The Ghost Network โ€” A New Investigation Series
Letter A: The Invisible Infrastructure Empire
An Israeli National, Kentucky Shells, and the Pattern That Connects NSO Group to Bulletproof Hosting

๐Ÿ‘ป The Ghost Network

In March 2026, a JavaScript backdoor hit inboxes across Eastern Europe. Targets: the Ministry of Finance of Transnistria, a Ukrainian FMCG holding, a Russian oil-refining enterprise, and automotive groups in Poland and Germany. The C2 infrastructure was hosted on OMEGATECH (AS202412) and spam delivery on GHOSTYNETWORKS (AS205759).

Both networks trace to a single individual: Daniel Mishayev, an Israeli national operating from a residential address in Hauzenberg, Bavaria โ€” population 11,000.

This could be where the story ends. Another bulletproof hosting operator. Another cybercrime facilitator. But when you trace the pattern โ€” Israeli national, geographic registration arbitrage, shell companies in multiple jurisdictions, proxy infrastructure that makes attribution impossible โ€” you find yourself looking at the same institutional pattern that produced NSO Group, Bright Data, Kape Technologies, and a dozen other Israeli-founded companies that control critical internet infrastructure from behind layers of corporate obfuscation.

This letter documents what we can prove. The conspiracy questions ask what the pattern implies.

7+
Spamhaus-Listed ASNs
37
IPs in Our Honeypot
642K
OMEGATECH Attacks (March)
150M+
Bright Data Proxy IPs
7 โ†’ 51
Israel IP Anomaly
0
Israeli IPs Attacking Us

I. Daniel Mishayev โ€” The Operator

Daniel Mishayev
ORG-DM262-RIPE ยท Country: IL (Israel) ยท LilienstraรŸe 5, 94051 Hauzenberg, Bavaria
NationalityIsraeli (RIPE country code: IL)
LocationHauzenberg, Bavaria, Germany (pop. 11,000)
CompanyPfcloud UG (HRB 12249, District Court Passau)
Commercial Brandwhitelabel.sh โ€” "Turnkey ASN provisioning"
RIPE OrganizationORG-DM262-RIPE (created 2024-02-17)
Direct ASNsAS51396 (Pfcloud), AS215460 (FELCLOUD, registered directly to "Daniel Mishayev, IL")
Enabled ASNsAS202412 (OMEGATECH), AS205759 (GHOSTYNETWORKS), AS197170 (TechTies), KPROHOST, VPSDEDICATED, STEALTHVM, STORMING
Spamhaus7+ ASNs on DROP/EDROP list
Our Honeypot37 IPs, 930 events across 5 ASNs
Intrinsec Data642,001 attacks from OMEGATECH IPs in March 2026 alone

II. The 7-to-51 Anomaly: Israel's Invisible Footprint

Our PostgreSQL intelligence database contains 7,994 unique IPs. When we filter by country = 'IL', we get 7 IPs with 0 honeypot hits. All are consumer mobile ISPs (Partner Communications, Pelephone, Cellcom). Zero attacks. Zero reconnaissance. Zero interaction with our honeypot.

But when we trace Israeli nationals and Israeli-founded entities โ€” regardless of where their infrastructure is geolocated โ€” we find 51 IPs with 961 hits.

MethodIPs FoundHoneypot HitsWhat's Visible
country = 'IL' (standard geolocation)70Consumer mobile only
Israeli nationals + Israeli-founded entities51961Bulletproof hosting, C2, proxies
GAP (invisible under standard analysis)44961100% of malicious activity

The gap: 44 IPs and 961 hits completely invisible under standard geolocation analysis. Every single Israeli-linked malicious IP is registered in the Netherlands, Germany, Turkey, Luxembourg, or the United States โ€” never in Israel itself. This is not a coincidence. This is geographic registration arbitrage as a systematic operational security practice.

Q: Is geographic registration arbitrage unique to Israeli operators?
A: No โ€” Russian operators do it too (Aeza: UK registration, Russian operators). Chinese operators do it. But the completeness of the Israeli pattern is unique in our dataset. ZERO Israeli-geolocated IPs attacking us, while 51 Israeli-linked IPs generate 961 events from 5+ countries. Russia, by contrast, shows hundreds of directly-attributed .ru IPs in our honeypot alongside its offshore operations. China shows thousands of directly-attributed .cn IPs.

Israel is the only country in our 7,994-IP dataset where 100% of associated malicious activity is invisible under standard geographic attribution. This suggests either an institutional practice of offshore registration, or that the small population of Israeli cyber operators happens to universally prefer non-Israeli hosting โ€” which amounts to the same thing operationally.

III. The Pattern: Unit 8200 โ†’ Private Sector โ†’ Infrastructure Control

Israel's Unit 8200 (IDF Military Intelligence, SIGINT division, 5,000+ personnel) has a documented institutional pipeline into the private sector:

This pipeline is not alleged. It is documented by the European Parliament (PEGA Committee, January 2023), litigated by Apple (Apple v. NSO Group, 2021), and reported by investigative journalists (DropSite News, Forbidden Stories). The pipeline converts military SIGINT capability into private-sector products that control internet infrastructure.

IV. The Infrastructure Spectrum

Israeli-connected entities now span the complete spectrum of internet infrastructure โ€” from the "security" end to the "criminal" end. The same country produces both the surveillance tools AND the infrastructure they target:

LayerEntityWhat It ControlsIsraeli Connection
SurveillanceNSO Group (Pegasus)Zero-click phone exploitationFounded by Unit 8200 alumni
SurveillanceCellebrite / CandiruDevice extraction / spywareUnit 8200 alumni
VPN/PrivacyKape TechnologiesExpressVPN, PIA, CyberGhost, ZenMateFounded by Koby Menachemi (Unit 8200)
VPN/PrivacyKape + vpnMentor/WizcaseVPN review sites that recommend Kape VPNsKape owns both products AND reviews
Proxy/DataBright Data (Luminati)150M+ residential proxy IPsTel Aviv HQ, Israeli-founded
Proxy/DataBright Data SDK in Smart TVs250M+ TV households as proxy nodesJune 2026: Samsung/LG/Roku apps
Cloud/HostingKamatera Inc.5 ASNs, 8+ entity namesIsraeli-founded, 315 Madison Ave (virtual office)
Cloud/HostingPfcloud UG / Mishayev7+ Spamhaus-listed ASNsIsraeli national (ORG-DM262-RIPE, country=IL)
BulletproofOMEGATECH / GHOSTYNETWORKS67 C2 servers, JS backdoor campaignEnabled by Mishayev's Pfcloud UG

The same national ecosystem produces NSO Group's Pegasus (sold to governments for surveillance) AND Daniel Mishayev's GHOSTYNETWORKS (used by criminals to attack governments). The same ecosystem produces Kape Technologies (controls what VPN you trust) AND Bright Data (controls 150 million residential proxy IPs including your smart TV).

V. Bright Data โ€” The Legal Version of What Mishayev Does Illegally

Source: Include Security Research (June 2026) + Qurium Foundation

Bright Data Ltd (formerly Luminati Networks, successor to Hola VPN) operates 72-150 million IP addresses as residential proxy exit nodes. In June 2026, Include Security discovered Bright Data's SDK embedded in Samsung, LG, and Roku smart TV applications โ€” turning 250 million TV households into proxy exit nodes.

SDK configuration: ignore_screen_on=true, ignore_on_call=true, 200GB/month bandwidth per device. The SDK bypasses user VPNs via NWParameters.requiresDNSResolution. TLS certificates reveal the legacy domain: *.luminatinet.com.

Qurium Foundation documented Bright Data enabling DDoS attacks against Philippine human rights organization Karapatan.

Q: What's the difference between Bright Data's 150M residential proxies and Mishayev's OMEGATECH proxy verification?
A: Scale and legality, not mechanism. Both convert unwitting users' devices into proxy exit nodes. Both sell access to those proxies to third parties. Both make the true origin of traffic invisible.

Bright Data does it "legally" โ€” through SDK agreements buried in app terms of service that nobody reads. Revenue: $500M+/year. They are an Israeli company with offices in Netanya.

Mishayev's operation does it illegally โ€” through malware (Socks5 Systemz, Remcos, AsyncRAT) that turns compromised computers into proxy exit nodes. He is an Israeli national operating from Bavaria.

The technical architecture is identical. The business model is identical. The national origin is identical. The only difference is whether the victim "consented" through an unread EULA or was compromised through malware. In both cases, 200GB/month of someone else's bandwidth is being sold to anonymous buyers.

Confidence: HIGH โ€” Include Security research is peer-reviewed. Bright Data's Israeli origin is public. Mishayev's Israeli nationality is in RIPE records.

VI. The Kamatera Parallel โ€” Same Pattern, Same Origin

Kamatera Inc. โ€” another Israeli-founded cloud provider โ€” operates the same geographic registration arbitrage as Mishayev:

  • 5 different ASNs (AS36007, AS396948, AS396949, AS41436, AS204548)
  • 8+ entity names (Kamatera Inc, CloudWebManage-SC, CloudWebManage, CloudWebManage-EU, CloudWebManage-IL-FR, Global Cloud Infrastructure LLC, Cloud Web Manage, IRT-KAMATERAINC-AP)
  • 315 Madison Avenue NYC as ARIN registration address โ€” a virtual office
  • Domain omc.co.il (OMC Group, Israeli) resolves on their Spain/Netherlands IPs
  • Israeli-founded but presents as US/EU cloud provider

Kamatera isn't bulletproof hosting โ€” it's legitimate cloud infrastructure. But the identity obfuscation pattern is identical to Mishayev's: multiple entity names, virtual offices, geographic registration in non-Israeli jurisdictions, Israeli origin invisible unless you trace corporate records. This is not one person's technique. This is an institutional practice.

VII. GHOSTYNETWORKS โ€” The AnonRDP Rebrand

Source: Intrinsec CTI Report (May 2026) + GBHackers

GHOSTYNETWORKS (AS205759) โ€” the latest incarnation in a chain of shell ASNs:

  • AnonRDP โ€” original brand ("Everything Allowed! 100% Bulletproof"), advertised on elitepvpers/BlackHatWorld
  • OPTIBOUNCE โ€” predecessor ASN, Kentucky-registered, now defunct
  • GHOSTYNETWORKS โ€” current incarnation (Jan 2026), 4/6 prefixes Spamhaus-flagged

Daniel Mishayev's name appears across multiple Kentucky-registered companies. Intrinsec established the chain with high confidence via BGP history and corporate records.

TeamPCP โ€” a sophisticated threat actor known for PUREHVNC RAT and malicious PyPI packages โ€” chose GHOSTYNETWORKS for their infrastructure. When advanced operators with custom tooling choose your hosting, it validates the abuse-tolerance guarantee.

VIII. The Campaign: JS Backdoor Against Energy and Finance

March-April 2026. The targets reveal the financial motivation โ€” and the geopolitical indifference:

Ministry of Finance of Transnistria
Breakaway state (Russian-backed) ยท Minimal cybersecurity ยท Handles significant financial flows
Ukrainian FMCG Holding
Fast-Moving Consumer Goods ยท Ukraine ยท Active war zone, stretched security resources
Russian Oil-Refining Enterprise
Energy/Petroleum ยท Russia ยท Sanctions-stressed, isolated from Western security vendors
Automotive Groups (Poland & Germany)
Manufacturing ยท Central Europe ยท High-value wire transfers, complex supply chains

The JS backdoor: obfuscated JavaScript in ZIP/RAR attachments, communicating on ports 2002/2004/7273 with outdated IE user-agent strings. C2 at scan.aryamint[.]com (158.94.211.76 โ€” OMEGATECH). Spam via mail.talruit[.]com (83.142.209.64 โ€” GHOSTYNETWORKS).

Q: Does targeting both Russian AND Ukrainian entities from Israeli-controlled infrastructure suggest state involvement?
A: The evidence is ambiguous but the pattern is notable. Israel maintains relationships with both Russia and Ukraine. Israeli intelligence services have historically operated in both countries. The targets (energy + finance ministries + automotive) are classic BEC/financial crime targets, suggesting criminal motivation.

However: BEC campaigns are the most common cover for intelligence collection. You compromise a finance ministry "for BEC" but the access grants visibility into state finances, procurement, personnel. An oil refinery's email gives you production data, supply contracts, sanctions-circumvention evidence. A Ukrainian holding's email reveals supply chain vulnerabilities.

We cannot prove state involvement. We CAN prove: (1) the operator is Israeli, (2) the infrastructure enables both criminal and intelligence activity, (3) the targets span both sides of the Russia-Ukraine conflict, (4) Israel is the only country in our dataset with 0% direct attribution for 100% offshore operations.

Confidence: MEDIUM โ€” The pattern is documented but the state nexus is circumstantial. What IS proven is that Mishayev's infrastructure hosts the campaign.

IX. The Submarine Cable Question

One more data point that contextualizes Israeli infrastructure control:

Source: Wikipedia (Unit 8200) + Middle East Eye + EIB Project Records

Google's Blue-Raman cable system (operational 2025) routes Europe-to-Asia traffic through Israel: Blue segment (Italy โ†’ Israel, 16 fiber pairs) connects to Raman segment (Israel โ†’ Jordan โ†’ India, 16 fiber pairs). Israel is the physical land bridge between Mediterranean and Indian Ocean fiber.

Unit 8200 reportedly maintains covert listening posts in Israeli embassies abroad and taps undersea cables (Wikipedia, sourced to multiple intelligence journalists). UK/US spy agencies use cable landing points for Middle East surveillance (Middle East Eye).

When an Israeli-operated proxy network routes your traffic, and Israeli-operated submarine cables carry your data, and Israeli-built surveillance tools monitor your device โ€” the question isn't whether Israel has capability. The question is where the "legitimate" infrastructure ends and the "criminal" infrastructure begins.

X. The Complete Mishayev Ecosystem โ€” Honeypot Evidence

ASNEntityIPsHitsThreat (max)Spamhaus
202412OMEGATECH LTD (Seychelles)7789100ASN-DROP
197170TechTies Inc. (Seychelles)1712862ASN-DROP
205759GHOSTYNETWORKS (Kentucky)212564/6 prefixes
51396Pfcloud UG (Germany)81โ€”Transit only
44382WhiteLabel Networks (Kentucky)30โ€”โ€”
TOTAL37930โ€”โ€”

HASSH fingerprint analysis confirms cross-ASN coordination:

  • a7a87fbe86774c2e: Links OMEGATECH (94.154.35.215, 178.16.54.226) to Private Layer Switzerland โ€” the same proxy factory documented in 038C
  • 2ec37a7cc8daf20b: 12-node cluster linking OMEGATECH (TR/DE/NL) to TechTies (NL) and external IPs (DigitalOcean, Scaleway, FranTech)
  • 16443846184eafde: Links GHOSTYNETWORKS (46.151.182.2) to Private Layer (179.43.186.241)

GHOSTYNETWORKS IP 46.151.182.2 shares commands with 15+ IPs across Linode, DigitalOcean, GCP, and shared credentials with 7+ IPs. This means either the same botnet operators are testing from GHOSTYNETWORKS AND major cloud providers, or GHOSTYNETWORKS provides proxy/bounce infrastructure for operators who also use legitimate clouds.

XI. The Kape + Bright Data Convergence

XII. The Question We Cannot Answer (Yet)

Q: Is Daniel Mishayev connected to Israeli intelligence services?
A: We have no evidence of a direct connection. What we have is a pattern:

1. Israeli national operating infrastructure used by criminal actors
2. Geographic registration arbitrage making Israeli origin invisible
3. The same arbitrage pattern used by documented Unit 8200-linked entities
4. Zero Israeli IPs in 7,994-IP honeypot dataset (100% offshore operation)
5. Infrastructure targeting BOTH sides of the Russia-Ukraine conflict
6. Covent Garden, London virtual office (shared by Virtualine, Aeza, Stark Industries)
7. The broader context: Israel produces both the surveillance tools (NSO, Cellebrite, Candiru) AND the infrastructure that evades surveillance (bulletproof hosting, proxy networks)

Mishayev may be a purely criminal entrepreneur with no state connection. Many Israeli nationals work in cybercrime with no intelligence links. But the institutional context cannot be ignored: when a nation's military intelligence unit has a documented pipeline into private-sector cyber companies, and a national of that country operates one of the largest bulletproof hosting franchises in the world using the same operational patterns as documented intelligence-linked entities โ€” the question must be asked even if it cannot yet be answered.

Confidence in Mishayev operating the infrastructure: HIGH (RIPE records, corporate filings, Intrinsec report).
Confidence in intelligence service connection: LOW/SPECULATIVE (pattern-based, no direct evidence).
We state both clearly because intellectual honesty requires it.
"Seven IPs. Zero hits. That's Israel in our honeypot database. The most sophisticated cyber-intelligence apparatus on Earth generates precisely zero direct signals. But trace the nationals โ€” the shell companies in Kentucky, the Seychelles IBCs, the Bavarian addresses, the Turkish LIRs โ€” and you find 51 IPs, 930 events, 7 Spamhaus-listed ASNs, 67 C2 servers, 16 malware families, and a JS backdoor campaign targeting the finance ministry of an unrecognized state. The ghost leaves no footprints in its own country. Only everywhere else."

XIV. The Documented Library: What Our OSINT Index Contains

Our Elasticsearch OSINT library โ€” 136,617 documents, 7.6 million semantic chunks โ€” contains the primary sources that document the infrastructure of control. These are not conspiracy theories. They are:

  • "The Palestine Laboratory" (Antony Loewenstein) โ€” How Israel tests surveillance on Palestinians then exports the technology worldwide
  • "The Walls Have Eyes" (Petra Molnar) โ€” Elbit Systems: $5.28 billion revenue, 18,000 employees, "espionage diplomacy" testing technology in conflict zones
  • "Science of Coercion" (Christopher Simpson) โ€” CIA's $1 billion annual psychological warfare budget (1950s), communication research weaponized for population control
  • "Manufacturing Consent" (Noam Chomsky) โ€” The propaganda model: corporate ownership, advertising, sourcing, flak, and anti-communism as media filters
  • RAND "Hostile Social Manipulation" (2019) โ€” State actors exploiting social media for influence operations, psychological operations forces, fragmentation of trust
  • NSA/FRA Intelligence Paper (2013, Snowden) โ€” NSA's relationship with Swedish SIGINT (FRA) established 1954 under UKUSA/Five Eyes
  • "The Secret History of the Five Eyes" โ€” The UKUSA Agreement: Britain + America dividing global signals intelligence
  • "No Place to Hide" / "Permanent Record" (Snowden) โ€” PRISM, upstream collection, the architecture of mass surveillance
  • Apple v. NSO Group Complaint (2021) โ€” Legal documentation of Pegasus spyware sold to 45+ countries
  • European Parliament PEGA Committee Report (2023) โ€” "The Impact of Pegasus on Fundamental Rights and Democratic Processes"
  • "Autocracy, Inc." (Anne Applebaum) โ€” How dictators share infrastructure, techniques, and technology across borders
  • LLM Generated Text Detection (2023) โ€” AI-powered influence operations creating "a more favorable operating environment for propagandists"
Key Quote โ€” "The Walls Have Eyes" (Petra Molnar)

"Israel may be known as 'the Harvard of counterterrorism,' but it is also the center of much of the world's surveillance technology that is normalized and tested out on Palestinians. One of the leading players in border surveillance and spyware, for example, is the Israeli company Elbit Systems. Headquartered in Haifa and started in 1966, Elbit Systems expanded from weapons logistics to become a surveillance powerhouse of nearly eighteen thousand employees worldwide with a revenue of $5.28 billion."

Key Quote โ€” "Science of Coercion" (Christopher Simpson)

"No comprehensive budget of U.S. psychological warfare activities is known to exist. CIA psychological warfare consultant James Burnham, however, put the overall figure at over $1 billion annually during its heyday in the early 1950s."

The science of coercion didn't end in the 1950s. It migrated. From broadcast propaganda to social media manipulation. From radio jamming to proxy network control. From CIA-funded academic research to Unit 8200 alumni startups. The tools changed. The objective โ€” control of the information environment โ€” did not.

XV. The Architecture of Control โ€” From Cables to Proxies

The internet was built for military communication (ARPANET, 1969). It was released for civilian use as an instrument of commerce and โ€” crucially โ€” as an instrument of surveillance. Every layer of the internet serves dual purposes:

LayerCivilian PurposeControl PurposeWho Controls It
Physical (cables)Carry data between continentsTapping points for SIGINT collectionFive Eyes + Israel (Blue-Raman cable)
Network (routing)Direct packets efficientlyTraffic analysis, BGP manipulationTransit providers (aurologic, etc.)
DNSTranslate names to IPsCensorship, surveillance, redirectionICANN + national registries
VPN/PrivacyProtect user trafficHoneypot: see who wants to hideKape Technologies (Unit 8200)
Proxy/CDNCache and accelerate contentMan-in-the-middle, traffic inspectionBright Data (150M+ nodes)
EndpointUser devicesZero-click exploitationNSO Group (Pegasus), Cellebrite
Bulletproof hostingHost any contentPlausible deniability for operationsPfcloud/Mishayev (Israeli national)

From submarine cable to endpoint exploitation, Israeli-connected entities maintain presence at every single layer. This is not hyperbole โ€” it is documented by the European Parliament, litigated in US courts, exposed by Snowden's NSA documents, and confirmed by our own honeypot data.

Q: Is the internet a tool of freedom or a tool of control?
A: Both. Simultaneously. By design.

The internet enables this publication. It enables you to read forensic evidence about criminal infrastructure operators. It enables whistleblowers to transmit documents. It enables encrypted communication.

The same internet enables Pegasus to compromise journalists' phones. Enables Bright Data to turn your TV into a proxy exit node. Enables Kape Technologies to own both the VPN you trust AND the review site that recommended it. Enables GHOSTYNETWORKS to deliver JS backdoors to finance ministries.

The relevant question is not "freedom or control" โ€” it's who has the capability to observe, redirect, and manipulate traffic at each layer, and whether that capability is subject to democratic oversight. The answer, as documented in every source above: the capability exists, it is concentrated in a small number of national ecosystems (primarily Five Eyes + Israel), and democratic oversight ranges from minimal (US/UK) to nonexistent (Israel).

Our honeypot proves one thing conclusively: the same infrastructure that enables surveillance also enables crime. Daniel Mishayev's GHOSTYNETWORKS hosts JS backdoors. It could equally host intelligence collection infrastructure. The network doesn't distinguish between the two. Neither, it seems, does the operator.

XVI. The Freedom Argument

We publish this because the internet was supposed to be free. Not free as in cost โ€” free as in speech. Free as in the ability to know what is being done to you, by whom, using what infrastructure.

Our honeypot costs $0 in cloud services. Our OSINT library runs on a refurbished workstation. Our threat intelligence pipeline uses open-source tools. We document criminal infrastructure using the same internet that criminal infrastructure uses to attack us.

That is the asymmetry they didn't account for. The same tools that enable mass surveillance enable mass transparency. The same cables that carry Pegasus exploits carry this article. The same routing infrastructure that hides Mishayev's shells also delivers our forensic analysis to anyone who searches for it.

When Intrinsec honeypots record 642,001 hits and publish the evidence freely, that is freedom. When we name Daniel Mishayev, trace his shells across five jurisdictions, and connect his infrastructure to sanctioned entities โ€” that is freedom. When we document the pattern from Unit 8200 to NSO to Pfcloud to GHOSTYNETWORKS โ€” that is what the internet was supposed to enable.

"The internet is a tool man created. The reason behind it is control. But every tool can be turned against its maker. They built the surveillance infrastructure. We built the honeypot. They host 67 C2 servers. We document all 67. They hide behind Kentucky shells and Seychelles IBCs. We publish their RIPE handles and phone numbers. They control the cables. We control the narrative. That is the only asymmetry that matters."

XVII. Indicators of Compromise

TypeIndicatorDescription
ASN205759GHOSTYNETWORKS (AnonRDP rebrand)
ASN202412OMEGATECH-AS (Virtualine front)
ASN197170TechTies (Tor + proxy)
ASN51396Pfcloud UG (Mishayev transit hub)
IPv483.142.209[.]64Spam sender (GHOSTYNETWORKS)
IPv491.92.243[.]79Spam + JS backdoor C2 (OMEGATECH)
IPv4158.94.211[.]76JS backdoor C2 (OMEGATECH)
IPv446.151.182[.]2GHOSTYNETWORKS (in our honeypot)
IPv494.154.35[.]215OMEGATECH (threat=100, in our honeypot)
Domainmail.talruit[.]comSpam sender domain
Domainscan.aryamint[.]comJS backdoor C2 domain
Domainmpwirerope[.]comSpam sender domain
Domainethara[.]orgThreat actor infrastructure
Domainwhitelabel[.]shMishayev's ASN provisioning service
SHA-256794fab796e48f97e976d99157913ab5beee5ae8ef2731bf2af2222ae5b6a1c65QUOTE_B0426.js
SHA-256ac842e4adb445a76aad135828d56116858a1b7d37b4a103f493e175816df9bb2PO 03603.zip
SHA-25633713a3650a3c1d64045c3832835dcacef92ad4f09c030fbe674454266880feaPO 26683.js
SHA-2567277f4dfb26a53f8ee47cac051a82f6709e07b6603f26ff3987cc64a137e07dcPO8767.rar
SHA-256232a179daf4db527c062b609ebb5f19310eea8f5c80afce6f763f5841110aed8PO8767.js
RIPEORG-DM262-RIPEDaniel Mishayev organization
CompanyHRB 12249 (Passau)Pfcloud UG registration

TI-2026-039A ยท The Ghost Network ยท Letter A
Published by LSN Threat Intelligence ยท June 23, 2026
Sources: Intrinsec CTI Report (May 2026), GBHackers, Spamhaus, RIPE NCC, Cowrie honeypot, threat_intel PostgreSQL, dossier_intel Elasticsearch (TI-2026-034B), Recorded Future, Include Security, Qurium Foundation, DropSite News, European Parliament PEGA Committee, Apple v. NSO Group (2021), "The Palestine Laboratory" (Loewenstein)
Cross-referenced: TI-2026-034B, TI-2026-038A-F, TI-019I, TI-010

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Ghost Network โ€” 1 / 7 Next โ†’