Campaign analysis and threat actor research derived from direct sensor observations.
These reports reconstruct campaigns from live adversary sessions, payload chains, and infrastructure pivots observed across the OHIIHO sensor network. Findings are published with the evidence, indicators, and detection logic required for independent assessment.
"Hydra Bot v5": A Redis Stager Designed to Deploy a P2PInfect Client and Miner
Analysis of an in-the-wild Redis deployment chain: artifacts for four known Redis abuse patterns delivered in 4.4 seconds, a stager not found in public datasets designed to deploy a P2PInfect-linked ELF and an apparent miner, and campaign infrastructure exposed through a hostname guard.
SuricataYARASigmaIOC 17 min readFortiBleed from the Target Side: What Stops Them [3/3]
Half the FortiBleed sprayer IPs — including several that received a success response — carry a threat score of zero and appear on no abuse feed at all. The only rule that catches 100% of them is a management-interface allowlist. This is Part 3 of three: the defenses that work, why standard SOC rules miss this spray, the ASN-level indicators, and the timeline gap that is the real lesson. With a companion Detection Brief.
IOC 12 min readFortiBleed from the Target Side: The Ecosystem [2/3]
The same stolen FortiBleed corpus is sprayed at one of our sensors, in parallel, by roughly a dozen operator clusters across about 13 autonomous systems — and a synthetic heartbeat fired by twelve machines on three 'different' networks within the same minute proves part of that crowd is one operator wearing several masks. This is Part 2 of three: the marketplace, the orchestrated fleet, the victims named by their own stolen passwords, and the validate-and-leave fingerprint of an Initial Access Broker.
27 min readFortiBleed from the Target Side: The Corpus [1/3]
We ran an internet-facing FortiGate honeypot for a month. It logged about 447,600 login attempts from about 34,600 IP addresses, and for three days we captured every submitted credential in cleartext. The corpus is not brute force: it is a stolen corpus of real corporate credentials being recycled, complete with FortiGate service accounts that exist only inside a device configuration backup. This is Part 1 of three: what FortiBleed actually is, and what the spray looks like from inside the device it targets.
IOC 19 min readResidential Broadband Botnet Uses AsyncSSH to Validate Credentials Across Four Regions
88 compromised residential broadband hosts — all on two Vietnamese ISPs — ran a coordinated SSH credential-validation campaign across four geographically distributed sensor regions over seven days. The same HASSH fingerprint, the same Python SSH library, zero successful logins: this is infrastructure reconnaissance, not exploitation.
IOC 8 min readIt Built the Business: Source Excerpts [2/2]
Redacted excerpts from the tooling behind the case: repeatable VM provisioning, port-mapped remote access, customer-abuse controls, fleet monitoring with an interactive viewer, attempts to weaken Windows application control, and the build loop that produced it. Selected and generalized; the full source, indicators, and attribution stay restricted.
11 min readThe AI Did Not Write the Phish. It Built the Business. [1/2]
Agentic AI built a working access-production capability for an operator with limited autonomy across the stack, in 72 hours. The security conversation keeps circling AI-written phishing; the real shift is bigger. The evidence is not a quote. It is the work loop.
18 min readBefore It Mines You, It Checks Whether You're Worth More: An SSH Botnet That Triages Hosts for Telegram Sessions and SIM-Box Fraud
A 16-node SSH botnet runs a nine-command triage script instead of dropping a miner — looking for Telegram Desktop session files, GSM modems, SMS spools, and SIM-management config, the hardware and data of SMS-fraud and 2FA-interception operations. It is a botnet that grades every host it lands on before deciding how to monetize it.
8 min readThe Honeypot-Detection Arms Race: Three Tiers of Checks Attackers Run Before They Trust Your Shell
Before they drop a payload, the better SSH botnets now ask whether they're standing in a honeypot. We captured three escalating tiers of that check on our sensors — from commodity CPU-core counting, to a seven-step environment-integrity routine, to a deep /proc-entropy and PID-reality battery we cannot find published anywhere. In every case the operator ran the checks and then proceeded to the payload. That last fact is the point.
8 min readOutlaw/mdrfckr relay activity from Syrian institutional IP space
An IP address in a network block attributed to Syrian government services (AS29256) is relaying activity consistent with Outlaw/mdrfckr botnet propagation. We assess this as compromised infrastructure, not state-directed activity. Our distributed honeypot network captured the relay chain end-to-end: a three-tier SSH scanning pipeline, a modern exploitation tool advertising ML-KEM-capable key exchange, the mdrfckr SSH key injection, and a 23-second automated burst of 18 reconnaissance commands. This is not new malware research. It is a field observation showing how old commodity botnets continue to exploit weak SSH hygiene and can quietly turn institutional infrastructure into relay nodes.
IOC 12 min readWatcher-NetAI / skn - Detection Brief [2/2]
Single-page SOC-facing summary of the Watcher-NetAI / skn cluster - top IOCs, four triage-priority hunts, links to the YARA / Sigma / IOC bundles, controlled-sharing contact. Full analysis in the main report.
5 min readWatcher-NetAI / skn: a Linux SSH botnet, with the scanner half-open [1/2]
An SSH-delivered Linux kit observed on two honeypot sensors drops a non-root systemd-user persistence unit, then runs a 10 MB Go scanner with intact DWARF: source tree, module name skn, capability map (scanner, SOCKS5, password-change cascade with VyOS fallback, embedded HTTP listener) all visible. The loader is hardened; the scanner is not. Stage-2 C2 on connexionlost.{net,zip} → 194.5.97[.]46.
YARASigmaIOC 36 min readTwo-Way Prometei: When the Linux Botnet Pivots Back to Windows [2/2]
17 Windows modules dropped alongside the Linux ELF in the same Prometei drop, including a Mimikatz variant frozen since 2023, a Tor stack masquerading as MSDTC and Smart Card services, and a Linux ELF that pivots back to Windows via WinRM (5985), Redis SLAVEOF (16379), and SMBv1-era dialects. One cross-platform toolkit, walker.ini glue, server-side fingerprint of the C2.
IOC 20 min readPrometei Goes Both Ways: Same C2, Both Operating Systems, Three Months Apart [1/2]
A fresh Prometei v3/v4 ELF on a Linux honeypot, beaconing to the same C2 IP, Tor onion, and UPlugPlay disguise convention eSentire flagged on the Windows side three months earlier. The JSON-trailer schema yields a parent-peer back-pointer per bot. Postscript: four parallel binary-churn cadences in the same toolkit, including bit-identical zsvc unpacked code across drops.
IOC 22 min readTurf Wars at Scale: Botnets Fighting for the Same Servers
42 post-auth payload deployments from 13 coordinated IPs on AS51396 over 58 hours. The eviction script that precedes each install maps the contested-infrastructure reality: Diicot self-eviction, XMRig, CNRig, Rete, and Kinsing artifacts competing on the same pools of exposed servers.
IOC 12 min readAdjacent campaigns and a defender's playbook [3/3]
Adjacent SSH brute-force campaigns observed alongside Sorry-worm: Multiverze sshd backdoor, Diicot/Opera updated 2026 build, Mirai-derived sshscan kit. Indicators in three confidence tiers, YARA and Sigma rules, hunting queries, a reproducible activity timeline, and defensive recommendations.
YARASigmaIOC 19 min readInside Sorry-worm: anatomy of a Go ransomware-worm hybrid [2/3]
Binary-level analysis of Sorry-worm: hardcoded RSA-2048 attribution-stable indicator, AES-CBC encryption pipeline, 48-byte fixed prefix on encrypted files, UNIX-nanosecond victim ID, embedded SSH wordlist, and the layered SSH scan that runs concurrently with encryption. The single most important property: encryption and SSH propagation occur concurrently in the same process.
19 min readCatching Sorry-worm in the wild [1/3]
A previously undocumented Linux ransomware-worm hybrid, propagating from compromised SSH relays approximately 8 hours after the sample's first public sandbox submission. Two independent propagation events from unrelated IPs, separated by ~7 hours, more consistent with autonomous worm-style propagation than a single hands-on session.
IOC 15 min readDetecting and Countering AI-Enabled Intrusions with Deception
Findings from four controlled wargame labs running ~1,000 LLM-driven intrusions against a HIIH Surface Live Host. Persistence is universal. Attackers come in three shapes. Counter-forensics has arrived - and counter-intelligence works.
4 min read