It connected yesterday. June 30, 2026. While we analyzed historical campaigns and profiled dead infrastructure, this one is still alive. Still connecting. Still checking. One session every eight days. Not scanning. Not exploiting. Not evaluating. Just asking: are you still there?

The most patient predator in the ecosystem.

I. Ninety-Seven Days and Counting

97
Days Active
12
Total Sessions
0.83s
Avg Duration
0
Commands Ever

March 25. The persistent watcher starts. Ninety-seven days later, it's still running. No other profiled actor approaches this longevity. The scanner fleet burned through its infrastructure in 26 days. The exploitation fleet lasted 80. The validator managed 81. This one outlasts them all โ€” because it does almost nothing.

Twelve sessions in 97 days. One connection every eight days, on average. Each lasts 0.83 seconds: connect, attempt credential, receive rejection (from the honeypot), disconnect. That's it. No commands. No downloads. No lateral movement. The absolute minimum footprint required to confirm: this target is still accepting SSH connections.

II. The Invisibility Gradient

ActorSessions/DayActive DaysDetection Risk
Scanner Fleet (055A)92426Very High
Exploitation Fleet (055B)24.580High
European Validator (055C)0.2881Low
Persistent Watcher (055D)0.1297+Negligible

The pattern is unmistakable: as you move up the supply chain, operations become exponentially quieter and proportionally longer-lived. The scanner trades longevity for volume. The watcher trades volume for permanence. At 0.12 sessions per day, it falls below every reasonable alerting threshold. No SIEM triggers on one failed login per week.

This is not a design flaw. It's the entire point. The watcher persists because it's invisible. It's invisible because it barely exists.

III. The Tool Choice

๐Ÿ”ง OpenSSH 7.9 (October 2018)

HASSH: b21d7cdcc8133dc2b430d1a039fece20

OpenSSH 7.9 was released in October 2018. It's not current, but it's not suspicious. Countless legitimate servers still run SSH clients from this era โ€” old CI systems, legacy jump boxes, monitoring scripts on LTS distributions. A connection from OpenSSH 7.9 looks like an admin checking a server from an older laptop. It blends.

Compare the tool choices across the supply chain: the scanner uses libssh2 (a library, clearly programmatic). The exploiter uses libssh (a different library, equally programmatic). The validator uses openssh_modern (legitimate client, looks human). The watcher uses OpenSSH 7.9 (slightly old, looks like a lazy admin who hasn't updated). Each stage chooses a tool that minimizes suspicion for its operating profile.

IV. The Infrastructure

IPCountryASNProviderThreat Score
170.64.167.72AU14061DigitalOcean78
64.227.134.80IN14061DigitalOcean64
206.189.157.111US14061DigitalOceanโ€”
207.154.232.101DE14061DigitalOceanโ€”
152.207.251.198BR31708โ€”โ€”
177.69.176.208BRโ€”โ€”โ€”
45.192.184.50CU396982โ€”โ€”
216.180.246.85US30058โ€”โ€”
85.215.66.55DE8560โ€”โ€”
89.187.80.32โ€”โ€”โ€”โ€”
216.227.189.55USโ€”โ€”โ€”
95.130.170.146โ€”โ€”โ€”โ€”

Four DigitalOcean droplets ($4-5/month each) provide the backbone. Total cost: $16-20/month for a global monitoring network. Add the other 8 IPs on various providers: perhaps $50-60/month total. For that price, the operator maintains a geographically-distributed uptime monitoring system that can detect whether compromised servers are still accessible from multiple continents.

This is the exact same architecture as legitimate services like Pingdom, UptimeRobot, or StatusCake. Except instead of monitoring customer websites, it monitors criminal infrastructure.

V. The Four-Stage Supply Chain

Complete Architecture โ€” All Four Stages Confirmed

StageActorFrequencyDurationProduct
1. Map055A Scanner924/day26 daysVulnerable target list
2. Compromise055B Exploiter24.5/day80 daysImplanted SSH keys
3. Evaluate055C Validator0.28/day81 daysAsset value profiles
4. Monitor055D Watcher0.12/day97+ daysAvailability status

The supply chain operates like any mature business: acquisition (scanning), conversion (exploitation), qualification (evaluation), and retention (monitoring). The watcher ensures the business doesn't lose assets silently. If a compromised server goes offline, the watcher detects it within 8 days. That's the SLA of criminal infrastructure management.

VI. Read Between the Lines

Why Zero Successes?

The watcher has zero successful logins on the honeypot. This isn't failure โ€” it's target specificity. The watcher connects to KNOWN compromised servers using KNOWN credentials. When it hits the honeypot (which it didn't compromise), it fails and moves on. On real targets โ€” servers where the exploitation fleet planted keys โ€” these connections succeed silently. We see the misses. The hits are invisible to us.

The Operator Above Rotation

Scanner fleets rotate every 26-30 days (054E). The watcher persists for 97+ days โ€” three full rotation cycles. It operates ABOVE the rotation layer. It watches regardless of which scanner generation feeds the pipeline. This implies a persistent management layer that outlives any individual campaign.

VII. The Thread Forward

Next: The Small Cells

Beyond the major actors, the dataset contains numerous clusters of 3-6 IPs. The long tail. Individual operators? Test environments? Each too small to profile individually, but collectively they represent a significant portion of the threat landscape. What patterns emerge when you study the small instead of the large?

โ†’ TI-2026-055E "The Small Cells"

Continuity

โ† TI-2026-055C "The European Cell" โ€” the validator whose assets this watcher monitors

โ† TI-2026-054E "Waves and Tides" โ€” the rotation cycles this watcher transcends

โ†’ TI-2026-055E "The Small Cells" โ€” the long tail of small operators

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Actor Profiles โ€” 4 / 7 Next โ†’