๐ป The Ghost Network
In March 2026, a JavaScript backdoor hit inboxes across Eastern Europe. Targets: the Ministry of Finance of Transnistria, a Ukrainian FMCG holding, a Russian oil-refining enterprise, and automotive groups in Poland and Germany. The C2 infrastructure was hosted on OMEGATECH (AS202412) and spam delivery on GHOSTYNETWORKS (AS205759).
Both networks trace to a single individual: Daniel Mishayev, an Israeli national operating from a residential address in Hauzenberg, Bavaria โ population 11,000.
This could be where the story ends. Another bulletproof hosting operator. Another cybercrime facilitator. But when you trace the pattern โ Israeli national, geographic registration arbitrage, shell companies in multiple jurisdictions, proxy infrastructure that makes attribution impossible โ you find yourself looking at the same institutional pattern that produced NSO Group, Bright Data, Kape Technologies, and a dozen other Israeli-founded companies that control critical internet infrastructure from behind layers of corporate obfuscation.
This letter documents what we can prove. The conspiracy questions ask what the pattern implies.
I. Daniel Mishayev โ The Operator
| Nationality | Israeli (RIPE country code: IL) |
| Location | Hauzenberg, Bavaria, Germany (pop. 11,000) |
| Company | Pfcloud UG (HRB 12249, District Court Passau) |
| Commercial Brand | whitelabel.sh โ "Turnkey ASN provisioning" |
| RIPE Organization | ORG-DM262-RIPE (created 2024-02-17) |
| Direct ASNs | AS51396 (Pfcloud), AS215460 (FELCLOUD, registered directly to "Daniel Mishayev, IL") |
| Enabled ASNs | AS202412 (OMEGATECH), AS205759 (GHOSTYNETWORKS), AS197170 (TechTies), KPROHOST, VPSDEDICATED, STEALTHVM, STORMING |
| Spamhaus | 7+ ASNs on DROP/EDROP list |
| Our Honeypot | 37 IPs, 930 events across 5 ASNs |
| Intrinsec Data | 642,001 attacks from OMEGATECH IPs in March 2026 alone |
II. The 7-to-51 Anomaly: Israel's Invisible Footprint
Our PostgreSQL intelligence database contains 7,994 unique IPs. When we filter by country = 'IL', we get 7 IPs with 0 honeypot hits. All are consumer mobile ISPs (Partner Communications, Pelephone, Cellcom). Zero attacks. Zero reconnaissance. Zero interaction with our honeypot.
But when we trace Israeli nationals and Israeli-founded entities โ regardless of where their infrastructure is geolocated โ we find 51 IPs with 961 hits.
| Method | IPs Found | Honeypot Hits | What's Visible |
|---|---|---|---|
| country = 'IL' (standard geolocation) | 7 | 0 | Consumer mobile only |
| Israeli nationals + Israeli-founded entities | 51 | 961 | Bulletproof hosting, C2, proxies |
| GAP (invisible under standard analysis) | 44 | 961 | 100% of malicious activity |
The gap: 44 IPs and 961 hits completely invisible under standard geolocation analysis. Every single Israeli-linked malicious IP is registered in the Netherlands, Germany, Turkey, Luxembourg, or the United States โ never in Israel itself. This is not a coincidence. This is geographic registration arbitrage as a systematic operational security practice.
Israel is the only country in our 7,994-IP dataset where 100% of associated malicious activity is invisible under standard geographic attribution. This suggests either an institutional practice of offshore registration, or that the small population of Israeli cyber operators happens to universally prefer non-Israeli hosting โ which amounts to the same thing operationally.
III. The Pattern: Unit 8200 โ Private Sector โ Infrastructure Control
Israel's Unit 8200 (IDF Military Intelligence, SIGINT division, 5,000+ personnel) has a documented institutional pipeline into the private sector:
| Unit 8200 Alumni | Company Founded | What It Does | Scale |
|---|---|---|---|
| Gil Shwed, Shlomo Kramer | Check Point Software | Network security / firewall | $20B+ market cap |
| Niv Carmi, others | Palo Alto Networks | Enterprise security | $100B+ market cap |
| Shalev Hulio, Omri Lavie | NSO Group | Pegasus spyware | Deployed in 45+ countries |
| Various | Cellebrite | Phone extraction/forensics | Used by 100+ law enforcement agencies |
| Various | Candiru | Spyware (DevilsTongue) | Sold to government clients |
| Koby Menachemi | Kape Technologies | VPN empire (ExpressVPN, PIA, CyberGhost) | Taken private $1.6B (2023) |
| Derry Shribman | Bright Data (Luminati) | Residential proxy network | 150M+ IPs, $500M+/yr revenue |
This pipeline is not alleged. It is documented by the European Parliament (PEGA Committee, January 2023), litigated by Apple (Apple v. NSO Group, 2021), and reported by investigative journalists (DropSite News, Forbidden Stories). The pipeline converts military SIGINT capability into private-sector products that control internet infrastructure.
IV. The Infrastructure Spectrum
Israeli-connected entities now span the complete spectrum of internet infrastructure โ from the "security" end to the "criminal" end. The same country produces both the surveillance tools AND the infrastructure they target:
| Layer | Entity | What It Controls | Israeli Connection |
|---|---|---|---|
| Surveillance | NSO Group (Pegasus) | Zero-click phone exploitation | Founded by Unit 8200 alumni |
| Surveillance | Cellebrite / Candiru | Device extraction / spyware | Unit 8200 alumni |
| VPN/Privacy | Kape Technologies | ExpressVPN, PIA, CyberGhost, ZenMate | Founded by Koby Menachemi (Unit 8200) |
| VPN/Privacy | Kape + vpnMentor/Wizcase | VPN review sites that recommend Kape VPNs | Kape owns both products AND reviews |
| Proxy/Data | Bright Data (Luminati) | 150M+ residential proxy IPs | Tel Aviv HQ, Israeli-founded |
| Proxy/Data | Bright Data SDK in Smart TVs | 250M+ TV households as proxy nodes | June 2026: Samsung/LG/Roku apps |
| Cloud/Hosting | Kamatera Inc. | 5 ASNs, 8+ entity names | Israeli-founded, 315 Madison Ave (virtual office) |
| Cloud/Hosting | Pfcloud UG / Mishayev | 7+ Spamhaus-listed ASNs | Israeli national (ORG-DM262-RIPE, country=IL) |
| Bulletproof | OMEGATECH / GHOSTYNETWORKS | 67 C2 servers, JS backdoor campaign | Enabled by Mishayev's Pfcloud UG |
The same national ecosystem produces NSO Group's Pegasus (sold to governments for surveillance) AND Daniel Mishayev's GHOSTYNETWORKS (used by criminals to attack governments). The same ecosystem produces Kape Technologies (controls what VPN you trust) AND Bright Data (controls 150 million residential proxy IPs including your smart TV).
V. Bright Data โ The Legal Version of What Mishayev Does Illegally
Bright Data Ltd (formerly Luminati Networks, successor to Hola VPN) operates 72-150 million IP addresses as residential proxy exit nodes. In June 2026, Include Security discovered Bright Data's SDK embedded in Samsung, LG, and Roku smart TV applications โ turning 250 million TV households into proxy exit nodes.
SDK configuration: ignore_screen_on=true, ignore_on_call=true, 200GB/month bandwidth per device. The SDK bypasses user VPNs via NWParameters.requiresDNSResolution. TLS certificates reveal the legacy domain: *.luminatinet.com.
Qurium Foundation documented Bright Data enabling DDoS attacks against Philippine human rights organization Karapatan.
Bright Data does it "legally" โ through SDK agreements buried in app terms of service that nobody reads. Revenue: $500M+/year. They are an Israeli company with offices in Netanya.
Mishayev's operation does it illegally โ through malware (Socks5 Systemz, Remcos, AsyncRAT) that turns compromised computers into proxy exit nodes. He is an Israeli national operating from Bavaria.
The technical architecture is identical. The business model is identical. The national origin is identical. The only difference is whether the victim "consented" through an unread EULA or was compromised through malware. In both cases, 200GB/month of someone else's bandwidth is being sold to anonymous buyers.
Confidence: HIGH โ Include Security research is peer-reviewed. Bright Data's Israeli origin is public. Mishayev's Israeli nationality is in RIPE records.
VI. The Kamatera Parallel โ Same Pattern, Same Origin
Kamatera Inc. โ another Israeli-founded cloud provider โ operates the same geographic registration arbitrage as Mishayev:
- 5 different ASNs (AS36007, AS396948, AS396949, AS41436, AS204548)
- 8+ entity names (Kamatera Inc, CloudWebManage-SC, CloudWebManage, CloudWebManage-EU, CloudWebManage-IL-FR, Global Cloud Infrastructure LLC, Cloud Web Manage, IRT-KAMATERAINC-AP)
- 315 Madison Avenue NYC as ARIN registration address โ a virtual office
- Domain
omc.co.il(OMC Group, Israeli) resolves on their Spain/Netherlands IPs - Israeli-founded but presents as US/EU cloud provider
Kamatera isn't bulletproof hosting โ it's legitimate cloud infrastructure. But the identity obfuscation pattern is identical to Mishayev's: multiple entity names, virtual offices, geographic registration in non-Israeli jurisdictions, Israeli origin invisible unless you trace corporate records. This is not one person's technique. This is an institutional practice.
VII. GHOSTYNETWORKS โ The AnonRDP Rebrand
GHOSTYNETWORKS (AS205759) โ the latest incarnation in a chain of shell ASNs:
- AnonRDP โ original brand ("Everything Allowed! 100% Bulletproof"), advertised on elitepvpers/BlackHatWorld
- OPTIBOUNCE โ predecessor ASN, Kentucky-registered, now defunct
- GHOSTYNETWORKS โ current incarnation (Jan 2026), 4/6 prefixes Spamhaus-flagged
Daniel Mishayev's name appears across multiple Kentucky-registered companies. Intrinsec established the chain with high confidence via BGP history and corporate records.
TeamPCP โ a sophisticated threat actor known for PUREHVNC RAT and malicious PyPI packages โ chose GHOSTYNETWORKS for their infrastructure. When advanced operators with custom tooling choose your hosting, it validates the abuse-tolerance guarantee.
VIII. The Campaign: JS Backdoor Against Energy and Finance
March-April 2026. The targets reveal the financial motivation โ and the geopolitical indifference:
The JS backdoor: obfuscated JavaScript in ZIP/RAR attachments, communicating on ports 2002/2004/7273 with outdated IE user-agent strings. C2 at scan.aryamint[.]com (158.94.211.76 โ OMEGATECH). Spam via mail.talruit[.]com (83.142.209.64 โ GHOSTYNETWORKS).
However: BEC campaigns are the most common cover for intelligence collection. You compromise a finance ministry "for BEC" but the access grants visibility into state finances, procurement, personnel. An oil refinery's email gives you production data, supply contracts, sanctions-circumvention evidence. A Ukrainian holding's email reveals supply chain vulnerabilities.
We cannot prove state involvement. We CAN prove: (1) the operator is Israeli, (2) the infrastructure enables both criminal and intelligence activity, (3) the targets span both sides of the Russia-Ukraine conflict, (4) Israel is the only country in our dataset with 0% direct attribution for 100% offshore operations.
Confidence: MEDIUM โ The pattern is documented but the state nexus is circumstantial. What IS proven is that Mishayev's infrastructure hosts the campaign.
IX. The Submarine Cable Question
One more data point that contextualizes Israeli infrastructure control:
Google's Blue-Raman cable system (operational 2025) routes Europe-to-Asia traffic through Israel: Blue segment (Italy โ Israel, 16 fiber pairs) connects to Raman segment (Israel โ Jordan โ India, 16 fiber pairs). Israel is the physical land bridge between Mediterranean and Indian Ocean fiber.
Unit 8200 reportedly maintains covert listening posts in Israeli embassies abroad and taps undersea cables (Wikipedia, sourced to multiple intelligence journalists). UK/US spy agencies use cable landing points for Middle East surveillance (Middle East Eye).
When an Israeli-operated proxy network routes your traffic, and Israeli-operated submarine cables carry your data, and Israeli-built surveillance tools monitor your device โ the question isn't whether Israel has capability. The question is where the "legitimate" infrastructure ends and the "criminal" infrastructure begins.
X. The Complete Mishayev Ecosystem โ Honeypot Evidence
| ASN | Entity | IPs | Hits | Threat (max) | Spamhaus |
|---|---|---|---|---|---|
| 202412 | OMEGATECH LTD (Seychelles) | 7 | 789 | 100 | ASN-DROP |
| 197170 | TechTies Inc. (Seychelles) | 17 | 128 | 62 | ASN-DROP |
| 205759 | GHOSTYNETWORKS (Kentucky) | 2 | 12 | 56 | 4/6 prefixes |
| 51396 | Pfcloud UG (Germany) | 8 | 1 | โ | Transit only |
| 44382 | WhiteLabel Networks (Kentucky) | 3 | 0 | โ | โ |
| TOTAL | 37 | 930 | โ | โ | |
HASSH fingerprint analysis confirms cross-ASN coordination:
- a7a87fbe86774c2e: Links OMEGATECH (94.154.35.215, 178.16.54.226) to Private Layer Switzerland โ the same proxy factory documented in 038C
- 2ec37a7cc8daf20b: 12-node cluster linking OMEGATECH (TR/DE/NL) to TechTies (NL) and external IPs (DigitalOcean, Scaleway, FranTech)
- 16443846184eafde: Links GHOSTYNETWORKS (46.151.182.2) to Private Layer (179.43.186.241)
GHOSTYNETWORKS IP 46.151.182.2 shares commands with 15+ IPs across Linode, DigitalOcean, GCP, and shared credentials with 7+ IPs. This means either the same botnet operators are testing from GHOSTYNETWORKS AND major cloud providers, or GHOSTYNETWORKS provides proxy/bounce infrastructure for operators who also use legitimate clouds.
XI. The Kape + Bright Data Convergence
Kape Technologies (Israeli, Unit 8200-linked):
- Owns ExpressVPN ($936M acquisition), CyberGhost, PIA, ZenMate โ controls what VPN you trust
- Owns vpnMentor and Wizcase โ controls the reviews that recommend those VPNs
- Formerly "Crossrider" โ an adware company (rebranded 2018)
- Founded by Teddy Sagi (convicted of fraud, 1996) and Koby Menachemi (Unit 8200)
- Taken private for $1.6 billion in 2023 โ now invisible to public scrutiny
Bright Data (Israeli, Tel Aviv HQ):
- Formerly Luminati Networks, successor to Hola VPN (which sold users as exit nodes without consent)
- 150 million+ residential proxy IPs
- SDK in Samsung/LG/Roku smart TVs โ 250M+ households as exit nodes
- Documented enabling DDoS against Philippine human rights organization (Qurium)
- Revenue: $500M+/year selling proxy access
Together: one Israeli company controls what VPN you use (and can see your traffic entering), another Israeli company controls 150M residential exit nodes (and can see traffic exiting), and a third Israeli company (NSO) can compromise your device regardless. The complete traffic lifecycle โ ingress, egress, and endpoint โ is observable by Israeli-connected entities.
XII. The Question We Cannot Answer (Yet)
1. Israeli national operating infrastructure used by criminal actors
2. Geographic registration arbitrage making Israeli origin invisible
3. The same arbitrage pattern used by documented Unit 8200-linked entities
4. Zero Israeli IPs in 7,994-IP honeypot dataset (100% offshore operation)
5. Infrastructure targeting BOTH sides of the Russia-Ukraine conflict
6. Covent Garden, London virtual office (shared by Virtualine, Aeza, Stark Industries)
7. The broader context: Israel produces both the surveillance tools (NSO, Cellebrite, Candiru) AND the infrastructure that evades surveillance (bulletproof hosting, proxy networks)
Mishayev may be a purely criminal entrepreneur with no state connection. Many Israeli nationals work in cybercrime with no intelligence links. But the institutional context cannot be ignored: when a nation's military intelligence unit has a documented pipeline into private-sector cyber companies, and a national of that country operates one of the largest bulletproof hosting franchises in the world using the same operational patterns as documented intelligence-linked entities โ the question must be asked even if it cannot yet be answered.
Confidence in Mishayev operating the infrastructure: HIGH (RIPE records, corporate filings, Intrinsec report).
Confidence in intelligence service connection: LOW/SPECULATIVE (pattern-based, no direct evidence).
We state both clearly because intellectual honesty requires it.
"Seven IPs. Zero hits. That's Israel in our honeypot database. The most sophisticated cyber-intelligence apparatus on Earth generates precisely zero direct signals. But trace the nationals โ the shell companies in Kentucky, the Seychelles IBCs, the Bavarian addresses, the Turkish LIRs โ and you find 51 IPs, 930 events, 7 Spamhaus-listed ASNs, 67 C2 servers, 16 malware families, and a JS backdoor campaign targeting the finance ministry of an unrecognized state. The ghost leaves no footprints in its own country. Only everywhere else."
XIV. The Documented Library: What Our OSINT Index Contains
Our Elasticsearch OSINT library โ 136,617 documents, 7.6 million semantic chunks โ contains the primary sources that document the infrastructure of control. These are not conspiracy theories. They are:
- "The Palestine Laboratory" (Antony Loewenstein) โ How Israel tests surveillance on Palestinians then exports the technology worldwide
- "The Walls Have Eyes" (Petra Molnar) โ Elbit Systems: $5.28 billion revenue, 18,000 employees, "espionage diplomacy" testing technology in conflict zones
- "Science of Coercion" (Christopher Simpson) โ CIA's $1 billion annual psychological warfare budget (1950s), communication research weaponized for population control
- "Manufacturing Consent" (Noam Chomsky) โ The propaganda model: corporate ownership, advertising, sourcing, flak, and anti-communism as media filters
- RAND "Hostile Social Manipulation" (2019) โ State actors exploiting social media for influence operations, psychological operations forces, fragmentation of trust
- NSA/FRA Intelligence Paper (2013, Snowden) โ NSA's relationship with Swedish SIGINT (FRA) established 1954 under UKUSA/Five Eyes
- "The Secret History of the Five Eyes" โ The UKUSA Agreement: Britain + America dividing global signals intelligence
- "No Place to Hide" / "Permanent Record" (Snowden) โ PRISM, upstream collection, the architecture of mass surveillance
- Apple v. NSO Group Complaint (2021) โ Legal documentation of Pegasus spyware sold to 45+ countries
- European Parliament PEGA Committee Report (2023) โ "The Impact of Pegasus on Fundamental Rights and Democratic Processes"
- "Autocracy, Inc." (Anne Applebaum) โ How dictators share infrastructure, techniques, and technology across borders
- LLM Generated Text Detection (2023) โ AI-powered influence operations creating "a more favorable operating environment for propagandists"
"Israel may be known as 'the Harvard of counterterrorism,' but it is also the center of much of the world's surveillance technology that is normalized and tested out on Palestinians. One of the leading players in border surveillance and spyware, for example, is the Israeli company Elbit Systems. Headquartered in Haifa and started in 1966, Elbit Systems expanded from weapons logistics to become a surveillance powerhouse of nearly eighteen thousand employees worldwide with a revenue of $5.28 billion."
"No comprehensive budget of U.S. psychological warfare activities is known to exist. CIA psychological warfare consultant James Burnham, however, put the overall figure at over $1 billion annually during its heyday in the early 1950s."
The science of coercion didn't end in the 1950s. It migrated. From broadcast propaganda to social media manipulation. From radio jamming to proxy network control. From CIA-funded academic research to Unit 8200 alumni startups. The tools changed. The objective โ control of the information environment โ did not.
XV. The Architecture of Control โ From Cables to Proxies
The internet was built for military communication (ARPANET, 1969). It was released for civilian use as an instrument of commerce and โ crucially โ as an instrument of surveillance. Every layer of the internet serves dual purposes:
| Layer | Civilian Purpose | Control Purpose | Who Controls It |
|---|---|---|---|
| Physical (cables) | Carry data between continents | Tapping points for SIGINT collection | Five Eyes + Israel (Blue-Raman cable) |
| Network (routing) | Direct packets efficiently | Traffic analysis, BGP manipulation | Transit providers (aurologic, etc.) |
| DNS | Translate names to IPs | Censorship, surveillance, redirection | ICANN + national registries |
| VPN/Privacy | Protect user traffic | Honeypot: see who wants to hide | Kape Technologies (Unit 8200) |
| Proxy/CDN | Cache and accelerate content | Man-in-the-middle, traffic inspection | Bright Data (150M+ nodes) |
| Endpoint | User devices | Zero-click exploitation | NSO Group (Pegasus), Cellebrite |
| Bulletproof hosting | Host any content | Plausible deniability for operations | Pfcloud/Mishayev (Israeli national) |
From submarine cable to endpoint exploitation, Israeli-connected entities maintain presence at every single layer. This is not hyperbole โ it is documented by the European Parliament, litigated in US courts, exposed by Snowden's NSA documents, and confirmed by our own honeypot data.
The internet enables this publication. It enables you to read forensic evidence about criminal infrastructure operators. It enables whistleblowers to transmit documents. It enables encrypted communication.
The same internet enables Pegasus to compromise journalists' phones. Enables Bright Data to turn your TV into a proxy exit node. Enables Kape Technologies to own both the VPN you trust AND the review site that recommended it. Enables GHOSTYNETWORKS to deliver JS backdoors to finance ministries.
The relevant question is not "freedom or control" โ it's who has the capability to observe, redirect, and manipulate traffic at each layer, and whether that capability is subject to democratic oversight. The answer, as documented in every source above: the capability exists, it is concentrated in a small number of national ecosystems (primarily Five Eyes + Israel), and democratic oversight ranges from minimal (US/UK) to nonexistent (Israel).
Our honeypot proves one thing conclusively: the same infrastructure that enables surveillance also enables crime. Daniel Mishayev's GHOSTYNETWORKS hosts JS backdoors. It could equally host intelligence collection infrastructure. The network doesn't distinguish between the two. Neither, it seems, does the operator.
XVI. The Freedom Argument
We publish this because the internet was supposed to be free. Not free as in cost โ free as in speech. Free as in the ability to know what is being done to you, by whom, using what infrastructure.
Our honeypot costs $0 in cloud services. Our OSINT library runs on a refurbished workstation. Our threat intelligence pipeline uses open-source tools. We document criminal infrastructure using the same internet that criminal infrastructure uses to attack us.
That is the asymmetry they didn't account for. The same tools that enable mass surveillance enable mass transparency. The same cables that carry Pegasus exploits carry this article. The same routing infrastructure that hides Mishayev's shells also delivers our forensic analysis to anyone who searches for it.
When Intrinsec honeypots record 642,001 hits and publish the evidence freely, that is freedom. When we name Daniel Mishayev, trace his shells across five jurisdictions, and connect his infrastructure to sanctioned entities โ that is freedom. When we document the pattern from Unit 8200 to NSO to Pfcloud to GHOSTYNETWORKS โ that is what the internet was supposed to enable.
"The internet is a tool man created. The reason behind it is control. But every tool can be turned against its maker. They built the surveillance infrastructure. We built the honeypot. They host 67 C2 servers. We document all 67. They hide behind Kentucky shells and Seychelles IBCs. We publish their RIPE handles and phone numbers. They control the cables. We control the narrative. That is the only asymmetry that matters."
XVII. Indicators of Compromise
| Type | Indicator | Description |
|---|---|---|
| ASN | 205759 | GHOSTYNETWORKS (AnonRDP rebrand) |
| ASN | 202412 | OMEGATECH-AS (Virtualine front) |
| ASN | 197170 | TechTies (Tor + proxy) |
| ASN | 51396 | Pfcloud UG (Mishayev transit hub) |
| IPv4 | 83.142.209[.]64 | Spam sender (GHOSTYNETWORKS) |
| IPv4 | 91.92.243[.]79 | Spam + JS backdoor C2 (OMEGATECH) |
| IPv4 | 158.94.211[.]76 | JS backdoor C2 (OMEGATECH) |
| IPv4 | 46.151.182[.]2 | GHOSTYNETWORKS (in our honeypot) |
| IPv4 | 94.154.35[.]215 | OMEGATECH (threat=100, in our honeypot) |
| Domain | mail.talruit[.]com | Spam sender domain |
| Domain | scan.aryamint[.]com | JS backdoor C2 domain |
| Domain | mpwirerope[.]com | Spam sender domain |
| Domain | ethara[.]org | Threat actor infrastructure |
| Domain | whitelabel[.]sh | Mishayev's ASN provisioning service |
| SHA-256 | 794fab796e48f97e976d99157913ab5beee5ae8ef2731bf2af2222ae5b6a1c65 | QUOTE_B0426.js |
| SHA-256 | ac842e4adb445a76aad135828d56116858a1b7d37b4a103f493e175816df9bb2 | PO 03603.zip |
| SHA-256 | 33713a3650a3c1d64045c3832835dcacef92ad4f09c030fbe674454266880fea | PO 26683.js |
| SHA-256 | 7277f4dfb26a53f8ee47cac051a82f6709e07b6603f26ff3987cc64a137e07dc | PO8767.rar |
| SHA-256 | 232a179daf4db527c062b609ebb5f19310eea8f5c80afce6f763f5841110aed8 | PO8767.js |
| RIPE | ORG-DM262-RIPE | Daniel Mishayev organization |
| Company | HRB 12249 (Passau) | Pfcloud UG registration |
TI-2026-039A ยท The Ghost Network ยท Letter A
Published by LSN Threat Intelligence ยท June 23, 2026
Sources: Intrinsec CTI Report (May 2026), GBHackers, Spamhaus, RIPE NCC, Cowrie honeypot, threat_intel PostgreSQL, dossier_intel Elasticsearch (TI-2026-034B), Recorded Future, Include Security, Qurium Foundation, DropSite News, European Parliament PEGA Committee, Apple v. NSO Group (2021), "The Palestine Laboratory" (Loewenstein)
Cross-referenced: TI-2026-034B, TI-2026-038A-F, TI-019I, TI-010