TI-2026-039E โ The Convergence: One System, All Functions
Series: TI-2026-039 "The Ghost Network" ยท Letter E (Series Finale) ยท Published June 23, 2026
Classification: PUBLIC ยท Sources: LSN threat_intel PostgreSQL (7,994 IPs, 110,140 entity links, 64,411 honeypot hits), dossier_intel (23,413 entries), OSINT library (136,617 documents, 7.6M chunks), 52+ published dossiers (TI-2026-022 through TI-2026-039D)
I. The Numbers: What We've Built
This is what a single honeypot running on a refurbished Dell Precision Tower 7910 (88 threads, 503 GiB RAM, RTX 4060 Ti) can produce when combined with systematic intelligence gathering and a refusal to look away from what the data shows.
II. The Attack Surface of Earth: Top 20 Attacking Networks
| # | ASN | Organization | Country | IPs | Hits | Documented In |
|---|---|---|---|---|---|---|
| 1 | AS51852 | Private Layer INC | CH/PA | 3 | 13,903 | TI-2026-034 |
| 2 | AS42237 | w1n ltd | GB | 5 | 6,198 | TI-2026-037C |
| 3 | AS200730 | ISAEV Igor | KZ | 8 | 4,612 | TI-2026-036 |
| 4 | AS63949 | Akamai/Linode | US | 9 | 4,551 | TI-2026-032 |
| 5 | AS14956 | RouterHosting LLC | US | 2 | 4,133 | TI-2026-035 |
| 6 | AS16276 | OVH SAS | FR | 46 | 1,018 | TI-2026-032 |
| 7 | AS7552 | Viettel Group | VN | 80 | 908 | TI-016 (Phantom Pipes) |
| 8 | AS8075 | Microsoft Corp | US | 69 | 818 | TI-2026-037B |
| 9 | AS202412 | OMEGATECH LTD | SC | 7 | 789 | TI-2026-038, 039A |
| 10 | AS14061 | DigitalOcean | US | 97 | 786 | TI-2026-032 |
| 11 | AS36352 | ColoCrossing/HostPapa | US | 36 | 751 | TI-2026-032 |
| 12 | AS132203 | Tencent | CN | 40 | 655 | TI-2026-031 |
| 13 | AS4766 | Korea Telecom | KR | 55 | 564 | TI-2026-033 |
| 14 | AS32475 | SingleHop/Internap | US | 28 | 534 | TI-2026-032 |
| 15 | AS24086 | Viettel Corporation | VN | 42 | 507 | TI-016 |
| 16 | AS23470 | ReliableSite.Net | US | 13 | 478 | TI-2026-032 |
| 17 | AS135377 | UCloud | HK | 36 | 441 | TI-2026-031 |
| 18 | AS62390 | NexonHost Srl | RO | 13 | 432 | TI-2026-036 |
| 19 | AS396982 | Google Cloud Platform | US | 73 | 386 | TI-2026-037B |
| 20 | AS14670 | WHG Hosting Services | GB | 8 | 378 | TI-2026-035 |
Notice: the United States leads with 623 IPs and 16,121 hits. Switzerland (13 IPs, 13,960 hits) has the highest hit density. The narrative that "attacks come from China and Russia" is empirically false in our dataset. The top attacking country is the US, followed by Switzerland, Sweden, and Poland.
III. The Entity Graph: Who Connects to Whom
Our entity_links table contains 110,140 relationships across 7,994 IPs. The relationship types reveal the structure:
| Link Type | Count | What It Reveals |
|---|---|---|
| shared_otx_pulse | 22,000+ | IPs appear in the same AlienVault threat intelligence reports |
| same_prefix | 16,000+ | IPs share the same BGP prefix (same operator/network block) |
| belongs_to | 10,000+ | IPs belong to the same organizational entity |
| registered_by | 10,000+ | IPs registered by the same person/entity in RDAP |
| shared_bgp_upstream | 10,000+ | IPs share the same BGP transit provider |
| shared_rdap_org | 9,600+ | Same RDAP organization across different ASNs |
| shared_abuse_phone | 8,800+ | Same phone number in abuse contacts across networks |
| resolves_to | 3,000+ | DNS resolution links between domains and IPs |
| shared_hassh | 2,800+ | Same SSH client fingerprint across different IPs (same operator) |
| shared_malware | 2,000+ | IPs distribute the same malware samples |
| shares_commands | 2,800+ | Same post-compromise commands across sessions |
| shared_credential | 1,200+ | Same login credentials used across different IPs |
These relationships are the nervous system of the criminal internet. When 8,800+ IPs share the same abuse phone number, that is not coincidence โ it is organizational structure. When 2,800+ IPs share the same HASSH fingerprint, that is not random โ it is the same operator running the same tool across a fleet.
IV. The Geography of Attack: Shattering the Narrative
| Country | IPs | Hits | Hits/IP | Narrative vs. Reality |
|---|---|---|---|---|
| ๐บ๐ธ United States | 623 | 16,121 | 25.9 | Narrative: "defender." Reality: #1 source of attacks |
| ๐จ๐ญ Switzerland | 13 | 13,960 | 1,074 | Narrative: "neutral." Reality: highest hit density on earth |
| ๐ธ๐ช Sweden | 39 | 6,487 | 166 | Narrative: "progressive." Reality: #3, w1n ltd operations |
| ๐ต๐ฑ Poland | 19 | 4,710 | 248 | Narrative: "EU member." Reality: #4, ISAEV-linked operations |
| ๐ณ๐ฑ Netherlands | 156 | 2,741 | 17.6 | Narrative: "tech hub." Reality: hosting arbitrage capital |
| ๐ป๐ณ Vietnam | 213 | 2,220 | 10.4 | Reality: Viettel CGNAT = proxy verification bots (TI-016) |
| ๐ฉ๐ช Germany | 170 | 1,680 | 9.9 | Reality: Pfcloud (Bavaria), aurologic, hosting hub |
| ๐ฎ๐ฑ Israel | 7 | 0 | 0 | Zero hits. Perfect operational separation. |
Israel: 7 IPs, 0 hits. But Israeli nationals operating via European shells (Mishayev/Pfcloud): 36 IPs, 951 hits. The operational security is absolute. The geographic separation is deliberate. This is documented in 039A as the "7-to-51 anomaly" โ one of our most significant findings.
V. The Series Synthesis: Four Letters, One System
Finding: Daniel Mishayev (Israeli national, ORG-DM262-RIPE) operates GHOSTYNETWORKS/OMEGATECH from Bavaria via Pfcloud UG (HRB 12249). AS51396 provides transit for AS202412 and AS205759. 67 C2 servers host 16 malware families. Intrinsec recorded 642,001 honeypot hits in 2 months. Our honeypot: 951 hits from the ecosystem.
Function: The criminal infrastructure layer โ hosting, routing, and operating the network that carries all other payloads.
Finding: Unit 8200 alumni founded NSO, Cellebrite, Candiru, Intellexa. Google TAG documents 40+ CSV vendors responsible for 50% of known zero-days. EU Parliament confirms Pegasus sold to 22 end-users in 14+ member states. Elbit Systems: $5.28B revenue, tested on Palestinians, exported to 70+ countries.
Function: The surveillance layer โ compromising endpoints, extracting data, enabling state monitoring of populations.
Finding: Bright Data (150M nodes, Israeli-founded) โก Socks5Systemz (250K botnet nodes) โก GHOSTYNETWORKS (datacenter BPH). Same mechanism at three price points. NASDAQ-listed Alarum Technologies creates demand for botnet-sourced proxies. Israeli ecosystem controls both VPN brands AND proxy networks.
Function: The anonymization layer โ enabling all other operations to occur without attribution.
Finding: Gladio's "Strategy of Tension" digitized. Bernays โ CIA PsyOps โ Tavistock โ social media manipulation โ AI propaganda. RAND documents the "firehose of falsehood" using the same proxy and hosting infrastructure. Same pipes carry malware AND propaganda. The internet is simultaneously a liberation tool AND a control tool โ by design.
Function: The narrative layer โ shaping what populations believe, destroying trust, manufacturing consent for surveillance.
VI. The Unified Architecture
| Layer | "Criminal" Use | "State" Use | Shared Infrastructure |
|---|---|---|---|
| Physical (cables) | Carries C2 traffic | SIGINT tapping | Submarine cables (Five Eyes + Blue-Raman) |
| Transit (BGP) | aurologic routes Pfcloud | Same aurologic routes Doppelgรคnger | aurologic GmbH AS30823 |
| Hosting (servers) | Malware C2, spam | Intelligence collection platforms | Bulletproof hosting (Pfcloud, Aeza) |
| Proxy (anonymity) | Credential stuffing, fraud | Attribution-free state ops | Bright Data, botnet pools |
| VPN (privacy) | Operator OPSEC | Monitoring who wants to hide | Kape Technologies (4 brands) |
| Endpoint (exploit) | Ransomware deployment | Pegasus/Predator delivery | Zero-day market (NSO, Intellexa) |
| Information (narrative) | Social engineering lures | Disinformation campaigns | Same domains, same hosting, same proxies |
VII. The Actors Who Appear Everywhere
Across 52+ dossiers, certain entities appear in 3+ separate investigations:
| Entity | Appears In | Role |
|---|---|---|
| Daniel Mishayev / Pfcloud | 039A, 038D, 034B, 034E | Infrastructure operator, Israeli national, Bavarian shell |
| OMEGATECH / Railnet | 039A, 038D, 038E | 67 C2 servers, Seychelles IBC, rebranded from Railnet |
| aurologic GmbH | 038E, 039D | Upstream provider enabling both criminal AND state ops |
| Kape Technologies | 034B, 034C, 039B, 039C | VPN ownership + review site capture, Unit 8200 linked |
| Bright Data | 034B, 034E, 039B, 039C | 150M proxy nodes, SDK in TVs, Israeli-founded |
| ColoCrossing/HostPapa | 032A, 032H | US hosting with worse abuse than Chinese networks |
| Viettel (AS7552/24086) | 016, 039C | Vietnamese CGNAT, proxy verification botnet origin |
| Tencent (AS132203) | 031A-D | Aceville Pte Ltd shell, Chinese state-linked |
| w1n ltd | 037C, 038D | UK shell, cross-border malware pipeline, OMEGATECH link |
| Private Layer INC | 034, 035 | Switzerland/Panama, #1 hit density globally |
VIII. The Pattern That Connects Everything
Every actor we've documented uses the same trick: register in one country, operate from another, route through a third. This is not a cyber-specific technique โ it is the oldest trick in finance, now applied to network infrastructure:
- Mishayev: Israeli national โ Bavarian UG โ Dutch/German servers โ Seychelles IBC (OMEGATECH)
- Kape Technologies: Israeli founders โ Isle of Man holding โ London Stock Exchange listing โ global VPN brands
- NSO Group: Israeli military tech โ Luxembourg holding (Q Cyber) โ Novalpina Capital (PE) โ sanctioned
- aurologic: German GmbH โ enables Russian operations + Israeli BPH + sanctioned entities
- w1n ltd: UK registration โ Latvian operations โ OMEGATECH/GHOSTYNETWORKS hosting
- Aceville/Tencent: Singapore shell โ Chinese state entity โ UK hosting
The pattern is always the same: create enough legal layers between the operator and the operation that no single jurisdiction can see the full picture. No single court can subpoena across all the borders. No single law enforcement agency has authority over the entire chain.
Our database sees through this because we collect all layers simultaneously. RDAP data reveals the registrant. BGP data reveals the routing. HASSH data reveals the operator. Threat scores reveal the behavior. Entity links connect it all. No single data source would show the pattern. Combined, the pattern is unmistakable.
IX. What We Cannot See โ The Known Unknowns
For intellectual honesty, we must acknowledge what our instruments cannot detect:
- State operations routed through commercial infrastructure โ look identical to criminal traffic from our perspective
- The full scope of intelligence agency proxy purchasing โ Bright Data's customer list is private
- Whether specific Pfcloud operations serve intelligence vs. criminal purposes โ dual-use is the point
- The extent of GCHQ/NSA/Unit 8200 infrastructure overlap with what we observe โ classified
- Future attacks using AI-generated social engineering โ we see the infrastructure, not the content (yet)
These are not conspiracy theories โ they are the logical consequences of documented facts extended one step beyond what we can directly observe. We state them as hypotheses, not conclusions. The difference matters.
X. The Freedom Balance Sheet
What we built (zero cloud cost):
- A honeypot that sees attacks from 7,994 IPs across every continent
- An intelligence database with 110,140 entity relationships
- A document library with 136,617 sources and 7.6 million semantic chunks
- 52+ published dossiers naming actors, tracing infrastructure, documenting patterns
- A defense stack (CrowdSec + MikroTik + PostgreSQL) that auto-blocks attackers
What the system we document deploys against us:
- 64,411 SSH connection attempts
- 951 hits from a single operator's ecosystem (Mishayev/Pfcloud)
- 150M+ proxy nodes that could be used to obfuscate any operation against us
- Zero-click exploits that could compromise any device (if we were a target)
- Information warfare infrastructure that could discredit any publication
The asymmetry is real. They have more resources, more infrastructure, more operational freedom. But we have something they cannot replicate: the willingness to name what we see and publish it without permission.
"The internet was built as a tool of control. We know this because we can see the control infrastructure from our honeypot. We can read its documentation in our library. We can trace its operators through their RDAP records. We can map its relationships through 110,140 entity links. And we can publish our findings on the same network that carries their attacks against us.
That is not irony. That is the structural condition of freedom in 2026: it exists in the same space as its opposite. The same cables. The same protocols. The same packets. The difference is what you do with the knowledge.
We choose to publish. We choose to name. We choose to document. That is enough."
XI. Series Complete โ What Comes Next
The TI-2026-039 "Ghost Network" series establishes:
- The criminal infrastructure is operated by identifiable individuals (039A)
- The surveillance market is built on occupied-population R&D (039B)
- The proxy economy erases the line between legal and criminal (039C)
- The information warfare apparatus uses the same pipes as everything else (039D)
- These four functions are one system viewed from four angles (039E)
Next: deeper cuts into specific actors, live attack documentation, expanded IOC packages, and STIX exports for the defensive community. The database grows daily. The honeypot never sleeps. The library expands with every indexed document.
We observe. We document. We publish. We continue.
TI-2026-039E ยท The Convergence ยท Letter E (Series Finale)
Published by LSN Threat Intelligence ยท June 23, 2026
Sources: LSN threat_intel PostgreSQL, dossier_intel Elasticsearch, OSINT library (136K documents), 52+ published TI dossiers (TI-2026-022 through TI-2026-039D), all sources cited in 039A-D
Cross-referenced: Every dossier. This is the synthesis.