TI-2026-032: The American Mirror A ยท B ยท C ยท D ยท E ยท F ยท G ยท H

032C โ€” The Internap Inheritance

Two Bankruptcies, One Ransomware Cover-Up, and the Most Dangerous US ASN in Our Database

Executive Summary

SingleHop/Internap Holding LLC (AS32475) carries the highest average threat score of any US provider in our entire database: 70.5. For context, ColoCrossing scored 47.5 (032A) and the combined Psychz+MULTACOM scored 58.3 (032B). Internap is in a class by itself.

The corporate history explains the infrastructure neglect: Internap acquired SingleHop for $132 million in 2018, filed Chapter 11 bankruptcy in March 2020, emerged in May 2020, suffered a ransomware attack in September 2022, deleted the incident report from its own transparency page, then filed Chapter 11 again in April 2023. It emerged from its second bankruptcy in August 2023 and rebranded to HorizonIQ in January 2024.

A company that has spent more time in bankruptcy court than out of it does not invest in abuse monitoring. Its 40 tracked IPs โ€” every single one at abuse_score=100, every high-threat one in the same botnet โ€” are the residue of institutional collapse.

I. The Corporate Autopsy

$132MSingleHop Acquisition (2018)
2ร—Chapter 11 Filings
Sept 2022Ransomware Attack
HorizonIQJan 2024 Rebrand

The timeline tells the entire story:

DateEventSignificance
1996Internap founded in SeattlePioneer in intelligent routing
1999IPO on NASDAQPublicly traded infrastructure company
2000Acquired CO Space ($271M)Entry into data center services
Feb 2018Acquired SingleHop ($132M cash)Added IaaS/cloud capabilities
Mar 16, 2020Chapter 11 bankruptcy #1Failed to find buyer/strategic partner
May 11, 2020Emerged from bankruptcyShed debt, new CEO
Jun 2020โ€“2022Sold Houston, Canada, Japan, network assetsSystematic asset stripping
Sep 28, 2022Ransomware attackData loss across multitenant hosting. INAP deleted incident report.
Apr 28, 2023Chapter 11 bankruptcy #2Lenders take control
Aug 1, 2023Emerged from bankruptcy #2Company restructured under creditor control
Jan 24, 2024Rebranded to HorizonIQName change to distance from history

Between February 2018 (SingleHop acquisition) and January 2024 (HorizonIQ rebrand), Internap went through: one $132M acquisition, two Chapter 11 bankruptcies, one ransomware attack with data loss, one cover-up attempt, the sale of assets in Houston, Canada, Japan, and nine additional colocation sites, and a complete rebrand. At no point in this six-year corporate death spiral was "abuse monitoring" a strategic priority.

II. The Ransomware Cover-Up

The Deleted Report

On September 28, 2022, Internap's "ServerIntellect" product suffered a ransomware attack that affected multitenant website, database, and email hosting services, causing data loss. INAP published an incident report on its "Operational Transparency" page.

On October 5, 2022 โ€” seven days later โ€” INAP removed the incident report.

TechRadar reported that the removal appeared to be an attempt to conceal the full effects of the attack. INAP subsequently discontinued its multitenant hosting services entirely.

A company that deletes its own security incident reports is not a company that processes abuse complaints with diligence.

III. The Infrastructure Numbers

40IPs Tracked
70.5Avg Threat Score
546Honeypot Hits
95Top Threat Score

The registrant split reveals the corporate archaeology โ€” two entities coexisting on the same ASN:

RDAP RegistrantIPsAvg ThreatHoneypot HitsNature
Internap Holding LLC2972.0474US parent (post-acquisition)
SingleHop BV1163.672Dutch entity (pre-acquisition)

SingleHop BV โ€” a Dutch company (Besloten Vennootschap) โ€” still holds 11 IP registrations on AS32475 despite Internap acquiring SingleHop in 2018. This means either the RDAP records were never updated after the acquisition (administrative neglect) or the Dutch entity still technically operates these allocations for regulatory/tax reasons.

The Internap-direct registrations carry higher threat (72.0 vs 63.6) โ€” the US parent's IPs are more dangerous than the Dutch subsidiary's. This is the inverse of what we might expect if the acquired company's infrastructure was the problem.

IV. The Perfect Botnet Score

Here is the most damning statistic in the entire TI-2026-032 series:

100% Campaign Membership

Every single IP at threat โ‰ฅ 60 on AS32475 belongs to the same botnet campaign: hassh-14b2ddda386a4d10.

Not most. Not the majority. Every single one. Twenty IPs. All libssh2_1.11.0. All the same HASSH fingerprint. All scanning our honeypot with identical SSH client signatures.

IPThreatHitsRegistrantSubnet
184.154.153.1319518Internap Holding LLC184.154.x.x
184.154.157.1769554Internap Holding LLC184.154.x.x
184.154.157.1849524Internap Holding LLC184.154.x.x
198.20.127.1589418SingleHop BV198.20.x.x
108.178.7.349124Internap Holding LLC108.178.x.x
107.6.164.2408812SingleHop BV107.6.x.x
173.236.16.748812Internap Holding LLC173.236.x.x
107.6.182.1098618SingleHop BV107.6.x.x
184.154.156.138624Internap Holding LLC184.154.x.x
65.60.61.2288424Internap Holding LLC65.60.x.x
173.236.82.2468412Internap Holding LLC173.236.x.x
96.127.172.2158418Internap Holding LLC96.127.x.x
96.127.172.2188418Internap Holding LLC96.127.x.x
69.175.33.1708330Internap Holding LLC69.175.x.x
184.154.78.388312Internap Holding LLC184.154.x.x
96.127.175.1548212Internap Holding LLC96.127.x.x
65.60.61.2318118Internap Holding LLC65.60.x.x
69.175.92.217842Internap Holding LLC69.175.x.x
198.20.127.163786SingleHop BV198.20.x.x
198.20.104.207746SingleHop BV198.20.x.x

Note the 184.154.x.x block: four IPs in this /16, three at threat=95 (the highest in the entire 032 series). This prefix โ€” 184.154.0.0/16 โ€” is a legacy Internap allocation and contains the most dangerous cluster we've documented on any US provider.

V. The PE Acquisition Playbook

Internap's trajectory follows a pattern familiar in US infrastructure: the private equity roll-up followed by financial extraction.

  1. Acquire aggressively โ€” SingleHop for $132M, CO Space for $271M, iWeb, VitalStream, Voxel
  2. Lever up โ€” take on debt to fund acquisitions
  3. Strip assets โ€” sell off pieces when debt service overwhelms revenue
  4. Bankruptcy โ€” restructure under Chapter 11, shed obligations
  5. Repeat โ€” emerge, strip more assets, bankrupt again
  6. Rebrand โ€” when the name is too toxic, change it

Each bankruptcy strips away operational capacity โ€” including abuse response teams, security monitoring staff, and compliance functions. What remains is infrastructure on autopilot: IP allocations that continue routing traffic, AS numbers that continue appearing in BGP tables, and servers that continue running whatever customers put on them.

After Internap's second bankruptcy in 2023, the company was restructured under creditor control. The creditors โ€” primarily banks and bondholders โ€” care about recovering their capital. They do not care about abuse reports on AS32475.

VI. The Running Total

Three letters into TI-2026-032, the aggregate picture:

ProviderLetterIPsAvg ThreatTop ThreatBotnet Nodes
ColoCrossing/HostPapa032A7447.59933
Psychz + MULTACOM032B6758.39160
SingleHop/Internap032C4070.59539
TOTAL (3 letters)โ€”18155.899132

132 botnet nodes across three US provider groups, all in the same hassh-14b2ddda386a4d10 campaign. That's 21% of the 628-IP global botnet operating from four American companies โ€” a company in bankruptcy, a company acquired by a Canadian domain registrar, and two LA-based hosting providers. The infrastructure that attacks the world does so from American soil, through American companies, protected by American incorporation law.

VII. The Conspiratorial Reading

Read Between the Lines

Why does a bankrupt company's infrastructure get MORE dangerous, not less?

Internap's avg threat of 70.5 is the highest of any US provider. You'd expect a company in financial distress to LOSE customers โ€” including malicious ones. Instead, the threat score is higher than Psychz (59.7), MULTACOM (57.0), and ColoCrossing (47.5). The botnet operator isn't leaving Internap โ€” they're concentrating there. A company that can't pay its bondholders certainly can't staff an abuse desk.

What happened to the abuse team during bankruptcy?

Chapter 11 allows companies to reject executory contracts and reduce headcount. Abuse monitoring staff are typically among the first cuts โ€” they're a cost center with no revenue. The result: a company that processes zero abuse reports for months at a time, during which botnet operators discover it's safe to deploy more nodes.

Who actually controls AS32475 now?

After the second bankruptcy, Internap Holding LLC emerged under creditor control and rebranded to HorizonIQ. The creditors are banks and bondholders. The AS number, the IP allocations, the peering arrangements โ€” these are financial assets on a balance sheet. The question of who ensures they're not being used for criminal purposes doesn't appear in a creditor committee's mandate.

The SingleHop BV anomaly

Why does a Dutch corporate entity still hold 11 IP registrations on a US ASN six years after being acquired? RDAP records should have been updated. Either nobody bothered (consistent with operational neglect), or the Dutch entity exists for a reason โ€” perhaps regulatory, perhaps tax-related, perhaps as an artifact of the 2018 acquisition deal structure that was never unwound because both subsequent bankruptcies had more pressing concerns.

The ransomware and the silence

A hosting company that deletes its own ransomware incident report isn't just covering up one attack โ€” it's signaling to the entire market that transparency is optional. If INAP deleted evidence of an attack on its own infrastructure, what are the odds it processes abuse reports about attacks from its infrastructure? The deletion and the 70.5 average threat score are symptoms of the same institutional pathology.

VIII. Conclusions

SingleHop/Internap/HorizonIQ is what happens when infrastructure becomes a financial instrument rather than a service. Two bankruptcies, a ransomware cover-up, and systematic asset stripping have produced the most dangerous US ASN in our database โ€” not because the company is malicious, but because it has ceased to function as a responsible network operator.

The botnet operator behind hassh-14b2ddda386a4d10 has deployed 39 nodes on AS32475 โ€” the third-highest concentration after OVH (45) and Psychz (34). The operator knows that a company cycling through bankruptcy proceedings won't investigate suspicious SSH scanning from its IP space. Institutional failure creates operational opportunity.

Next: the largest US presence in our database โ€” DigitalOcean, a NYSE-listed public company with 350 tracked IPs.

Methodology & Sources

Data sources: LSN Threat Intelligence Platform (8,000+ IPs), Cowrie SSH honeypot, ARIN RDAP, PeeringDB AS32475, AbuseIPDB, Wikipedia/Internap corporate history, SEC EDGAR filings, TechRadar ransomware coverage. Cross-referenced with TI-2026-032A/032B and hassh-14b2ddda386a4d10 campaign analysis.

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The American Mirror โ€” 3 / 8 Next โ†’