The Full Pipeline

Every day, our honeypot captures thousands of SSH login attempts. Most security teams dismiss these as noise โ€” failed brute-force attacks against hardened systems. But these scans are not noise. They are Step 1 of a pipeline that generates billions of dollars annually โ€” a pipeline documented end-to-end by five US and EU regulatory agencies, yet never shown as a single connected chain.

This investigation connects what we observe (industrial credential scanning) to what governments measure (FinCEN's $590M in ransomware SARs in six months, FBI IC3's $12.5B in total cybercrime losses) to what sanctions regimes target (Garantex, GRU Unit 74455, Aeza Group). Each stage is documented. The full chain has never been assembled in one place โ€” until now.

Core Thesis: The cybercrime economy is not a single gang. It is a supply chain of specialization โ€” credential harvesters feed Initial Access Brokers, who supply ransomware affiliates, who pay through cryptocurrency launderers, who route through sanctioned entities with state protection. Our honeypot captures the entry point.

Stage 1: The Scan โ€” What Our Honeypot Captures

๐Ÿ“Š Observed Campaigns (30-day window)

CampaignIPsCountriesAttemptsStrategy
libssh_0.11.x1,3138444,341Mass scanning botnet
libssh2_1.11.06284816,253Lease-laundered scanner
libssh_0.9.64215914,222Botnet (24 successes)
Go SSH (crypto/ssh)320437,115IAB credential harvester
Outlaw/mdrfckr80+17+3,200+Multi-stage attack chain

Source: [HONEYPOT] LSN Cowrie honeypot, 30-day observation window. Cross-ref: TI-2026-026O-GO, 019M, DOSSIER-018.

These are not random script kiddies. The Go SSH campaign (HASSH 16443846184eafde) shows zero post-authentication activity โ€” it harvests credentials and moves on. This is the behavioral signature of an Initial Access Broker feeder: collect access, sell access, never use access. Our prior investigation (TI-2026-026O-GO) estimates this single campaign generates $384Kโ€“$5.4M/year in credential sales.

The top-threat IPs paint the infrastructure picture:

  • 87.251.64.176 (ISAEV, KZ/PL) โ€” 4,304 hits, 3,922 successes, threat_score=100. Bulletproof hosting linked to darknet markets.
  • 94.154.35.215 (Omegatech, SC/NL) โ€” 560 hits, all successful. Seychelles-registered, 30+ open ports. Criminal hosting infrastructure.
  • 179.61.232.244 (WHG "Private Customer") โ€” RIPE-redacted registration, geo-discrepancy US/GB. Part of the IPXO lease-laundering chain documented in 019M.
  • 172.110.219.251 (YSZ Trading, HK/ES) โ€” Shell ASN, RIPE-NCC-HM-MNT. The "cartography of nowhere" architecture from 019M.

Stage 2: The Market โ€” Initial Access Brokers

๐Ÿ“‹ Documented Bridge: Access โ†’ Ransomware

CISA Advisory AA24-241A explicitly documents the pipeline: "Initial access brokers (IABs) sell access to compromised networks. Ransomware affiliates purchase this access to deploy ransomware. The IAB model has professionalized the initial compromise phase."

Source: [OSINT-LIB] CISA Advisories AA24-241A, AA24-109A, AA23-061A; CrowdStrike Global Threat Report 2024.

The credentials our honeypot captures are worth $50โ€“$500 each on IAB markets (KELA/Mandiant pricing data). The Go scanner's 333 successful logins in 30 days represent $16Kโ€“$166K in monthly inventory from a single campaign โ€” and we observe 5+ simultaneous campaigns.

CrowdStrike's 2024 report documents the commoditization: "Access advertisements increased 20% year-over-year. The average time from initial access to ransomware deployment decreased to under 24 hours." The supply chain has industrialized. Stage 1 feeds Stage 2 feeds Stage 3 at speed.

Stage 3: The Ransomware โ€” Deployment and Extortion

๐Ÿ’ฐ Scale of the Monetization Phase

  • FinCEN Financial Trend Analysis (Oct 2021): $590 million in ransomware-related SAR filings in H1 2021 alone โ€” exceeding the $416M total for all of 2020.
  • FBI IC3 Report 2023: 2,825 ransomware complaints; total cybercrime losses $12.5 billion.
  • FinCEN Advisory FIN-2021-A004: Mandates BSA/AML reporting for ransomware payments, documenting the financial system's awareness of the pipeline.

Source: [OSINT-LIB] FinCEN Financial Trend Analysis (FIN-2021-A004), FBI IC3 Internet Crime Report 2023.

The arithmetic is stark. Each $30 credential enables a $10Kโ€“$500K+ ransomware attack. The Go scanner's estimated $384Kโ€“$5.4M in annual credential sales enables $128Mโ€“$240M+ in downstream ransomware revenue. The leverage ratio is approximately 1:44 โ€” every dollar invested in scanning yields $44 in extortion.

MITRE ATT&CK documents the mechanical spine: T1078 (Valid Accounts) and T1021 (Remote Services) โ€” the exact techniques our honeypot captures โ€” are the #1 and #2 initial access vectors for ransomware deployment. Our observations are not tangential to ransomware. They are the ransomware supply chain's input.

Stage 4: The Laundering โ€” Cryptocurrency Infrastructure

๐Ÿฆ Follow the Money

  • Europol Crypto Tracing Report: Documents BTC-e (Alexander Vinnik), mixing services, privacy coins as primary laundering rails.
  • Treasury DeFi Risk Assessment (2023): "DeFi services present illicit finance risks, including from ransomware proceeds, stolen funds, and scams."
  • 019M Evidence: RDP.sh (bulletproof service) accepts BTC/ETH/XMR/USDT via Cryptomus โ€” the infrastructure itself operates in crypto only.

Source: [OSINT-LIB] Europol Crypto Tracing Report; US Treasury DeFi Illicit Finance Risk Assessment 2023. [XREF] Investigation 019M.

The laundering layer is now multi-rail:

  1. Direct exchange: Garantex/Grinex processed $100M+ linked to darknet/ransomware before OFAC designation.
  2. Mixers/tumblers: FinCEN documents increased mixer use in SARs ("designed to conceal or obfuscate the source or owner of CVC").
  3. Privacy coins: Monero (XMR) provides protocol-level untraceability โ€” used by both ransomware operators and hosting providers.
  4. DeFi bridges: Treasury identifies cross-chain bridges as a growing laundering vector.

From 019M: The IPXO lease-laundering chain (AbuseRadar โ†’ Internet Utilities LATAM โ†’ netutils-mnt โ†’ IPXO) demonstrates that IP addresses themselves are laundered through the same shell-company architecture used for financial laundering. Lease-laundered IP space is the network equivalent of money laundering.

Stage 5: The State Nexus โ€” Where Crime Meets Geopolitics

๐Ÿ›๏ธ The Circle Closes

  • GRU Sandworm Indictment (2020): 6 Russian GRU officers (Unit 74455) charged for NotPetya, Olympic Destroyer, French elections interference โ€” using the same TTPs (T1078, T1021) as the criminal scanners we observe.
  • 019M Finding: GCS LLP routes Iranian institutional IROST space under a GB LLP ASN โ€” sanctions evasion at the routing layer.
  • DOSSIER-018: Viettel military telecom (38 IPs) running attack infrastructure; Afghan government running Outlaw botnet.
  • OFAC Sanctions: Garantex/Grinex, Aeza Group (BianLian ransomware support), Proton66 โ€” all sanctioned, all connected to state actors.

Source: [OSINT-LIB] GRU Sandworm Indictment (WDPA 2020); ODNI Annual Threat Assessment 2024. [XREF] 019M, DOSSIER-018.

The pipeline comes full circle. State intelligence services (GRU Unit 74455) use the same credential-scanning techniques our honeypot captures. The ransomware payments flow through sanctioned exchanges (Garantex) that service both criminal and state actors. The infrastructure providers (Aeza Group, Proton66) are sanctioned for supporting both Russian disinformation and BianLian ransomware โ€” the same company, serving both masters.

From DOSSIER-018: Five of six compromised national telecoms we observe have no international cybercrime treaty obligation (outside the Budapest Convention). The state nexus is not merely tolerated โ€” it is structurally unaddressable under current international law.

The Structural Finding

๐Ÿ”— The Kill Chain Is an Economy, Not a Gang

The fundamental insight: this is not a vertically integrated criminal organization. It is a supply chain of specialization where each stage operates independently, connected by market mechanisms:

  1. Scanners harvest credentials (we observe this)
  2. Brokers aggregate and price access (CISA documents this)
  3. Affiliates deploy ransomware (FinCEN measures this)
  4. Launderers convert crypto to clean value (Europol/Treasury track this)
  5. States provide protection + shared infrastructure (OFAC sanctions this)

No single law enforcement action can disrupt the full chain because no single entity controls the full chain. Taking down Garantex didn't stop the laundering โ€” Grinex emerged within weeks. Arresting GRU officers doesn't stop the scanning โ€” the Go scanner operates independently. The specialization IS the resilience.

Cross-Investigation Map

StageThis InvestigationCross-Reference
1. Scanning5 campaigns, 2,700+ IPsTI-2026-026O-GO (Go scanner detail), 019M (libssh2 + WHG)
2. IAB MarketCISA advisories, pricing dataTI-2026-026O-GO ($384K-$5.4M estimate)
3. RansomwareFinCEN $590M, IC3 $12.5BDOSSIER-018 (Outlaw/mdrfckr chain)
4. LaunderingEuropol, Treasury DeFi019M (IPXO lease-laundering, Garantex)
5. State NexusGRU indictment, ODNI019M (GCS/Iran), DOSSIER-018 (Viettel/Afghan gov)

Methodology Note

This investigation uses three evidence tiers:

  • [HONEYPOT] โ€” Direct observation from our Cowrie SSH honeypot (first-party data)
  • [OSINT-LIB] โ€” Primary-source government documents from our OSINT library (FinCEN, FBI, CISA, Europol, Treasury, DOJ indictments)
  • [XREF] โ€” Cross-references to existing published investigations (019M, TI-2026-026O-GO, DOSSIER-018)

Every quantitative claim is sourced. Where sources disagree, the disagreement is noted. Implications are tagged [DOCUMENTED] (directly stated in sources) or [INFERRED] (logical extension of documented facts).

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous Kill Chain Economy โ€” 1 / 12 Next โ†’