We investigate the infrastructure behind cybercrime and state-sponsored operations: bulletproof hosting supply chains, phishing campaigns, malware delivery networks. All findings are based on publicly available data and original research.
Aggregate activity across the multi-region honeypot network. Figures are anonymised totals from the monthly TLP:CLEAR report — no individual sensor identifiers, addresses, or locations are disclosed.
Notable: 884 WannaCry-matching PE32 binaries, a Panchan Go SSH worm using Discord as secondary C2, and 3,383 TLS sessions to api[.]telegram[.]org (Telegram Bot API as malware C2). Full analysis — April 2026 Monthly Report.
TLP:CLEAR incident reports and threat analysis, available in English and Russian.
For collaboration, responsible disclosure, abuse reporting, or access to restricted research materials:
infra.observer@proton.me
Aleksei Fokin — Threat Intelligence Analyst