Two Clocks: Campaigns 126 and 157, and What Six Weeks of the Front Door Revealed

TI-2026-059F ยท Series: The Front Door ยท Classification: HIGH ยท Confidence: HIGH

The capstone of The Front Door series. Five dossiers followed five intent classes. This one steps back to the campaign layer โ€” 124 coordinated operations the platform has clustered from six weeks of web-edge telemetry โ€” and uses the two campaigns we were asked to examine, 126 and 157, to show that they are not two attacks but two settings of one dial.

Executive Summary

Behind the raw traffic sits a detector that groups coordinated activity into campaigns. As of this writing it has clustered 124 campaigns, covering 1,181 IPs with 1,758 memberships โ€” meaning IPs recur across campaigns, and that recurrence is itself an operator fingerprint.

It clusters them by exactly three signatures:

temporal_burst          81 campaigns   (spin up, fire, vanish)
shared_exploit_paths    37 campaigns   (same wordlist, many flags)
empty_ua_asn_cluster     6 campaigns   (one header, one ASN, persistent)

Those three methods are not an implementation detail. They are the observable shadow of three ways coordinated web attacks are actually run โ€” and each one is a dossier in this series. The two campaigns at the centre of this report, 126 and 157, sit at opposite ends of the same model: the persistent botnet and the ephemeral flash. Same cloud, same reputation-renting logic, two clock-speeds.

The Two Clocks

Campaign 126 โ€” the marathonCampaign 157 โ€” the sprint
Detectionempty-UA ASN clustertemporal burst
OriginMicrosoft Azure (AS8075)Google Cloud (AS396982)
Nodes200 IPs33 VMs
Requests36,3421,394
Duration~3 weeks (04โ€“30 Jun)~10 hours (15 Jun)
Intentshell_uploadcredential_harvest
Fingerprintone empty User-Agent90 secret paths in 2s/node
Modelpersistent, patient, broadephemeral, instant, gone

Campaign 126 is the marathon. Two hundred Azure nodes, unified by a single blank User-Agent, quietly hunting webshells across the internet for three weeks. It maximises coverage over time: keep a steady footprint, sweep everything, stay under the radar of anyone watching for spikes.

Campaign 157 is the sprint. Thirty-three Google Cloud VMs blink into existence, each fires roughly ninety distinct secret-file requests in about two seconds, and the whole operation is over in ten hours. It maximises evasion through speed: complete the survey before any reputation system can react, then discard every address.

They look like different threats. They are the same operator's model at two settings of a dial โ€” and an operator can turn that dial at will.

The Same Cloud Underneath Both

The top campaigns by volume tell one story over and over:

CampaignOriginIPsRequestsIntent
126 Empty-UA Botnet AS8075 (US)Azure20036,342shell_upload
180 Burst 2026-06-25 AS8075Azure208,120shell_upload
123 Empty-UA Botnet AS8075 (GB)Azure244,310shell_upload
190 Burst 2026-06-27 AS8075Azure183,679shell_upload
163 Burst 2026-06-17 AS8075Azure93,581shell_upload

Microsoft Azure (AS8075) dominates the leaderboard, and it appears in both detection classes โ€” persistent empty-UA botnets and temporal bursts. That is the 059B finding confirmed at campaign scale: the same disposable cloud, run at both clock-speeds, is the engine of the modern web threat. Google Cloud supplies the sprints (157); AWS supplies a share of the harvest (059A). The hyperscalers are not the victims here. They are the launch pad.

What the Series Adds Up To

Five dossiers, one conclusion. Laid end to end:

The unifying architecture is a two-tier structure: a disposable, reputation-renting hyperscaler layer on top (Azure, GCP, AWS) for volume and evasion, and a thin, persistent bulletproof shell layer underneath (TechTies in Seychelles, Cloudzy/RouterHosting) for durability and monetisation. The cloud IPs rotate; the shells are the fixed point.

Read Between the Lines

Q: If IPs recur across 124 campaigns, why not just build a great blocklist? Because the recurrence is mostly in the shells and signatures, not the cloud endpoints โ€” and the cloud endpoints are the volume. By the time an Azure or GCP address earns a place on your blocklist, the campaign that used it has ended and the address may now serve a legitimate customer. A blocklist of ephemeral hyperscaler IPs is a museum of addresses the attacker has already thrown away. The 1,758 memberships prove the operators recur; the individual IPs do not.

Q: Which is more dangerous โ€” the persistent botnet or the ephemeral burst? Wrong question; they cover for each other. The burst out-runs reputation systems (gone before you can list it); the persistent botnet out-waits rate limiters (too slow to trip a spike alarm). A defence tuned to one is blind to the other. That complementarity is exactly why the operator keeps both in the toolkit โ€” and why only detection that spans both timescales, keyed on behaviour rather than identity, actually works.

Q: The honeypot watched port 22 for years. Did the threat really move? The brute-forcers never left the back door โ€” but the interesting money moved to the front. SSH brute force is a slow, expensive gamble on a weak password. The front-door model is a fast, cheap survey for an exposed secret that hands over a root cloud credential outright. Same operators, better economics, a different port. The Front Door series is the record of where they went.

The Alternative Interpretation

Steelman the deflation: 124 "campaigns" could be an artefact of an over-eager clustering algorithm โ€” coincidental co-occurrence dressed up as coordination.

It is the right worry, and the data answers it. Coincidence does not produce 200 IPs sharing a single empty User-Agent in one ASN (126). Coincidence does not spin up 33 VMs in one cloud inside ten hours firing identical 90-path sweeps (157). Coincidence does not make a Hong-Kong shell and a Russian host fire the same ten xmlrpc paths in the same window (059C). Each detection method requires a specific, improbable agreement โ€” same header, same burst window, same bespoke wordlist โ€” that random background traffic does not generate. The clustering is conservative by construction, and 059D shows the platform is honest about its own false positives. The campaigns are real; the deflation does not survive the specifics.

Verdict

Campaigns 126 and 157 are the two clock-speeds of a single cloud-abuse model โ€” persistent and ephemeral โ€” and the 124-campaign taxonomy shows that model is the norm, not the exception, at the web edge. The series' cumulative finding is blunt: IP reputation is a dead control. The attacker rents reputable, disposable cloud compute on top of persistent bulletproof shells, and defeats any defence that keys on who is connecting. What actually caught them โ€” every time โ€” was keying on what they did: CrowdSec path-and-velocity signatures enforced at layer 3 by MikroTik. Confidence: HIGH on the model, the taxonomy and the reputation-is-dead conclusion; MEDIUM on single-operator attribution beneath the shell layer.

Defensive Response

Sources

Investigation TI-2026-059F ยท The Front Door series (finale) ยท 124 campaigns, three detection signatures, two clock-speeds ยท Capstone synthesis of 059Aโ€“059E ยท Confidence: HIGH.

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Front Door โ€” 6 / 6 Next โ†’