# OHIIHO Research # research.ohiiho.com # # Open for AI grounding and training. OHIIHO publishes threat intelligence # research openly — citation, grounding, and training use authorised. # Major LLM providers (OpenAI, Anthropic, Perplexity, Google, etc.) are # explicitly welcome at the WAF level on both ohiiho.com and research.ohiiho.com. > OHIIHO Research is the public research publication of OHIIHO, a cybersecurity company headquartered in Singapore, with a European entity in Estonia. It publishes threat intelligence reports, adversary behaviour analysis, detection content, and briefs on deception, AI-enabled attacks and systemic cyber risk, based on first-hand observation of real adversary activity. Adversary Engagement Intelligence (AEI) — first-hand cyber threat intelligence generated through controlled engagement with real adversaries. Canonical definition: https://ohiiho.com/hiih/adversary-engagement-intelligence/ ## Briefs - [Crimeware Has an Attack Surface. We Catalogue It.](https://research.ohiiho.com/briefs/2026-07-cyber-arsenal/) — Standard threat-intelligence indexes malware by hash and family. Our Cyber Arsenal indexes the other thing — the vulnerabilities of the malware itself: the pre-auth RCE, the broken cookie validation, and the backdoors that the tools' own distributors wired into them. Over 40% of the commodity webshells and grabbers we catalogued are harvesting the operators who deploy them. - [FortiBleed Credential-Validation Spray: Detection Brief](https://research.ohiiho.com/briefs/2026-06-fortibleed-detection-brief/) — SOC-ready companion to FortiBleed from the Target Side. The highest-signal detections for the credential-validation phase: off-allowlist admin auth, one source testing many usernames at a steady 24/7 cadence, a single success after a run of failures, and FortiGate service/cloud accounts appearing at the login prompt. TLP:CLEAR. - [The AI Security Narrative Has Two Halves. We're Mostly Looking at One.](https://research.ohiiho.com/briefs/2026-05-ai-security-other-half/) — The vulnpocalypse framing assumes defense is static while offense gets new tools. Looking at the actual research and product landscape, that misses what's happening on the defensive side at the same time. - [Deterrence by Cognitive Compromise](https://research.ohiiho.com/briefs/2026-04-deterrence-by-cognitive-compromise/) — You can't deter a machine. But you can deter the operator behind it - by making the machine a liability. When intention itself becomes retrievable, the offensive economics of agentic operations changes shape. - [Baseline Conditions](https://research.ohiiho.com/briefs/2026-04-baseline-conditions/) — OHIIHO works on systemic cyber risk and digital sovereignty - how digital infrastructures behave when core security assumptions fail. Compromise, degradation, and uncertainty as default conditions, not edge cases. ## Reports - ["Hydra Bot v5": A Redis Stager Designed to Deploy a P2PInfect Client and Miner](https://research.ohiiho.com/reports/2026-09-hydra-bot-v5-redis-cryptomining/) — Analysis of an in-the-wild Redis deployment chain: artifacts for four known Redis abuse patterns delivered in 4.4 seconds, a stager not found in public datasets designed to deploy a P2PInfect-linked ELF and an apparent miner, and campaign infrastructure exposed through a hostname guard. - [FortiBleed from the Target Side: What Stops Them [3/3]](https://research.ohiiho.com/reports/2026-06-fortibleed-in-the-open-defense/) — Half the FortiBleed sprayer IPs — including several that received a success response — carry a threat score of zero and appear on no abuse feed at all. The only rule that catches 100% of them is a management-interface allowlist. This is Part 3 of three: the defenses that work, why standard SOC rules miss this spray, the ASN-level indicators, and the timeline gap that is the real lesson. With a companion Detection Brief. - [FortiBleed from the Target Side: The Ecosystem [2/3]](https://research.ohiiho.com/reports/2026-06-fortibleed-in-the-open-ecosystem/) — The same stolen FortiBleed corpus is sprayed at one of our sensors, in parallel, by roughly a dozen operator clusters across about 13 autonomous systems — and a synthetic heartbeat fired by twelve machines on three 'different' networks within the same minute proves part of that crowd is one operator wearing several masks. This is Part 2 of three: the marketplace, the orchestrated fleet, the victims named by their own stolen passwords, and the validate-and-leave fingerprint of an Initial Access Broker. - [FortiBleed from the Target Side: The Corpus [1/3]](https://research.ohiiho.com/reports/2026-06-fortibleed-in-the-open/) — We ran an internet-facing FortiGate honeypot for a month. It logged about 447,600 login attempts from about 34,600 IP addresses, and for three days we captured every submitted credential in cleartext. The corpus is not brute force: it is a stolen corpus of real corporate credentials being recycled, complete with FortiGate service accounts that exist only inside a device configuration backup. This is Part 1 of three: what FortiBleed actually is, and what the spray looks like from inside the device it targets. - [Residential Broadband Botnet Uses AsyncSSH to Validate Credentials Across Four Regions](https://research.ohiiho.com/reports/2026-06-asyncssh-residential-botnet/) — 88 compromised residential broadband hosts — all on two Vietnamese ISPs — ran a coordinated SSH credential-validation campaign across four geographically distributed sensor regions over seven days. The same HASSH fingerprint, the same Python SSH library, zero successful logins: this is infrastructure reconnaissance, not exploitation. - [It Built the Business: Source Excerpts [2/2]](https://research.ohiiho.com/reports/2026-06-ai-built-the-business-source-excerpts/) — Redacted excerpts from the tooling behind the case: repeatable VM provisioning, port-mapped remote access, customer-abuse controls, fleet monitoring with an interactive viewer, attempts to weaken Windows application control, and the build loop that produced it. Selected and generalized; the full source, indicators, and attribution stay restricted. - [The AI Did Not Write the Phish. It Built the Business. [1/2]](https://research.ohiiho.com/reports/2026-06-ai-built-the-business/) — Agentic AI built a working access-production capability for an operator with limited autonomy across the stack, in 72 hours. The security conversation keeps circling AI-written phishing; the real shift is bigger. The evidence is not a quote. It is the work loop. - [Before It Mines You, It Checks Whether You're Worth More: An SSH Botnet That Triages Hosts for Telegram Sessions and SIM-Box Fraud](https://research.ohiiho.com/reports/2026-06-sms-simbox-triage-botnet/) — A 16-node SSH botnet runs a nine-command triage script instead of dropping a miner — looking for Telegram Desktop session files, GSM modems, SMS spools, and SIM-management config, the hardware and data of SMS-fraud and 2FA-interception operations. It is a botnet that grades every host it lands on before deciding how to monetize it. - [The Honeypot-Detection Arms Race: Three Tiers of Checks Attackers Run Before They Trust Your Shell](https://research.ohiiho.com/reports/2026-06-honeypot-detection-arms-race/) — Before they drop a payload, the better SSH botnets now ask whether they're standing in a honeypot. We captured three escalating tiers of that check on our sensors — from commodity CPU-core counting, to a seven-step environment-integrity routine, to a deep /proc-entropy and PID-reality battery we cannot find published anywhere. In every case the operator ran the checks and then proceeded to the payload. That last fact is the point. - [Outlaw/mdrfckr relay activity from Syrian institutional IP space](https://research.ohiiho.com/reports/2026-05-outlaw-syria-relay/) — An IP address in a network block attributed to Syrian government services (AS29256) is relaying activity consistent with Outlaw/mdrfckr botnet propagation. We assess this as compromised infrastructure, not state-directed activity. Our distributed honeypot network captured the relay chain end-to-end: a three-tier SSH scanning pipeline, a modern exploitation tool advertising ML-KEM-capable key exchange, the mdrfckr SSH key injection, and a 23-second automated burst of 18 reconnaissance commands. This is not new malware research. It is a field observation showing how old commodity botnets continue to exploit weak SSH hygiene and can quietly turn institutional infrastructure into relay nodes. - [Watcher-NetAI / skn - Detection Brief [2/2]](https://research.ohiiho.com/reports/2026-05-watcher-netai-skn-brief/) — Single-page SOC-facing summary of the Watcher-NetAI / skn cluster - top IOCs, four triage-priority hunts, links to the YARA / Sigma / IOC bundles, controlled-sharing contact. Full analysis in the main report. - [Watcher-NetAI / skn: a Linux SSH botnet, with the scanner half-open [1/2]](https://research.ohiiho.com/reports/2026-05-watcher-netai-skn/) — An SSH-delivered Linux kit observed on two honeypot sensors drops a non-root systemd-user persistence unit, then runs a 10 MB Go scanner with intact DWARF: source tree, module name skn, capability map (scanner, SOCKS5, password-change cascade with VyOS fallback, embedded HTTP listener) all visible. The loader is hardened; the scanner is not. Stage-2 C2 on connexionlost.{net,zip} → 194.5.97[.]46. - [Two-Way Prometei: When the Linux Botnet Pivots Back to Windows [2/2]](https://research.ohiiho.com/reports/2026-05-prometei-cross-platform-pivot/) — 17 Windows modules dropped alongside the Linux ELF in the same Prometei drop, including a Mimikatz variant frozen since 2023, a Tor stack masquerading as MSDTC and Smart Card services, and a Linux ELF that pivots back to Windows via WinRM (5985), Redis SLAVEOF (16379), and SMBv1-era dialects. One cross-platform toolkit, walker.ini glue, server-side fingerprint of the C2. - [Prometei Goes Both Ways: Same C2, Both Operating Systems, Three Months Apart [1/2]](https://research.ohiiho.com/reports/2026-05-prometei-asia-c2-linux-side/) — A fresh Prometei v3/v4 ELF on a Linux honeypot, beaconing to the same C2 IP, Tor onion, and UPlugPlay disguise convention eSentire flagged on the Windows side three months earlier. The JSON-trailer schema yields a parent-peer back-pointer per bot. Postscript: four parallel binary-churn cadences in the same toolkit, including bit-identical zsvc unpacked code across drops. - [Turf Wars at Scale: Botnets Fighting for the Same Servers](https://research.ohiiho.com/reports/2026-05-turf-wars-diicot-ssh-botnet/) — 42 post-auth payload deployments from 13 coordinated IPs on AS51396 over 58 hours. The eviction script that precedes each install maps the contested-infrastructure reality: Diicot self-eviction, XMRig, CNRig, Rete, and Kinsing artifacts competing on the same pools of exposed servers. - [Adjacent campaigns and a defender's playbook [3/3]](https://research.ohiiho.com/reports/2026-05-sorry-worm-playbook/) — Adjacent SSH brute-force campaigns observed alongside Sorry-worm: Multiverze sshd backdoor, Diicot/Opera updated 2026 build, Mirai-derived sshscan kit. Indicators in three confidence tiers, YARA and Sigma rules, hunting queries, a reproducible activity timeline, and defensive recommendations. - [Inside Sorry-worm: anatomy of a Go ransomware-worm hybrid [2/3]](https://research.ohiiho.com/reports/2026-05-sorry-worm-anatomy/) — Binary-level analysis of Sorry-worm: hardcoded RSA-2048 attribution-stable indicator, AES-CBC encryption pipeline, 48-byte fixed prefix on encrypted files, UNIX-nanosecond victim ID, embedded SSH wordlist, and the layered SSH scan that runs concurrently with encryption. The single most important property: encryption and SSH propagation occur concurrently in the same process. - [Catching Sorry-worm in the wild [1/3]](https://research.ohiiho.com/reports/2026-05-catching-sorry-worm/) — A previously undocumented Linux ransomware-worm hybrid, propagating from compromised SSH relays approximately 8 hours after the sample's first public sandbox submission. Two independent propagation events from unrelated IPs, separated by ~7 hours, more consistent with autonomous worm-style propagation than a single hands-on session. - [Detecting and Countering AI-Enabled Intrusions with Deception](https://research.ohiiho.com/reports/2026-04-detecting-ai-enabled-intrusions/) — Findings from four controlled wargame labs running ~1,000 LLM-driven intrusions against a HIIH Surface Live Host. Persistence is universal. Attackers come in three shapes. Counter-forensics has arrived - and counter-intelligence works. ## Arsenal — Crimeware tool dissections - [WSO (Web Shell by Orb)](https://research.ohiiho.com/arsenal/wso/) — The workhorse of the Russian webshell scene — compact, battle-tested, zero authentication on default install, and carrying a W0rm supply-chain backdoor that gives a third party unauthenticated RCE on every host the operator compromises. Five independent attack surfaces. Highest severity in corpus. - [whmcs-killer-v3](https://research.ohiiho.com/arsenal/whmcs-killer/) — WHMCS-targeting webshell with six independent attack vectors — W0rm supply-chain RCE, trivial client-side session forgery, pre-auth file inclusion with eval, arbitrary file upload, SQL injection, and stored XSS. Every vector is pre-auth. Harvests the WHMCS billing database: client records, payment details, hosting credentials, domain registrations. - [viper.php (Viper 1337)](https://research.ohiiho.com/arsenal/viper/) — Minimal file uploader ecosystem by Viper 1337 — multiple variants (XxX.php, 098.php, pwn.php) carrying a Hmei7-linked supply-chain beacon in base64-encoded eval blocks. One variant uses GIF89a magic-byte prefix for MIME-type evasion. - [unzipper](https://research.ohiiho.com/arsenal/unzipper/) — Legitimate archive extraction utility poisoned with W0rm supply-chain injection. Pre-auth RCE on every request, dynamic C2 email via MD5-of-Pastebin, and a dedupe mechanism that reports each compromised install exactly once. - [symlink.php](https://research.ohiiho.com/arsenal/symlink/) — cPanel privilege escalation tool using symlink traversal across account boundaries — also carrying a W0rm supply-chain injection with pre-auth RCE that fires before any of the tool's own cookie-based authentication. - [Stupidc0de Backdoor](https://research.ohiiho.com/arsenal/stupidc0de/) — The flagship Tier-2 card. 90 KB / 2030 lines — the largest tool in the corpus. Indonesian scene (Stupidc0de Family: Putra-Attacker, Daryun, Shor7cut, Osvaldas, Sinkaroid). Zero authentication on 12+ function modules. Pre-auth RCE, LFI, and arbitrary upload all confirmed live. Five runtime supply-chain remote-includes. WordPress admin reset module. zone-h mass-defacement notifier. - [smtpfu*ker](https://research.ohiiho.com/arsenal/smtpfu-ker/) — SMTP brute-force tool obfuscated with PHPJiaMi commercial packer. Tests credential lists against mail servers — the commercial obfuscation suggests the author treats this as a product, not a throwaway script. - [shell-checker (selmasker)](https://research.ohiiho.com/arsenal/shell-checker/) — Disguised as a webshell validation tool — but the checker is the shell. Indonesian scene (JExCoders / XploitSec-ID). Every string literal is base64-encoded to defeat grep. Hidden GET-branch backdoor accepts unauthenticated file uploads to the webroot — confirmed live. Config-trap pattern: operator fills in their own email, making every hit report to them (and to anyone reading the source). - [rintod / toolol](https://research.ohiiho.com/arsenal/rintod/) — Minimal file uploader at 330 bytes — the smallest and cleanest tool in the corpus. Indonesian scene (GitHub rintod/toolol). No backdoor, no auth, no obfuscation, no beacon in the analyzed sample — the lowest observed supply-chain risk in the corpus. Used by Flash-X as stage-0 dropper to plant full shells after initial RCE. - [r57](https://research.ohiiho.com/arsenal/r57/) — Classic Russian webshell and one of the earliest full-featured PHP shells to circulate widely. Carries a W0rm supply-chain backdoor and a pre-auth local file inclusion on the very first line of source — the operator's tool is compromised before it even loads. - [Ninja](https://research.ohiiho.com/arsenal/ninja/) — Full-featured webshell with embedded PHPMailer, a redistributor-injected JavaScript tracking beacon, and a hardcoded plaintext password. Turns every compromised server into a phishing platform while reporting the operator's activity to a third-party ad network. - [MySQL-interface](https://research.ohiiho.com/arsenal/mysql-interface/) — Standalone web-based MySQL administration tool carrying a W0rm supply-chain backdoor. Pre-auth RCE via GET parameter fires before any panel authentication. Hardcoded panel credentials (tryag_vb/102030). A lightweight phpMyAdmin alternative poisoned by its own redistributor. - [mails_grabber](https://research.ohiiho.com/arsenal/mails-grabber/) — Database email harvester from the Algerian scene. Two authors in one 8 KB file: SparkyDz (UI) and G-B (engine). Zero authentication. Walks every database, table, and column on the server, regex-matches email addresses, validates and deduplicates, then appends to file. Bulk mode accepts pasted lists of MySQL credentials. - [m4r5-sh3ll](https://research.ohiiho.com/arsenal/m4r5-sh3ll/) — Indonesian-scene webshell with modern Bootstrap 4 dark UI, community-public default credentials, and eval(base64_decode()) obfuscated core. Built for the bigsecc hacker community — the most user-friendly shell in Tier 1. - [IndoXploit](https://research.ohiiho.com/arsenal/indoxploit/) — Indonesian-scene webshell with 10 outbound TLS-disabled connections, a W0rm supply-chain backdoor that fires on every unauthenticated visit, and trivially crackable MD5 auth. Every deployment is MITM-able and pre-auth exploitable simultaneously. - [Flash-X uploaders](https://research.ohiiho.com/arsenal/flashx-uploaders/) — Two minimal uploaders (~1.7 KB each) with byte-identical hidden mail() beacons to the kit author. Attributed to XPROADSHELL / BAZOOKA, distributed by 0XNIGHTSEC. The beacons fire on every page load, invisible to the operator. Half-broken obfuscation leaks two author handles from one file. Re-skin only difference between variants. - [dbkiss](https://research.ohiiho.com/arsenal/dbkiss/) — Legitimate open-source database admin tool (DBKiss 1.11) with the most discreet W0rm supply-chain injection in the corpus. The backdoor hides inside a define() block and fires pre-auth at PHP parse time — before the application even starts. - [DamaneDz Config Grabber](https://research.ohiiho.com/arsenal/damanedz-grabber/) — Symlink-based config grabber from the Algerian scene (DamaneDz, 2013). Zero authentication. Creates a permissive directory with .htaccess override, then symlinks ~120 well-known CMS and billing config paths to harvest credentials across shared-hosting tenants. - [cpanel_cracker](https://research.ohiiho.com/arsenal/cpanel-cracker/) — Misnamed config grabber — no brute-force logic exists despite the name. Malaysian scene (Donnazmi / AnonGhost, 2014). Default page load returns /etc/passwd without authentication. Stealth-404 evasion blocks search engine crawlers. Symlink grabber targets ~120 CMS and billing config paths. - [c99](https://research.ohiiho.com/arsenal/c99/) — The original webshell — attributed to locus7s / Locus7 group. Ships with zero authentication by default and a cookie-driven PHP object injection that gives any visitor full control. The ancestor of the modern PHP shell ecosystem. - [b374k](https://research.ohiiho.com/arsenal/b374k/) — Gold standard compact webshell with anti-bot 404 evasion. Returns a fake 404 page to automated scanners while serving the real shell to interactive browsers. W0rm supply-chain infected in redistributed copies. - [Alfa3](https://research.ohiiho.com/arsenal/alfa3/) — The kit's 'alfa3.php' is not a separate, older 'alfa3' family — it is an Alfa Shell V4 'Tesla' build, with the Hmei7 mail() surveillance beacon and create_function obfuscation. It is a distinct file from alfav4-tesla.php (different hash and size), not a byte-identical copy. - [Alfa Shell V4 "Tesla"](https://research.ohiiho.com/arsenal/alfa-v4-tesla/) — The most deployed variant of the Alfa webshell family. Full-featured control panel with file manager, database browser, and CGI backdoor installer — and a hidden mail() beacon that reports every compromised host back to the kit author. - [0byt3m1n1-V2](https://research.ohiiho.com/arsenal/0byt3m1n1/) — File manager webshell v2.2 with zero authentication and a runtime supply-chain dropper. Indonesian scene (zerobyte-id). No password, no session, no token — every function is open to any visitor. On every page load, fetches its own source from a hardcoded GitHub URL and writes it to the webroot. ## Detections — YARA, Sigma, Suricata rules and IOC files - [Detection packs index](https://research.ohiiho.com/detections/) — downloadable rules tied to published reports ## About OHIIHO - Main site: https://ohiiho.com - Category: https://ohiiho.com/hiih/adversary-engagement-intelligence/ — Adversary Engagement Intelligence, defined by OHIIHO - Product: https://ohiiho.com/hiih/ — HIIH Surface, OHIIHO's implementation of AEI (Early Access) - Contact: hello@ohiiho.com