slatterysec.com/reports/2026/04/2026-04-monthly-summary.html
sensors 8 up last session 4m ago 24h captures 312 unique src 87

slattery@sec:~/reports$ cat 2026-04-monthly-summary.md

HONEYPOT REPORT // MONTHLY SUMMARY // APRIL 2026

April 2026 — Monthly Honeypot Summary

Full month: 2026-04-01 – 2026-04-30  |  Six reporting periods  |  Sensor: Cowrie v2.x (SSH + HTTP)  |  Host: VPS / RackNerd
SSH WEB MONTHLY SUMMARY 4 BOTNET FAMILIES REDTAIL PERSISTENT
TOTAL SSH EVENTS
264,841
across all 6 periods
AUTH ATTEMPTS
~83,000
est. from period totals
MDRFCKR IMPLANTS
17,537
SSH key injections — all periods
PEAK SINGLE DAY
36,617
Apr 21 — canary mass scan
BOTNET FAMILIES
4
Redtail · Kurayami · Demon · Canary C2
REDTAIL SCP UPLOADS
418+
est. across month
WEB .ENV PROBES
1,059+
P6 alone — persistent all month
PHPUNIT RCE HITS
951+
libredtail-http — all periods

Executive summary

April 2026 was the most active month recorded on these sensors since deployment. Six five-day reporting periods captured a sustained escalation in both SSH and web attack volume, with total SSH events reaching an estimated 264,841 — more than ten times the baseline observed in early 2025. The month was defined by three concurrent threat tracks running in parallel across all six periods: the mdrfckr SSH key persistence campaign (17,537 confirmed implants), the Redtail cryptominer operation (persistent SCP payload delivery from 130.12.180.51, PHPUnit RCE sweeps via libredtail-http across both sensors), and a sustained .env credential harvesting operation from a small cluster of IPs rotating spoofed User-Agents.

Three new botnet families made first appearances during the month: Kurayami (P3, Apr 11–15), Demon DDoS (P4, Apr 16–20), and a Canary C2 operation (P5, Apr 21–25) that progressed from a mass reachability scan — 5,175 sessions from 113.87.226.234 echoing ok to confirm shell access — to confirmed payload delivery of ARM and Motorola 68k binaries from 87.121.79.73. The Apr 21 single-day record of 36,617 events was driven by this canary scan. The final period (P6, Apr 26–30) saw the highest total event count of any period (117,570) with Apr 30 producing the highest single-day unique-IP count (546), suggesting continued botnet ramp-up as the month closed.

The libredtail-http user agent appeared on both the SSH and web sensors every single period of the month — the clearest cross-sensor indicator of persistent, multi-vector Redtail infrastructure targeting this honeypot throughout April.

SSH events by period

P1
Apr 1–5
16,491
P2
Apr 6–10
23,470
P3
Apr 11–15
20,823
P4
Apr 16–20
59,761
P5
Apr 21–25
26,726
P6
Apr 26–30
117,570

P4 spike driven by a single-day mass canary scan (Apr 21: 36,617 events). P6 total is the highest period of the month despite no single-day anomaly — sustained elevated volume across all five days, with Apr 30 alone producing 32,946 events.

Period-by-period breakdown

perioddatesssh eventsmdrfckr injectionskey findingsreport
P1Apr 1–516,4912,431 Redtail multi-arch SCP upload; phpunit CVE-2017-9841 web probes; 458-req admin brute force burst view >>
P2Apr 6–1023,4703,159 Redtail operator returns with identical binary set; new Hammz.sh dropper; 80.66.66.10 dominant SSH source (20k+ events) view >>
P3Apr 11–1520,8233,418 Kurayami DDoS botnet first observed; Redtail operator returns for third week with updated dropper; first RCE attempt via curl targeting AWS credentials view >>
P4 ▲Apr 16–2059,7613,956 Single-day record (36,617 on Apr 21) driven by mass canary scan; Demon DDoS botnet first observed; Redtail shifts to daily deployment cadence; mdrfckr injections up 63% since P1 view >>
P5Apr 21–2526,7263,252 Canary follow-on payload confirmed (87.121.79.73 — ARM + m68k binaries); 185.177.72.x subnet curl RCE expanding; 130.12.180.51 Redtail uploads peak at 126 sessions; new breach-list credential root:nPSpP4PBW0 view >>
P6 ▲Apr 26–30117,5701,321 Highest period event total; Apr 30 spike (32,946 events / 546 unique IPs); 87.251.64.0/24 coordinated cluster emerges; Mirai 345gs5662d34 pair first appearance; libredtail-http PHPUnit surge (796 hits) view >>

Botnet family timeline

Persistent actors — full month

actor / indicatorP1P2P3P4P5P6
mdrfckr SSH key implant2,4313,1593,4183,9563,2521,321
libredtail-http (web)4758161717796 ↑
130.12.180.51 Redtail SCP~100723684126 ↑
213.209.159.175 .env harvest508 ↑ peak
185.177.72.x curl RCE.11.52 + .30
185.177.72.61 l9explore/.git
87.251.64.0/24 SSH cluster5,967 ↑ new
SSH events (period total)16,49123,47020,82359,76126,726117,570

Top indicators of compromise — full month

typevaluecontext
SSH pub key...mdrfckr (RSA)17,537 implants across all 6 periods — most persistent SSH IOC of the month
IP130.12.180.51Redtail SCP payload delivery — active P1–P5, 418+ upload sessions
IP113.87.226.234Canary C2 — 5,175 sessions Apr 21, echo-ok shell confirmation sweep
IP87.121.79.73Canary C2 payload server — ok, 00okarm5/6/7, 00okm68k binary delivery
IP213.209.159.175Top .env harvester — present all 6 periods, 508 requests in P6 alone
IP185.177.72.52curl RCE — URL-encoded dot obfuscation, JS config harvest, AWS cred probe
IP80.66.66.10Dominant SSH source P2 — 20k+ events
IP87.251.64.0/24Coordinated SSH cluster — 5,967 events, first appearance P6
UAlibredtail-httpRedtail botnet — present on web sensor every period, 951+ total hits
UAcurl/8.7.1185.177.72.52 + .30 — coordinated web RCE and admin enumeration
credentialroot:3245gs5662d34mdrfckr campaign — 3,141+ attempts across month
credentialroot:nPSpP4PBW0New breach-list credential — first appearance P5
credential345gs5662d34 / 345gs5662d34Mirai IoT pair — first appearance P6, 1,280 attempts
CVECVE-2017-9841PHPUnit eval-stdin RCE — web sensor, all periods
CVECVE-2021-36260Hikvision camera RCE — /SDK/webLanguage probing
path/%61%64%6D%69%6E/.%65%6EvURL-encoded /admin/.env — WAF evasion — first observed P6

MITRE ATT&CK mapping — full month

technique idnameobserved
T1110.001 / T1110.003Brute ForceSustained all month — default credentials, breach lists, IoT pairs, password spraying
T1078Valid AccountsIoT defaults (345gs5662d34), cloud image defaults (ubuntu/ubuntu), toor
T1098.004SSH Authorized Keysmdrfckr key — 17,537 implants across all 6 periods
T1222File/Dir Permissions Modificationchattr -ia .ssh; chmod -R go= ~/.ssh — every mdrfckr session
T1018Remote System DiscoveryCanary scan — 5,175 sessions confirming shell execution (echo-ok)
T1059.004Unix Shellok dropper; clean.sh / setup.sh Redtail chains; curl pipe-to-bash
T1105Ingress Tool TransferRedtail SCP (130.12.180.51, 418+ sessions); 87.121.79.73 ARM/m68k delivery
T1496Resource HijackingRedtail cryptominer — persistent all month; CPU/mem recon pre-deployment
T1190Exploit Public-Facing ApplicationCVE-2017-9841 PHPUnit RCE (951+ hits); CVE-2021-36260 Hikvision
T1552.001Credentials In Files.env harvesting all month; .aws/credentials; database.js; constants.js
T1595.002Vulnerability ScanningSystematic CVE/misconfiguration probing — all periods
T1027 / T1027.001ObfuscationPercent-encoding (/admin/.env, phpinfo%2ephp); UA string rotation
T1036MasqueradingSpoofed browser UAs — rotating per-request on .env harvesters
T1572Protocol Tunneling523 direct-tcpip requests observed P5
T1583 / T1584Acquire / Compromise InfrastructureHetzner DE, OVH FR, GCP, DigitalOcean infrastructure used by multiple actors

Analyst observations

Three trends stand out from April 2026. First, the mdrfckr campaign is not opportunistic — 17,537 implants across a single month, consistently executing the same two-step chattr + key-inject playbook, indicates an organized operation maintaining a credential database and re-exploiting previously accessed systems. Second, Redtail is operating across both sensors simultaneously — the libredtail-http UA on the web sensor and the SCP payload delivery on the SSH sensor are not coincidentally timed; they are the same infrastructure running parallel access vectors. Third, the Canary C2 operation is notable for its architecture breadth — dropping Motorola 68k binaries alongside standard ARM variants suggests automated tooling that shotguns payload types rather than targeting a specific device category.

The P6 volume surge (117,570 events, Apr 26–30) with no corresponding payload or novel TTP observed — just raw connection volume — is consistent with a botnet expanding its scan pool rather than executing a targeted campaign. Whether that translates to a significant May event remains to be seen.

Individual period reports linked in the breakdown table above. Full session transcripts, raw JSON logs, and captured binaries available on request. All IOCs as observed — IPs undefanged.