๐Ÿ  TI-2026-042L โ€” The Polish Anomaly: One Country, 48 Exploitation Credentials

Series: Glass Houses Revisited | Letter 12 of 26 | Published: 2026-06-23
Abstract: Poland: 5 IPs, 48 exploitation credentials. The most disproportionate concentration in our entire database. babygirl, babygirl1, iloveyou1, iloveyou2, dragon, love, love123. This letter examines why Poland produces this anomaly and what the Catholic Church's documented "code of silence" means for a country where 87% identify as Catholic.
5
POLISH IPs
48
EXPLOITATION CREDENTIALS
9.6
CREDS PER IP (vs 1.4 avg)

I. The Statistical Anomaly

The global average is approximately 1.4 exploitation-vocabulary credentials per IP. Poland produces 9.6 per IP โ€” nearly 7x the average. From just 5 IPs, Poland generates the densest exploitation credential concentration in our database:

  • root:babygirl, root:babygirl1 โ€” diminutive + number variant
  • root:iloveyou, root:iloveyou1, root:iloveyou2 โ€” grooming language, numbered sequence
  • root:love, root:love123 โ€” base + number variant
  • root:dragon โ€” power/control symbol
  • root:angel1 โ€” exploitation hierarchy term, numbered

The numbered variants (babygirl/babygirl1, iloveyou/iloveyou1/iloveyou2) suggest a systematic dictionary, not random passwords. Someone assembled a credential list that includes exploitation terms with numeric incrementing โ€” the pattern of an operator who has used these terms before and variations for different purposes.

II. The Catholic Code of Silence

"We should not be surprised to learn that the UN Committee on the Rights of the Child said Catholic Church officials had imposed a 'code of silence' on clerics to prevent them from reporting cases of child abuse by clergy to police and moved abusers from parish to parish."

Poland: 87% Catholic. One of the most Catholic countries on earth. The Catholic Church has documented institutional policies of concealing child abuse. In 2020, a documentary "Don't Tell Anyone" revealed the scale of clerical abuse in Poland โ€” and faced intense institutional resistance.

We do not claim that Polish IP addresses carry exploitation credentials because Poland is Catholic. We document that a country where the institution most associated with systematic child abuse cover-ups has the deepest cultural penetration ALSO produces the highest per-IP concentration of exploitation-vocabulary credentials in our data. The correlation is documented. The causation requires investigation that only Polish authorities can perform โ€” and Polish institutional culture may prevent.

III. The Geographic Context

Poland sits at the intersection of Western European demand and Eastern European supply in documented trafficking routes. The European Commission's anti-trafficking reports consistently identify Poland as both a source and transit country. The same geographic position that makes Poland a trafficking corridor also makes Polish IPs a nexus for digital exploitation infrastructure.

VII. The Monster in Polish Infrastructure: ISAEV (4,336 Hits)

87.251.64.176. One IP address. 4,336 honeypot hits. This is the single most active attacker in our entire database. Nothing else comes close.

ISAEV Igor (AS200730) โ€” The Numbers:
  • 4,336 honeypot hits from primary IP alone
  • 177 entity relationships (5 types: shared HASSH, credentials, SSH keys, OTX, RDAP)
  • 100% threat score
  • Triple geographic discrepancy: ASN = Kazakhstan, prefix = Russia, geolocation = Poland
  • 6-node attack cluster (Go scanner, HASSH eff4c24daffc8532)
  • 94% silent logins โ€” execute zero commands after successful authentication
  • RIPE identity: "Isaev Igor Maratovich, Almaty" โ€” thin public footprint, NovaHost = default Plesk page

A Kazakh identity. Russian routing. Polish infrastructure. Three jurisdictions. One operator. The largest sustained attack campaign we've ever recorded, transiting through Poland โ€” the same Poland where hundreds of thousands of people are physically trafficked annually.

VIII. What 94% Silent Logins Mean

DOSSIER-018 documented: of 17,044 successful logins in our honeypot, 16,061 (94%) execute zero commands. ISAEV accounts for 3,670 of these silent entries. They log in. They do nothing. They leave.

This is not exploitation. This is not credential testing for financial gain. This is counter-intelligence:

  • Mapping who has honeypots (identifying monitoring infrastructure)
  • Testing which credentials work where (building a database for future operations)
  • Determining response times and alerting thresholds
  • Identifying blind spots in global monitoring coverage
The Exploitation Connection: Once you know where the honeypots are, you know where they are NOT. Blind spots in monitoring are where trafficking infrastructure can operate undetected. A counter-intelligence operation of this scale (4,336 hits, mapping global honeypot coverage) produces a map of surveillance gaps. That map is operationally valuable to anyone running infrastructure that must avoid detection โ€” including trafficking operations.

IX. MEVSPACE: The Polish Enabler

MEVSPACE sp. z o.o. (AS201814) is the upstream provider that enables ISAEV's operations. Documented across five separate investigations (TI-011, TI-024, TI-025, TI-025A, TI-033):

MEVSPACE Profile:
  • Polish bulletproof hosting company
  • Provides BGP upstream for ISAEV (AS200730)
  • Hosts Windows attack workstations (195.3.220.88, Python paramiko tools)
  • 17 OTX threat intelligence pulses (known botnet infra)
  • Linked to Tor relay hosting (AS210558) โ€” noted by Tor Project
  • Operator: RIPE-registered Polish company with commercial front

Two laundering architectures: (1) ISAEV = offshore shell (thin Kazakh identity, Russian routing, darknet operations). (2) MEVSPACE = respectable front (Polish LLC, commercial website, legitimate-appearing hosting). One enables the other.

The same Polish infrastructure that provides Tor relays (anonymity for trafficking communications) ALSO provides upstream for the world's most active attack operator. Anonymity and attack capability share infrastructure because they share operators โ€” and share customers.

X. Poland as Trafficking Transit: The Physical Corridor

The OSINT Library (Sex Slaves: Human Trafficking) documents:

"Several hundred thousand people are trafficked to or within the European Union annually. Women and children are most commonly affected."

Poland's geographic position: between Eastern European source countries (Ukraine, Belarus, Moldova, Romania) and Western European destination countries (Germany, Netherlands, UK, France). Poland is the primary land transit corridor for EU-bound trafficking. The E30 motorway (Warsawโ†’Berlin) is documented as a trafficking route.

The same geographic logic applies to both physical and digital traffic:

  • Physical: Victims trafficked from Ukraine/Belarus โ†’ through Poland โ†’ to Germany/Western Europe
  • Digital: ISAEV attacks originate from Kazakhstan/Russia โ†’ transit through Poland (MEVSPACE) โ†’ target global infrastructure

Same country. Same function. Transit. The infrastructure that carries 4,336-hit attack traffic also provides Tor anonymity nodes. The Tor nodes that provide anonymity for attack operations also provide anonymity for trafficking communications. Poland is the intersection.

XI. The 48 Credentials: Vocabulary That Follows Infrastructure

48 exploitation-vocabulary credentials from Polish IP addresses: daddygirl, baby, babygirl, princess, slave, angel, kitten, young, master. Disproportionate for a country with 38 million people (0.5% of world population, ~2% of EU internet users).

Why does Poland carry exploitation vocabulary at higher density than its population would predict? Because exploitation vocabulary follows exploitation infrastructure. Where MEVSPACE provides bulletproof hosting and Tor relays, operators who deal in exploitation also concentrate. The same anonymity that protects ISAEV's counter-intelligence protects exploitation operations. The same infrastructure serves both.

Credential Correlation: root:daddygirl2 (documented in 042F/042M โ€” CloudHost Singapore/Indonesia). root:kitten (documented in 042F/042K โ€” ARTMOTION Kosovo). root:slave (documented in 042E โ€” Bosnia). root:princess (documented in 042F โ€” Microsoft Netherlands). The same exploitation vocabulary appears globally โ€” but concentrates in darknet hosting jurisdictions. Poland is one. Kosovo is another. Singapore is a third. The operators share vocabulary because they share networks.

XII. The Triple-Jurisdiction Architecture

ISAEV's operation uses three jurisdictions:

  1. Kazakhstan (identity/registration) โ€” RIPE records name "Isaev Igor Maratovich, Almaty." Kazakhstan does not cooperate with European cybercrime investigations without bilateral treaty (does not exist for Poland).
  2. Russia (routing) โ€” prefix routed through RU. Russia does not cooperate with any Western cybercrime investigation under any circumstances.
  3. Poland (physical infrastructure) โ€” EU member, NATO member, Budapest Convention signatory. Polish law enforcement CAN act. But Mevspace provides the legitimate front, ISAEV's Kazakh identity provides the deniability, and Russian routing provides the opacity.

Backup: Shesternin Vladimir Anatolievich (AS212835, Russia) โ€” named Russian individual providing BGP backup. The triangle has redundancy. When one path fails, the operation continues.

XIII. Cross-Reference: The ISAEV Network Across Investigations

ISAEV documented in:
  • DOSSIER-018 โ€” Silent Army: 3,670 silent logins, counter-intelligence finding
  • TI-2026-024 โ€” ISAEV Transit: Mevspace upstream + Shesternin backup
  • TI-2026-037A โ€” 6-node Go scanner cluster (HASSH eff4c24daffc8532)
  • TI-011 โ€” MEVSPACE as attack workstation platform
  • TI-2026-025/025A โ€” MEVSPACE bulletproof hosting profile, Tor relay context
  • CAMP-HASSHEFF4C24DAFFC85 โ€” Campaign-level HASSH cluster investigation

Six separate investigations converge on the same infrastructure. This is the most-investigated single operator in our database.

XIV. Sources and Methodology

Primary Sources:
  • LSN Honeypot โ€” PL country: 30 IPs, ISAEV entity relationships (177), HASSH cluster analysis
  • OSINT Library โ€” "Sex Slaves: Human Trafficking" (EU transit trafficking through Poland)
  • Cross-references: DOSSIER-018, TI-011, TI-2026-024, TI-2026-025, TI-2026-037A, CAMP-HASSHEFF4C24DAFFC85
  • RIPE NCC โ€” AS200730 (ISAEV), AS201814 (MEVSPACE), AS212835 (Shesternin) registrations
  • BGP analysis โ€” upstream relationships, prefix routing, geographic discrepancy mapping
Methodology: Honeypot data via Cowrie SSH/Telnet trap. HASSH fingerprinting for client identification. Entity relationships via shared HASSH, SSH keys, credentials, OTX pulses, RDAP organizations. BGP upstream analysis via route prefix and transit relationships. Silent login pattern detection (94% zero-command sessions). Credential vocabulary correlation across countries.
โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous Glass Houses Revisited โ€” 12 / 26 Next โ†’