TI-2026-039E โ€” The Convergence: One System, All Functions

Series: TI-2026-039 "The Ghost Network" ยท Letter E (Series Finale) ยท Published June 23, 2026
Classification: PUBLIC ยท Sources: LSN threat_intel PostgreSQL (7,994 IPs, 110,140 entity links, 64,411 honeypot hits), dossier_intel (23,413 entries), OSINT library (136,617 documents, 7.6M chunks), 52+ published dossiers (TI-2026-022 through TI-2026-039D)

FINAL THESIS: There is no separation between cybercrime infrastructure, surveillance infrastructure, propaganda infrastructure, and state operations infrastructure. They are one system. The same ASNs. The same upstream providers. The same jurisdictional arbitrage. The same actors. Different payloads, same pipes. We can prove this because we observe all layers simultaneously from a single honeypot โ€” and because we index the documents that reveal the historical architecture of this convergence. This letter presents the complete picture.

I. The Numbers: What We've Built

7,994
IPs in threat_intel DB
110,140
Entity relationship links
64,411
Total honeypot hits
23,413
Dossier intelligence entries
136,617
OSINT library documents
7.6M
Semantic chunks indexed
52+
Published dossiers

This is what a single honeypot running on a refurbished Dell Precision Tower 7910 (88 threads, 503 GiB RAM, RTX 4060 Ti) can produce when combined with systematic intelligence gathering and a refusal to look away from what the data shows.

II. The Attack Surface of Earth: Top 20 Attacking Networks

#ASNOrganizationCountryIPsHitsDocumented In
1AS51852Private Layer INCCH/PA313,903TI-2026-034
2AS42237w1n ltdGB56,198TI-2026-037C
3AS200730ISAEV IgorKZ84,612TI-2026-036
4AS63949Akamai/LinodeUS94,551TI-2026-032
5AS14956RouterHosting LLCUS24,133TI-2026-035
6AS16276OVH SASFR461,018TI-2026-032
7AS7552Viettel GroupVN80908TI-016 (Phantom Pipes)
8AS8075Microsoft CorpUS69818TI-2026-037B
9AS202412OMEGATECH LTDSC7789TI-2026-038, 039A
10AS14061DigitalOceanUS97786TI-2026-032
11AS36352ColoCrossing/HostPapaUS36751TI-2026-032
12AS132203TencentCN40655TI-2026-031
13AS4766Korea TelecomKR55564TI-2026-033
14AS32475SingleHop/InternapUS28534TI-2026-032
15AS24086Viettel CorporationVN42507TI-016
16AS23470ReliableSite.NetUS13478TI-2026-032
17AS135377UCloudHK36441TI-2026-031
18AS62390NexonHost SrlRO13432TI-2026-036
19AS396982Google Cloud PlatformUS73386TI-2026-037B
20AS14670WHG Hosting ServicesGB8378TI-2026-035

Notice: the United States leads with 623 IPs and 16,121 hits. Switzerland (13 IPs, 13,960 hits) has the highest hit density. The narrative that "attacks come from China and Russia" is empirically false in our dataset. The top attacking country is the US, followed by Switzerland, Sweden, and Poland.

III. The Entity Graph: Who Connects to Whom

Our entity_links table contains 110,140 relationships across 7,994 IPs. The relationship types reveal the structure:

Link TypeCountWhat It Reveals
shared_otx_pulse22,000+IPs appear in the same AlienVault threat intelligence reports
same_prefix16,000+IPs share the same BGP prefix (same operator/network block)
belongs_to10,000+IPs belong to the same organizational entity
registered_by10,000+IPs registered by the same person/entity in RDAP
shared_bgp_upstream10,000+IPs share the same BGP transit provider
shared_rdap_org9,600+Same RDAP organization across different ASNs
shared_abuse_phone8,800+Same phone number in abuse contacts across networks
resolves_to3,000+DNS resolution links between domains and IPs
shared_hassh2,800+Same SSH client fingerprint across different IPs (same operator)
shared_malware2,000+IPs distribute the same malware samples
shares_commands2,800+Same post-compromise commands across sessions
shared_credential1,200+Same login credentials used across different IPs

These relationships are the nervous system of the criminal internet. When 8,800+ IPs share the same abuse phone number, that is not coincidence โ€” it is organizational structure. When 2,800+ IPs share the same HASSH fingerprint, that is not random โ€” it is the same operator running the same tool across a fleet.

IV. The Geography of Attack: Shattering the Narrative

CountryIPsHitsHits/IPNarrative vs. Reality
๐Ÿ‡บ๐Ÿ‡ธ United States62316,12125.9Narrative: "defender." Reality: #1 source of attacks
๐Ÿ‡จ๐Ÿ‡ญ Switzerland1313,9601,074Narrative: "neutral." Reality: highest hit density on earth
๐Ÿ‡ธ๐Ÿ‡ช Sweden396,487166Narrative: "progressive." Reality: #3, w1n ltd operations
๐Ÿ‡ต๐Ÿ‡ฑ Poland194,710248Narrative: "EU member." Reality: #4, ISAEV-linked operations
๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands1562,74117.6Narrative: "tech hub." Reality: hosting arbitrage capital
๐Ÿ‡ป๐Ÿ‡ณ Vietnam2132,22010.4Reality: Viettel CGNAT = proxy verification bots (TI-016)
๐Ÿ‡ฉ๐Ÿ‡ช Germany1701,6809.9Reality: Pfcloud (Bavaria), aurologic, hosting hub
๐Ÿ‡ฎ๐Ÿ‡ฑ Israel700Zero hits. Perfect operational separation.

Israel: 7 IPs, 0 hits. But Israeli nationals operating via European shells (Mishayev/Pfcloud): 36 IPs, 951 hits. The operational security is absolute. The geographic separation is deliberate. This is documented in 039A as the "7-to-51 anomaly" โ€” one of our most significant findings.

V. The Series Synthesis: Four Letters, One System

039A โ€” The Ghost Network (Infrastructure)

Finding: Daniel Mishayev (Israeli national, ORG-DM262-RIPE) operates GHOSTYNETWORKS/OMEGATECH from Bavaria via Pfcloud UG (HRB 12249). AS51396 provides transit for AS202412 and AS205759. 67 C2 servers host 16 malware families. Intrinsec recorded 642,001 honeypot hits in 2 months. Our honeypot: 951 hits from the ecosystem.

Function: The criminal infrastructure layer โ€” hosting, routing, and operating the network that carries all other payloads.

039B โ€” The Surveillance Market (Control)

Finding: Unit 8200 alumni founded NSO, Cellebrite, Candiru, Intellexa. Google TAG documents 40+ CSV vendors responsible for 50% of known zero-days. EU Parliament confirms Pegasus sold to 22 end-users in 14+ member states. Elbit Systems: $5.28B revenue, tested on Palestinians, exported to 70+ countries.

Function: The surveillance layer โ€” compromising endpoints, extracting data, enabling state monitoring of populations.

039C โ€” The Proxy Economy (Anonymity)

Finding: Bright Data (150M nodes, Israeli-founded) โ‰ก Socks5Systemz (250K botnet nodes) โ‰ก GHOSTYNETWORKS (datacenter BPH). Same mechanism at three price points. NASDAQ-listed Alarum Technologies creates demand for botnet-sourced proxies. Israeli ecosystem controls both VPN brands AND proxy networks.

Function: The anonymization layer โ€” enabling all other operations to occur without attribution.

039D โ€” The Information War (Narrative)

Finding: Gladio's "Strategy of Tension" digitized. Bernays โ†’ CIA PsyOps โ†’ Tavistock โ†’ social media manipulation โ†’ AI propaganda. RAND documents the "firehose of falsehood" using the same proxy and hosting infrastructure. Same pipes carry malware AND propaganda. The internet is simultaneously a liberation tool AND a control tool โ€” by design.

Function: The narrative layer โ€” shaping what populations believe, destroying trust, manufacturing consent for surveillance.

VI. The Unified Architecture

Layer"Criminal" Use"State" UseShared Infrastructure
Physical (cables)Carries C2 trafficSIGINT tappingSubmarine cables (Five Eyes + Blue-Raman)
Transit (BGP)aurologic routes PfcloudSame aurologic routes Doppelgรคngeraurologic GmbH AS30823
Hosting (servers)Malware C2, spamIntelligence collection platformsBulletproof hosting (Pfcloud, Aeza)
Proxy (anonymity)Credential stuffing, fraudAttribution-free state opsBright Data, botnet pools
VPN (privacy)Operator OPSECMonitoring who wants to hideKape Technologies (4 brands)
Endpoint (exploit)Ransomware deploymentPegasus/Predator deliveryZero-day market (NSO, Intellexa)
Information (narrative)Social engineering luresDisinformation campaignsSame domains, same hosting, same proxies

VII. The Actors Who Appear Everywhere

Across 52+ dossiers, certain entities appear in 3+ separate investigations:

EntityAppears InRole
Daniel Mishayev / Pfcloud039A, 038D, 034B, 034EInfrastructure operator, Israeli national, Bavarian shell
OMEGATECH / Railnet039A, 038D, 038E67 C2 servers, Seychelles IBC, rebranded from Railnet
aurologic GmbH038E, 039DUpstream provider enabling both criminal AND state ops
Kape Technologies034B, 034C, 039B, 039CVPN ownership + review site capture, Unit 8200 linked
Bright Data034B, 034E, 039B, 039C150M proxy nodes, SDK in TVs, Israeli-founded
ColoCrossing/HostPapa032A, 032HUS hosting with worse abuse than Chinese networks
Viettel (AS7552/24086)016, 039CVietnamese CGNAT, proxy verification botnet origin
Tencent (AS132203)031A-DAceville Pte Ltd shell, Chinese state-linked
w1n ltd037C, 038DUK shell, cross-border malware pipeline, OMEGATECH link
Private Layer INC034, 035Switzerland/Panama, #1 hit density globally

VIII. The Pattern That Connects Everything

Q: What is the single pattern that connects all 52+ dossiers?
A: Jurisdictional arbitrage.

Every actor we've documented uses the same trick: register in one country, operate from another, route through a third. This is not a cyber-specific technique โ€” it is the oldest trick in finance, now applied to network infrastructure:

  • Mishayev: Israeli national โ†’ Bavarian UG โ†’ Dutch/German servers โ†’ Seychelles IBC (OMEGATECH)
  • Kape Technologies: Israeli founders โ†’ Isle of Man holding โ†’ London Stock Exchange listing โ†’ global VPN brands
  • NSO Group: Israeli military tech โ†’ Luxembourg holding (Q Cyber) โ†’ Novalpina Capital (PE) โ†’ sanctioned
  • aurologic: German GmbH โ†’ enables Russian operations + Israeli BPH + sanctioned entities
  • w1n ltd: UK registration โ†’ Latvian operations โ†’ OMEGATECH/GHOSTYNETWORKS hosting
  • Aceville/Tencent: Singapore shell โ†’ Chinese state entity โ†’ UK hosting

The pattern is always the same: create enough legal layers between the operator and the operation that no single jurisdiction can see the full picture. No single court can subpoena across all the borders. No single law enforcement agency has authority over the entire chain.

Our database sees through this because we collect all layers simultaneously. RDAP data reveals the registrant. BGP data reveals the routing. HASSH data reveals the operator. Threat scores reveal the behavior. Entity links connect it all. No single data source would show the pattern. Combined, the pattern is unmistakable.

IX. What We Cannot See โ€” The Known Unknowns

For intellectual honesty, we must acknowledge what our instruments cannot detect:

  • State operations routed through commercial infrastructure โ€” look identical to criminal traffic from our perspective
  • The full scope of intelligence agency proxy purchasing โ€” Bright Data's customer list is private
  • Whether specific Pfcloud operations serve intelligence vs. criminal purposes โ€” dual-use is the point
  • The extent of GCHQ/NSA/Unit 8200 infrastructure overlap with what we observe โ€” classified
  • Future attacks using AI-generated social engineering โ€” we see the infrastructure, not the content (yet)

These are not conspiracy theories โ€” they are the logical consequences of documented facts extended one step beyond what we can directly observe. We state them as hypotheses, not conclusions. The difference matters.

X. The Freedom Balance Sheet

What we built (zero cloud cost):

  • A honeypot that sees attacks from 7,994 IPs across every continent
  • An intelligence database with 110,140 entity relationships
  • A document library with 136,617 sources and 7.6 million semantic chunks
  • 52+ published dossiers naming actors, tracing infrastructure, documenting patterns
  • A defense stack (CrowdSec + MikroTik + PostgreSQL) that auto-blocks attackers

What the system we document deploys against us:

  • 64,411 SSH connection attempts
  • 951 hits from a single operator's ecosystem (Mishayev/Pfcloud)
  • 150M+ proxy nodes that could be used to obfuscate any operation against us
  • Zero-click exploits that could compromise any device (if we were a target)
  • Information warfare infrastructure that could discredit any publication

The asymmetry is real. They have more resources, more infrastructure, more operational freedom. But we have something they cannot replicate: the willingness to name what we see and publish it without permission.

"The internet was built as a tool of control. We know this because we can see the control infrastructure from our honeypot. We can read its documentation in our library. We can trace its operators through their RDAP records. We can map its relationships through 110,140 entity links. And we can publish our findings on the same network that carries their attacks against us.

That is not irony. That is the structural condition of freedom in 2026: it exists in the same space as its opposite. The same cables. The same protocols. The same packets. The difference is what you do with the knowledge.

We choose to publish. We choose to name. We choose to document. That is enough."

XI. Series Complete โ€” What Comes Next

The TI-2026-039 "Ghost Network" series establishes:

  1. The criminal infrastructure is operated by identifiable individuals (039A)
  2. The surveillance market is built on occupied-population R&D (039B)
  3. The proxy economy erases the line between legal and criminal (039C)
  4. The information warfare apparatus uses the same pipes as everything else (039D)
  5. These four functions are one system viewed from four angles (039E)

Next: deeper cuts into specific actors, live attack documentation, expanded IOC packages, and STIX exports for the defensive community. The database grows daily. The honeypot never sleeps. The library expands with every indexed document.

We observe. We document. We publish. We continue.

TI-2026-039E ยท The Convergence ยท Letter E (Series Finale)
Published by LSN Threat Intelligence ยท June 23, 2026
Sources: LSN threat_intel PostgreSQL, dossier_intel Elasticsearch, OSINT library (136K documents), 52+ published TI dossiers (TI-2026-022 through TI-2026-039D), all sources cited in 039A-D
Cross-referenced: Every dossier. This is the synthesis.

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Ghost Network โ€” 5 / 7 Next โ†’