The Midtier: Reputable Enough to Launder
TI-2026-077D ยท The Laundered Vector, Part D โ The Finale Confidence: HIGH Classification: TLP:WHITE
The last question
Three letters in, we know a great deal. An attack was laundered through a commercial VPN (Part A); the pipe cannot be blocked without punishing the innocent (Part B); the two vectors are one coordinated operation, though the VPN erased the proof of exactly how many hands (Part C). One question remains, and it is the one that explains all the others: why this pipe?
Of all the ways to hide, why did the operator route through AS212238 โ a clean British CDN โ rather than a flagged bulletproof host in some permissive jurisdiction? The answer is the most counterintuitive finding in the series, and it closes it: the operator chose this network because it is respectable. Respectability is not an obstacle the attacker overcame. It is the product the attacker bought.
Deliberately, provably clean
Look at AS212238 the way a defender's reputation tooling would, and every light is green. Its risk score is a low 23.5. It carries no bulletproof flag. It is not Spamhaus-listed. It is a real content-delivery network (CDNEXT / Datacamp) with a named administrator (Jiri Prochazka), a proper RIPE allocation, 3,391 announced IPv4 prefixes, and a legitimate PeeringDB presence. There is nothing to flag. By every automated measure a security team might consult, this is a low-risk, ordinary, reputable network.
That is not a gap in the data. That is the finding. The attacker did not want a network that looks dangerous โ a network that looks dangerous gets blocked. They wanted a network that looks safe, because a network that looks safe gets waved through. The cleanliness of AS212238 is not something the laundering had to work around; it is the entire reason the laundering works. The operator went shopping for a good reputation and bought one.
The Armory already proved this
This is not a new idea; it is the perfection of one the census documented at length. The Bulletproof Shelf (TI-2026-075V) set out to find where attackers store their tooling and discovered something that surprised the intuition: most of it does not hide on flagged bulletproof ranges at all. It hides on ordinary, reputable, disposable cloud โ Google Cloud, OVH, Hetzner โ because reputation is what does not get blocked. The bulletproof shelf, the genuinely permissive underworld, turned out to be the minority of attack hosting; the reputable cloud was the majority.
The VPN midtier is that principle taken to its logical conclusion. Where the bulletproof host sells permissiveness โ "we won't act on abuse reports" โ the midtier sells invisibility โ "we look so normal that no one files the report, and if they do, no one dares block us." And invisibility is worth more than permissiveness, because the permissive host, for all its refusal to act, still looks dirty and still gets blocked at the far end by cautious defenders. The respectable one does not. A bulletproof host protects you from takedown; a reputable midtier protects you from ever being noticed. The second is the better product, and AS212238 is what it looks like: a clean CDN carrying a shared VPN, laundering an attack in plain, well-lit sight.
One hop from the underworld
Here is the twist that completes the portrait. For all its spotless reputation, AS212238 does not live in a different world from the bulletproof floor. It is routed right beside it.
Its BGP-upstream entity graph โ the map of which networks it exchanges routes with โ reads like a guest list from two very different parties standing next to each other. Alongside the ordinary carriers sit a striking roster of genuinely bulletproof networks:
- MangoTeleservice, Bangladesh (AS17806) โ risk 97.6, bulletproof.
- X99 Internet, Brazil (AS272786) โ risk 95.5, bulletproof.
- Host4Geeks (AS393960) โ risk 91.6, bulletproof.
- IP Volume inc, Seychelles (AS202425) โ risk 75.4, bulletproof.
- Bunny Communications (AS5065) โ risk 54.7, bulletproof.
And the dossier's connection graph records a specific direct upstream edge: AS212238 --bgp_upstream--> AS212552, BitCommand LLC (Armenia, risk 35.8) โ a small, low-profile provider of exactly the kind that sits in the seam between the reputable midtier and the bulletproof floor: obscure enough to attract little scrutiny, connected enough to route traffic.
None of these adjacent networks is the culprit of our attack, and it would be sloppy to imply otherwise โ routing adjacency is a weak link, and reputable networks peer widely. But the neighborhood is the signature. A spotless CDN whose routing table is thick with a Seychelles bulletproof host, a Bangladeshi bulletproof transit provider, and a dim Armenian upstream is displaying the topological fingerprint of the midtier: clean on its own record, one hop from the dirty. The laundry sits, as laundries do, exactly between the clean money and the dirty โ touching both.
This gives defenders something actionable that a reputation score alone never would: a hunting heuristic. A reputable network whose BGP neighborhood is unusually thick with bulletproof and obscure providers deserves behavioural scrutiny its own clean score would never trigger. The company a network keeps is a signal its score cannot capture.
Named, already, by the library
The corpus did not stumble onto this network โ it had already named its role. AS212238 is documented in TI-2026-066E, whose subtitle is, with no embellishment needed, "The Bulletproof Midtier โ Hiding Above Consequence." It appears in 023A (The VPN Laundromat), 034C (The Privacy Empire: From Adware to Four VPNs), and 041D (The Cloud Complicity). The category was defined; this live attack is simply the category caught working.
And "hiding above consequence" is the exact phrase for what the midtier does. It sits above the level where consequences land. Abuse reports slide off a reputable CDN โ they get filed, triaged, and lost in the volume of a legitimate business. Blocks never come, because blocking a respectable network is a decision no one wants to own. The midtier is not un-punishable because it is protected; it is un-punishable because it is above the altitude at which punishment operates. It floats over consequence, wearing the face of a CDN.
Why reputation cannot save you here
Step back to the mechanism, because it is the finale's real lesson and it is structural, not a bug to be patched.
The entire security industry leans on reputation. Block the bad ASNs. Trust the good ones. Score the ambiguous middle. It is a sensible model, and against most threats it works. The midtier is engineered to defeat it โ not by cheating the score, but by earning a good one honestly.
AS212238's reputation is genuinely clean because most of what it carries is genuinely legitimate. It really is a real CDN. It really does serve millions of real VPN users. So a reputation score, doing its job correctly, reports it as low-risk โ and is therefore correctly useless for finding the laundered attack inside it. This is the trap: a reputation score is an aggregate, a measurement of the average. The attack is a needle. And the midtier is the haystack the attacker chose precisely because its average looks clean. You cannot find a needle by measuring the haystack's mean, and the whole point of the midtier is to be a haystack whose mean is reassuring.
A defender who trusts the clean score is not making a mistake of diligence. They are trusting the exact property the attacker purchased. The reputation is real, the traffic behind it is mostly innocent, and the score is right โ and none of that helps, because the one hostile needle does not move the aggregate. Reputation was defeated not by defeating reputation, but by hiding inside a genuinely good one.
The series closes on one rule
Across four letters, from four different angles, the same conclusion held โ and stacking them is the finale's whole argument:
- The origin is laundered (Part A). Geography is a VPN's server menu, not a nationality.
- The pipe cannot be blocked (Part B). It is shared with the innocent majority, and the attacker re-exits for free.
- The operator count is erased (Part C). The VPN washes away the reused-key and timing signals that would name the hand.
- The reputation is bought (Part D). The network is clean by construction, so its score is clean and useless.
Every property a defender might key on โ geography, network, reputation, identity โ is defeated by the laundering, and defeated on purpose. This is not four separate problems. It is one design, seen four times: a machine for making everything about an attack look fine except the one thing that cannot be made to look fine.
Because there is exactly one property left standing, and it is the one the whole series is named for. Behaviour. What the traffic does. The credential harvest. The shell upload. The admin hunt. The libssh scan, the root:blank, the history worm. That behaviour is the attack itself, and it cannot be laundered, because to launder it away would be to stop attacking. The VPN can move the attacker to any country, hide them behind any reputation, erase how many they are โ and none of it changes that a hand reached for the lock.
That is why vectors don't lie. Every vector can be made to lie โ the source, the geography, the reputation, the identity โ except the one that is the attack itself. The behaviour is the vector that has nothing to hide behind, because it is the thing being hidden. Read that vector, and the whole apparatus of laundering โ the VPN, the shared pipe, the clean midtier, the bulletproof neighbors โ collapses into what it always was: an elaborate way of hiding a hand that is still, unmistakably, reaching for the lock.
The translation, for everybody
The last piece, in plain words: criminals do not hide in scary-looking places. They hide in respectable ones โ a nice building, a clean company, a good address โ because respectable places do not get raided. The most valuable thing a criminal's front can have is not a strong lock but a good reputation, because a good reputation means nobody looks twice. This network is a nice, clean, reputable building that happens to sit one street from a very bad neighborhood, and a criminal rented an office in it precisely so that everything about them would look fine.
You will never catch that criminal by checking whether the building has a good reputation โ it does, honestly, because almost everyone in it is legitimate. You catch them the same way you catch anyone: not by where they are or how nice the address is, but by watching what they do. They looked respectable in every way a form can measure. The only thing that gave them away was the act.
Reading the midtier โ for defenders
- Stop equating clean reputation with benign traffic. Respectability is the attacker's most-purchased camouflage. The cleaner the network, the better a laundered attack inside it evades reputation-based defence.
- Hunt on routing neighborhood, not just score. A reputable ASN whose BGP upstreams are thick with bulletproof and obscure providers is displaying the midtier signature โ scrutinise its behaviour beyond what its score would trigger.
- Accept that reputation cannot find the needle. The midtier scores clean by construction because its aggregate is genuinely clean. Detect on per-source behaviour, the only signal that separates the needle from the mean.
- Treat geography, network, reputation, and identity as laundered by default. For any attack through a VPN/proxy/midtier, assume all four are defeated. Build detection and response entirely on per-source, per-intent behaviour.
The Laundered Vector โ complete
Four letters, one live attack, one network, read to the end. It arrived wearing fourteen flags and not one was true; it came through a pipe that could not be blocked; it was one coordinated hand whose count the pipe erased; and it hid inside a reputation it had honestly bought. Everything about it was engineered to look fine.
Everything except what it did. And what it did was the only thing that was ever true about it.
The Laundered Vector โ complete.
The series
| A โ The Laundered Vector | The attack, the VPN attribution, the thesis |
|---|---|
| B โ The Pipe That Hides | Why you cannot block a VPN; judge the act |
| C โ One Hand, Two Doors | The cross-vector operator, and its honest limit |
| D โ The Midtier | Reputable enough to launder; the finale |
Cross-references
- TI-2026-066E โ The Bulletproof Midtier โ the category this network defines, named "Hiding Above Consequence."
- TI-2026-075V โ The Bulletproof Shelf โ most tooling hides on reputable, not bulletproof, networks.
- TI-2026-023A / 034C / 041D โ The VPN Laundromat / The Privacy Empire / The Cloud Complicity โ AS212238's documented laundering role.
- TI-2026-077AโC โ The Laundered Vector โ the attack, the pipe, and the operator this finale explains.
This dossier documents the reputable-midtier laundering layer for defensive purposes. AS212238 (Datacamp) is a lawful CDN and VPN substrate; the finding concerns why its very legitimacy makes it an attractive laundering layer, and why defence must therefore rest on behaviour rather than reputation. Adjacent networks named are routing neighbours, not accused parties. TLP:WHITE.