TI-2026-048A โ The Nine Commands
๐ Executive Summary
In spring, a hand-built investigation โ TI-2026-002 โ caught a synchronised botnet running an identical nine-command reconnaissance playbook across 15 residential devices in 14 countries. This dossier opens The Long Memory by proving that the same operation never stopped.
The byte-identical nine commands ran again on 112.185.48.244 (June 3 and June 26) and on 211.48.137.43 (April 28). The platform now binds the operation to a single SSH fingerprint โ HASSH f45fb203โฆ (libssh2_1.11.1) โ shared by 49 IPs, and thirteen nodes from the 002 spring roster recur inside the summer cluster. Same script. Same machines. Three months on.
Read closely, the nine commands are a complete asset-triage routine that simultaneously:
- ๐ Detects MikroTik routers โ via the RouterOS-only
/ip cloud print. - โ๏ธ Evicts rival miners โ a competitive presence check before deployment.
- ๐ฑ Steals Telegram Desktop sessions โ copying
tdatafor password-free, 2FA-free account takeover. - ๐ก Hunts SMS gateways & GSM modems โ SIM farms for 2FA interception and SMS fraud.
- ๐ท๏ธ Checks an infection marker โ
D877F783D5D3EF8Csโ and ๐ฐ๏ธ tests the shell for a honeypot before committing.
No malware was downloaded here โ the recon never needed to. Nine commands already confessed the entire business model, and the fingerprint proved who was speaking.
๐ฏ The Nine-Command Sequence
Every node executes this exact sequence in well under ninety seconds โ connect, run nine commands, disconnect:
The platform's intel-linker tags the whole session with one TTP label: reconnaissance. Decoded line by line, nothing is idle:
[Mm] character-class is the deliberate idiom that stops grep matching its own line โ the mark of someone who writes shell daily.D877F783D5D3EF8C is the hard-coded Telegram Desktop tdata key constant; locating it finds every session store โ and doubles as an "already-owned" infection tag.๐ฌ Step 7 โ The Full Target List
The single most revealing command enumerates five distinct asset classes at once:
Two prize classes, one ls. Telegram tdata: copy the folder and you are the victim on Telegram โ no password prompt, no second factor. SMS/GSM gateways: control one and you can read inbound SMS (intercept 2FA codes), send premium-rate SMS, and run smishing at scale.
The asset-triage decision tree
What the nine commands set up is a branch table โ the same logic TI-2026-002 reconstructed, still in force:
| If the box isโฆ | โฆthen the operator | Monetisation |
|---|---|---|
| a MikroTik router | hijacks it โ DNS poisoning, VPN tunnel, SOCKS proxy, traffic sniffing, reboot-persistent scripts | Proxy/anonymity, credential capture |
| running Telegram | steals tdata for account takeover, impersonation, crypto scams | Fraud, extortion, scam distribution |
| a SIM farm / GSM modem | abuses the gateway for 2FA interception, SMS fraud, SIM-swap | 2FA bypass โ bank/crypto takeover |
| just CPU | deploys a miner โ after evicting any competitor | Stolen compute (Monero) |
| already marked | skips it โ already owned by this or an allied operator | (deconfliction) |
๐ฐ๏ธ The Continuity Proof โ Spring Nodes, Summer Cluster
This is the heart of The Long Memory. TI-2026-002 documented 15 nodes between March 21 and April 11. Months later, the same HASSH fingerprint cluster contains the very same addresses โ proof it is one continuous campaign, not a look-alike:
| Node (recurs in both) | Country ยท ISP | Seen in 002 (spring) | In summer HASSH cluster |
|---|---|---|---|
121.165.204.105 | ๐ฐ๐ท Korea Telecom | Mar 24 | โ |
222.108.39.109 | ๐ฐ๐ท Korea Telecom | Mar 28 | โ |
183.98.76.106 | ๐ฐ๐ท Korea Telecom | Apr 5 | โ |
218.145.181.48 | ๐ฐ๐ท Korea Telecom | Apr 6 | โ |
173.185.74.18 | ๐บ๐ธ Windstream | Apr 4 & 7 | โ |
171.241.43.241 | ๐ป๐ณ Viettel | Apr 9 | โ |
81.18.37.142 | ๐ฐ๐ฟ Radiobaylanys | Apr 8 | โ |
87.249.188.12 | ๐ธ๐ช Ljusnet | Apr 10 | โ |
202.44.227.204 | ๐น๐ญ Internet Thailand | Apr 11 | โ |
178.160.209.67 | ๐ฆ๐ฒ Telecom Armenia | Mar 21 | โ |
85.30.212.24 | ๐ท๐บ Rostelecom | Mar 23 | โ |
5.187.97.40 | ๐ฌ๐ต Canal Telecom | Mar 31 | โ |
144.2.91.96 | ๐จ๐ญ Swisscom | Apr 1 | โ |
Thirteen of fifteen spring nodes are still in the cluster โ and fresh ones (112.185.48.244, 211.48.137.43) run the identical script. The campaign didn't migrate; it endured.
๐ The Grown Roster โ 49 Nodes, One Fingerprint
Where 002 mapped 15 nodes by hand, automated HASSH + shared-command clustering now resolves 49 IPs to the same operation across roughly twenty countries โ overwhelmingly residential and mobile broadband (compromised home routers and CPE, not datacentres):
| IP | Country | ISP / ASN | Note |
|---|---|---|---|
112.185.48.244 | ๐ฐ๐ท KR | Korea Telecom AS4766 | Jun 3 & Jun 26 โ repeat visitor |
211.48.137.43 | ๐ฐ๐ท KR | Korea Telecom AS4766 | Apr 28 |
116.34.14.135 | ๐ฐ๐ท KR | LG Powercomm | |
59.22.201.143 ยท 121.171.115.207 ยท 14.55.31.113 | ๐ฐ๐ท KR | Korea Telecom AS4766 | KT is the dominant cluster |
118.70.239.231 ยท 118.71.201.155 | ๐ป๐ณ VN | FPT Telecom | |
109.63.130.95 | ๐ท๐บ RU | MegaFon (mobile) | |
75.89.156.112 | ๐บ๐ธ US | Windstream | GreyNoise malicious |
47.185.144.12 ยท 162.40.175.174 ยท 173.19.19.38 ยท 148.75.192.89 | ๐บ๐ธ US | Frontier / Windstream / Mediacom / Cablevision | residential |
90.224.74.107 ยท 92.33.193.44 ยท 92.33.220.174 ยท 188.151.176.48 | ๐ธ๐ช SE | Telia / Telenor / Tele2 | |
152.52.158.42 | ๐ฎ๐ณ IN | Bharti Airtel | |
90.76.178.5 ยท 217.97.46.229 | ๐ซ๐ท๐ต๐ฑ | Orange (FR / PL) | |
219.78.63.235 | ๐ญ๐ฐ HK | HKT | |
148.216.255.251 | ๐ฒ๐ฝ MX | Alestra | |
36.92.154.210 | ๐ฎ๐ฉ ID | Telkom Indonesia | |
89.236.237.151 | ๐บ๐ฟ UZ | IST Telekom | |
โฆplus the 13 recurring spring nodes above โ 49 IPs total on HASSH f45fb203โฆ. | |||
๐งฌ How the Platform Knows It Is One Operation
The addresses never repeat enough to matter โ so identity is reconstructed from things the operator cannot cheaply change. Two independent signals converge:
HASSH hashes the SSH client's key-exchange/cipher/MAC offer โ a build-specific signature of the attacker's tool, not its location. Shared-command clustering hashes the exact command strings and groups every IP that issued them. When the same 49 residential addresses across twenty countries share both a client fingerprint and a byte-identical command set, coincidence is excluded: it is one toolkit, many disposable hosts.
Behavioral fingerprint
libssh2_1.11.1 โ a C library, i.e. an automated tool, never a human typing.๐ช The Ugly Mirror โ A Stolen Copy of a Documented Industry
Strip the criminal framing and look at what this kit hunts โ inbound SMS spools, GSM modems, SIM managers, QMI interfaces, messaging sessions โ and it is indistinguishable from a product catalogue. It is one: the commercial lawful-interception and surveillance industry, exposed in the WikiLeaks Spy Files.
| What the botnet hunts | The commercial equivalent (Spy Files) |
|---|---|
GSM modem / SMS-gateway capture (/dev/ttyGSM*, smsd.conf) | Cobham "SHOGI GSM Interception"; SS8 IP interception |
| SMS / IM / VoIP content interception | AQSACOM "Enhanced Lawful Interception" of email/IM/VoIP |
| SS7 / mobile-core tapping | Group2000 "LIMA" (SS7/UMTS interception, Nokia provisioning) |
| Mass aggregation of intercepted comms | Amesys "from lawful to massive interception" โ later tied to mass surveillance in Libya under Gaddafi |
The capability the surveillance vendors sold to states for millions โ intercept the SMS, own the second factor, read the messages โ is what a residential botnet now improvises with nine shell commands and a stolen tdata folder. The criminal who copies a session directory and the appliance that taps an SMS gateway are reaching for the same files for the same reason.
This thread โ the convergence of criminal telecom-theft and the documented interception industry โ is developed in full in a later letter of this series.
โ๏ธ Verdict
Nine commands, no malware, and the whole operation is legible: a maintained, professionally-written recon kit that fingerprints the host, evicts rivals, and triages every box toward its most profitable abuse โ MikroTik hijack, Telegram takeover, SMS-gateway/2FA fraud, or mining โ testing for a honeypot before it commits.
What the pipeline adds to the hand-built spring report is memory. TI-2026-002 saw a snapshot: 15 nodes over three weeks. The HASSH and shared-command graph turns that snapshot into a film โ the same operation, byte-identical, still running three months later across 49 residential nodes, thirteen of them the very same machines. The operator changed their address a thousand times and their toolkit not once.
An attacker's identity is not its IP. It is the script it cannot stop running โ and a honeypot remembers the script long after the address is gone.
๐ Related & Coming Next
- TI-2026-002 โ MikroTik Recon & Telegram Stealer Botnet (the spring snapshot this dossier proves continuous)
- Next in The Long Memory: 048B โ The Frozen Signature ยท 048C โ Identity Without an Address ยท 048D โ The Re-tasking ยท 048E โ Ninety Days ยท the Ugly Mirror (Spy Files / Amesys, in full)
Series: ๐งฌ The Long Memory ยท Letter: A ยท Classification: TLP:WHITE
Data sources: LSN SSH honeypot (Cowrie) โ session transcripts fc5c209c6e9e / e197528fba1c (112.185.48.244) and 44e271009a20 (211.48.137.43); ip_evolution; ip_identity (HASSH f45fb203c31069bb280067b71ed92ccb + shares_commands cluster); cross-referenced against published TI-2026-002. OSINT: WikiLeaks Spy Files (Cobham, SS8, AQSACOM, Group2000 LIMA, Amesys).
Investigation: TI-2026-048A ยท 3 actors ยท 9 evidence ยท 8 findings ยท 4 connections ยท 2 infrastructure records ยท monitoring window 2026-03-21 โ 2026-06-26.