Executive Summary
Across four dossiers (036A-036D), we have mapped the Romanian Corridor from its corporate foundations to its operational reality. Now we connect it to the global infrastructure documented in the Kill Chain Economy series (035A-035L). The result: Romania is not an isolated phenomenon. It is a node in a global mesh where the same campaigns, the same fingerprints, and the same business models appear across continents.
The libssh2_1.11.0 campaign alone โ 628 IPs, 48 countries โ threads through OVH (France), SingleHop (US), Psychz (US), ColoCrossing (US), MULTACOM (US), M247 (Romania), NexonHost (Romania), PIO-Hosting (Germany), and ReliableSite (US). These providers appeared independently in the Kill Chain Economy series. They are not independent. They are the same infrastructure viewed through different corporate registrations in different jurisdictions.
๐ธ๏ธ Key Finding: The Campaign Web
Seven HASSH scanning campaigns have Romanian participation. Together, they represent 2,648 unique IPs across 84+ countries โ a coordinated global scanning apparatus that uses Romanian infrastructure as one of its transit layers:
| Campaign | Total IPs | Countries | RO IPs | RO ASNs | Strategy |
|---|---|---|---|---|---|
| libssh_0.11.x | 1,313 | 84 | 2 | X-ZONE IT, ZMC | Scanner |
| libssh2_1.11.0 | 628 | 48 | 35 | M247, NexonHost, DIGI, InternetBroker | Scanner |
| libssh_0.12.0 | 607 | 71 | 0 | โ | Scanner |
| Paramiko | 63 | 27 | 1 | M247 | Pentest |
| libssh_0.10.x | 34 | 16 | 0 | โ | Scanner |
| libssh2_1.11.1 | 31 | 9 | 1 | Feo Prest | Scanner |
| libssh_0.7.4 | 12 | 8 | 0 | โ | Unknown |
Romania's heaviest participation is in the libssh2_1.11.0 campaign: 35 IPs from 4 Romanian ASNs. M247 contributes 20, NexonHost contributes 13. These two SRLs alone account for 5.3% of a 628-node global botnet. They are the campaign's 7th and 11th largest infrastructure providers โ ranked alongside OVH, SingleHop, and Psychz. Not rogue actors. Infrastructure suppliers on the same tier as the largest hosting companies in the world.
๐ Exhibit A: The Kill Chain Economy Convergence
Cross-referencing the Romanian Corridor with the Kill Chain Economy series reveals that every major provider documented in TI-2026-035 also appears in Romanian-connected campaigns:
| Provider | 035 Series Finding | Romanian Connection | Shared Campaign |
|---|---|---|---|
| OVH (AS16276) | 035B: largest hoster by abuse volume | 45 IPs in libssh2 campaign | hassh-14b2ddda386a4d10 |
| SingleHop (AS32475) | 035B: 40 IPs, avg threat 70.5 | 39 IPs alongside M247+NexonHost | hassh-14b2ddda386a4d10 |
| Psychz (AS40676) | 035B: 36 IPs, 33 at abuse=100 | 34 IPs in same scanning fleet | hassh-14b2ddda386a4d10 |
| ColoCrossing (AS36352) | 035B: 74 IPs, 46 at abuse=100 | 33 IPs coordinating with RO nodes | hassh-14b2ddda386a4d10 |
| MULTACOM (AS35916) | 035B: mass scanning infrastructure | 26 IPs in same campaign | hassh-14b2ddda386a4d10 |
| FranTech (AS53667) | 035B: BuyVM, abuse-tolerant | 13 IPs alongside M247 | hassh-14b2ddda386a4d10 |
| PIO-Hosting (AS198584) | 035G: German-Dutch corridor | 15 IPs in same campaign | hassh-14b2ddda386a4d10 |
| DigitalOcean (AS14061) | 035B: cloud provider abuse | 11 IPs in scanner fleet | hassh-14b2ddda386a4d10 |
This is the convergence we predicted in TI-2026-035K. The same campaigns use the same providers across the same jurisdictions. The Romanian Corridor is not a local phenomenon โ it is one on-ramp to a global highway. The highway was built by the American hosting industry (035 series), paved by the European transit layer (M247, OVH, Hetzner), and connected at every junction by the same SSH fingerprints.
๐ Exhibit B: The Registrant Web
The libssh2_1.11.0 campaign's top 10 RDAP registrants reveal an interlocking web of companies that appears across both series:
| Rank | Registrant | IPs | Phone | |
|---|---|---|---|---|
| 1 | Internap Holding LLC (SingleHop) | 27 | abuse@horizoniq.com | +1-877-843-7627 |
| 2 | Psychz Networks | 28 | noc@psychz.net | +1-626-549-2801 |
| 3 | Servers Factory LLC (M247) | 17 | iphostmaster@serversfactory.com | +1(302)327-4003 |
| 4 | MULTACOM Corporation | 12 | abuse@multacom.com | +1-661-554-0287 |
| 5 | tzulo, inc. | 9 | noc@tzulo.com | +1-847-847-2048 |
| 6 | SingleHop BV (Netherlands) | 9 | abuse@horizoniq.com | +1-877-843-7627 |
| 7 | RIPE-NCC-END-MNT (s-host.com.ua) | 9 | abuse@s-host.com.ua | +35795718296 |
| 8 | TENNET-MNT (NexonHost) | 8 | ab@vpz.ro | +40723.996.387 |
| 9 | Brander Group Inc. | 8 | report@abuseradar.com | +1 702 560 5616 |
| 10 | Psychz Networks (second block) | 8 | noc@psychz.net | +1-626-549-2801 |
Servers Factory (M247's US arm) and NexonHost sit at positions 3 and 8 in this global ranking. Between them, they contribute 25 IPs to a single campaign. The other registrants โ Psychz, SingleHop, MULTACOM, tzulo โ are the same companies documented in the Kill Chain Economy. The Romanian Corridor connects to the American abuse-tolerant hosting tier through shared campaigns and shared infrastructure.
๐ Exhibit C: The SSH Key Bridges
SSH key sharing provides the hardest evidence of operational connections between jurisdictions. From the Romanian Corridor investigation:
| Romanian IP | Shares Key With | Other ASN | Other Country | Implication |
|---|---|---|---|---|
| 185.255.100.198 (M247/ServersFact.) | 198.46.134.148 | โ | US | Same operator or provisioning system |
| 185.255.100.198 (M247/ServersFact.) | 45.142.3.73 | โ | โ | Cross-ASN deployment from single authority |
| M247 internal pair 1 | M247 internal pair 1 | AS9009 | Multi | Internal key reuse across subsidiaries |
| M247 internal pair 2 | M247 internal pair 2 | AS9009 | Multi | Template deployment pattern |
SSH key sharing across ASN boundaries means one of two things: either the same person deployed both machines from the same private key, or the same provisioning template was used. Both indicate common control that transcends the corporate separation between entities.
๐ Exhibit D: The AbuseRadar Nexus
One abuse intermediary connects multiple Romanian entities:
| Entity | Uses AbuseRadar | Context |
|---|---|---|
| Aokigahara SRL (AS215659) | report@abuseradar.com | RDAP registrant |
| NexonHost (via IPXO Latin America) | report@abuseradar.com | IP lease registrant |
| Brander Group Inc. (US) | report@abuseradar.com | Campaign registrant #9 |
AbuseRadar acts as a complaint proxy โ abuse reports go to AbuseRadar instead of the actual operator. This adds a layer of indirection between the complainer and the infrastructure. The same service used by both a Romanian anime-themed SRL and a US-registered company in the same global campaign. The intermediary layer connects what the corporate layer separates.
๐ Exhibit E: The Corridor Map โ Complete
The Romanian Corridor, fully mapped across 5 dossiers:
| Layer | Romanian Component | Global Connection | Dossier |
|---|---|---|---|
| Transit | M247 (AS9009) โ 5,000 prefixes, 60 IXPs | Peers with every major IX globally | 036B |
| Bulletproof | NexonHost (AS62390) โ risk 93.3 | IPXO marketplace, 628-node campaign | 036C |
| C2 | ROMARG (AS205275) โ risk 96.0, botnet | libssh_0.9.6 botnet classified | 036D |
| Burned | Bunea TELECOM โ 3ร ASN-DROP | Pattern: use โ burn โ replace | 036C |
| Fresh | Feo Prest (AS208137) โ ASN-DROP in 3 months | Latest cycle of the pipeline | 036C |
| Ideology | FlokiNET Romania โ 2.5ร threat vs Iceland | Freedom hosting meets regulatory arbitrage | 036D |
| Anonymity | Aokigahara (AS215659) โ "Private Customer" | AbuseRadar intermediary network | 036E |
| Tor | OVO/Virtono/Hosteroid exits via M247 | False relay diversity from single ASN | 036B |
| Scanning | 35 RO IPs in libssh2_1.11.0 campaign | 628 IPs, 48 countries, 16,253 attempts | 036A |
| Attack | Servers Factory LLC โ 20 IPs, all abuse=100 | Delaware LLC, US-registered, RO-operated | 036B |
โ The Final Questions
A network implies coordination. An ecosystem implies emergent behavior from shared incentives. The evidence supports ecosystem: M247 doesn't coordinate with NexonHost. They share the same HASSH fingerprints because they both service customers who use the same scanning tools. Bunea TELECOM doesn't coordinate with Feo Prest. They follow the same SRL playbook because the incentive structure is identical.
The ecosystem is self-organizing: cheap SRLs, accessible RIPE membership, available transit (M247), minimal enforcement, and foreign victims. No conspiracy required. Just structural incentives producing structural outcomes.
The corridor has no single point of closure. Removing M247 would disrupt transit but not SRL formation. Tightening SRL rules would slow formation but not stop IPXO leasing. Blocking RIPE allocations would shift registrations to other jurisdictions. Each intervention addresses one layer while the others compensate.
The only structural intervention would be making infrastructure provision for known-malicious operations a criminal offense โ which would require a new legal category that doesn't exist in any EU jurisdiction. And it would catch legitimate providers too.
The Romanian Corridor is a feature, not a bug. The internet was designed to route around failure โ and enforcement is, from the protocol's perspective, just another kind of failure. BGP doesn't distinguish between legitimate and malicious prefixes. RIPE doesn't distinguish between legitimate and malicious LIRs. The protocol layer is value-neutral by design.
Every corridor we close creates pressure that opens another. The Kill Chain Economy documented American providers. The Romanian Corridor documented European transit. Tomorrow's series will document Asian infrastructure, African IP space, or Pacific Island registrations. The corridor is wherever the enforcement gradient is steepest โ wherever it's cheapest to operate and hardest to prosecute.
โ๏ธ Series Assessment: The Romanian Corridor
Confidence: HIGH across all findings. Evidence sourced from honeypot telemetry (75+ Romanian IPs), HASSH campaign analysis (7 campaigns, 2,648+ IPs), RDAP registration forensics (8 ASNs), Spamhaus ASN-DROP (4 listings), PeeringDB infrastructure data, SSH key forensics, AbuseIPDB correlation, and OSINT library documents.
Key numbers across 5 dossiers:
- 8 Romanian ASNs investigated
- 47 M247 IPs + 13 NexonHost IPs + 24 FlokiNET IPs + 11 Aokigahara IPs + 2 ROMARG IPs + 2 Feo Prest IPs = 99+ IPs analyzed
- 4 Spamhaus ASN-DROP listings (Bunea TELECOM ร3, Feo Prest ร1)
- 1 transit empire (M247): 5,000 prefixes, 60 IXPs, 5-10 Tbps
- 1 global scanning campaign traced from Romania to 48 countries
- 10 national subsidiaries in M247 that all geolocate to Bucharest
- 3 generations of Romanian cyber evolution mapped
The Romanian Corridor is not a criminal conspiracy. It is an economic structure that emerges wherever corporate formation is cheap, internet exchange is dense, and enforcement mandates have gaps. Romania occupies this position today. The same structural analysis applies to any jurisdiction where these three conditions converge.
The corridor doesn't end at Romania's borders. It runs through Delaware (Servers Factory LLC), through Lithuania (IPXO), through Iceland (FlokiNET), through the Seychelles (OVO Systems), through Austria (EDIS). The corridor is not a place. The corridor is a business model.
๐ Complete Series Index
- TI-2026-036A "The Romanian Corridor" โ Overview: 75 IPs, 8 ASNs, the landscape
- TI-2026-036B "The M247 Empire" โ AS9009: 5,000 prefixes, Servers Factory, subsidiary web
- TI-2026-036C "The SRL Factory" โ โฌ0.20 to ASN: RIPE pipeline, Bunea TELECOM triple-DROP
- TI-2026-036D "Hackerville to Hosting" โ Three generations: Guccifer โ fraud โ infrastructure
- TI-2026-036E "The Connections" โ Global mesh: cross-campaign, cross-series convergence
Kill Chain Economy Cross-References:
- TI-2026-035B-035G โ Provider-by-provider analysis of American abuse-tolerant tier
- TI-2026-035E "The Geography of Impunity" โ Jurisdictional arbitrage model
- TI-2026-035K "The Convergence" โ Global convergence of cybercrime/surveillance/state