TI-2026-048B โ The Second Factor
๐ Executive Summary
Letter A decoded the nine commands. Letter B answers the question the decode raised: why those two prizes? A Telegram session and an SMS gateway look unrelated โ until you notice they are two doors into the same room. Both defeat the second factor.
A stolen Telegram tdata folder logs the attacker in with no password and no 2FA prompt. A hijacked SMS gateway makes the attacker the recipient of the victim's one-time codes. The botnet that fingerprints home routers is, in function, a machine for harvesting the thing that stands between a stolen password and a drained bank account.
- ๐ Both of the kit's prizes are routes around multi-factor authentication โ session theft and OTP interception.
- ๐ NIST already said SMS is weak: SP 800-63B classes PSTN/SMS verification as RESTRICTED. The criminals industrialise the gap the standard named.
- ๐ฐ๏ธ The capability is a stolen copy of the lawful-interception industry exposed in the WikiLeaks Spy Files โ Amesys, Cobham, AQSACOM, Group2000, SS8.
- ๐ฑ๐พ That industry's history is ugly: Amesys interception technology was used for mass surveillance in Libya.
- ๐ธ The payoff is documented: FBI IC3, US Treasury, Europol โ account takeover, SIM-swap, crypto theft, laundered through low-KYC swaps.
- โ๏ธ The law already has a name for it: aggravated identity theft.
The only stable difference between the SMS-interception appliance a state buys and the botnet that hunts your home router's SIM slot is a warrant and an invoice.
๐ What the Second Factor Is โ and Why It's the Linchpin
A password is something you know; it leaks constantly. So the world bolted on a second factor โ something you have โ and for most of the planet that "something" became a phone: an SMS code, or a logged-in messaging app.
That decision quietly made the phone the master key. Reset your email, your bank, your exchange, your crypto wallet โ and the proof of "you" is a six-digit SMS or a tap in an app. Own the phone's message path, and you own everything chained to it. The botnet understood this before most defenders did: it does not chase the password at all. It chases the factor that recovers the password.
Two doors into the same room
~/.local/share/TelegramDesktop/tdata and you resume an already-authenticated session. No password, no code, no prompt. The second factor is simply skipped.smsd.conf, /dev/ttyGSM*, qmuxd, simman) and the victim's inbound one-time codes arrive at your screen. The second factor still works โ for the attacker.๐ The Standard Already Knew โ NIST SP 800-63B
This is not a novel weakness the criminals discovered. The United States' own digital-identity authority deprecated the SMS factor years ago. NIST Special Publication 800-63B, Section 5.1.3.3:
"RESTRICTED," in NIST's vocabulary, is a warning label: the mechanism has known weaknesses, its use must be justified, and a migration path away from it is expected. SMS one-time codes ride the Public Switched Telephone Network โ the very path the botnet seizes when it hijacks an SMS gateway or a SIM.
So the operation does not break cryptography or defeat a hardware key. It attacks the one factor the standards body had already flagged as untrustworthy โ and which the world deployed anyway, by the billions, because a phone number was convenient.
๐ช The Mirror โ An Industry Built to Do Exactly This
Strip away the criminal framing and describe the capability plainly: intercept a target's SMS, reconstruct their webmail and chats, own their phone's message path. That is not a hacker's wish-list. It is a product catalogue โ and WikiLeaks published it as the Spy Files.
The same files the nine-command kit hunts on a home router are the files a multi-billion-dollar "lawful interception" industry built appliances to capture, lawfully, for governments:
| What the botnet steals | The commercial product (Spy Files) | Vendor |
|---|---|---|
| Webmail / IM / chat content | EAGLE EYE โ IP TAP: passive deep-packet inspection with "reconstruction logicโฆ when intercepting complex applications such as webmail and IM/chat", 1โ10 Gbps, long-term retention | Amesys / ALTRON |
| Inbound/outbound SMS & GSM | SHOGI GSM Interception; ABILITY 3G GSM | Cobham; ABILITY |
| IM / VoIP / email lawful intercept | Enhanced Lawful Interception of IP apps | AQSACOM |
| Mobile-core / SS7 tapping | LIMA (SS7 / UMTS interception, Nokia provisioning) | Group2000 |
| Bulk IP interception & analysis | SS8 IP Interception + social-network analysis | SS8 |
| Endpoint message theft | lawful-intercept trojans, WIFI Intercept | DigiTask et al. |
Amesys even branded the scale: AMESYS COMINT, AMESYS STRATEGIC MASSIVE. The botnet's nine commands are the street-corner version of "STRATEGIC MASSIVE" โ the same interception goal, minus the rack-mounted appliance and the government contract.
๐ฑ๐พ The Ugly Reality, Proven by History
It would be comforting to call the interception industry a regrettable-but-lawful necessity. History does not allow it. The clearest documented case attaches to the very vendor whose EAGLE EYE appears in the catalogue above: Amesys.
Amesys' deep-packet-interception technology was sold to and deployed by the Gaddafi regime in Libya, where it was used to monitor dissidents, journalists and opposition figures โ people who were subsequently detained and, in documented instances, tortured. The capability marketed as "lawful interception of webmail and IM/chat" became, in practice, an instrument of state repression. The episode produced one of the first criminal-complaint investigations in Europe against a surveillance vendor for complicity in such abuses.
That is the thread this series promised to pull. The botnet hunting a SIM slot in someone's home router is not doing something new and exotic. It is doing something old and industrial โ the interception of human communication and identity โ that states normalised, vendors productised, and history has already condemned in at least one concrete, prosecuted instance.
๐ธ Follow the Money โ Where a Stolen Factor Cashes Out
A harvested session or an intercepted code is not the payday; it is the key to one. The downstream economy is well documented:
Catalogues investment- and account-takeover fraud at multi-billion-dollar scale, and explicitly recommends MFA and out-of-band verification to a "known verified number" โ the exact control an SMS-gateway hijack neutralises.
Documents how stolen funds and identity-theft proceeds (e.g. the Baller Ape rug-pull indictment) move through decentralized finance and crypto-swap services with lenient or non-existent KYC.
Describes crypto-swapping services that convert well-known coins into privacy coins to launder proceeds, "even advertising their non-compliance" โ the wash cycle for second-factor theft.
The pipeline is linear and each stage is sourced: recon (the nine commands) โ second-factor theft (session or SMS gateway) โ account/SIM-swap takeover โ crypto drain โ low-KYC swap laundering. The home router the botnet fingerprints sits at the very start of a chain that ends in a privacy-coin mixer.
โ๏ธ The Law Already Named It
There is no legal ambiguity about the criminal side. Using a stolen Telegram session or an intercepted SMS code to act as the victim is, in U.S. law, the "transfer, possession, and use, without lawful authority, of a means of identification of another person" โ Aggravated Identity Theft, 18 U.S.C. ยง 1028A, charged in DOJ indictments from APT41 to commodity fraud crews.
Set that beside the lawful-interception warrant and the symmetry is exact: both authorise reading another person's communications and assuming their identity on a system. One is a crime with a mandatory consecutive sentence; the other is a procurement line item. The act is identical; only the authorisation differs.
๐บ One Capability, Three Masks
The whole letter resolves to a single uncomfortable diagram โ the same interception capability wearing three faces:
| Mask | Who | Authorisation | Documented by |
|---|---|---|---|
| ๐๏ธ The State | Gaddafi-era Libya, others | Sovereign power (or none) | Amesys/Libya deployment history |
| ๐ข The Vendor | Amesys, Cobham, AQSACOM, SS8, Group2000 | "Lawful interception" contract | WikiLeaks Spy Files |
| ๐ฆ The Botnet | the nine-command operator (and its kind) | None โ aggravated identity theft | LSN honeypot (Letters A & B) |
Read top to bottom, it is a story of diffusion: a capability invented and normalised at the top of the stack leaks downward until it is a commodity any botnet can wield against a stranger's home router. The phone-as-second-factor put a tap point in every pocket; the only question left was who would reach it first.
โ๏ธ Verdict
The persistent botnet of Letter A is, at its core, an authentication-defeat operation. It hunts Telegram sessions and SMS gateways because both deliver the same thing: the second factor โ by skipping it, or by stealing it. It targets the one mechanism the standards body had already condemned (NIST's RESTRICTED label on SMS), wields a capability the surveillance industry built and sold (the Spy Files catalogue), inherits a history already written in blood (Amesys in Libya), monetises through a documented crypto-laundering tail (IC3, Treasury, Europol), and commits an offence the law already names (aggravated identity theft).
That is the "ugly reality proven by history" this series set out to find: the criminal did not innovate. They commoditised. The interception of identity and communication is an old industrial capability, normalised at the top of the power structure and now leaking out the bottom โ and the cheapest place to reach it turned out to be the SIM slot in a compromised home router.
Kill the SMS factor and you take both of the botnet's doors off the board at once. The standard told us to do it years ago. The botnet is the bill for not listening.
๐ Related & Coming Next
- TI-2026-048A โ The Nine Commands (the recon this letter reframes)
- TI-2026-002 โ MikroTik Recon & Telegram Stealer Botnet
- Next in The Long Memory: 048C โ Identity Without an Address ยท 048D โ The Re-tasking ยท 048E โ Ninety Days
Series: ๐งฌ The Long Memory ยท Letter: B ยท Classification: TLP:WHITE
Data sources: LSN SSH honeypot (TI-2026-048A Step-7 analysis). OSINT library: NIST SP 800-63B (PSTN/SMS RESTRICTED); WikiLeaks Spy Files (Amesys EAGLE EYE / COMINT / STRATEGIC MASSIVE; Cobham SHOGI GSM; AQSACOM; Group2000 LIMA; SS8); FBI IC3 2023; US Treasury DeFi Risk Assessment 2023; Europol crypto-tracing; DOJ APT41 indictment (18 U.S.C. ยง 1028A). Amesys/Libya per documented deployment history.
Investigation: TI-2026-048B ยท 3 actors ยท 7 evidence ยท 5 findings ยท 4 connections ยท cross-referenced to TI-2026-048A and TI-2026-002.