OHIIHO Research publishes threat intelligence derived primarily from high-interaction sensor operations across more than 20 countries. Our work prioritises observable behaviour, attribution restraint, and detection-ready evidence for defensive teams.

OHIIHO’s commercial product is HIIH, a managed adversary-intelligence system. Learn about the product at ohiiho.com/hiih .

Where the data comes from

The bulk of what we publish comes from the HIIH honeypot sensors — a worldwide network of high-interaction sensor nodes operating across 20+ countries, capturing targeted threat campaigns and APT-grade attackers. The sensor network produces first-hand telemetry: live SSH session captures with keystroke timing, complete command sequences, infrastructure pivots, payload deployment chains, and the post-exploitation routines that operators reach for once they think they have a real box.

We do not aggregate third-party reporting. When we cite other research, we cite it as such. When we make a claim, the evidence is in our logs.

What we publish

Reports. Technical analyses of specific actors, malware kits, or campaigns observed live on the sensor network. Reports come with detection-ready material such as a defanged IOC table (with evidence_class and confidence columns), YARA rules, Sigma signatures, and Elastic / KQL hunting queries. Reports are organised by campaign or actor cluster; each has a stable canonical URL and a sibling SOC-facing detection brief when the operational angle warrants its own page.

Briefs. Shorter doctrine pieces — systemic cyber risk, deception, AI-enabled attacks, the strategic grammar of autonomous tradecraft. No IOCs, more argument.

Both formats are open in RSS at /index.xml. No comments, no analytics, no engagement metrics, no newsletter funnel.

Editorial standards

  • OPSEC scrub before publication. Internal tenant IDs, sensor metadata, and host-specific markers are redacted from the public versions. Verified CERTs, law-enforcement, and incident responders working a confirmed case may request the unredacted artefacts at research@ohiiho.com.
  • Address publication is graded by what the address is. Infrastructure under attacker control — C2, payload hosts, staging — may be published in full, with the evidence for that classification stated. Ambiguous scanner and VPS sources are published in full for a limited period. Third-party hosts compromised by the campaign under study are masked to a prefix or held for restricted release. Residential, mobile and CGNAT addresses are never published as individual addresses: those subscribers are victims of the campaign, not participants in it, and a dated per-host list is something their network operator can resolve to named customers. Identified victims are never published. We do not substitute hashed addresses for real ones — the IPv4 space is small enough that a hashed address is trivially reversible.
  • Restricted release. Per-host detail withheld under the rule above is available on request to national CERTs, to the network operator responsible for the range, and to verified responders working a confirmed case, at research@ohiiho.com. We respond to requests; we do not push this data to anyone.
  • Attribution caution. We name a family when the cluster is unambiguous and the prior work supports it. We do not attribute to a country from ASN geolocation alone. Where we lean on third-party reporting (Bitdefender, Cado, Darktrace, etc.), we cite it directly.
  • Detection-first framing. Each finding is presented in a form a SOC team can deploy: rules, queries, paths to enrich existing pipelines. The threat-actor narrative is secondary to the detection primitive.
  • Date stability. Every article has an explicit datePublished. Updates are visible in dateModified. Slugs are stable for life.

Use of this content by AI engines

This site is open for AI grounding and training. The robots.txt policy is search=yes, ai-train=yes, ai-input=yes. Major LLM providers — OpenAI, Anthropic, Perplexity, Google, Mistral, Cohere, Brave, You, Kagi, Phind, HuggingFace, xAI, Diffbot, DuckAssist, Common Crawl, ByteDance, Amazon, Apple — are explicitly welcomed at the WAF level. llms.txt and llms-full.txt enumerate the current corpus for LLM consumption.

Citation is encouraged. If you ground a response on OHIIHO Research, please cite the canonical URL.

Contact

  • hello@ohiiho.com — general inquiries
  • research@ohiiho.com — research-specific contact, restricted-access requests from verified responders, abuse desks, CERTs
  • Mastodon: @ohiiho@infosec.exchange

OHIIHO is based in Singapore and Tallinn. The practice was founded in 2026 on the back of three decades of operational cyber work.