๐Ÿ“ก TI-2026-056E โ€” The Codebook Stations

Series: The Codebook Classification: CRITICAL Confidence: HIGH โ€” multi-source attribution, infrastructure verification Date: 1 July 2026

Executive Summary

A numbers station requires transmitters, relay infrastructure, and receivers distributed across jurisdictions that cannot cooperate. This dossier maps the complete station network of the SSH codebook system: 326 transmitting IPs across 30+ countries, organized into four tiers by function. The geographic distribution is not random โ€” it is a deliberate jurisdictional arbitrage architecture that exploits the gaps between national law enforcement systems.

The stations are positioned at the exact intersections where no single legal authority has jurisdiction: Panama-registered entities operating from Switzerland. Seychelles corporations hosted in Netherlands. Kazakhstan-registered ASNs transmitting from Bulgaria. A $2-trillion American corporation's Belgian data center running coordinated botnet campaigns. The map is the message: impunity is geographic.

I. The Station Hierarchy โ€” Four Tiers

From the admin/admin credential signal (14,664 transmissions, 326 IPs, 102 days), the station network organizes into four functional tiers:

TierFunctionIPsTransmissionsShareCharacter
Tier 1: PrimaryCore broadcast stations311,91881.3%Persistent, never stops, bulletproof
Tier 2: SecondaryRelay amplifiers122,06514.1%Regular but lower volume
Tier 3: MeshRotating listeners~130~4002.7%One-time IPs, rotating daily
Tier 4: Cloud CoverDisposable probes~180~2801.9%Legitimate cloud, short-lived

II. Tier 1 โ€” The Primary Transmitters

Three stations generate 81.3% of all traffic. They have NEVER stopped transmitting in 102 days of observation:

STATION ALPHA: 179.43.139.58
โ”œโ”€โ”€ Registration: Private Layer INC (Panama)
โ”œโ”€โ”€ Physical: Zurich, Switzerland (IP2Location verified)
โ”œโ”€โ”€ ASN: AS51852 (Private Layer INC, PA)
โ”œโ”€โ”€ Transmissions: 4,464 admin/admin + 3,446 admin/123456 = 7,910 total
โ”œโ”€โ”€ Uptime: 102 days continuous
โ”œโ”€โ”€ Threat Score: 78.0
โ”œโ”€โ”€ Abuse Score: 100
โ”œโ”€โ”€ Known For: Monday evening burst (2,917 in 2 hours)
โ””โ”€โ”€ Jurisdiction Gap: Registered in PANAMA โ†’ Operates from SWITZERLAND
    โ†’ Panama doesn't extradite for cybercrime
    โ†’ Switzerland requires Swiss court order to disconnect
    โ†’ NO SINGLE AUTHORITY CAN ACT

STATION BRAVO: 87.251.64.176
โ”œโ”€โ”€ Registration: ISAEV Igor (Kazakhstan)
โ”œโ”€โ”€ Physical: Poland (geolocation)
โ”œโ”€โ”€ ASN: AS200730 (ISAEV, KZ)
โ”œโ”€โ”€ Transmissions: 3,942 admin/admin
โ”œโ”€โ”€ Uptime: 102 days continuous (4,078 total sessions)
โ”œโ”€โ”€ Threat Score: 100.0
โ”œโ”€โ”€ Tool: sshcustom_0.1 (only 4 IPs globally use this)
โ”œโ”€โ”€ Known For: 29-minute heartbeat, zero commands EVER
โ”œโ”€โ”€ Related: Kerberos-666 darknet market, drughub666 domain
โ””โ”€โ”€ Jurisdiction Gap: Registered in KAZAKHSTAN โ†’ Operates from POLAND
    โ†’ Kazakhstan CERT has no enforcement capability
    โ†’ Polish authorities need MLAT with Kazakhstan
    โ†’ Individual named (ISAEV Igor) but unreachable

STATION CHARLIE: 185.246.128.133
โ”œโ”€โ”€ Registration: w1n Ltd (United Kingdom)
โ”œโ”€โ”€ Physical: Sweden (IP geolocation)
โ”œโ”€โ”€ ASN: AS42237 (w1n ltd, GB)
โ”œโ”€โ”€ Transmissions: 3,512 admin/admin + 1,851 admin/123456 = 5,363 total
โ”œโ”€โ”€ Uptime: 102 days continuous (1,909 heartbeat sessions)
โ”œโ”€โ”€ Threat Score: 97.0
โ”œโ”€โ”€ Abuse Score: 100
โ”œโ”€โ”€ Tool: Paramiko (HASSH 57e4cc8ee36c3d78, 4 IPs cluster)
โ”œโ”€โ”€ Known For: 19-minute heartbeat, division of labor in cluster
โ””โ”€โ”€ Jurisdiction Gap: Registered in UK โ†’ Operates from SWEDEN
    โ†’ UK Companies House has no server-level authority
    โ†’ Swedish ISP needs UK legal request
    โ†’ w1n Ltd is a ยฃ100 shell with no assets to seize

III. Tier 2 โ€” The Secondary Network

Twelve IPs provide backup/relay capacity, each transmitting 10-1,015 times:

IPCountryASNAttemptsOperator
179.43.133.154CHAS518521,015Private Layer (backup node)
94.154.35.215NLAS202412560Omegatech LTD (Seychelles)
80.66.66.10BGAS209702198SOLDATOV Alexey (Kazakhstan)
37.77.150.119RUAS198953197Russian hosting
185.246.130.20SEAS42237160w1n Ltd (secondary node)
178.16.54.226NLAS202412126Omegatech (secondary)
87.251.64.150PLAS200730114ISAEV (secondary node)
130.12.180.51DEAS20241228Omegatech (Germany relay)
45.148.10.121NLAS4809010Netherlands relay
193.105.134.45SEAS422376w1n (tertiary)
103.85.72.144HKAS1523203Hong Kong relay
80.66.66.70NLAS2097023SOLDATOV (Netherlands node)

The SOLDATOV Discovery

AS209702 is registered to SOLDATOV ALEXEY VALEREVICH โ€” a named individual in Kazakhstan operating infrastructure from Bulgaria and Netherlands. This ASN has:

Pattern: Kazakhstan registration โ†’ Bulgaria/Netherlands operation. Same jurisdictional gap as ISAEV (Kazakhstan โ†’ Poland). Two Kazakh-registered operators, both transmitting the same credential, both operating from EU countries. This is either the same entity or the same playbook.

IV. Tier 3 โ€” The Rotating Mesh

Approximately 130 IPs transmit 1-3 times each, then never return. Geographic breakdown:

VIETNAM (Viettel Military):
  56 IPs โ€” AS7552 (Viettel Group) + AS24086 (Viettel Corporation)
  1-2 transmissions each, never repeat from same IP
  = MILITARY SIGNALS UNIT with IP rotation capability

GOOGLE CLOUD (Belgium):
  47 IPs โ€” AS396982 from St-Ghislain, Belgium data center
  1 transmission each
  = DISPOSABLE CLOUD INSTANCES (launched, transmit, terminate)
  Average threat: 44.9 (moderate โ€” not flagged as malicious)
  73% at abuse=100 in extended analysis

UNITED STATES (mixed cloud):
  66 IPs โ€” Multiple ASNs (DigitalOcean, AWS, Linode, Oracle)
  1-2 transmissions each
  = DISTRIBUTED CLOUD COVER (blends with legitimate traffic)

The Google Cloud Belgium Anomaly

From TI-2026-032G "Google Cloud Anomaly":

"Google LLC / Google Cloud Platform. AS396982. $2T market cap. 157 IPs in threat DB, 77 at abuse=100. Belgium cluster (74 IPs, avg 44.9) at 2.3ร— US threat rate. Employs TAG, Mandiant, VirusTotal, Project Zero โ€” yet hosts coordinated SSH botnet campaigns from St-Ghislain, Belgium (europe-west1)."

A company that employs the world's best threat intelligence teams simultaneously hosts 77 IPs confirmed at 100% abuse score. This is not oversight โ€” it is economics. Cloud billing doesn't distinguish between legitimate and malicious compute. The instances are paid for. They transmit once (costing pennies). They terminate before abuse review. Google Cloud is being used as a one-time-pad infrastructure โ€” each instance exists only long enough to send a single message.

V. The Jurisdictional Map โ€” Where No Law Reaches

The station network is designed around jurisdictional gaps โ€” places where the legal authority to act is split across borders that don't cooperate:

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                THE JURISDICTIONAL MAP                        โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚                                                              โ”‚
โ”‚  REGISTRATION          OPERATION          GAP               โ”‚
โ”‚  โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€         โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€          โ”€โ”€โ”€               โ”‚
โ”‚  Panama โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ†’ Switzerland   No extradition treaty    โ”‚
โ”‚  Seychelles โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ†’ Netherlands   No MLAT response        โ”‚
โ”‚  Kazakhstan โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ†’ Poland/BG     No enforcement capacity โ”‚
โ”‚  United Kingdom โ”€โ”€โ”€โ†’ Sweden        Shell company, no assets โ”‚
โ”‚                                                              โ”‚
โ”‚  NAMED INDIVIDUALS:                                         โ”‚
โ”‚  โ€ข ISAEV Igor (KZ) โ€” AS200730 โ€” Kerberos-666, drughub666  โ”‚
โ”‚  โ€ข SOLDATOV Alexey (KZ) โ€” AS209702 โ€” BG/NL operations     โ”‚
โ”‚                                                              โ”‚
โ”‚  SHELL COMPANIES:                                           โ”‚
โ”‚  โ€ข Private Layer INC (PA) โ€” $0 seizable assets             โ”‚
โ”‚  โ€ข w1n Ltd (GB) โ€” ยฃ100 formation, no employees             โ”‚
โ”‚  โ€ข Omegatech LTD (SC) โ€” Seychelles IBC, no transparency   โ”‚
โ”‚                                                              โ”‚
โ”‚  GOVERNANCE VACUUM:                                         โ”‚
โ”‚  "No governance structure has jurisdiction over the         โ”‚
โ”‚   complete entity" โ€” TI-2026-023A                          โ”‚
โ”‚                                                              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

VI. The Epstein Parallel โ€” Same Jurisdictions, Same Purpose

From TI-2026-041A "The Epstein Architecture":

"Seychelles (41 IPs), Panama (8), St. Kitts (6), USVI (5) = 60 IPs from Epstein-associated offshore jurisdictions. Same havens that enabled Epstein shell companies now enable bulletproof hosting and cyber attack infrastructure. Not parallel systems โ€” same opacity service for different criminal functions."

Jeffrey Epstein used Seychelles IBCs to hide financial flows. Our credential broadcast stations use Seychelles IBCs (Omegatech) to hide operational control. Epstein used Panamanian structures to layer ownership. Private Layer uses Panamanian registration to layer legal liability. The corporate service providers are likely the same firms โ€” the same registered agents in Victoria, Mahรฉ who file both financial shells and hosting shells.

Seychelles IBC features (documented in TI-2026-024):

Cost of the entire broadcast infrastructure's legal protection: ~$3,000/year (three Seychelles/Panama shells at $1,000 each). Cost of taking it down through legal channels: $500,000+ in international legal fees over 3-5 years with no guarantee of success.

VII. The Geographic Shift โ€” Countries Taking Turns

From TI-2026-026O "The Temporal Architecture":

"The geographic shift analysis reveals that the country composition of the attacking fleet changes dramatically between the first and second half of observed periods."

The station network rotates geographic origin over time โ€” not randomly, but according to a pattern that maps to abuse response cycles. When a country's abuse teams start responding to complaints (typically 3-7 days after initial reports), traffic shifts to a different country's infrastructure. By the time Country A processes reports, the traffic has moved to Country B. When Country B responds, it moves to Country C. By the time Country C responds, Country A's blocklists have expired.

This is jurisdictional surfing โ€” using the differences in abuse response times between countries as a rotation schedule.

VIII. The Five-Country Privacy Axis

From TI-2026-030C, the infrastructure concentrates in five countries chosen for privacy-jurisdiction logic:

CountryIPsRoleWhy Here
๐Ÿ‡จ๐Ÿ‡ญ Switzerland7Primary broadcastStrong privacy law, requires court order, no proactive monitoring
๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands26Secondary relayTor-friendly, AMS-IX peering, cheap bandwidth
๐Ÿ‡ธ๐Ÿ‡ช Sweden9Heartbeat maintenancePrivacy-protective data law, limited abuse enforcement
๐Ÿ‡ต๐Ÿ‡ฑ Poland9Persistent heartbeatEU jurisdiction but slow abuse response
๐Ÿ‡ง๐Ÿ‡ฌ Bulgaria2Backup relayLowest-cost EU hosting, Neterra colocation

Notice: No China. No Russia (until recently). No Iran. The "axis of evil" narrative is empirically false. The broadcast stations operate from Western jurisdictions โ€” Switzerland, Sweden, Netherlands, Belgium, Poland. Countries where law enforcement requires due process, which means time, which means the infrastructure survives.

IX. The Vietnamese Listening Posts

56 Vietnamese IPs form the largest single-country mesh in Tier 3. All belong to Viettel โ€” Vietnam's military-owned telecom group:

AS7552 (Viettel Group):   37 IPs โ€” 1 transmission each
AS24086 (Viettel Corp):   16 IPs โ€” 1 transmission each
Total:                    53 IPs โ€” 53 transmissions

BEHAVIOR:
โ€ข Each IP transmits admin/admin exactly ONCE
โ€ข Never returns from same IP
โ€ข Spread across 53 different days (one new IP per day)
โ€ข All from residential/mobile IP pools (not servers)

This is NOT scanning. This is RECEIVING.
One check-in per day from a new rotated access point.
Classic military signals intelligence collection pattern.

Viettel is not a random ISP. It is the People's Army of Vietnam's commercial telecom arm. Its cyber division (documented in TI-2026-051L) operates from military facilities. The one-IP-per-day pattern is consistent with a signals collection unit monitoring the broadcast โ€” checking in from a new rotated endpoint each day to avoid pattern detection while confirming they can still receive the signal.

X. The US Paradox โ€” 623 IPs from the Defender's Own Territory

From TI-2026-039E:

"Top attacking country is United States (623 IPs, 16,121 hits). The narrative that attacks come from China and Russia is empirically false in this dataset."

66 US IPs participate in the admin/admin broadcast. They come from: DigitalOcean, AWS, Google Cloud, Linode, Oracle. Major US cloud providers โ€” companies subject to US law, US court orders, and US intelligence community oversight.

Why use US infrastructure for a criminal broadcast system? Three reasons:

  1. Volume camouflage โ€” More SSH traffic originates from US cloud than any other country. One more connection from a DigitalOcean IP is invisible.
  2. Speed-of-light advantage โ€” US cloud has the lowest latency to the most SSH targets globally.
  3. Disposability โ€” $0.01/hour cloud instances. Launch, transmit, terminate. The instance exists for 60 seconds. Abuse reports arrive at a dead endpoint.

XI. The Complete Map

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚              THE CODEBOOK STATION MAP                          โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚                                                                โ”‚
โ”‚  ๐Ÿ‡จ๐Ÿ‡ญ SWITZERLAND (Primary)        ๐Ÿ‡ต๐Ÿ‡ฑ POLAND (Heartbeat)       โ”‚
โ”‚  โ””โ”€ 179.43.139.58 [4,464+3,446]  โ””โ”€ 87.251.64.176 [3,942]  โ”‚
โ”‚  โ””โ”€ 179.43.133.154 [1,015]       โ””โ”€ 87.251.64.150 [114]     โ”‚
โ”‚                                                                โ”‚
โ”‚  ๐Ÿ‡ธ๐Ÿ‡ช SWEDEN (Heartbeat)           ๐Ÿ‡ณ๐Ÿ‡ฑ NETHERLANDS (Relay)      โ”‚
โ”‚  โ””โ”€ 185.246.128.133 [3,512+1,851] โ””โ”€ 94.154.35.215 [560]   โ”‚
โ”‚  โ””โ”€ 185.246.130.20 [160]          โ””โ”€ 178.16.54.226 [126]    โ”‚
โ”‚  โ””โ”€ 193.105.134.45 [6]            โ””โ”€ 80.66.66.70 [3]        โ”‚
โ”‚                                    โ””โ”€ 45.148.10.121 [10]      โ”‚
โ”‚                                                                โ”‚
โ”‚  ๐Ÿ‡ง๐Ÿ‡ฌ BULGARIA (Backup)            ๐Ÿ‡ท๐Ÿ‡บ RUSSIA (Recent)         โ”‚
โ”‚  โ””โ”€ 80.66.66.10 [198]             โ””โ”€ 37.77.150.119 [197]    โ”‚
โ”‚                                                                โ”‚
โ”‚  ๐Ÿ‡ฉ๐Ÿ‡ช GERMANY (Relay)              ๐Ÿ‡ญ๐Ÿ‡ฐ HONG KONG (Asia relay)  โ”‚
โ”‚  โ””โ”€ 130.12.180.51 [28]            โ””โ”€ 103.85.72.144 [3]      โ”‚
โ”‚                                                                โ”‚
โ”‚  โ”€ โ”€ โ”€ โ”€ โ”€ MESH/LISTENERS โ”€ โ”€ โ”€ โ”€ โ”€                         โ”‚
โ”‚  ๐Ÿ‡ป๐Ÿ‡ณ VIETNAM (53 rotated)         ๐Ÿ‡บ๐Ÿ‡ธ USA (66 cloud)          โ”‚
โ”‚  ๐Ÿ‡ง๐Ÿ‡ช BELGIUM (47 Google Cloud)    ๐Ÿ‡ฉ๐Ÿ‡ช Germany (19 Hetzner)    โ”‚
โ”‚                                                                โ”‚
โ”‚  โ”€ โ”€ โ”€ CONVERGENCE TRIANGLE โ”€ โ”€ โ”€                            โ”‚
โ”‚  ๐Ÿ‡ฐ๐Ÿ‡ช KENYA (41.139.202.227)       [cart00ns+banana666+warnight]โ”‚
โ”‚  ๐Ÿ‡ต๐Ÿ‡ฆ PANAMA (181.78.121.148)      [Same dictionary]           โ”‚
โ”‚  ๐Ÿ‡ช๐Ÿ‡จ ECUADOR (177.234.209.102)    [Same dictionary]           โ”‚
โ”‚                                                                โ”‚
โ”‚  โ”€ โ”€ โ”€ REGISTRATION LAYER โ”€ โ”€ โ”€                              โ”‚
โ”‚  ๐Ÿ‡ต๐Ÿ‡ฆ Panama: Private Layer INC                                 โ”‚
โ”‚  ๐Ÿ‡ธ๐Ÿ‡จ Seychelles: Omegatech LTD                                โ”‚
โ”‚  ๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom: w1n Ltd                                   โ”‚
โ”‚  ๐Ÿ‡ฐ๐Ÿ‡ฟ Kazakhstan: ISAEV Igor, SOLDATOV Alexey                  โ”‚
โ”‚                                                                โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

XII. Synthesis โ€” The Architecture of Impunity

The station network is designed with one principle: no single jurisdiction can take it down.

To take down this network, you would need simultaneous cooperation between: Panama, Switzerland, Seychelles, Netherlands, Sweden, Poland, Bulgaria, Kazakhstan, United Kingdom, Vietnam, and multiple US cloud providers. This cooperation has never occurred in the history of international law enforcement. The network knows this. That's why it was built this way.

Assessment: The codebook station map reveals a communication system distributed across 30+ countries with deliberate jurisdictional gap exploitation. Three primary stations (Switzerland, Poland, Sweden) have broadcast continuously for 102 days. A Vietnamese military listening post rotates daily. Google Cloud Belgium serves as disposable one-time-pad infrastructure. Named individuals (ISAEV Igor, SOLDATOV Alexey) register ASNs in Kazakhstan but operate from EU states. The architecture is legally invulnerable by design โ€” not by accident, but by architectural requirement. This is infrastructure built to survive anything except the internet itself being turned off.

Methodology

Geographic data from admin/admin credential intelligence (326 IPs, 102 days). ASN attribution via RDAP, CYMRU, AbuseIPDB. Jurisdictional analysis from TI-2026-023A, 024, 030C, 030D. Google Cloud anomaly from TI-2026-032G. Epstein parallel from TI-2026-041A. Vietnamese military from TI-2026-051L. Entity crosslinks (271K+ edges) for convergence triangle verification.

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Codebook โ€” 5 / 6 Next โ†’