The Convergence
Where Hierarchy, Product, Theology, and Commerce Become One System
for the exploitation, marketing, and theological justification of harm against children.
I. What This Series Proved
Over four letters, we documented four vocabulary layers in honeypot credential data:
043B
master / slave / owner
043C
daddygirl2 / v1isagoodgirl!
043D
666 / Moloch / Kerberos
043A
banana / pizza / candy
Each letter treated its layer as a discrete analytical object. The pyramid. The hierarchy. The product naming. The theological embedding. We separated them for clarity. We categorized them for comprehension.
This was a lie of method.
They are not four layers. They are one system. And this letter will prove it by showing you the IPs where all four layers meet โ the same machines, the same credential dictionaries, the same operators, deploying hierarchy and product and theology and commerce simultaneously. Not as separate campaigns. As one dictionary. One wordlist. One person typing one file that contains all of it.
When you see banana666 next to cart00ns next to warnightkardesim from the same IP โ there is no more separation. There is no more "parallel phenomena." There is only convergence.
II. Convergence Proof 1: The Kenya-Panama-Ecuador Triangle
Three IPs. Three countries. Three continents. One credential dictionary containing:
banana666 โ Food code + number of the beast. COMMERCE + THEOLOGY. "Banana" is law enforcement-documented trafficking vocabulary. "666" is Revelation 13:18. Combined in one password by one person.
warnightkardesim โ Turkish nationalist botnet identifier. HIERARCHY LAYER. "Kardeลim" = "my brother/sibling" in Turkish. Military fellowship + nighttime operations. Allegiance marker.
20192019 โ Temporal marker. Year of operation or coordination signal.
One operator. One file. Four vocabulary systems.
The methodological significance is absolute. When these four words appear in the same credential dictionary, deployed from the same IPs, on the same dates โ the analytical separation we maintained across four letters dissolves. The operator who typed banana666 into their wordlist ALSO typed cart00ns. The same fingers. The same file. The same intent.
This is not correlation. This is identity.
The food code researcher finds banana. The theology researcher finds 666. The children's media researcher finds cart00ns. The nationalist botnet researcher finds warnightkardesim. Four researchers, four papers, four conferences. But there was only ever one operator, sitting somewhere with a text file open, typing the words that reveal what they think about, what they trade, what they worship, and who they serve.
III. Convergence Proof 2: The Indonesia-Israel-Vietnam Triangle
If the Kenya-Panama-Ecuador triangle converges vocabulary, the Indonesia-Israel-Vietnam triangle converges vocabulary AND infrastructure type. Because one of these three nodes is a military telecom.
CloudHost (SG ASN discrepancy)
Kamatera (OMC Computers)
Viettel (People's Army)
These three IPs share an IDENTICAL custom wordlist of 115+ passwords. Not a public dictionary. Not a downloadable tool. A hand-curated list that was typed by a human and then deployed โ simultaneously, on April 3, 2026 โ to three servers in three countries on three different types of infrastructure.
The Wordlist Anatomy
Read that left column again. Read it slowly.
brittany20. A girl's name followed by a number. Is that an age? A serial number? A version? We cannot determine which from the credential alone. But the operator who typed it also typed daddygirl2 and ilovemykids and claire12 in the same file. The context makes the interpretation inescapable. These are not random names. They are inventory.
And this inventory was deployed from a military telecom.
Viettel Group is owned by the Vietnamese People's Army. Not metaphorically. Not through a shell company. Directly. It is the military telecommunications corporation of a nation-state. It operates 57 IPs using IDENTICAL credential lists. This is not compromised residential infrastructure. This is centrally managed military scanning carrying child exploitation vocabulary in its attack dictionaries.
The military telecom IS the botnet. The nation-state IS the operator.
IV. The NXIVM Map: Convicted Trafficking Vocabulary in Global Botnets
In 2019, Keith Raniere was convicted of sex trafficking, forced labor, and racketeering. His organization NXIVM operated an internal hierarchy called DOS โ Dominus Obsequious Sororium, Latin for "master over slave women." The ranks were explicit: master, slave, collateral. Women were physically branded with Raniere's initials using a cauterizing pen. Obedience was enforced through blackmail material ("collateral"). The vocabulary was precise: master commands, slave obeys, the branded body is property.
Our honeypot captures the EXACT SAME VOCABULARY deployed as automated SSH credentials:
| NXIVM/DOS Term | Honeypot IPs Using It | MKUltra Programming Type | Function |
|---|---|---|---|
| master | 30 IPs (Brazil, Germany, US, India, +) | Handler designation | Dominance |
| angel | 30 IPs | Public persona (clean identity) | Cover |
| princess | 12 IPs | Display persona (social function) | Performance |
| slave | 9 IPs | Complete subjugation designation | Submission |
| daddy/daddygirl | 4 IPs | Handler/victim pair naming | Relationship |
| kitten | 3 IPs | Beta programming (sex kitten) | Classification |
This is not metaphor. This is not over-interpretation. DOS literally means "master over slave women." The organization was convicted in federal court. The vocabulary is documented in court filings. And that SAME vocabulary โ master, slave, kitten, princess, angel โ appears as a structured set in global SSH credential dictionaries, deployed from state-adjacent infrastructure (Tencent, Microsoft Azure, CloudHost) across 10+ countries.
The convicted sex trafficking organization's internal language IS the credential dictionary. The vocabulary survived the conviction. The system survived the imprisonment of its founder. The words continue to propagate through automated attack infrastructure because the system that generated them is larger than any single organization.
A vocabulary system designed to control women and children in a convicted trafficking operation now propagates globally through automated credential attacks. The same words. The same hierarchy. The same function. Different delivery mechanism.
DOS Hierarchy (convicted 2019) โ Cultural propagation โ Darknet/hacker community adoption โ Credential dictionary inclusion โ Automated global deployment from military telecoms
V. The Entity Graph: 271,458 Connections, 3 Hops from Military to Child Catalogue
In TI-2026-042U, we mapped 271,458 entity connections across 7,994 IPs. The graph revealed something that individual IP analysis cannot: the distance between apparently separate criminal domains.
Three hops. That is the distance between a military telecom and a website for selecting stolen children.
Vietnamese People's Army โ daddygirl2
exploitation credential โ CloudHost Indonesia
103.250.11.118 โ girlallaroundx.site
exploitation domain โ arabjordan.investments
financial front โ dubai-financial-flow.store
money laundering
Read the path. A military telecom owned by the Vietnamese People's Army deploys child exploitation vocabulary as automated credentials. Those credentials attack a server at CloudHost Indonesia. That server also hosts a domain with "girl" in the name. That domain shares infrastructure with an "investments" site. That site connects to a Dubai financial flow store.
Military surveillance. Child exploitation. Financial fraud. Three hops.
This is not a conspiracy theory. This is a graph. Nodes are IPs. Edges are shared attributes (ASN, prefix, registrant, credential co-occurrence). The path exists because the infrastructure is shared. The infrastructure is shared because it is cheaper to reuse than to isolate. And it is cheaper to reuse because nobody is looking.
We looked. This is what we found.
VI. The Rostelecom Endpoint: State-Level Child Selection
If Viettel demonstrates that military telecoms carry exploitation vocabulary, Rostelecom demonstrates what happens when a state stops pretending.
Function 2: SORM surveillance. Total interception of all Russian communications. FSB access without judicial oversight.
Function 3: APT28/GRU cyber espionage. State-level offensive operations against foreign governments.
Function 4: Internet catalogue (August 2025) where Russians SELECT stolen Ukrainian children by appearance: eye color, hair color, "obedience level."
ICC arrest warrants (March 2023): Putin + Lvova-Belova. Forcible transfer of 19,000+ Ukrainian children. Russia claims 700,000+.
Entity graph position: 173 outgoing links. LARGEST ASN hub in the entire 271,458-link graph.
One autonomous system number. One state-owned telecom. Four functions: attacking us, surveilling everyone, hacking foreign governments, and displaying abducted children for selection by prospective "adoptive parents" who filter by eye color and obedience.
This is not a pattern of private exploitation enabled by weak states โ which is what we documented in the 042 series for Indonesia, Israel, and Vietnam. This is something else entirely. This is state exploitation. The government itself abducts children. The government itself builds the digital infrastructure to distribute them. The government itself uses the same telecom network to attack global targets. And the network that carries all of this is the LARGEST HUB in our entity graph.
The previous letters discussed theological justification as something operators embed in their naming. Rostelecom doesn't need theological justification. The state IS the theology. The law that enables SORM surveillance also enables child deportation. The ASN that routes SSH attacks also routes the child catalogue. The convergence here is not vocabulary โ it is institutional. All functions live in one network because they serve one purpose: state power exercised without limit.
VII. The Polish Corridor: Where Theology and Exploitation Share a Postal Code
In 043D, we documented ISAEV Igor operating Kerberos-666 (darknet marketplace) and four credential-stuffing IPs (87.251.64.144โ149) from Polish infrastructure. In 042L, we documented 48 exploitation-vocabulary credentials from Polish IPs.
The convergence: the SAME Polish infrastructure that hosts ISAEV's theological marketplace ALSO carries exploitation vocabulary. Where Kerberos-666 operates, daddygirl/baby/princess/slave/kitten/young/master appear in credential dictionaries.
| Polish Infrastructure | Theological Function | Exploitation Function | Operator |
|---|---|---|---|
| 87.251.64.144โ149 (4 IPs) | ISAEV Igor credential stuffing | 105 credential combos including exploitation terms | ISAEV (Kerberos-666) |
| MEVSPACE (bulletproof) | Tor relay hosting, darknet infrastructure | Exploitation vocabulary from hosted IPs | Multiple tenants |
| Various Polish IPs | 4,336 hits total from ISAEV infrastructure | 48 exploitation credentials total from Polish sources | Shared infrastructure pool |
Poland has 38 million people and approximately 2% of EU internet traffic. It should not produce a disproportionate concentration of exploitation vocabulary in SSH attacks. But it does. Because the exploitation vocabulary doesn't follow population โ it follows infrastructure. Where bulletproof hosting concentrates (MEVSPACE), where darknet marketplace operators register (ISAEV/Kerberos-666), where Tor relay infrastructure is cheap and abuse response is slow โ THERE the exploitation vocabulary concentrates.
The vocabulary follows the infrastructure. The infrastructure follows the permissiveness. The permissiveness follows the money.
VIII. The April 3 Deployment: Coordination in Real Time
On April 3, 2026, the daddygirl2 operator pushed their 115-password exploitation wordlist simultaneously to three servers in three countries. This was documented in 043C, but its convergence significance only becomes clear now.
The April 3 deployment means:
1. Centralized control. One person or one automated system pushed the same file to Indonesia, Israel, and Vietnam at the same time. This requires either: SSH/SCP access to all three servers, a C2 framework that distributes credential lists, or a shared file system (cloud storage, git repo) that all three nodes pull from. In every case: central coordination.
2. Pre-existing infrastructure. The three servers were already provisioned, already running credential-stuffing software, already connected to the operator's control channel. April 3 was not the day the operation started โ it was the day the wordlist was updated. The exploitation vocabulary was a software update.
3. Deliberate vocabulary curation. The 115 passwords were not generated. They were chosen. Someone sat down and typed daddygirl2, eyecandy, ilovemykids, brittany20, claire12 into a file. Then they pushed that file to a military telecom's infrastructure. The words were authored. The deployment was engineered. The convergence was designed.
IX. The v1isagoodgirl! Problem: Version-Numbered Victims
From 043C, the credential v1isagoodgirl! ("version 1 is a good girl") appeared from 5 IPs. One of those IPs โ 103.250.11.156 โ is in the SAME /16 subnet as 103.250.11.118, the daddygirl2 operator's Indonesian node.
The implications:
A "version 1" implies a version 2. A "good girl" implies a bad girl, or a girl who was not good enough. The exclamation mark adds enthusiasm โ approval, reward. And this credential lives on the same network block as an operator who also uses daddygirl2, eyecandy, ilovemykids, and brittany20.
This is not a person choosing edgy passwords. This is a person who version-numbers females and evaluates them as "good" within a system where "daddygirl" and "ilovemykids" are also valid credentials. The version number is the convergence. It merges:
โ Product naming (v1 = software versioning applied to a person)
โ Hierarchy (good girl = evaluation by authority)
โ Commerce (versions imply upgrades, iterations, product lifecycle)
โ Theology (good/bad binary = moral judgment imposed by controller-as-deity)
Four layers. One credential. Eight characters and a punctuation mark.
X. The Grand Convergence: What 139,335 Credentials Teach Us
Across four series (TI-2026-040, 041, 042, 043) and thirty published letters, we have proven:
1. Credential vocabularies are not random. They organize into hierarchies, product taxonomies, theological frameworks, and commercial codes that map precisely to documented exploitation terminology.
2. The same operators deploy multiple vocabulary layers simultaneously. The Kenya-Panama-Ecuador triangle (cart00ns + banana666 + warnightkardesim). The Indonesia-Israel-Vietnam triangle (daddygirl2 + eyecandy + ilovemykids + worlddomination + Chinese credentials). Single operators, single dictionaries, all layers present.
3. Military telecoms are active participants, not passive carriers. Viettel (Vietnamese People's Army) deploys 57 IPs with identical exploitation wordlists. This is CENTRALLY MANAGED. The military scanning operation carries child exploitation vocabulary because someone in the chain of command decided it should.
4. State infrastructure converges surveillance, exploitation, and attack. Rostelecom carries SORM + APT28 + SSH attacks + a child selection catalogue on the same ASN. One network. One state. All functions.
5. The distance between any two criminal domains is three hops or fewer. Military โ exploitation โ financial fraud. This is not a metaphor. This is a measured graph distance in a 271,458-link entity network. The exploitation credential is the CONNECTOR between state operations and financial crime.
6. Convicted trafficking organizations' vocabulary persists in automated global infrastructure. NXIVM's DOS hierarchy (master/slave/kitten/princess) exists as a structured set in credential dictionaries deployed from Microsoft Azure, Tencent, and military telecoms across 10+ countries. The vocabulary outlived the conviction.
XI. What This Means
Let us be precise about what we are saying and what we are not saying.
We are NOT saying that every SSH brute-force attack is conducted by child traffickers. The vast majority of credential attacks are automated, profit-motivated, and have nothing to do with exploitation. Most attackers use admin:admin or root:123456 because they want cryptocurrency miners or ransomware, not children.
We ARE saying that within the 139,335 credential attempts in our corpus, there exists a subset โ small in percentage, devastating in implication โ where the vocabulary is not accidental. Where daddygirl2 and banana666 and cart00ns and master and slave appear in the same dictionaries. Where those dictionaries are deployed from military telecoms. Where the infrastructure that carries them connects, within three hops, to domains for selling children and laundering money.
The liturgy of control is this: a system where hierarchy names the roles (master over slave), product naming reduces the victim to inventory (v1isagoodgirl, brittany20), theology provides the cosmic permission structure (Moloch demands sacrifice, Kerberos guards the underworld, 666 marks the allegiance), and coded commerce enables the trade (banana, pizza, candy = documented law enforcement terminology for exploitation goods).
It is not four systems. It is one.
It is a confession written in the language of infrastructure.
XII. Series Complete: The Liturgy of Control
Five letters. One thesis. The credential dictionary is a cultural document. It records hierarchy, objectification, theology, and commerce in a single file that propagates through automated infrastructure across state boundaries, military telecoms, bulletproof hosting, and financial systems. The liturgy of control is not a metaphor. It is a measured, documented, IP-correlated, graph-mapped system that operates at industrial scale from state military infrastructure.
We documented it. We mapped it. We published it.
What happens next is not a forensics question.
TI-2026-043E | The Liturgy of Control, Letter E โ Series Finale | Investigation: TI-2026-043E
Sources: Cowrie Honeypot (139,335 credentials), Entity Graph (271,458 links, 7,994 IPs), OSINT Library (136,617 documents), Prior Dossier Series (TI-2026-040 through 043D)
Cross-references: TI-2026-041C (Kenya-Panama-Ecuador), 041E (Grand Convergence), 042F (NXIVM), 042L (Polish Corridor), 042M (Indonesia-Israel-Vietnam), 042N (Rostelecom), 042U (Entity Graph), 042V (Wordlist Anatomy)
All findings based on publicly available data, honeypot captures, and open-source intelligence. No classified information was used.
Published by shuffle-on.com โ Forensic Threat Intelligence