๐Ÿงฌ CRITICAL โ€” The botnet isn't stealing computers. It's stealing the second factor.

TI-2026-048B โ€” The Second Factor

TI-2026-048B ยท Series: ๐Ÿงฌ The Long Memory (Letter B) ยท TLP:WHITE
Why a residential botnet hunts Telegram sessions and SMS gateways โ€” and how that hunt is a stolen copy of an industry the world already put on trial.
2FA / MFA defeatSMS interceptionTelegram tdataSIM swapNIST 800-63BWikiLeaks Spy FilesAmesys / Libyaaggravated identity theft

๐Ÿ“‹ Executive Summary

Letter A decoded the nine commands. Letter B answers the question the decode raised: why those two prizes? A Telegram session and an SMS gateway look unrelated โ€” until you notice they are two doors into the same room. Both defeat the second factor.

A stolen Telegram tdata folder logs the attacker in with no password and no 2FA prompt. A hijacked SMS gateway makes the attacker the recipient of the victim's one-time codes. The botnet that fingerprints home routers is, in function, a machine for harvesting the thing that stands between a stolen password and a drained bank account.

  • ๐Ÿ”‘ Both of the kit's prizes are routes around multi-factor authentication โ€” session theft and OTP interception.
  • ๐Ÿ“œ NIST already said SMS is weak: SP 800-63B classes PSTN/SMS verification as RESTRICTED. The criminals industrialise the gap the standard named.
  • ๐Ÿ›ฐ๏ธ The capability is a stolen copy of the lawful-interception industry exposed in the WikiLeaks Spy Files โ€” Amesys, Cobham, AQSACOM, Group2000, SS8.
  • ๐Ÿ‡ฑ๐Ÿ‡พ That industry's history is ugly: Amesys interception technology was used for mass surveillance in Libya.
  • ๐Ÿ’ธ The payoff is documented: FBI IC3, US Treasury, Europol โ€” account takeover, SIM-swap, crypto theft, laundered through low-KYC swaps.
  • โš–๏ธ The law already has a name for it: aggravated identity theft.

The only stable difference between the SMS-interception appliance a state buys and the botnet that hunts your home router's SIM slot is a warrant and an invoice.

๐Ÿ” What the Second Factor Is โ€” and Why It's the Linchpin

A password is something you know; it leaks constantly. So the world bolted on a second factor โ€” something you have โ€” and for most of the planet that "something" became a phone: an SMS code, or a logged-in messaging app.

That decision quietly made the phone the master key. Reset your email, your bank, your exchange, your crypto wallet โ€” and the proof of "you" is a six-digit SMS or a tap in an app. Own the phone's message path, and you own everything chained to it. The botnet understood this before most defenders did: it does not chase the password at all. It chases the factor that recovers the password.

Two doors into the same room

Door 1 โ€” the session. Copy ~/.local/share/TelegramDesktop/tdata and you resume an already-authenticated session. No password, no code, no prompt. The second factor is simply skipped.
โ†• both defeat MFA
Door 2 โ€” the gateway. Hijack an SMS gateway (smsd.conf, /dev/ttyGSM*, qmuxd, simman) and the victim's inbound one-time codes arrive at your screen. The second factor still works โ€” for the attacker.
Takeaway โ€” session theft bypasses the second factor; gateway theft redirects it. Either way, the nine-command recon was shopping for the keys to every account the victim recovers by phone.

๐Ÿ“œ The Standard Already Knew โ€” NIST SP 800-63B

This is not a novel weakness the criminals discovered. The United States' own digital-identity authority deprecated the SMS factor years ago. NIST Special Publication 800-63B, Section 5.1.3.3:

"Use of the PSTN for out-of-band verification is RESTRICTEDโ€ฆ the verifier SHALL verify that the pre-registered telephone number being used is associated with a specific physical device." โ€” NIST SP 800-63B, Digital Identity Guidelines: Authentication & Lifecycle Management

"RESTRICTED," in NIST's vocabulary, is a warning label: the mechanism has known weaknesses, its use must be justified, and a migration path away from it is expected. SMS one-time codes ride the Public Switched Telephone Network โ€” the very path the botnet seizes when it hijacks an SMS gateway or a SIM.

So the operation does not break cryptography or defeat a hardware key. It attacks the one factor the standards body had already flagged as untrustworthy โ€” and which the world deployed anyway, by the billions, because a phone number was convenient.

๐Ÿ” Reading between the lines โ€” the criminal economy lives in the gap between what the standard says and what is deployed. NIST said "move off SMS"; the market said "later." That "later" is the attack surface. Every account still recoverable by SMS is a door the standard already told you to brick up.
Takeaway โ€” the durable defence is institutional, not clever: phishing-resistant factors (FIDO2 / passkeys / hardware keys) take both of the botnet's doors off the board. The recon list is, in effect, a map of everything that still trusts a phone.

๐Ÿชž The Mirror โ€” An Industry Built to Do Exactly This

Strip away the criminal framing and describe the capability plainly: intercept a target's SMS, reconstruct their webmail and chats, own their phone's message path. That is not a hacker's wish-list. It is a product catalogue โ€” and WikiLeaks published it as the Spy Files.

The same files the nine-command kit hunts on a home router are the files a multi-billion-dollar "lawful interception" industry built appliances to capture, lawfully, for governments:

What the botnet stealsThe commercial product (Spy Files)Vendor
Webmail / IM / chat contentEAGLE EYE โ€” IP TAP: passive deep-packet inspection with "reconstruction logicโ€ฆ when intercepting complex applications such as webmail and IM/chat", 1โ€“10 Gbps, long-term retentionAmesys / ALTRON
Inbound/outbound SMS & GSMSHOGI GSM Interception; ABILITY 3G GSMCobham; ABILITY
IM / VoIP / email lawful interceptEnhanced Lawful Interception of IP appsAQSACOM
Mobile-core / SS7 tappingLIMA (SS7 / UMTS interception, Nokia provisioning)Group2000
Bulk IP interception & analysisSS8 IP Interception + social-network analysisSS8
Endpoint message theftlawful-intercept trojans, WIFI InterceptDigiTask et al.

Amesys even branded the scale: AMESYS COMINT, AMESYS STRATEGIC MASSIVE. The botnet's nine commands are the street-corner version of "STRATEGIC MASSIVE" โ€” the same interception goal, minus the rack-mounted appliance and the government contract.

Takeaway โ€” the technique has an institutional anchor, and it is not the underground. It is the surveillance-industrial complex. The criminal kit is its commoditisation โ€” capability that once cost millions, now nine lines of shell.

๐Ÿ‡ฑ๐Ÿ‡พ The Ugly Reality, Proven by History

It would be comforting to call the interception industry a regrettable-but-lawful necessity. History does not allow it. The clearest documented case attaches to the very vendor whose EAGLE EYE appears in the catalogue above: Amesys.

Amesys' deep-packet-interception technology was sold to and deployed by the Gaddafi regime in Libya, where it was used to monitor dissidents, journalists and opposition figures โ€” people who were subsequently detained and, in documented instances, tortured. The capability marketed as "lawful interception of webmail and IM/chat" became, in practice, an instrument of state repression. The episode produced one of the first criminal-complaint investigations in Europe against a surveillance vendor for complicity in such abuses.

The same sentence โ€” "intercept webmail and IM/chat, retain long-term, reconstruct the target's communications" โ€” describes a Spy Files product, a tool of dictatorship, and the goal of a residential botnet. Only the buyer changes. โ€” synthesis of WikiLeaks Spy Files (Amesys EAGLE EYE) and the documented Libya deployment

That is the thread this series promised to pull. The botnet hunting a SIM slot in someone's home router is not doing something new and exotic. It is doing something old and industrial โ€” the interception of human communication and identity โ€” that states normalised, vendors productised, and history has already condemned in at least one concrete, prosecuted instance.

๐Ÿ” Reading between the lines โ€” "lawful interception" is a licence, not a property of the technology. The appliance does not know whether a warrant exists; it only knows how to read the SMS. When the same capability leaks into a botnet, the warrant simply vanishes and the function remains. The ugly truth is that the criminal did not invent the harm โ€” they inherited it.

๐Ÿ’ธ Follow the Money โ€” Where a Stolen Factor Cashes Out

A harvested session or an intercepted code is not the payday; it is the key to one. The downstream economy is well documented:

FBI IC3 (2023)
Catalogues investment- and account-takeover fraud at multi-billion-dollar scale, and explicitly recommends MFA and out-of-band verification to a "known verified number" โ€” the exact control an SMS-gateway hijack neutralises.
US Treasury โ€” DeFi Risk (2023)
Documents how stolen funds and identity-theft proceeds (e.g. the Baller Ape rug-pull indictment) move through decentralized finance and crypto-swap services with lenient or non-existent KYC.
Europol โ€” Crypto Tracing
Describes crypto-swapping services that convert well-known coins into privacy coins to launder proceeds, "even advertising their non-compliance" โ€” the wash cycle for second-factor theft.

The pipeline is linear and each stage is sourced: recon (the nine commands) โ†’ second-factor theft (session or SMS gateway) โ†’ account/SIM-swap takeover โ†’ crypto drain โ†’ low-KYC swap laundering. The home router the botnet fingerprints sits at the very start of a chain that ends in a privacy-coin mixer.

Takeaway โ€” the recon's "is there a SIM here?" question is a financial query. A SIM farm or a Telegram session is inventory; the exchange account it unlocks is the revenue.

โš–๏ธ The Law Already Named It

There is no legal ambiguity about the criminal side. Using a stolen Telegram session or an intercepted SMS code to act as the victim is, in U.S. law, the "transfer, possession, and use, without lawful authority, of a means of identification of another person" โ€” Aggravated Identity Theft, 18 U.S.C. ยง 1028A, charged in DOJ indictments from APT41 to commodity fraud crews.

Set that beside the lawful-interception warrant and the symmetry is exact: both authorise reading another person's communications and assuming their identity on a system. One is a crime with a mandatory consecutive sentence; the other is a procurement line item. The act is identical; only the authorisation differs.

๐Ÿ”บ One Capability, Three Masks

The whole letter resolves to a single uncomfortable diagram โ€” the same interception capability wearing three faces:

MaskWhoAuthorisationDocumented by
๐Ÿ›๏ธ The StateGaddafi-era Libya, othersSovereign power (or none)Amesys/Libya deployment history
๐Ÿข The VendorAmesys, Cobham, AQSACOM, SS8, Group2000"Lawful interception" contractWikiLeaks Spy Files
๐Ÿฆ  The Botnetthe nine-command operator (and its kind)None โ€” aggravated identity theftLSN honeypot (Letters A & B)

Read top to bottom, it is a story of diffusion: a capability invented and normalised at the top of the stack leaks downward until it is a commodity any botnet can wield against a stranger's home router. The phone-as-second-factor put a tap point in every pocket; the only question left was who would reach it first.

The second factor was always a phone you do not fully control. The interception industry proved the tap was possible; the botnet proved it was cheap.

โš–๏ธ Verdict

The persistent botnet of Letter A is, at its core, an authentication-defeat operation. It hunts Telegram sessions and SMS gateways because both deliver the same thing: the second factor โ€” by skipping it, or by stealing it. It targets the one mechanism the standards body had already condemned (NIST's RESTRICTED label on SMS), wields a capability the surveillance industry built and sold (the Spy Files catalogue), inherits a history already written in blood (Amesys in Libya), monetises through a documented crypto-laundering tail (IC3, Treasury, Europol), and commits an offence the law already names (aggravated identity theft).

That is the "ugly reality proven by history" this series set out to find: the criminal did not innovate. They commoditised. The interception of identity and communication is an old industrial capability, normalised at the top of the power structure and now leaking out the bottom โ€” and the cheapest place to reach it turned out to be the SIM slot in a compromised home router.

Kill the SMS factor and you take both of the botnet's doors off the board at once. The standard told us to do it years ago. The botnet is the bill for not listening.

Series: ๐Ÿงฌ The Long Memory ยท Letter: B ยท Classification: TLP:WHITE

Data sources: LSN SSH honeypot (TI-2026-048A Step-7 analysis). OSINT library: NIST SP 800-63B (PSTN/SMS RESTRICTED); WikiLeaks Spy Files (Amesys EAGLE EYE / COMINT / STRATEGIC MASSIVE; Cobham SHOGI GSM; AQSACOM; Group2000 LIMA; SS8); FBI IC3 2023; US Treasury DeFi Risk Assessment 2023; Europol crypto-tracing; DOJ APT41 indictment (18 U.S.C. ยง 1028A). Amesys/Libya per documented deployment history.

Investigation: TI-2026-048B ยท 3 actors ยท 7 evidence ยท 5 findings ยท 4 connections ยท cross-referenced to TI-2026-048A and TI-2026-002.

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Long Memory โ€” 2 / 5 Next โ†’