TI-2026-043 โ€” THE LITURGY OF CONTROL
043A 043B 043C 043D 043E 043F 043G 043H 043I 043J

TI-2026-043F

The Programming Manual

Series: The Liturgy of Control (TI-2026-043)
Classification: TLP:WHITE โ€” Public Release
Published: 24 June 2026
Investigation: TI-2026-043F
Data Source: PostgreSQL honeypot database via pentesting-v2 MCP API
Evidence Items: 12 (IDs 8753โ€“8764)
Actors: 5 | Infrastructure: 8 | Connections: 5 | Findings: 6

Executive Summary

In 1973, CIA Director Richard Helms ordered the destruction of all MKUltra files. Twenty thousand pages survived โ€” misfiled in the agency's financial records office. Four years later, in 1977, the United States Senate held hearings on what those pages revealed: a systematic program of human experimentation involving LSD, sensory deprivation, hypnosis, sexual abuse, and the deliberate creation of dissociative identities in unwilling subjects, many of them children.

The files were destroyed. The program was officially terminated. But something survived that no shredder could reach: the vocabulary.

This dossier documents a finding that should disturb anyone who reads it carefully. 270+ credential entries in our honeypot corpus โ€” captured from automated SSH scanning botnets probing infrastructure worldwide โ€” use precise terminology from MKUltra and its successor program, Monarch. Not similar words. Not approximate matches. The exact vocabulary of a Senate-confirmed CIA mind control program, deployed as operational code in criminal scanning infrastructure fifty years after Director Helms lit the match.

Critical Finding

The credential dictionary is not a random word list. It is a structured document with categories, levels, and vocabulary that maps precisely to a Senate-confirmed CIA program. alice = dissociative programming. kitten = Beta/sexual programming. matrix = base program. trigger = activation command. ghost = self-destruct. The programming manual was declassified. The programming continues.

All credential data in this dossier was sourced from the PostgreSQL honeypot database via the pentesting-v2 platform MCP API (sec_intel_search, honeypot_ip_dossier, honeypot_asn_dossier tools). No deprecated data sources were used.


I. The Declassified Program

BLUEBIRD โ†’ ARTICHOKE โ†’ MKULTRA โ†’ MKSEARCH

The lineage is documented. Not alleged โ€” documented. In the Senate hearing transcripts that sit in our OSINT library, the progression reads like version control for human suffering:

Evidence โ€” MKUltra Senate Hearing 1977

Project BLUEBIRD (1950): Defensive interrogation techniques. Project ARTICHOKE (1951): Offensive mind control. Project MKULTRA (1953): 149+ subprojects across 80+ institutions. Project MKSEARCH (1964): Continuation under new name after initial exposures. Director Helms ordered files destroyed in 1973. Senator Church's committee documented human experimentation without consent โ€” on US citizens, on prisoners, on mental patients, on children.

Source: MKUltra_Senate_Hearing_1977.pdf โ€” OSINT Library (Conspiracy & Alternative Perspectives)

The 149 subprojects included experiments with LSD, mescaline, barbiturates, heroin, MDMA, psilocybin, scopolamine, cannabis, and sodium pentothal. They included sensory deprivation, electroshock, hypnosis, isolation, verbal and sexual abuse, and โ€” critically for our purposes โ€” the systematic creation of dissociative identity states using a combination of trauma, drugs, and repetitive symbolic conditioning.

The conditioning used vocabulary. Specific vocabulary. The handlers needed words that would function as triggers โ€” activation commands that could switch between programmed identities. They chose words from children's literature, fairy tales, and religious mythology. Words that could be spoken in public without arousing suspicion. Words that a child would already know.

Alice. Rabbit. Mirror. Kitten. Angel. Princess. Puppet. Ghost.

In 1973, Helms destroyed the files. He could not destroy the words.

Operation Midnight Climax

Whitney Webb's "One Nation Under Blackmail" โ€” both volumes are in our OSINT library โ€” documents MKUltra Subproject 42, which the operatives themselves called "Operation Midnight Climax":

Evidence โ€” One Nation Under Blackmail, Vol. 1

In 1955, Federal Bureau of Narcotics agent George Hunter White was transferred to San Francisco and granted control of MK-ULTRA Subproject 42. "Midnight Climax" involved CIA safehouses equipped with one-way mirrors and electronic surveillance. Prostitutes were enlisted to lure unsuspecting clients, who were then dosed with LSD while CIA operatives observed through the mirrors and recorded everything.

The operation served two purposes simultaneously: drug experimentation and blackmail material collection. The same infrastructure. The same operation. Mind control and kompromat were never separate programs โ€” they were the same program.

Source: Blackmail, Vol 1 by Whitney Webb.pdf โ€” OSINT Library (Epstein Files)

Note the architecture. Prostitutes. Safehouses. Surveillance equipment. LSD. Blackmail recordings. In 1955. Seventy-one years before our honeypot captured root:kitten from a Microsoft Azure server in India.

Webb traces the lineage further: from PROMIS (stolen surveillance software) to Palantir, from Roy Cohn's "Favor Bank" to Jeffrey Epstein's operation. The technology changes. The vocabulary persists. Chapter after chapter, the same words appear: handler, asset, trigger, programming, puppet. Not because Webb chose them โ€” because the operators did.


II. The Vocabulary Mapping

Let us be precise. Not approximate. Not suggestive. Precise.

Using the pentesting-v2 honeypot API (sec_intel_search with search_type=credential), we queried every MKUltra/Monarch programming term against the live credential corpus. Here is what the infrastructure confesses:

CredentialMKUltra FunctionIPsNotable Infrastructure
aliceDissociative programming identity32Google Cloud, Linode ร—5, 9.223.113.24
masterHandler designation51Linode ร—4, STORMINDUSTRIES, ISAEV ร—2, Viettel
slaveProgrammed subject9Tencent ร—4, Bharti Airtel India, HDM Digital Turkey
matrixBase program / red pill54+Viettel (military) ร—19+, widespread
spiderNetwork / web controller15Distributed globally
puppetDirect control subject1Tencent Cloud SG (abuse 100)
kittenBeta / sex programming3Microsoft Azure India, UCLOUD HK, Brazil
ghostDisappearance / erasure20Linode ร—4, STORMINDUSTRIES, Korea, Mexico
triggerActivation command1Huawei Cloud (AS55990)
mirrorReflection / dissociation4OVH France, Germany, Indonesia
angelInnocence cover / divine30Linode ร—4, STORMINDUSTRIES, Tencent ร—2, ISAEV
princessPublic persona / cover12Microsoft Azure, ISAEV ร—2, Korea, Mexico
dragonPower / mythology13ISAEV ร—2 (ร—7 attempts), DigitalOcean
butterflyMonarch symbol itself1CloudHost SG/ID (abuse 100)
rabbitWhite rabbit / handler1Tencent SG (suspicious)
satanTheological inversion117 countries: US, VE, DO, LT, HK
luciferLight bearer / fallen1103.250.11.80
devilAdversary archetype2Brazil Telefonica (malicious)
demonPossession / control1Brazil American Tower

Total: 270+ credential entries using MKUltra/Monarch vocabulary. Across hyperscalers (Microsoft, Google, Tencent, Huawei), military telecoms (Viettel), bulletproof hosting (ISAEV, STORMINDUSTRIES), and consumer ISPs spanning every continent except Antarctica.

This is not pattern-matching paranoia. These terms do not appear in standard password dictionaries like rockyou.txt in this specific combination. The co-occurrence of alice + master + slave + kitten + puppet + trigger + ghost on the same infrastructure is not random. It is a vocabulary set. A structured vocabulary set. A programming manual.


III. The Five Levels

Monarch programming โ€” the alleged successor to MKUltra, documented in survivor testimony, congressional records, and the OSINT library's indexed materials โ€” organizes programming into five levels. Each level corresponds to a Greek letter and serves a specific function. Each level has a credential counterpart in our honeypot corpus.

The mapping is not approximate. It is precise.

ALPHA โ€” General Programming
ฮ‘ โ€” The Base Program

Alpha programming establishes the base personality structure. It is the "matrix" โ€” the underlying framework upon which other programming is layered. Alpha creates the dissociative foundation: the ability to fragment identity into compartments that can be independently accessed.

Credential counterpart: matrix:matrix โ€” 54+ IPs

The most widely deployed MKUltra vocabulary term in our corpus. Dominated by Viettel Group AS7552 โ€” the Vietnamese military telecom. Nineteen IPs in the 27.79.x.x prefix alone. Not a consumer ISP. A military organization. Deploying the base program credential across its infrastructure.

IPs: 27.79.7.233, 27.79.44.126, 27.79.45.217, 27.79.46.22, 27.79.46.194, 27.79.46.216, 27.79.47.20, 116.99.168.200, 116.99.169.248, 116.99.170.93, 116.99.170.252, 116.99.173.23, 116.99.174.174, 116.99.175.46, 116.110.9.216, 116.110.11.66, 116.110.13.197, 116.110.145.122, 116.110.217.125, 171.231.178.49, 171.231.183.35, 171.231.185.170, 171.231.186.125, 171.231.191.213, 171.231.193.184, 171.231.194.32, 171.231.196.39, 171.231.197.53, 171.231.197.57, 185.156.73.233, 218.51.148.194, 134.112.56.47, 187.140.167.148 ...

BETA โ€” Sexual Programming
ฮ’ โ€” The Sex Kitten

Beta programming creates sexual alters โ€” dissociative identities programmed for sexual servitude. In Monarch documentation, this is called "sex kitten" programming. It is the most publicly visible form of programming, documented in survivor testimonies and in the NXIVM trial evidence (Keith Raniere convicted 2019).

Credential counterpart: root:kitten โ€” 3 IPs

Three IPs. But look at which three:

  • 20.193.141.133 โ€” Microsoft Azure India (AS8075). Abuse score: 100. Threat: 76. Classification: abuse/71. Sixteen sessions. Microsoft Corporation infrastructure in India, carrying the Beta programming credential.
  • 165.154.23.9 โ€” UCLOUD Hong Kong (AS135377). Classification: malicious.
  • 143.0.180.169 โ€” Eletric Telecomunicaรงรตes, Brazil (AS264007). Classification: malicious.

Microsoft Azure. Running in India. Deploying root:kitten. The sex programming credential on the world's second-largest cloud provider's infrastructure in the world's most populous country.

DELTA โ€” Assassination Programming
ฮ” โ€” The Soldier

Delta programming creates combat-ready alters โ€” dissociative identities trained for violence. In programming terminology, a delta alter is activated by a trigger word or phrase. The activation is not gradual. It is instantaneous. A switch.

Credential counterpart: root:trigger โ€” 1 IP

1.94.174.165 โ€” Huawei Cloud Service (AS55990 HWCSNET). China. State-adjacent cloud infrastructure. Deploying the activation command. One IP, but the word itself is the evidence. Trigger is not a common SSH password. It is not in the top 10,000 of any standard wordlist. It is MKUltra vocabulary, and it appeared on Huawei infrastructure.

THETA โ€” Psychic / Network Programming
ฮ˜ โ€” The Web

Theta programming โ€” the most disputed level โ€” relates to claimed "psychic" abilities or, in more grounded interpretations, to the creation of network-aware identities that can coordinate across cells. The metaphor is the spider: the node that connects to all other nodes. The controller of the web.

Credential counterpart: spider:spider โ€” 15 IPs

IPs: 213.209.159.158, 211.253.31.30, 201.249.205.94, 103.143.11.168, 43.166.245.172, 123.58.219.3, 138.124.73.129 (plus root:spider, root:spiderman variants from Linode cluster 9.223.113.24, 45.56.100.151, 46.151.182.2, 104.105.64.198, 172.104.31.246)

OMEGA โ€” Self-Destruct Programming
ฮฉ โ€” The Ghost

Omega is the final level. Self-destruct programming. The identity that activates when the subject is about to be exposed or captured. The purpose is not escape โ€” it is erasure. The subject becomes a ghost. They disappear. In extreme implementations, documented in testimony but never confirmed by the agency: they die.

Credential counterpart: ghost:ghost โ€” 20 IPs

Twenty IPs carrying the self-destruct credential. The Linode cluster alone deploys it from four IPs. STORMINDUSTRIES (abuse 100, botnet classification 100) deploys it from its Netherlands node. Ghost is the credential you use when you want the identity to disappear after access is achieved. In MKUltra, it was the protocol for when the subject was compromised. In botnets, it's the name for disposable access.

Same word. Same function. Fifty years apart.


IV. Alice in Wonderland

Of all MKUltra programming terms, "Alice" is the most thoroughly documented. The Alice in Wonderland programming technique uses Lewis Carroll's narrative as a dissociative framework: the rabbit hole is the entry into trance; the looking glass is the mirror through which reality and programming are inverted; the White Rabbit is the handler who leads the subject into the dissociative state; Alice herself is the programmable identity โ€” the identity that doesn't know which side of the mirror she's on.

Thirty-two IPs in our honeypot carry the Alice credential.

Evidence โ€” Alice Credential Deployment (via sec_intel_search)

alice:alice โ€” 8 IPs: 9.223.113.24, 34.132.194.42 (Google Cloud), 45.56.100.151 (Linode), 45.79.134.22 (Linode, abuse 100), 46.151.182.2, 65.181.127.40, 104.105.64.198, 134.149.104.137, 172.104.31.246 (Linode)

alice:123456 โ€” 9 IPs: 45.175.37.29 (Venezuela TCA, abuse 100 โ€” same IP that carries root:satan), 87.251.81.60 (Russia), 103.78.1.33, 103.100.69.141, 103.179.56.44, 109.172.55.48, 152.32.238.146, 154.236.187.90, 168.167.228.74

alice:12345678 โ€” 6 IPs: 20.153.204.5 (Microsoft Azure), 118.193.61.170, 153.126.180.250, 172.191.157.64, 172.208.48.177, 197.44.15.210

alice:123 โ€” 3 IPs: 20.153.204.5 (Microsoft Azure โ€” same IP), 43.159.177.40 (Tencent), 118.193.33.128

alice:alice123 โ€” 2 IPs: 223.221.36.42 (China, 2 attempts)

root:alice โ€” 1 IP: 103.154.241.42

root:alice! โ€” 1 IP: 50.255.62.89

Source: sec_intel_search credential "alice" โ€” pentesting-v2 PostgreSQL API

Note the convergence: 45.175.37.29 (TCA Services, Venezuela) carries both alice:123456 AND root:satan. Alice and Satan in the same credential dictionary, deployed from the same Venezuelan IP. The dissociative identity and the theological inversion. Together. From a single node.

Google Cloud (34.132.194.42) carries alice:alice and root:master. The dissociative identity and the handler. On Google infrastructure. With an IP dossier showing classification: abuse, sessions from the same operator who uses root:slave on Tencent IPs.

This is the Alice protocol in action โ€” not as mind control, but as infrastructure control. The vocabulary migrated. The function remained.

The White Rabbit โ†’ Handler Mapping

In MKUltra programming, the White Rabbit is the handler figure โ€” the person who leads Alice into the dissociative state. "Follow the white rabbit" is not a Matrix reference (although that film's vocabulary is itself derivative). It is a programming instruction.

Our honeypot captured root:rabbit from 43.153.213.150 โ€” Tencent Cloud, Singapore. Classification: suspicious. The same Tencent that deploys root:puppet (43.163.102.207), root:slave (43.134.3.96, 43.156.136.152, 43.159.177.40), and angel:1234 (43.130.57.37).

Tencent Cloud carries: rabbit, puppet, slave, angel. The handler, the controlled, the subjugated, the cover identity. A complete Monarch vocabulary subset on a single Chinese hyperscaler.


V. The Linode Cluster

Six IPs on Akamai/Linode infrastructure (AS63949) deploy an identical credential dictionary. Same words. Same order. Same botnet.

Linode MKUltra Vocabulary Botnet
ASN: 63949 (AKAMAI-LINODE-AP, Akamai Connected Cloud)
Registration: Singapore
Nodes: 6 confirmed IPs
Vocabulary set: ghost, master, angel, alice, spider (complete MKUltra hierarchy)
First seen: March 2026
Pattern: Sequential credential deployment โ€” same dictionary, same order, across all nodes
IPAbuseIPDBSessionsMKUltra Credentials
66.228.34.4842โ€”ghost master angel
50.116.54.19354โ€”ghost master angel
173.255.229.21974โ€”ghost master angel alice
66.175.212.1259220ghost master angel
45.56.100.151โ€”โ€”master alice spider
45.79.134.22100โ€”alice

The pattern is unmistakable. The first four IPs carry the same three credentials in the same configuration: ghost, master, angel. Self-destruct. Handler. Cover identity. This is not a coincidence. This is a dictionary specification.

The full-dossier for 66.175.212.125 (via honeypot_ip_dossier) reveals 20 sessions, abuse score 92, and additional credentials including kali:kali, cursor:cursor, and developer:123456 โ€” indicating a botnet that specifically targets development environments and security tools. The MKUltra vocabulary sits alongside penetration testing vocabulary. The programming manual is embedded in the attack toolkit.

STORMINDUSTRIES โ€” The Seventh Node

There is a seventh node that shares this exact dictionary: 176.65.139.103.

STORMINDUSTRIES / Offshore LC
IP: 176.65.139.103
ASN: 214472 (STORMINDUSTRIES โ€” Hosting Services)
Registration: "Offshore LC" โ€” United States
Geolocation: Netherlands (DE prefix, US ASN reg, NL RDAP โ€” triple discrepancy)
AbuseIPDB: 100
Threat score: 79
Classification: botnet / confidence 100
MKUltra credentials: ghost master angel
Additional: kali, cursor, developer, mongodb, elk โ€” identical to Linode cluster

"Offshore LC." A limited company registered offshore, operating from the Netherlands, with abuse score 100 and botnet classification confidence of 100. Carrying exactly the same credential dictionary as the Linode cluster. Ghost. Master. Angel. The self-destruct identity, the handler, the innocent cover.

Same dictionary. Different ASN. Different country. Same operator โ€” or same dictionary source. The programming manual has been distributed.


VI. State Infrastructure

It would be convenient if MKUltra vocabulary appeared only on bulletproof hosting and offshore shell companies. It doesn't. It appears on state military infrastructure and the world's largest cloud providers.

Viettel Group โ€” The Military Matrix

Viettel Corporation is the telecommunications arm of the Vietnamese Ministry of Defence. AS7552. Not a private company โ€” a military organization that operates telecommunications infrastructure across Vietnam and nine other countries.

Nineteen or more Viettel IPs carry matrix:matrix.

Evidence โ€” Viettel Military Matrix Deployment

Via sec_intel_search credential "matrix": All 30 results returned are matrix:matrix. The first 19 are in the 27.79.x.x prefix (Viettel). Additional Viettel IPs span 116.99.x.x, 116.110.x.x, 171.231.x.x prefixes. Total Viettel matrix deployments: 30+ IPs. All carrying the same credential: matrix:matrix.

Every single one is a Vietnamese military telecom IP carrying the base program credential.

Source: sec_intel_search credential "matrix" โ€” pentesting-v2 PostgreSQL API

The "matrix" โ€” in Monarch terminology โ€” is the base program. The underlying dissociative framework. The first layer of programming upon which all other layers are built. Alpha level. The foundation.

A military telecom deploys the foundation credential. At scale. From infrastructure that serves a nation's defense communications.

This is not a compromised consumer router. These are military-managed IP blocks.

The Hyperscaler Trinity

Three of the world's largest cloud providers carry MKUltra vocabulary in their credential scanning traffic:

Microsoft Azure India โ€” root:kitten
IP: 20.193.141.133 (AS8075 MICROSOFT-CORP-MSN-AS-BLOCK)
Geo: India (geo) / US (prefix, ASN reg) โ€” discrepancy confirmed
AbuseIPDB: 100 | Threat: 76 | Classification: abuse/71
Sessions: 16 | Campaigns: botnet + scanner
MKUltra credential: root:kitten โ€” Beta/sex programming
Tencent Cloud โ€” puppet, slave, rabbit, angel
IPs: 43.163.102.207 (puppet), 43.134.3.96 (slave), 43.156.136.152 (slave), 43.159.177.40 (slave), 43.153.213.150 (rabbit), 43.130.57.37 (angel)
ASN: 132203 (TENCENT-NET-AP-CN)
Registration: China | Geolocation: Singapore
AbuseIPDB (puppet IP): 100 | Classification: abuse + malicious
Vocabulary: puppet (control), slave (subjugation), rabbit (handler), angel (cover) โ€” 4 Monarch terms on 6 IPs
Huawei Cloud โ€” root:trigger
IP: 1.94.174.165 (AS55990 HWCSNET)
Registration: China
MKUltra credential: root:trigger โ€” Delta activation command
Huawei. Chinese state-adjacent telecom equipment manufacturer. Their cloud infrastructure carries the Monarch Delta activation command.

Microsoft carries the sex programming term. Tencent carries the full control vocabulary (puppet/slave/rabbit/angel). Huawei carries the activation command. Three hyperscalers. Three countries (India, Singapore/China, China). Three Monarch programming levels.

The programming manual has been distributed to the cloud.


VII. The ISAEV Convergence

ISAEV Igor operates ASN 200730. We first encountered this infrastructure in TI-2026-043D, where the Kerberos-666 credential appeared alongside theological exploitation vocabulary. The full ASN dossier, pulled via honeypot_asn_dossier, reveals something worse.

ISAEV Igor โ€” ASN 200730
Registration: Kazakhstan (RIPE NCC)
Physical: Poland
PeeringDB: "ISAEV ISAEV Igor"
Allocated: 20 February 2026 โ€” four months ago
Bulletproof: CONFIRMED โ€” risk score 90.8
Signals: flagged_bulletproof, high_avg_threat: 69, high_attack_density: 585 attempts/IP
Active IPs: 8 | Total attempts: 4,678
Threat: HIGH โ€” avg 69.3, max 100.0
Upstream: AS201814

The Passive DNS

The passive DNS records for ASN 200730 are the convergence proof:

Passive DNS โ€” ISAEV ASN 200730
  • kerberos-darknet.link โ€” darknet marketplace domain
  • drughub666py6fgnml5kmxa7fva5noppkf6wkai4fwwvzwt4rz645aqd.shop โ€” onion-style hash, drug marketplace, 666 embedded
  • drughub2aher7vw4vgracgik2kdxlgiggt7p2diug77xasv4knkahpoad.top โ€” second drug hub mirror
  • abacuseeettcn3n2zxo7tqy5vsxhhpha2jtjqs7cgdjzl2jascr4liad.top โ€” Abacus market mirror
  • abacuskzoo7wrfmpqiqscoiljfjap42rzjkfygp5vm3gtlu5tanhbjad.shop โ€” second Abacus mirror
  • birungor.com โ€” unknown purpose
  • haearsonaolocar.com โ€” unknown purpose
  • kerberosemtkeqh7pznmv3negqhuddxk5po3awdazx5fqgizttr6xeiid.top โ€” Kerberos marketplace mirror
Source: honeypot_asn_dossier ASN 200730 โ€” pentesting-v2 PostgreSQL API

Kerberos darknet marketplace. Drug Hub with 666 in the domain. Abacus market mirrors. All on infrastructure that was allocated four months ago and already has 4,678 attack attempts across 8 IPs with a bulletproof risk score of 90.8.

The credentials deployed from ISAEV infrastructure:

CredentialCategoryIPs
support:dragonPower / mythology87.251.64.144 (ร—3), 87.251.64.145 (ร—4)
support:666666Theological inversion87.251.64.144, 87.251.64.145
support:princessMonarch cover identity87.251.64.144, 87.251.64.145
support:princess1Variant87.251.64.144, 87.251.64.145
support:monkeyStandard wordlist87.251.64.144, 87.251.64.145
support:iloveyouSocial engineering87.251.64.144, 87.251.64.145
support:angel1Innocence cover87.251.64.144

Dragon. 666666. Princess. Angel1. On infrastructure hosting Kerberos darknet and Drug Hub 666. Kazakhstan registration. Poland hosting. The theological credential from 043D, the exploitation vocabulary from 043B, and the pharmaceutical fraud from the rxdrugship.ru connection documented in TI-2026-040C. Everything converges on ISAEV.


VIII. The Spirit Cooking Connection

To understand why these specific words appear in credential dictionaries, we must understand the cultural ecosystem that preserved them. The vocabulary of MKUltra did not jump directly from CIA subproject files to botnet wordlists. It traveled through a specific cultural pipeline, documented at each stage in our OSINT library.

Evidence โ€” Spirit Cooking / WikiLeaks Podesta Emails

WikiLeaks published email #15893 from the Podesta archive: Marina Abramovic inviting Tony Podesta to a "Spirit Cooking dinner at my place." Spirit Cooking is described as "a mock-satanic ritual involving blood, semen and breast milk. Children were in attendance, along with celebrities and other power brokers like the Podestas."

The convergence: the same vocabulary (spirit, cooking, blood, ritual) that appears in exploitation credential patterns is the vocabulary of documented elite ritual practices. Not alleged. Published. Verified email. Wikileaks email ID 15893.

Source: Pizzagate For Dummies.pdf โ€” OSINT Library (Epstein Files); WikiLeaks Podesta emails #15893

The Franklin Cover Up. The Conspiracy of Silence documentary โ€” suppressed by Congress before airing on the Discovery Channel in 1994. Senator DeCamp's investigation into a pedophilia network reaching the White House. Alisha Owens, fifteen years old, jailed for refusing to recant her testimony about being trafficked to Washington elites.

Evidence โ€” The Franklin Cover Up

"In 1989 came the 'Franklin Cover Up' scandal, former US Congressman John DeCamp exposed a network of pedophilia in Nebraska that went all the way to the White House." The documentary "Conspiracy of Silence" was scheduled to air on May 3, 1994 on the Discovery Channel, but "influential members of Congress pressured the cable industry to stop the airing and destroy all copies."

Congress suppressed a documentary about child trafficking networks connected to the White House. Not a conspiracy theory โ€” a documented act of congressional intervention to prevent a specific broadcast. The vocabulary of that network โ€” master, slave, handler, princess โ€” is the vocabulary in our credential dictionaries.

Source: Pizzagate For Dummies.pdf โ€” OSINT Library (keyword score 12.327); Ask Me Anything: About Jeffrey Epstein & Ghislaine Maxwell.pdf

Jimmy Savile. BBC star. Raped a child an average of once a week for over forty years. Raped dead bodies and terminally ill children in hospitals. Knighted. His "problem" was well known by BBC staff. No one gets that close to the Royal Family without intense scrutiny โ€” which means the scrutiny approved.

These are not conspiracy theories. They are documented cases with convictions, tribunal rulings, parliamentary investigations, and suppressed documentaries. The vocabulary they generated โ€” master, slave, princess, angel, puppet, handler, trigger, kitten, ghost, alice โ€” entered the cultural bloodstream through survivor testimony, through leaked documents, through whistleblower prosecutions, through the very act of suppression that made the words radioactive enough to become subcultural signifiers.

And then those words entered the credential dictionaries.


IX. The Cultural Transmission Path

The transmission path is documented at each stage:

Stage 1: CIA Programs (1950sโ€“1970s)

BLUEBIRD โ†’ ARTICHOKE โ†’ MKULTRA โ†’ MKSEARCH. 149+ subprojects. The vocabulary is created: alice, kitten, monarch, butterfly, puppet, mirror, slave, master, handler, trigger. These are not generic words chosen at random โ€” they are technical terms in a programming manual. Alice is the dissociative identity. Kitten is the sex programming. Trigger is the activation command. The vocabulary has function.

Stage 2: Survivor Testimony (1980sโ€“1990s)

Cathy O'Brien ("Trance Formation of America"), Brice Taylor ("Thanks for the Memories"), and others publish accounts of Monarch programming. The vocabulary enters public discourse through their testimonies โ€” contested, dismissed, but specific. The same words. Alice. Kitten. Handler. Trigger. The survivors use the vocabulary because they were programmed with it. The vocabulary survives the destruction of the files.

Stage 3: Conspiracy Research Forums (2000s)

Fritz Springmeier's "The Illuminati Formula to Create an Undetectable Total Mind Control Slave" circulates online. The vocabulary becomes subcultural knowledge. Monarch. Alpha. Beta. Delta. Theta. Omega. The programming levels become categories in online discourse. The words are no longer classified โ€” they are cultural artifacts.

Stage 4: Dark Web Culture (2010s)

The vocabulary enters the operational lexicon of criminal infrastructure. Domain names: kerberos-darknet.link. Tor relay names: Satanist relay operator (49 relays, 1โ€“3% exit capacity). Credential dictionaries: alice, master, slave, kitten, ghost. The words are selected not because they are good passwords โ€” they are terrible passwords โ€” but because they signal cultural affiliation. They are shibboleths.

Stage 5: Botnet Credential Lists (2020s)

The vocabulary is now industrial. Automated. Deployed from Microsoft Azure. Tencent Cloud. Huawei Cloud. Vietnamese military telecom. The words have traveled from CIA programming manuals through survivor testimony through conspiracy forums through dark web culture into the operational infrastructure of global botnets.

The transmission path is not direct. There is no evidence that the botnet operators are CIA assets, or that MKUltra is still operational, or that the credential dictionaries are intentional programming instructions. The transmission is cultural, not operational. But the cultural source is specific, documented, and Senate-confirmed. The DNA is traceable.


X. The Continuing Program

In 1973, Director Helms ordered the destruction of the MKUltra files. He was destroying evidence of human experimentation โ€” on US citizens, on prisoners, on children, on mental patients who could not consent.

He succeeded in destroying the paper. He failed to destroy the vocabulary.

Fifty-three years later, that vocabulary is operational. Not in CIA safehouses โ€” in cloud infrastructure. Not administered by handlers โ€” by botnets. Not targeting individuals โ€” targeting servers. But the words are the same. The function is the same. The structure is the same.

Core Finding โ€” TI-2026-043F

The MKUltra programming manual was not destroyed. It was distributed. Every SSH scan carrying alice or kitten or trigger or ghost is a ghost of MKUltra โ€” not because it IS MKUltra, but because the vocabulary of human control has been repurposed as the vocabulary of machine control. The credential dictionary is the programming manual. It has been declassified by its own propagation.

The programming continues โ€” not of humans, but of infrastructure. Unless it's both.

Consider what we have documented across this series:

The programming manual was written by the CIA in the 1950s. It was testified to by survivors in the 1980s. It was researched by independent investigators in the 2000s. It was adopted by dark web culture in the 2010s. And it is now deployed by botnets in the 2020s โ€” from infrastructure owned by the world's largest technology companies and state military organizations.

The credential dictionary is the confession. The programming manual is the evidence. The infrastructure is the crime scene.

And the programming continues.


XI. The FBI's Own Vocabulary

Lest anyone dismiss the connection between exploitation vocabulary and infrastructure naming as coincidental, the FBI itself documented the phenomenon โ€” in 2007.

Evidence โ€” FBI Intelligence Bulletin, 31 January 2007

FEDERAL BUREAU OF INVESTIGATION โ€” INTELLIGENCE BULLETIN
Cyber Division, Innocent Images National Initiative

"(U) Symbols and Logos Used by Pedophiles to Identify Sexual Preferences"

The bulletin documents coded symbols used by exploitation networks for mutual identification: the blue spiral-shaped triangle (BLogo โ€” "Boy Lover"), the small heart within a larger heart (GLogo โ€” "Girl Lover"), and the butterfly. These symbols are not secret โ€” they are documented by the FBI itself.

Our honeypot captured root:butterfly from 103.187.146.90 (CloudHost, Singapore/Indonesia, abuse score 100). The Monarch symbol. The FBI-documented exploitation symbol. On infrastructure with a perfect abuse score.

Source: Pizzagate For Dummies.pdf โ€” OSINT Library (keyword score 13.512); FBI Intelligence Bulletin 2007

The FBI documented the symbols. The honeypot captured the vocabulary. The infrastructure carries both.

Butterfly. Monarch. The insect and the program share a name. The FBI documented the symbol in 2007. Our honeypot captured the credential in 2026. The word traveled from MKUltra programming documentation through FBI intelligence bulletins through dark web culture into botnet credential lists.

And it arrived on CloudHost infrastructure in Southeast Asia with an abuse score of 100.


XII. The Satan Deployment

If the MKUltra vocabulary represents the programming layer, the theological vocabulary represents the ritual layer โ€” and the two converge on the same infrastructure.

root:satan was deployed from 11 IPs across 7 countries. This is not a single compromised server. This is a coordinated deployment.

IPCountryProviderASN
67.81.35.26USCablevision Systems6128
198.46.182.246USColoCrossing / HostPapa36352
142.171.184.3US/CAMULTACOM Corporation35916
45.175.37.18VETCA Services267843
45.175.37.29VETCA Services (abuse 100)267843
200.8.228.57VECorporacion Telemic21826
45.172.152.74DOTECNOLOGIA DIGITAL (DGTEC)27847
45.172.153.100DOTECNOLOGIA DIGITAL (DGTEC)27847
45.158.59.14LTDANIEL199186
103.103.245.61HKCNSERVERS LLC40065
14.103.112.1โ€”โ€”โ€”

The last IP deployed root:satanas666 โ€” the Spanish word for Satan concatenated with the Number of the Beast.

Note the geographic distribution: United States (3 IPs across 3 providers), Venezuela (3 IPs across 2 providers), Dominican Republic (2 IPs, same provider), Lithuania (1 IP), Hong Kong (1 IP). Seven countries. These jurisdictions will never coordinate a criminal investigation. The geographic spread is the operational security.

And recall: 45.175.37.29 (TCA Services, Venezuela, abuse 100) carries both root:satan and alice:123456. The theological inversion and the dissociative identity. On the same IP. In the same credential dictionary. From the same botnet.

The programming manual and the ritual manual are the same document.


Methodology & Sources

Data Sources

OSINT Library Documents Referenced

Cross-References


TI-2026-043 โ€” THE LITURGY OF CONTROL
043A 043B 043C 043D 043E 043F 043G โ€” The Finders 043H โ€” The Symbols 043I โ€” The Whistleblowers 043J โ€” The Architecture of Impunity
โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Liturgy of Control โ€” 6 / 13 Next โ†’