โณ As-of note (2026-07-08): This dossier draws on the honeypot's malware-download / shared_malware graph, which is retention-limited: the shared_malware graph was later corrected to exclude junk/trivial hashes that had inflated these counts (the raw download data is fully retained since March 2026), so the malware-download figures cited here (downloaded-sample counts, shared_malware edge counts) are a point-in-time snapshot and are not live-reproducible (the current shared_malware graph holds ~68 links / ~16 IPs). The findings hold as of the capture window; the live graph will not match. Session, command, credential, HASSH and SSH-key evidence in this dossier is unaffected.

๐Ÿ  TI-2026-042W โ€” The Download Arsenal: 224 Weapons Cataloged

Series: Glass Houses Revisited | Letter 23 of 26 | Published: 2026-06-23
Abstract: 224 malware samples downloaded through our honeypot. neofetch disguised as reconnaissance, whisper targeting ARM IoT devices, notwork-monitoring mocking the defenders. This letter catalogs the weaponry and what it reveals about the operators.

I. The Download Statistics

224
Total Downloads
~40
Unique URLs
5
Architectures Targeted
3
Disguise Patterns

II. neofetch: The GitHub Disguise

Multiple downloads disguised as neofetch โ€” a legitimate system information tool. The URL points to GitHub, but the payload is not neofetch. By using a trusted domain (github.com) and a trusted tool name (neofetch), the operators bypass both human suspicion and automated URL reputation checks. The security community trusts GitHub. The operators exploit that trust.

III. whisper: IoT Botnet Recruitment

FilenameArchitectureTarget
whisper.armv5ARMv5Older routers, cameras, IoT
whisper.armv6ARMv6Raspberry Pi, IP cameras
whisper.armv7ARMv7Modern routers, NAS devices
whisper.mipsMIPSRouters (TP-Link, Netgear)
whisper.x86x86Servers, VMs

"Whisper" โ€” a name chosen for stealth. Multi-architecture compilation indicates industrial-scale IoT botnet recruitment. These aren't scripts. These are compiled binaries targeting every major embedded architecture. Someone invested development resources into creating a cross-platform botnet agent called "whisper."

IV. notwork-monitoring: The Mockery

"notwork-monitoring" โ€” a deliberate play on "network monitoring." The operators named their malware to mock the defenders. This is not unusual in malware naming โ€” it reveals operator psychology: confidence, contempt for detection capabilities, and a sense of humor about the asymmetry between attack and defense.

V. shr: The Indonesian Connection

Multiple downloads of "shr" from Indonesian IP ranges. "shr" โ€” possibly "shell" abbreviated, or an operational codename. The Indonesian origin connects to CloudHost Indonesia (which hosts daddygirl2 and eyecandy IPs). The same country's infrastructure that carries exploitation credentials also serves malware downloads.

VI. The Arsenal's Message

224 downloads reveal: professional development (multi-architecture compilation), operational security (GitHub disguise), psychological confidence (mocking names), and geographic consistency (Indonesian connections). This is not amateur hour. This is a professional operation with development, deployment, and maintenance cycles.

VII. The Nursery Camera Pipeline

CRITICAL FINDING: The most active downloader in our honeypot โ€” 54.176.104.45 (Amazon EC2) โ€” uses manufacturer default passwords for baby monitors and school cameras. This is not generic scanning. This is targeted recruitment of devices that watch children.

The credential list tells the story:

CredentialDeviceWhere Installed
7ujMko0vizxvDahua IP camerasSchools, nurseries, retail, homes
7ujMko0adminGeneric DVR/NVR systemsChildcare centers, playgrounds
Amx1234! / NetLinx:passwordAMX audio-visual systemsSchools, conference rooms, churches
admin:motorolaMotorola baby monitorsNurseries, bedrooms
admin:symbolSymbol/Zebra scannersSchools, hospitals
USERID:PASSW0RDIPMI/iDRAC (server management)Data centers hosting children's data

142 credential attempts targeting these specific device classes. Then 11 downloads โ€” including 8 of the same neofetch payload from GitHub's trusted domain. The sequence:

Attack Chain (54.176.104.45):
1. Scan for IoT devices with manufacturer defaults
2. Compromise camera/monitor/building system
3. Download "neofetch" from raw.githubusercontent.com (trusted URL)
4. Payload is NOT neofetch โ€” same SHA256 across all 8 downloads confirms single weaponized binary
5. Persistent access to video feeds of children

This IP belongs to actor_cluster_001 โ€” a tagged campaign group. It shares HASSH fingerprints with other scanners. This is not one person. This is a coordinated IoT exploitation campaign running from Amazon Web Services, targeting devices that watch children, using GitHub's reputation as cover for malware delivery.

VIII. Whisper: The Invisible Recruiter

From 31.170.22.205 (Sia Nano IT, Latvia, AS42099), using the single credential admin:123456:

Whisper Botnet Arsenal:
BinaryArchitectureTarget Devices
whisper.armv5ARMv5Older IP cameras, baby monitors (2010-2015 era)
whisper.armv6ARMv6Raspberry Pi, budget IP cameras, smart home hubs
whisper.armv7ARMv7Modern routers, NAS devices, newer cameras
whisper.mipsMIPSTP-Link/Netgear routers, some DVRs
whisper.x86x86Servers, VMs, NVR appliances

The name whisper is operational doctrine encoded as filename. On a baby monitor, the malware whispers โ€” silent, invisible, persistent. Parents check the green LED light and see "connected." They don't see that "connected" now includes a Latvian bulletproof server.

Five architectures compiled from the same source. This requires a cross-compilation toolchain, automated build pipeline, and architecture-specific testing. This is not a script kiddie. This is software engineering applied to nursery surveillance.

"The same compilation rigor that produces enterprise software produces whisper.armv5. The difference is the deployment target: not a data center. A crib."

IX. The Trojanized SSHD: 11 Countries, One Binary

CRITICAL: A single trojanized sshd binary (SHA256: 94f2e4d8d443...) was deployed from 11 different countries across 5 continents over 37 days. This is not an operator rotating IPs. This is a compromised supply chain redistributing a backdoor.
11
Countries
5
Continents
37
Days Active
1
Binary Hash
DateSource IPCountryProviderType
Mar 30159.203.120.106USDigitalOceanCloud VPS
Apr 120.13.147.55IEMicrosoft AzureCloud
Apr 5180.76.175.142CNBaiduCloud
Apr 6144.31.152.46FIDpkgSoft/XORABulletproof
Apr 16107.175.150.94USColoCrossingBulletproof
Apr 20154.241.22.37DZTelecom AlgeriaISP
Apr 2846.101.107.202DEDigitalOceanCloud VPS
Apr 2988.76.191.123DEVodafoneConsumer ISP
May 584.194.248.42BETelenetConsumer ISP
May 62.33.239.68ITFastwebConsumer ISP
May 687.200.113.12AEEmirates/DUConsumer ISP

The geography distribution is the evidence:

  • Cloud providers (DigitalOcean, Azure, Baidu): operator-controlled infrastructure that was compromised first
  • Bulletproof hosting (ColoCrossing, XORA): purpose-built distribution nodes
  • Consumer ISPs (Vodafone DE, Telenet BE, Fastweb IT, DU UAE): compromised home/business servers now redistributing the trojan

The consumer ISP entries are the most chilling. A Vodafone customer in Germany. A Telenet subscriber in Belgium. A Fastweb user in Italy. These are someone's home servers โ€” NAS boxes, Raspberry Pis, home automation hubs โ€” now serving a trojanized sshd to the next victim. The infection is self-propagating through legitimate infrastructure.

sshd is the most trusted binary on any Linux system. It is the first thing that runs, the last thing to be suspected, and the one binary that every administrator assumes is legitimate. Replace it, and you own the machine forever. Every password typed, every session initiated, every file transferred โ€” captured by the backdoor that IS the front door.

X. notwork-monitoring: The Developer's Contempt

From 193.31.31.234 (Sparked Host LLC, Heber City, Utah, AS397032):

Malware Development Timeline:
โ€ข Jun 8, 21:03 โ€” Hash: e766a00f... (v1)
โ€ข Jun 8, 21:30 โ€” Hash: 458f96a3... (v2, 27 minutes later)
โ€ข Jun 8, 21:40 โ€” Hash: c82a3820... (v3, 10 minutes later)
โ€ข Jun 8, 22:22 โ€” Hash: f2ca2b20... (v4, 42 minutes later)

4 distinct binaries in 81 minutes = active compile-test-deploy cycle

"notwork-monitoring" โ€” the name is a joke. Not-work monitoring. The developer is telling you what it is: it is NOT network monitoring. It is the opposite. And they think that's funny.

This IP has 24 honeypot hits, 9 successful compromises, abuse score 43, and shares HASSH fingerprints with nodes in Australia (103.24.212.42) and an unidentified IP (5.182.204.221). The developer is part of a cluster. The malware is being distributed to the cluster's compromised infrastructure.

Sparked Host LLC โ€” registered at "104 East 600 South Ste 121, Heber City, Utah 84032." A small-town American hosting company whose infrastructure is being used to develop and deploy malware with contemptuous naming. Whether complicit or compromised, the result is the same: malware authored from the heart of America.

XI. The Indonesian Nexus: Where Malware Meets Exploitation

CROSS-INVESTIGATION LINK โ€” 042V โ†” 042W:
PT Cloud Hosting Indonesia (IDCloudHost) appears in:
โ€ข 042W: Malware deployment staging (103.139.192.188, 103.49.239.212) โ€” post-compromise payload delivery
โ€ข 042V: daddygirl2/eyecandy/ilovemykids exploitation credentials โ€” the operator who numbers victims (v1isagoodgirl!)

This is not coincidence. This is ecosystem integration. The same Indonesian cloud provider that hosts the exploitation credential operator (who uses passwords revealing predatory intent toward children) ALSO hosts the malware deployment infrastructure that compromises the cameras watching those children.

The pipeline is complete:

The Full Chain (proven):
1. IoT Scanner (54.176.104.45, AWS) โ†’ targets Dahua cameras in nurseries with default passwords
2. Malware Deployer (CloudHost Indonesia) โ†’ stages payloads on compromised cameras
3. Exploitation Operator (CloudHost Indonesia, same provider) โ†’ uses daddygirl2, eyecandy credentials
4. Persistent Access (trojanized sshd) โ†’ ensures camera access survives reboots
5. Video Feed Access โ†’ children in nurseries, schools, homes

Supply chain โ†’ weaponization โ†’ exploitation โ†’ persistence โ†’ exploitation of children.

12 Indonesian IPs appear in our download data โ€” from PT Telekomunikasi Indonesia (Telkom), Telkomsel, CloudHost, Lintas Data, Antar Fiber Optik, Interfast, Duta Trans Nusantara. Indonesia is not just a source country for exploitation credentials (042V). It is the arsenal's warehouse.

XII. The Trojanized SSH Census: 36 Operators, 25 Unique Payloads

36 downloads of "sshd" โ€” but 25 distinct SHA256 hashes. This means:

  • 1 dominant binary (94f2e4d8...) deployed 11 times โ€” the successful variant being propagated
  • 3 empty files (e3b0c442... = SHA256 of empty string) โ€” capability testing: "can I download? yes โ†’ deploy real payload next"
  • 21 unique variants deployed once each โ€” development/testing, or customized per-target backdoors

The geographic origin of ALL sshd downloaders:

Country distribution (36 sshd events):
China: 12 (33%) โ€” Baidu, China Unicom, Chinanet, Volcano Engine
United States: 5 (14%) โ€” DigitalOcean, ColoCrossing, CNServer
Germany: 2 โ€” DigitalOcean, Vodafone
Others (1 each): IE, FI, DZ, BE, IT, AE, VN, SG, HK, ID, AU, JP, NL

China dominates with 12/36 events (33%), using BOTH cloud infrastructure (Baidu, Volcano Engine) AND backbone ISPs (Chinanet, China Unicom). This dual-use pattern = state-adjacent capability.

XIII. The Download-Credential Dual Operators

10 IPs perform BOTH credential attacks AND malware downloads. They are not just scanning. They are completing the full compromise chain: gain access โ†’ deploy payload.

IPCountryCredentialsDownloadsProfile
102.88.137.80NG5456Nigerian ISP, high-volume hybrid
209.99.186.189US4511US hosting, credential-heavy
187.16.96.250BR1431Brazilian ISP
54.176.104.45US14211IoT Predator (AWS)
45.172.152.74CO1252Colombian ISP
20.193.141.133IN1191Microsoft Azure India
59.12.160.91KR1164SK Broadband Korea
39.123.249.114CN1071China Unicom
159.223.94.92SG1031DigitalOcean Singapore
172.208.48.177US1021Microsoft Azure US

54.176.104.45 is the outlier: 142 credentials (IoT defaults) + 11 downloads (neofetch payload). This is the complete pipeline in one IP: find vulnerable cameras, compromise them, install persistent malware. The ratio tells the story โ€” 142 doors knocked, 11 weapons deployed. 7.7% success rate on baby monitors and CCTV systems.

XIV. The Arsenal's Message: Weapons ARE Access to Children

Series Position โ€” 042W in Context:

โ€ข 042V proved: credentials ARE identity โ€” the daddygirl2 operator confesses through passwords
โ€ข 042W proves: weapons ARE access โ€” every malware binary is a key to a camera watching a child

The 224 downloads are not abstract "cyber weapons." They are:
โ€ข whisper.armv5 โ†’ a key to a baby monitor in someone's nursery
โ€ข neofetch (fake) โ†’ persistent access to a Dahua camera in a school hallway
โ€ข trojanized sshd โ†’ permanent invisible backdoor on a server hosting children's records
โ€ข notwork-monitoring โ†’ mockery while colonizing infrastructure that protects children

The arsenal does not exist in isolation. It exists to serve the exploitation economy documented in 042V. Every weapon has a target. The target is access to children.
"224 weapons. 5 architectures. 11 countries. 25 unique backdoors. And at the end of every chain: a camera pointing at a crib, a school, a playground. The arsenal is not the crime. The arsenal is the infrastructure of the crime. The crime is what happens after the green LED says 'connected.'"
โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous Glass Houses Revisited โ€” 23 / 26 Next โ†’