Skip to content

2026

47 Networks, 68 Seconds

47 different chunks of the internet, each a full /24 block of up to 256 addresses, started scanning my infrastructure within 68 seconds of each other. 47 entire networks, most of them belonging to a single hosting provider. 6 months of logs turned up more than a dozen of these synchronized waves, and at least 3 of them weren't one-time events. The same operators came back days later and ran the exact same target list again, like clockwork.

MDRFCKR - a (almost) decade old botnet

Between May 3 and June 3, 2026, a threat actor operating under the handle "mdrfckr" conducted a sustained SSH credential-stuffing campaign against my internet-facing SSH honeypots. The campaign deployed 3,929 successful authentication events from 1,702 unique source IPs across 32+ countries. Upon gaining access, the attacker deployed a persistent SSH public key bearing the "mdrfckr" comment - a classic botnet recruitment / persistence mechanism.