermath: UnitedHealth Group (parent company) reported $2.87 billion in total costs through Q3 2024. Over 100 million Americans received breach notification letters โ the largest healthcare breach in U.S. history. Pharmacies, hospitals, and clinics couldn't process prescriptions for weeks. Patients died because their medical records were inaccessible.
The twist: After receiving the $22M payment, ALPHV/BlackCat pulled an exit scam โ they kept the money without providing the decryption key to their own affiliate. The affiliate then re-extorted Change Healthcare using the stolen data. Change Healthcare may have paid twice.
โ Could Change Healthcare Have Been Prevented by Honeypot Intelligence?
The initial access was a credential stuffing attack against Citrix. Our honeypot captures exactly this kind of activity. Could upstream intelligence have prevented the worst healthcare breach in history?
Almost certainly yes. The ALPHV affiliate who accessed Change Healthcare used credentials that were likely purchased from an IAB who acquired them through automated credential scanning โ the exact pipeline our honeypot documents. If the credential patterns and source IPs had been shared with Change Healthcare's security team, they could have: (1) preemptively blocked the source IPs, (2) identified that their Citrix portal lacked MFA, (3) monitored for the specific credential patterns being tested. The information existed. The sharing didn't happen. $2.87 billion in damage from a problem that costs $0 to prevent โ if the right intelligence reaches the right people.
Sources: HHS HIPAA Breach Portal; UnitedHealth Q3 2024 SEC filing; ALPHV affiliate dispute details from vx-underground
โ What If the ALPHV Exit Scam Was Planned Before the Attack?
ALPHV collected $22M from Change Healthcare, then "shut down" claiming FBI seizure โ but the seizure banner was fake. The affiliate was left unpaid. Was this planned?
The timeline is suspicious: ALPHV was already under FBI pressure (seizure of their leak site in December 2023), and they knew their days were numbered. The Change Healthcare attack may have been their retirement heist โ the largest single payment they could extract before disappearing. The exit scam wasn't an accident. It was a retirement plan. The $22 million (350 BTC at the time) was moved through mixing services and likely converted through sanctioned-jurisdiction exchanges. ALPHV's operators retired wealthy while their affiliate was left holding stolen data worth nothing without the brand name to back the extortion. The ransomware brand was always the product โ and Change Healthcare was its final sale.
Sources: FBI ALPHV seizure (Dec 2023); Blockchain analysis of 350 BTC transaction; ALPHV affiliate complaints on RAMP forum
Case 2: Colonial Pipeline (May 2021)
The chain: Compromised VPN password (no MFA, found in dark web dump) โ DarkSide ransomware affiliate โ Colonial Pipeline billing systems encrypted โ 5,500 miles of pipeline shut down โ gas shortages across southeastern U.S. โ $4.4 million ransom paid โ FBI recovered $2.3 million (63 BTC) via warrant
The aftermath: The U.S. government declared a state of emergency. Gas prices spiked. Airlines re-routed flights. The attack demonstrated that critical infrastructure depends on IT systems that can be reached by a single compromised password.
The credential: A single VPN password, likely obtained through credential stuffing or a previous breach dump. No multi-factor authentication. One password shut down nearly half the East Coast's fuel supply.
โ How Similar Is the Colonial Pipeline Attack to What Our Honeypot Sees Daily?
Colonial Pipeline was compromised through a VPN credential found in a dark web dump. Our honeypot sees tens of thousands of credential attempts per month. Is there a direct connection?
The connection is methodological, not necessarily operational. The credential that compromised Colonial Pipeline was likely harvested through the same type of scanning our honeypot captures โ automated credential testing against internet-facing services. The difference: Colonial's VPN credential succeeded against a production system instead of a honeypot. Our data shows that the campaigns testing credentials against our honeypot are testing them against thousands of other targets simultaneously. Among those targets are hospitals, pipeline operators, water treatment facilities, and power grids. Every scan we capture is a scan that also hit critical infrastructure.
Sources: DOJ Colonial Pipeline report; DarkSide affiliate TTP analysis; Honeypot credential overlap with known breach databases
Case 3: Genesis Market (Takedown: April 2023)
The platform: Automated marketplace selling access "bots" โ packages containing browser fingerprints, cookies, saved passwords, and session tokens. Over 80 million credential packages from 2 million+ victims. Prices: $0.70 to $300 per bot.
The takedown: Operation Cookie Monster, coordinated across 17 countries, 119 arrests, FBI seized the domain. The largest single law enforcement action against an access marketplace.
The aftermath: Within months, competitors filled the gap. Russian Market expanded. New automated shops appeared. The 80 million stolen credentials remained in circulation. The supply chain didn't stop โ it redistributed.
โ If Genesis Market Sold 80 Million Bots, How Many Were Harvested by the Same Type of Scanning We Observe?
Genesis Market's inventory came from infostealers deployed through phishing and through โ post-compromise payloads dropped after SSH/RDP brute force. What percentage came from the SSH scanning pipeline?
Exact figures aren't public, but analysis of Genesis Market's inventory by cybersecurity researchers estimated that 15-25% of bots came from server-side compromises (SSH/RDP/VPN) rather than client-side infostealers (phishing/malvertising). That's 12-20 million bots harvested through the exact methodology our honeypot captures. Each of those bots represents a server that was scanned, brute-forced, and had credential-harvesting malware deployed โ the same playbook we watch daily. Our honeypot data isn't just academic. It represents one node in a pipeline that produced 12-20 million compromised servers sold on a single marketplace.
Sources: FBI Operation Cookie Monster advisory; Genesis Market inventory analysis (Trellix); Server-side vs client-side compromise ratio estimates
๐ Read Between the Lines
Three case studies. Three different targets. Three different ransomware brands. But the same supply chain: credential scanning โ access brokering โ monetization. Change Healthcare ($2.87B damage), Colonial Pipeline (national emergency), Genesis Market (80M credentials). These aren't outliers. They're the normal output of the system we've mapped. Our honeypot captured 5,438 sessions from 1,313 IPs in 30 days. Across the internet, similar honeypots and โ more importantly โ real servers face this same volume. The supply chain operates at industrial scale. These case studies aren't the worst outcomes. They're the documented outcomes. For every Change Healthcare that makes headlines, there are hundreds of smaller organizations that pay quietly and never report.
Chapter 8: The Uncomfortable Infrastructure โ Cloud Providers as Attack Platforms
The distribution of attack infrastructure across our dataset reveals something the cloud industry doesn't want discussed:
| Provider | Attack IPs | Type | Avg Threat Score | Abuse Response |
|---|---|---|---|---|
| DigitalOcean | 171 | Legitimate cloud | 60+ | Slow (days) |
| Tencent Cloud | 150 | Legitimate cloud (China) | 70+ | Minimal for int'l reports |
| UCloud | 113 | Chinese cloud provider | 65+ | Non-responsive |
| Microsoft Azure | 108 | Legitimate cloud | 55+ | Moderate (hours-days) |
| Korea Telecom | 100 | National ISP | 60+ | Slow |
| OVH | 86 | Legitimate hosting | 65+ | Moderate |
| Google Cloud | 79 | Legitimate cloud | 60+ | Good (hours) |
Together, legitimate cloud providers host more attack infrastructure than all bulletproof hosting providers combined. DigitalOcean alone hosts more attack IPs (171) than many countries produce.
โ Why Do Cloud Providers Tolerate This?
171 IPs on DigitalOcean. 108 on Microsoft Azure. 79 on Google Cloud. These companies have multi-billion-dollar security teams. Why do they host more attack infrastructure than bulletproof hosters?
Because the attackers are paying customers. Each of those 171 DigitalOcean droplets costs $4-24/month. That's $684-$4,104/month in revenue from attack infrastructure alone โ from our dataset. Across the entire internet, the number is orders of magnitude larger. Cloud providers have a financial incentive to minimize abuse enforcement: every shut-down instance is lost revenue, and the attacker simply respawns on the same platform or a competitor. The abuse teams exist to manage liability, not prevention. Their goal is to demonstrate they act on reports, not to prevent abuse from occurring. This is why response times are measured in days rather than minutes: fast enforcement costs revenue; slow enforcement is plausibly diligent.
Sources: DigitalOcean pricing; Attack IP distribution from honeypot data; Cloud provider abuse response time analysis
โ What If Cloud Providers Profit More from Cybercrime Than They Lose?
A thought experiment: what if the revenue from abuse infrastructure exceeds the cost of abuse enforcement?
Consider the math. Our honeypot sees 171 DigitalOcean IPs involved in scanning campaigns. Extrapolate across the internet: DigitalOcean has ~700,000 customers. If even 1% are involved in scanning/abuse (7,000 accounts), that's 7,000 ร $10/month average = $840,000/year in abuse-related revenue. DigitalOcean's abuse team probably costs $2-5M/year. But if they enforced too aggressively, they'd lose the $840K AND see the abusers migrate to competitors (where they generate competitor revenue). The Nash equilibrium is exactly what we observe: slow enforcement, reactive not proactive, and an implicit tolerance for churn-and-respawn patterns. The industry has collectively optimized for minimum viable enforcement โ enough to satisfy regulators, not enough to actually stop abuse.
Sources: DigitalOcean annual report (customer count); Industry abuse enforcement analysis; Game theory applied to cloud provider incentives
โ What If the Chinese Cloud Providers Aren't Just "Non-Responsive" โ What If They're State-Aligned?
Tencent Cloud (150 IPs) and UCloud (113 IPs) together account for 263 attack IPs โ more than DigitalOcean. Both are subject to Chinese National Security Law. Is their non-responsiveness negligence or policy?
China's National Security Law (2015) and Cybersecurity Law (2017) require all Chinese companies to "support, assist, and cooperate" with national intelligence work. This applies to Tencent and UCloud. When international abuse reports go unanswered, there are two interpretations: (1) the companies are genuinely overwhelmed and under-resourced, or (2) the scanning operations are not considered abuse by the authorities who oversee these companies. Intelligence agencies worldwide use SSH scanning for reconnaissance. If Chinese intelligence services use Tencent Cloud and UCloud as scanning infrastructure, those companies have no legal authority to shut it down โ and every legal obligation to stay quiet about it. The "non-responsive" abuse desk may be the most honest response they can give.
Sources: China National Security Law (2015), Article 7; China Cybersecurity Law (2017), Article 28; Tencent Cloud terms of service; UCloud governance structure
โ Are Cloud Providers Legally Liable for the Ransomware Attacks Launched from Their Infrastructure?
If DigitalOcean hosts the scanning infrastructure that discovers the credential that gets sold to the IAB that gets sold to the ransomware affiliate that encrypts a hospital โ is DigitalOcean liable?
Under current law, no. Section 230 of the Communications Decency Act (U.S.) provides broad immunity for platform providers. EU's Digital Services Act imposes obligations around transparency and "systemic risk" but hasn't been applied to infrastructure-layer providers. The legal framework treats cloud providers as neutral utilities โ like phone companies that aren't liable for crimes planned over their networks. But the analogy breaks down: phone companies don't know who's making criminal calls. Cloud providers know exactly which instances are scanning the internet โ the network traffic patterns are unmistakable. They choose not to act on that knowledge. Whether the law changes to address this gap depends on whether a future lawsuit successfully argues that a cloud provider's knowledge of ongoing abuse creates a duty to prevent it. Post-Change Healthcare, that argument is getting more compelling.
Sources: 47 U.S.C. ยง 230; EU Digital Services Act (2024); Cloud provider ToS abuse clauses; Legal precedent for platform liability
๐ Read Between the Lines
The industry's dirty secret: bulletproof hosting is a distraction. The real infrastructure enabling cybercrime isn't hidden in Seychelles shell companies or Moldovan data centers. It's running on the same AWS, GCP, Azure, and DigitalOcean accounts that host legitimate businesses. The attackers don't need bulletproof hosting โ they need disposable hosting. Cloud providers offer exactly that: instant provisioning, pay-by-the-hour pricing, and abuse enforcement that moves slower than attack campaigns operate. The supply chain doesn't depend on a few bad-actor providers. It depends on the entire cloud industry's tolerance for abuse.
Chapter 9: The Takedown Treadmill โ Why Law Enforcement Can't Win
The past three years have seen the most aggressive law enforcement campaign against cybercrime infrastructure in history. The results are instructive:
| Operation | Date | Target | Result | Long-term Impact |
|---|---|---|---|---|
| Cookie Monster | Apr 2023 | Genesis Market | 119 arrests, domain seized | Russian Market expanded to fill gap |
| Duck Hunt | Aug 2023 | Qakbot botnet | 700,000 victims freed | Qakbot rebuilt within months |
| ALPHV Seizure | Dec 2023 | ALPHV/BlackCat leak site | Site seized temporarily | ALPHV resumed within hours, attacked Change Healthcare months later |
| Cronos | Feb 2024 | LockBit infrastructure | 34 servers seized, 2 arrested | LockBit resumed operations within weeks |
| Endgame | May 2024 | IcedID/SystemBC/Pikabot/Smokeloader/Bumblebee | 100+ servers seized, 4 arrested | Replacement loaders emerged within months |
| BreachForums (2nd) | Jun 2024 | BreachForums | Domain seized (again) | Forum rebirthed under new admin within weeks |
Pattern: Every takedown is followed by reconstitution. The infrastructure changes addresses but the capability persists.
โ Why Do Takedowns Fail to Stop Cybercrime?
Six major operations in 18 months. Hundreds of arrests. Thousands of servers seized. And our honeypot shows attack volume increasing over the same period. Why?
Because law enforcement targets infrastructure and individuals, not the economic incentives. Seizing a forum doesn't eliminate demand for stolen credentials. Arresting a developer doesn't invalidate the codebase. Taking down a botnet doesn't change the fact that millions of servers are still running default SSH passwords. Each takedown removes a node from the network while leaving the structural conditions that created it completely intact. It's like arresting drug dealers without addressing addiction: the market creates new suppliers faster than law enforcement can arrest them. The cybercrime supply chain is not a conspiracy โ it's an economic system. And you don't defeat an economic system with arrests.
Sources: Operation timelines from FBI/Europol press releases; Honeypot attack volume trends; Economic analysis of takedown impact
โ What If Some Takedowns Are Designed to Fail?
The ALPHV seizure in December 2023 was unusual: the FBI seized the .onion domain but ALPHV resumed operations within hours using a backup. Three months later, ALPHV attacked Change Healthcare for $22M. Was the "seizure" real?
The ALPHV seizure is one of the most contested law enforcement actions in cybersecurity. Multiple theories: (1) The FBI legitimately seized the site but lacked the operational capability to seize ALPHV's entire infrastructure, leaving backup systems intact. (2) The seizure was a controlled disruption โ the FBI wanted to degrade ALPHV's reputation without fully dismantling it, hoping affiliates would defect to other groups that were more infiltrated. (3) The seizure was performative โ a demonstration of capability intended for political audiences rather than operational impact. Whatever the truth, the outcome speaks loudest: ALPHV continued operating, attacked Change Healthcare, collected $22M, and then voluntarily "shut down" via exit scam. The FBI's seizure neither prevented the attack nor recovered the money. It's worth asking: if you were running ALPHV, would the FBI's action have concerned you?
Sources: FBI ALPHV seizure warrant; ALPHV resumption timeline; Change Healthcare attack chronology; Krebs on Security analysis
โ What If Law Enforcement Agencies Use These Groups as Intelligence Sources Before Shutting Them Down?
LockBit operated for 4+ years with over 2,000 attacks before Operation Cronos. ALPHV operated for 2+ years before its "seizure." Why such long timelines before action?
Intelligence agencies have a fundamental tension with law enforcement: shutting down a criminal operation means losing access to its intelligence value. A running ransomware group reveals: which countries' infrastructure is being targeted, which APT groups are moonlighting as affiliates, which cryptocurrency exchanges are laundering proceeds, which companies are paying ransoms secretly. This intelligence has national security value that may exceed the damage prevention value of early shutdown. The documented pattern โ years of operation followed by dramatic takedown โ is consistent with agencies harvesting intelligence before prosecution. The takedown happens when the intelligence value is exhausted, when political pressure makes inaction untenable, or when the group becomes too dangerous to tolerate. LockBit's 2,000+ attacks happened while agencies were watching. The question isn't whether they could have acted sooner. The question is what they learned during those 2,000 attacks that they valued more than prevention.
Sources: FBI LockBit advisory timeline; Operation Cronos details; Intelligence community oversight reports; Historical precedent (Silk Road infiltration timeline)
โ What If Some Ransomware Groups Are Protected by State Intelligence Services?
Russian-origin groups like LockBit, ALPHV, and Conti have never been prosecuted by Russian authorities despite U.S. indictments. Why not?
Russia's relationship with cybercriminal groups is well-documented but officially denied. The model appears to be informal mutual benefit: groups agree not to target Russian/CIS systems (all major ransomware includes Russian-language keyboard checks), and in exchange, Russian law enforcement provides implicit sanctuary. When the U.S. pressured Russia on cybercrime in 2021-2022, Russia arrested 14 REvil members in a dramatic raid โ then quietly released most of them after media attention faded. The arrests were diplomatic theater, not prosecution. The value proposition for Russia is clear: these groups generate billions in damage to Western economies and infrastructure, extract information from Western companies, and operate at no cost to the Russian state. Why would Russia shut down its most effective asymmetric warfare capability?
Sources: REvil arrests (Jan 2022) and subsequent releases; Ransomware Russian-keyboard checks (documented by Krebs, BleepingComputer); U.S.-Russia cybersecurity dialogue timeline; Conti leaks showing FSB connections
Chapter 10: The Systemic Truth โ Everyone Profits, No One Prevents
We started this investigation by watching SSH scanning campaigns hit our honeypot. We end it by confronting the systemic reality: the supply chain exists because every party in the ecosystem has an incentive to let it exist.
| Actor | Incentive to Prevent | Incentive to Tolerate | Net Behavior |
|---|---|---|---|
| Cloud Providers | Liability risk (low) | Revenue from abuse accounts | Minimum viable enforcement |
| ISPs | Abuse complaints | Customer retention | React only to complaints |
| Governments | Critical infrastructure risk | Intelligence value of running operations | Delayed takedowns |
| Cyber Insurance | Reduce payouts | Higher premiums, larger market | Cover the losses, increase premiums |
| Security Vendors | Solve the problem | Bigger problem = bigger market | Detect and respond (never prevent) |
| Target Organizations | Avoid breach | Security investment competes with profit | Under-invest until breached |
| Ransomware Groups | None | Billions in revenue | Maximize extraction |
โ Is the Cybersecurity Industry Incentivized to Solve Cybercrime โ Or Manage It?
The global cybersecurity market is worth $200+ billion annually. If cybercrime were eliminated, that market would collapse. Who benefits from the status quo?
The cybersecurity industry is the immune system that profits from the disease. CrowdStrike's revenue grew from $874M (2021) to $3.06B (2024). Palo Alto Networks: $4.3B to $6.9B. The entire industry's growth depends on threat volume increasing. No security company has a financial incentive to reduce threats to zero โ that would be a going-out-of-business strategy. Instead, the industry optimizes for detection and response โ catching attacks after they begin, not preventing them from being possible. The architectural changes that would actually prevent SSH scanning at scale (mandatory key-based auth, network-level anomaly detection, automated abuse response) would cost a fraction of what organizations spend on security products. But those changes would also eliminate the market for the products. The industry has found its equilibrium: enough security to make the problem manageable, not enough to make it solved.
Sources: CrowdStrike 10-K filings (2021-2024); Palo Alto Networks annual reports; Gartner Global Security Spending Forecast 2024
โ What If Cyber Insurance Is Making the Problem Worse?
Cyber insurance premiums hit $7.2 billion in 2023. Insurance companies pay ransoms on behalf of victims. Does insurance fuel the supply chain?
Yes, demonstrably. When an organization has cyber insurance that covers ransom payments, the calculus changes: paying $2M in ransom costs the organization nothing out of pocket (the insurer pays), while rebuilding systems without paying might cost $10M in downtime and recovery. The rational economic decision is to pay โ and ransomware operators know this. Groups like LockBit and ALPHV specifically target organizations with known cyber insurance policies, because insured targets are more likely to pay and more likely to pay quickly. Insurance companies have attempted to address this by requiring minimum security standards for coverage, but enforcement is lax and organizations routinely misrepresent their security posture on applications. The net effect: cyber insurance has created a reliable payment pipeline for ransomware operators, turning an unpredictable criminal enterprise into a subscription business.
Sources: Insurance Information Institute โ 2024 Cyber Insurance Report; AXA decision to stop covering ransom payments in France (2022); Lloyd's of London systemic risk exclusions
โ What Would Actually Stop This?
We've documented the supply chain from scan to ransomware. We've shown that every actor tolerates it. What would break the cycle?
Three things that would break the supply chain โ none of which are being seriously pursued:
1. Mandatory abuse response SLAs for cloud providers. If DigitalOcean had 4 hours to disable a reported scanning instance (instead of 4 days), the Go_SSH campaign's 320-IP infrastructure would be unsustainable. Legislation requiring this exists nowhere.
2. Ban ransom payments. If paying ransoms were illegal (as it is for terrorist ransoms in some jurisdictions), the economic incentive collapses. No payment = no revenue = no business model. The UK and Australia have discussed this; neither has implemented it.
3. Universal SSH key authentication. If password-based SSH authentication were disabled by default in all major operating systems, the entire credential-scanning supply chain would be destroyed. This is a one-line configuration change that would prevent billions of dollars in damage annually. No vendor has made it the default because it would increase support tickets from users who lose their keys.
Each of these solutions is technically trivial and politically impossible. The supply chain persists not because we can't stop it, but because stopping it would cost influential parties money.
Sources: NIST SSH hardening guidelines; UK Ransomware Payment Ban proposal (2024); Australia Ransomware Action Plan; SSH authentication best practices (CISA)
โ What If the Real Product of Cybercrime Isn't Money โ It's Control?
$1.1 billion in ransomware payments (2023, Chainalysis). But ransomware is also the perfect tool for political leverage. What if some attacks aren't about money?
Consider: NotPetya (2017) was disguised as ransomware but was actually a Russian military intelligence operation (GRU) targeting Ukraine that spread globally, causing $10B in damage. The payment mechanism was deliberately broken โ it was never intended to generate revenue. It was a weapon wearing ransomware clothing. Now consider: in our honeypot data, we observe campaigns with 92.7% success rates (87.251.64.176, ISAEV/Poland) that aren't testing random credentials โ they're replaying known-valid ones. These campaigns aren't scanning for money. They're scanning for access maintenance. Someone wants persistent access to specific targets. That's not criminal activity โ that's intelligence collection. The supply chain we've documented has two product lines: one produces money (ransomware), the other produces access for unnamed clients (APT/intelligence). Both use the same scanning infrastructure. Both appear identical in honeypot logs. One is crime. The other is espionage. And distinguishing between them requires asking who benefits from the access, not just who scans for it.
Sources: NotPetya attribution (U.S./UK/Australia joint attribution to GRU, 2018); Chainalysis 2024 Crypto Crime Report โ $1.1B ransomware payments; Honeypot credential replay analysis (87.251.64.176)
๐ The Final Read Between the Lines
We started with a honeypot. A single SSH service running on a single IP, watching what comes in. In 30 days, 1,313 IPs from 98 countries tried to log in. Five coordinated campaigns. 2,077 shared malware links. A botnet heartbeat protocol. Cloud providers hosting attack infrastructure they know about. Ransomware payments funding the next scanning campaign. Insurance companies paying the ransoms. Security vendors selling the detection. Governments watching for intelligence.
Everyone is in on it.
Not as a conspiracy โ nobody sat in a room and designed this. As a system โ a set of interlocking economic incentives that produce the same outcome a conspiracy would, without requiring coordination. The cloud providers don't need to agree with the ransomware groups. The insurance companies don't need to agree with the IABs. Each actor follows their own rational self-interest, and the system emerges.
The SSH scanner runs. The credential gets sold. The access gets brokered. The hospital gets encrypted. The ransom gets paid. The insurance premium goes up. The security vendor's stock goes up. And tomorrow, the scanner runs again.
The supply chain is complete.
Crosslinks โ This Investigation Connects To
- 026A: The Phantom ASN Ecosystem โ Introduction โ The overarching investigation this supply chain analysis belongs to
- 026B: The DigitalOcean Paradox โ Deep dive into the cloud provider hosting the most attack infrastructure (171 IPs)
- 026C: Tencent's Shadow โ Chinese cloud providers and the state-aligned question explored in Chapter 8
- 026D: UCloud's Silence โ The non-responsive abuse desk and what it means
- 026E: The Korea Telecom Anomaly โ National ISP infrastructure weaponized for scanning
- 026F: OVH โ The Hosting Harbor โ European hosting provider's role in the supply chain
- 026G: Google Cloud's Blindspot โ When the biggest tech company hosts attack payloads
- 026H: The Azure Irony โ Microsoft defending against attacks launched from Microsoft infrastructure
- 026I: Campaign Convergence โ How five campaigns share infrastructure and payloads
- 026J: The Abuse Report Graveyard โ Why reporting abuse doesn't stop abuse
- 026K: The Predecessor Network โ Historical infrastructure patterns feeding the current campaigns
- 026M: The 1,313 Machines โ Detailed analysis of every machine in the scanner fleet
- 026N: The Temporal Architecture โ When and why campaigns activate and deactivate
- 026O: Who Profits โ Following the money from scan to payout
Methodology
This investigation was conducted using:
- Primary data source: Cowrie SSH honeypot โ 30-day dataset capturing 5,438 sessions from 1,313 unique IPs across 98 countries, recording credentials, commands, downloads, SSH fingerprints, and client versions.
- Intelligence database: PostgreSQL threat_intel database containing 8,000+ enriched IP profiles with data from AbuseIPDB, Shodan, GreyNoise, RDAP, OTX, VirusTotal, Censys, Pulsedive, DShield, and IPInfo. 271,000+ entity links across 17 relationship types.
- Active reconnaissance: Tor-routed nmap/httpx/nuclei scans of attacker infrastructure revealing their own exposed services and vulnerabilities.
- Campaign detection: Multi-signal clustering using HASSH fingerprints, shared credentials, shared malware, temporal correlation, and service fingerprints.
- Open-source intelligence: Court documents, SEC filings, FBI advisories, Europol press releases, vendor research reports, cryptocurrency blockchain analysis.
- Economic analysis: IAB forum pricing data, ransomware payment databases (Chainalysis), insurance industry reports, cloud provider financial disclosures.
Limitations: Our honeypot represents a single vantage point. The campaigns we observe are simultaneously scanning millions of other targets. Our data captures the methodology, not the complete scale. Financial figures for illicit markets are estimates based on the best available research; actual volumes may be significantly higher. Attribution is presented with calibrated confidence levels โ where we don't know, we say we don't know.