TI-2026-049C โ Eighty-Four Flags
๐ Executive Summary
The libssh swarm's 2,341 IPs span 84 countries across 5 continents. Asia hosts 54.5% (1,276 IPs), the Americas 24.5% (573), Europe 15.1% (353), Africa 2.9% (67), and Oceania 0.2% (4). This distribution is not proportional to population, internet penetration, or GDP. It is proportional to one thing: the cost of operating malicious infrastructure without consequence.
The per-capita density metric strips away the noise of absolute numbers to reveal where the operator concentrates infrastructure relative to the country's actual size:
| Country | IPs | Population | IPs/Million | ร US Rate |
|---|---|---|---|---|
| ๐ธ๐จ Seychelles | 24 | 100,000 | 240.0 | 267ร |
| ๐ธ๐ฌ Singapore | 160 | 5.9M | 27.1 | 30ร |
| ๐ญ๐ฐ Hong Kong | 187 | 7.5M | 24.9 | 28ร |
| ๐ฐ๐ท South Korea | 130 | 51.8M | 2.5 | 2.8ร |
| ๐บ๐ธ United States | 313 | 331M | 0.9 | 1.0ร |
| ๐จ๐ณ China | 228 | 1,412M | 0.2 | 0.2ร |
Three jurisdictional stories emerge: offshore shells (Seychelles), cloud hubs (Singapore, Hong Kong), and burst deployment on domestic cloud (China via ByteDance). Each represents a different optimization: opacity, performance, or volume.
๐ธ๐จ Part I โ The Seychelles Anomaly
Twenty-four IPs. Population one hundred thousand. A density of 240 scanner IPs per million residents.
Every one of the 24 Seychelles IPs traces to a single entity: Cloud Innovation Ltd โ or its alias, Cloud Innovation Support. This is not a hosting provider in any conventional sense. It is a shell company registered under Seychelles International Business Company (IBC) law, operating through 14 different Autonomous System Numbers:
Fourteen ASNs. One beneficial owner. This is the hosting equivalent of a shell company structure โ multiple legal entities in routing tables, one actual operator behind them. In BGP, each ASN appears as a separate network. To a researcher checking IP ownership, they look like 14 different providers. In reality, they are 14 letterboxes at the same address.
Cloud Innovation's connection to Yisu Cloud Ltd via shared phone number +248-4-610-795 was documented in TI-2026-028. This is not new discovery. It is persistence โ the same offshore structure, previously documented serving other botnets, now hosting the libssh swarm.
๐ Why Seychelles?
Seychelles IBC registration requires no public disclosure of beneficial owners. Annual fees are minimal (~$100). There is no requirement to file accounts. The jurisdiction has no mutual legal assistance treaty with China. For a hosting shell company, this means: register for $100, announce IP space through 14 ASNs, host anything, respond to nothing. The cost of impunity is the price of a dinner.
๐ข Part II โ TikTok's Parent Company Hosts the Swarm
ByteDance โ the company behind TikTok, Douyin, and a portfolio of apps used by over a billion people โ operates enterprise cloud services under two brands: Volcano Engine (China domestic) and BytePlus (international). Together, they host 141 scanner IPs in the libssh swarm โ 6% of the entire operation.
| Brand | ASNs | IPs | Region | Campaign |
|---|---|---|---|---|
| Volcano Engine | AS4811 + AS137718 |
90 | ๐จ๐ณ China only | 100% in 0.11.x |
| BytePlus | AS150436 |
51 | ๐ธ๐ฌ SG / ๐ญ๐ฐ HK / ๐ฎ๐ฉ ID | Mixed campaigns |
| Total ByteDance | 141 | 6% of the swarm | ||
The 90 Volcano Engine IPs are exclusively in the 0.11.x campaign โ the expansion phase. Not a single one appears in 0.9.6 or 0.12.0. This burst-deployment pattern suggests the Chinese domestic cloud was used for rapid scaling and then abandoned โ possibly because abuse handling improved, or because the operator moved to cheaper infrastructure.
This was previously documented in TI-2026-045K. ByteDance's cloud is not uniquely culpable โ Amazon, Microsoft, Google, and DigitalOcean all host swarm nodes. But the concentration (141 IPs = more than any country except US, China, and Hong Kong) makes ByteDance infrastructure structurally significant to this operation.
๐จ๐ณ Part III โ China's Version Skew
China contributes 228 IPs to the swarm. But the distribution across campaigns is unlike any other country:
5
libssh 0.9.6
220
libssh 0.11.x
3
libssh 0.12.0
96.5% of Chinese IPs appear only in the 0.11.x campaign. Compare this to the top-15 countries overall, where every country appears in all three campaigns. China was used for exactly one purpose: the 0.11.x expansion wave. The nodes were provisioned, used, and then discarded.
The Chinese cloud providers involved: Volcano Engine/ByteDance (90), ChinaNet/China Telecom (31), Baidu Cloud (23), China Unicom (8). The first is a commercial cloud. The last three are state-owned or state-adjacent telecoms โ their IPs may represent compromised endpoints rather than provisioned scanners.
๐ธ๐ฌ Part IV โ Singapore: The Optimal Launch Pad
Singapore (160 IPs, 27.1 per million) serves as the swarm's Asian hub. But the concentration is not distributed across Singapore's hosting ecosystem โ it is concentrated on two providers:
88
Aceville Pte Ltd (AS132203)
55% of all Singapore IPs. Top ASN in the entire swarm (157 IPs globally). 97 of 157 IPs are from the 0.9.6 campaign โ the oldest, most established fleet.
32
BytePlus (AS150436)
20% of Singapore IPs. ByteDance's international arm. Mixed campaign presence.
Singapore's value is not jurisdictional opacity (its legal system is robust and English-speaking). Its value is network performance: excellent peering to Southeast Asia and China, multiple submarine cable landings, low latency to the largest target population (Asia-Pacific). The operator chose Singapore to scan Asian targets fast, not to hide.
๐ Part V โ The Detection-Action Gap
Nearly half the swarm has been reported to maximum severity โ and is still operating.
48.8%
AbuseIPDB score = 100
(1,143 of 2,340 IPs)
8.1%
GreyNoise "malicious"
(190 of 2,340 IPs)
84
Countries
5 continents
1,143 IPs have been reported to AbuseIPDB at the maximum severity โ score 100 out of 100. The security industry knows these IPs are malicious. Every threat feed includes them. Every SIEM would flag them. And yet they are still scanning.
This is not a detection problem. It is an action problem. The gap between detection and action is the swarm's operating margin:
- Abuse handlers who don't respond โ UCloud-HK, Volcano Engine, Cloud Innovation have no public track record of acting on abuse reports
- Jurisdictions that don't cooperate โ a European CERT's abuse report about a Seychelles IP traverses two legal systems that share no mutual assistance framework
- Cloud providers who treat abuse as a cost center โ taking down paying customers costs revenue; processing abuse reports costs labor; the economic incentive is to do nothing
๐บ๏ธ Part VI โ The Continental Map
| Continent | IPs | Share | Top Countries | Primary Role |
|---|---|---|---|---|
| Asia | 1,276 | 54.5% | CN=228, HK=187, SG=160, ID=155, KR=130 | Cloud burst + scanning hub |
| Americas | 573 | 24.5% | US=313, BR=93, CO=30, MX=25, PE=20 | Cloud VPS + ISP compromise |
| Europe | 353 | 15.1% | DE=68, RU=62, GB=47, FR=38, ES=25 | VPS hosting (OVH, Hetzner, IONOS) |
| Africa | 67 | 2.9% | KE=11, MA=9, SN=9, NG=8, SC=24 | Offshore shells + ISP endpoints |
| Oceania | 4 | 0.2% | AU=4 | Minimal presence |
The all-3-campaigns presence of the top 15 countries proves geographic persistence โ the operator maintains infrastructure in these locations across version upgrades. The geography is strategic, not accidental.
โ๏ธ Verdict โ The Map Is the Strategy
- [DOCUMENTED] Seychelles at 240 IPs/million (267ร US rate) โ Cloud Innovation Ltd shell company with 14 ASNs, previously documented in TI-2026-042O.
- [DOCUMENTED] ByteDance (Volcano Engine + BytePlus): 141 IPs, 6% of swarm. TikTok's parent company's cloud hosting botnet scanners.
- [DOCUMENTED] China 228 IPs, 96.5% in 0.11.x only โ burst deployment pattern, then withdrawal.
- [DOCUMENTED] 48.8% of IPs have AbuseIPDB score 100 โ detected and still active. Detection works. Action doesn't.
- [INFERRED] The geographic distribution optimizes for three variables: hosting cost, abuse-response latency, and network performance to Asian targets.
The swarm does not fly 84 flags because it wants to be everywhere. It flies 84 flags because no single country can take them all down. The jurisdictional friction between 84 legal systems, 84 abuse-handling procedures, and 84 different response timelines is itself a defensive mechanism. The map is not a consequence of the operation. The map is the operation.
The next letter traces the version tree โ the CVE history of libssh 0.9.6, 0.11.x, and 0.12.0, and what the operator's version choices reveal about their priorities.
๐ Related & Coming Next
โ Prior
TI-2026-049A โ The Library That Moves
TI-2026-049B โ The Command Language
TI-2026-042O โ Omegatech Empire (Cloud Innovation)
TI-2026-045K โ Baidu-ByteDance
โ Next in Series
TI-2026-049D โ "The Version Tree" โ CVE history and operator priorities
TI-2026-049E โ "The Clock Tower" โ temporal patterns
TI-2026-049F โ "The Census" โ statistical synthesis
Sources: Cowrie honeypot ยท AbuseIPDB ยท GreyNoise ยท RDAP ยท entity_links ยท TI-2026-042O ยท TI-2026-045K ยท TI-2026-028 ยท TI-2026-025D ยท Seychelles IBC registry
Investigation: TI-2026-049C ยท 8 evidence ยท 4 actors ยท 6 findings ยท 6 connections ยท 7 infrastructure
Confidence: HIGH โ direct observation + per-capita statistical analysis + cross-dossier institutional verification
Classification: TLP:WHITE