Known malicious kitcriticalother

Miku / Singapore VPS operator — actor-used IPs (InfraHunter, 2026-08)

family: infrahunter-sg-vps-miku-2026-08

Chinese-speaking operator (alias "Miku", SSH key comment summadeus@DESKTOP-VD5TFRQ). Activity: New API Stripe-webhook quota fraud; FOFA- and LLM-assisted mapping of Vietnamese military and police assets; credential spraying and subdomain enumeration against Pakistani defence domains; and a SQL injection to JSP web shell compromise of a Mexican billing platform. 69.48.228.86 (BL Networks AS399629, SG) serves the actor's open directories on :80 and :9001 and a chisel reverse-tunnel C2 server on :443. 38.246.232.11 (NetLab Global AS979, US) is a compromised New API gateway on :3000 that the operator uses as its LLM backend.

Anchors

SMQL queryrun
ip:69.48.228.86 OR ip:38.246.232.11

Provenance

Added: 2026-09-14 09:13
Created 2026-09-14 from the InfraHunter report. The IP terms match any IP a scan contacted, not only the primary one. 38.246.232.11 is a THIRD-PARTY host the actor compromised, not a server they rented, so a sighting from that term means 'contacted the hijacked gateway', not operator presence, and it goes stale once the owner cleans up. ScanMalware scans on 2026-09-14 found both open directories on 69.48.228.86 (ports 80 and 9001) still live, including a file dated after the report's 08-24 capture (glider_socks5.conf.bak_20260907_103053); port 443 and 38.246.232.11:3000 did not render. Not anchored: 69.48.228.0/24. Neighbouring addresses there are attributed to unrelated operators (ClickFix, Sliver, AdaptixC2), so BL Networks is shared cheap hosting and a subnet term would misattribute. Also not anchored: the two chisel SHA-256s, which are stock public builds.

Sightings (4)

HostScanScriptMatchWhen
38.246.232.11e7b63fce…—query2026-09-14 09:13
69.48.228.863e8a7985…—query2026-09-14 09:13
69.48.228.861fd3b5f1…—query2026-09-14 09:13
69.48.228.86850a05a5…—query2026-09-14 09:13