It connected yesterday. June 30, 2026. While we analyzed historical campaigns and profiled dead infrastructure, this one is still alive. Still connecting. Still checking. One session every eight days. Not scanning. Not exploiting. Not evaluating. Just asking: are you still there?
The most patient predator in the ecosystem.
I. Ninety-Seven Days and Counting
March 25. The persistent watcher starts. Ninety-seven days later, it's still running. No other profiled actor approaches this longevity. The scanner fleet burned through its infrastructure in 26 days. The exploitation fleet lasted 80. The validator managed 81. This one outlasts them all โ because it does almost nothing.
Twelve sessions in 97 days. One connection every eight days, on average. Each lasts 0.83 seconds: connect, attempt credential, receive rejection (from the honeypot), disconnect. That's it. No commands. No downloads. No lateral movement. The absolute minimum footprint required to confirm: this target is still accepting SSH connections.
II. The Invisibility Gradient
| Actor | Sessions/Day | Active Days | Detection Risk |
|---|---|---|---|
| Scanner Fleet (055A) | 924 | 26 | Very High |
| Exploitation Fleet (055B) | 24.5 | 80 | High |
| European Validator (055C) | 0.28 | 81 | Low |
| Persistent Watcher (055D) | 0.12 | 97+ | Negligible |
The pattern is unmistakable: as you move up the supply chain, operations become exponentially quieter and proportionally longer-lived. The scanner trades longevity for volume. The watcher trades volume for permanence. At 0.12 sessions per day, it falls below every reasonable alerting threshold. No SIEM triggers on one failed login per week.
This is not a design flaw. It's the entire point. The watcher persists because it's invisible. It's invisible because it barely exists.
III. The Tool Choice
๐ง OpenSSH 7.9 (October 2018)
OpenSSH 7.9 was released in October 2018. It's not current, but it's not suspicious. Countless legitimate servers still run SSH clients from this era โ old CI systems, legacy jump boxes, monitoring scripts on LTS distributions. A connection from OpenSSH 7.9 looks like an admin checking a server from an older laptop. It blends.
Compare the tool choices across the supply chain: the scanner uses libssh2 (a library, clearly programmatic). The exploiter uses libssh (a different library, equally programmatic). The validator uses openssh_modern (legitimate client, looks human). The watcher uses OpenSSH 7.9 (slightly old, looks like a lazy admin who hasn't updated). Each stage chooses a tool that minimizes suspicion for its operating profile.
IV. The Infrastructure
| IP | Country | ASN | Provider | Threat Score |
|---|---|---|---|---|
| 170.64.167.72 | AU | 14061 | DigitalOcean | 78 |
| 64.227.134.80 | IN | 14061 | DigitalOcean | 64 |
| 206.189.157.111 | US | 14061 | DigitalOcean | โ |
| 207.154.232.101 | DE | 14061 | DigitalOcean | โ |
| 152.207.251.198 | BR | 31708 | โ | โ |
| 177.69.176.208 | BR | โ | โ | โ |
| 45.192.184.50 | CU | 396982 | โ | โ |
| 216.180.246.85 | US | 30058 | โ | โ |
| 85.215.66.55 | DE | 8560 | โ | โ |
| 89.187.80.32 | โ | โ | โ | โ |
| 216.227.189.55 | US | โ | โ | โ |
| 95.130.170.146 | โ | โ | โ | โ |
Four DigitalOcean droplets ($4-5/month each) provide the backbone. Total cost: $16-20/month for a global monitoring network. Add the other 8 IPs on various providers: perhaps $50-60/month total. For that price, the operator maintains a geographically-distributed uptime monitoring system that can detect whether compromised servers are still accessible from multiple continents.
This is the exact same architecture as legitimate services like Pingdom, UptimeRobot, or StatusCake. Except instead of monitoring customer websites, it monitors criminal infrastructure.
V. The Four-Stage Supply Chain
Complete Architecture โ All Four Stages Confirmed
| Stage | Actor | Frequency | Duration | Product |
|---|---|---|---|---|
| 1. Map | 055A Scanner | 924/day | 26 days | Vulnerable target list |
| 2. Compromise | 055B Exploiter | 24.5/day | 80 days | Implanted SSH keys |
| 3. Evaluate | 055C Validator | 0.28/day | 81 days | Asset value profiles |
| 4. Monitor | 055D Watcher | 0.12/day | 97+ days | Availability status |
The supply chain operates like any mature business: acquisition (scanning), conversion (exploitation), qualification (evaluation), and retention (monitoring). The watcher ensures the business doesn't lose assets silently. If a compromised server goes offline, the watcher detects it within 8 days. That's the SLA of criminal infrastructure management.
VI. Read Between the Lines
Why Zero Successes?
The watcher has zero successful logins on the honeypot. This isn't failure โ it's target specificity. The watcher connects to KNOWN compromised servers using KNOWN credentials. When it hits the honeypot (which it didn't compromise), it fails and moves on. On real targets โ servers where the exploitation fleet planted keys โ these connections succeed silently. We see the misses. The hits are invisible to us.
The Operator Above Rotation
Scanner fleets rotate every 26-30 days (054E). The watcher persists for 97+ days โ three full rotation cycles. It operates ABOVE the rotation layer. It watches regardless of which scanner generation feeds the pipeline. This implies a persistent management layer that outlives any individual campaign.
VII. The Thread Forward
Next: The Small Cells
Beyond the major actors, the dataset contains numerous clusters of 3-6 IPs. The long tail. Individual operators? Test environments? Each too small to profile individually, but collectively they represent a significant portion of the threat landscape. What patterns emerge when you study the small instead of the large?
Continuity
โ TI-2026-055C "The European Cell" โ the validator whose assets this watcher monitors
โ TI-2026-054E "Waves and Tides" โ the rotation cycles this watcher transcends
โ TI-2026-055E "The Small Cells" โ the long tail of small operators