Quantitative Security – Q1 & Q2 2026 Review
Mid-Year / Year-to-Date Update | July 2026
Quantitative Security spent the first half of 2026 deliberately building the systems, methods, and operational tempo required to deliver high-fidelity protective intelligence at scale. Q1 focused on foundational tooling, defensive innovation, and internal capability development. Q2 scaled public education while maturing automated enrichment and analysis pipelines. The structured reports that began at the end of June and continued into July represent the public proof of that cumulative work — moving from raw telemetry to attributed, prioritized, and actionable intelligence products shared both publicly (via X long-form articles) and directly with federal agencies.
Q1 2026: Foundation & Tool Innovation
Designed, built, and publicly demonstrated a full operational command center supporting real-time threat hunting, traffic analysis, phishing simulation, network forensics, honeypot operations, decay attacks, and zero-trust enforcement.
Launched Phantom-QS, a browser-based Moving Target Defense platform. Its core innovation — Single Window Version Cycling — runs multiple Firefox versions (ESR, Beta, and Nightly) inside one window and cycles them at runtime. This continuously shifts memory layouts, engine internals, rendering behavior, and browser fingerprints, significantly raising the cost of attacker hooks, memory scraping, and GUI automation. Still in development.
Published a comprehensive company resume detailing the proprietary tooling suite and previously validated theories on flux networks, NTP exploitation vectors, and threat-actor tradecraft.
Publicly dissected commercial scam pipelines from malicious social advertising through Traffic Distribution Systems (TDS) with cloaking, scare pre-landers, Progressive Web App installers, botnet push notifications, and post-install Remote Access Trojans plus cryptojacking modules.
Conducted technical analysis of multi-tiered WHOIS honeypots and infrastructure shielding techniques (Cloudflare, reverse proxies, IP obfuscation) commonly used by certain actors.
These efforts established the automated log processing, OSINT enrichment, risk-tiering logic, and deception capabilities that underpinned every subsequent report.
Q2 2026: Scaling & Operational Proof
Q2 emphasized public education on AI-enhanced phishing, origin-aware email filtering concepts, and practical first-line defenses while the underlying platforms matured. The quarter closed with the first major series of structured protective intelligence products delivered as TLP:CLEAR long-form articles.
Full Protective Intelligence Report Series
Router-Log OSINT Enrichment
First major public demonstration of the automated enrichment pipelines. Thousands of raw router-log entries with heavy repetition were reduced to 126 unique external IP addresses. Every address received complete, automated enrichment covering ISP, organization, precise geolocation with coordinates, network path context, device details, origin indicators, and observed port/socket connections. Results were organized into clear categories (U.S. cloud/major infrastructure including AWS, Google, Microsoft Azure, Akamai, DigitalOcean, Censys, Shadowserver; UK/European ranges including notable Skynet Network LTD clusters; Asia/other) while preserving full coverage. Explicitly framed as a scalable workflow for converting network telemetry into prioritized protective intelligence and shared directly with federal agencies and partners.
1,676-IP Risk Hierarchy & TeamPCP Attribution
A large observed dataset of 1,676 unique IP addresses was analyzed and structured into a clear risk hierarchy. Eleven high-risk addresses clustered tightly in Netherlands-based abusive hosting ranges, primarily within TECHOFF SRV LIMITED infrastructure, showing direct overlap with TeamPCP (also tracked as PCPcat, ShellForce, DeadCatx3, and UNC6780). TeamPCP is an emerging cloud-native threat actor specializing in supply-chain compromises against developer tools, security scanners, and AI/ML infrastructure. Observed tradecraft includes dual C2 frameworks (Havoc and AdaptixC2), innovative decentralized C2 via CanisterWorm on the Internet Computer Protocol, credential harvesting from CI/CD pipelines, and collaboration with ransomware groups. The remaining ~996 addresses fell into the medium-risk tier and functioned as the supporting reconnaissance, proxy, VPN, and residential anonymity layer. The report mapped the full “attack ladder,” demonstrating how medium-risk infrastructure is used for discovery, testing, and operational security before operators escalate to high-risk ranges for execution and persistence.
Legitimate Google Edge Infrastructure vs. Phishing & Malvertising Campaigns
Cleanly separated high-confidence legitimate infrastructure from active malicious campaigns. Legitimate findings mapped directly to Google’s published edge and anycast nodes (consistent server headers, registrar data, and *.1e100.net domains) as well as standard Cloudflare-protected services. Malicious and high-risk clusters included compromised Japanese shared hosting (
), Verizon-themed phishing domains that exploited the January 2026 outage and related customer credit offers, and fully functional clones of insurance lead-generation sites that embedded anti-fraud bypass and tracking scripts. Supporting elements featured aggressive anti-bot cloaking and AI-crawler evasion. Activity aligned with commodity, financially motivated cybercrime ecosystems — phishing-as-a-service, malvertising, and affiliate fraud — rather than sophisticated nation-state operations.
High-Volume Spam/Phishing Campaign & QS-SLIE Deployment
Tracked a high-volume campaign targeting users with bad or limited credit. Operators used networks of short-lived and compromised domains hosting PHP redirectors (r*.php scripts with encoded tracking parameters) to deliver personal loan and Mastercard-branded lures, later mixed with fake job-application social engineering. Infrastructure analysis revealed overlaps with research-adjacent mail and web nodes as well as Netherlands-based hosting providers (notably NFOrce). QS-SLIE (QuantSec SpamLink Intelligence Extractor) was deployed to automatically extract full HTML bodies, parse links, domains, and tracking parameters, generate structured CSVs for graph analysis, and produce ready-to-deploy blocklists. Later samples showed professional HTML templates, extreme CSS-based obfuscation, and consistent redirector patterns. Delivered both strategic insight into the campaign’s maturation and immediate defensive artifacts.
HubSpot / US Family Health Plan Tracking-Domain Abuse
Full infrastructure review of an unexpected disenrollment-themed email claiming association with the US Family Health Plan. The message leveraged a legitimate HubSpot customer portal (portal identifier 491493) and associated tracking domain that resolved cleanly through HubSpot’s CDN. The landing page executed thorough client-side fingerprinting (automation frameworks, plugin consistency, hardware concurrency, screen metrics, platform/language data, endianness, high-DPI support, accelerometer permissions) before issuing a redirect. Secondary exploration via name-server reverse-IP lookups and MX records mapped related Secureserver/GoDaddy mail infrastructure and a large cluster of parked and suspended domains. Documented a growing and effective tactic: abusing already-authenticated, high-reputation third-party marketing platforms to achieve strong deliverability and low-noise collection of device and environmental intelligence while remaining inside trusted channels.
NTP Pool Volunteer-Server Security Assessment
Detailed reconnaissance of vendor-specific NTP Pool zones (including fedora, amazon, and related pools) enumerated more than 140 unique IP addresses and associated hostnames. While no high-confidence active threat-actor attribution was established for the primary hosts, multiple volunteer servers exhibited significant security deficiencies: long-uptime systems running end-of-life software (outdated OpenSSH, Apache, and database versions), exposure of unnecessary services, and at least one residential remote-desktop gateway (Apache Guacamole) answering public time queries. Highlighted enduring structural risks in volunteer-based critical infrastructure that underpins global time synchronization. Practical recommendations provided for NTP Pool operators, organizations relying on the pool, and the broader ecosystem.
Inbound Scanner Clusters & Dual-Use NTP/DNS Infrastructure
Converging inbound scanning activity was correlated with several distinct infrastructure sets. High-volume scanner nodes under Mevspace (AS201814) carried historical associations with the Nitrogen campaign and ALPHV/BlackCat ransomware affiliates. Additional noisy activity originated from Tamatiya EOOD (AS50360) ranges. A dual-use node at 142.202.190.19 (resolving to
) was observed participating in public NTP pools while simultaneously serving web content previously classified by commercial security systems as a phishing risk. Compiled all observed indicators, scan results, domain infrastructure, and related artifacts into a structured intelligence product with prioritized block candidates, domain watchlists, and concrete defensive recommendations (NTP source pinning, IoT/streaming device segmentation, firmware updates, residual callback monitoring).
Public Theory & Concept Threads (Q1–Q2 2026)
Alongside tooling and structured reports, Quantitative Security maintained a steady cadence of public theory and concept threads on X. These posts served as living documentation of evolving mental models, tradecraft hypotheses, and defensive frameworks — many of which later informed the enrichment pipelines, risk-tiering logic, and deception platforms.
Key public threads included:
Moving Target Defense & Single Window Version Cycling (March 2026)
Introduced the core conceptual foundation of Phantom-QS: running multiple Firefox versions (ESR + Beta + Nightly) inside a single window and cycling them at runtime. The thread framed the defensive inversion — “Deception is defense. Detection is attack” — and explained how continuous shifts in memory layouts, engine internals, rendering behavior, and fingerprints raise the cost of hooks, memory scraping, and GUI automation to the point of practical impossibility.
Browser Session Controller / Traffic-Mimetic Sleeper Model (July 2026)
Progressive conceptual model of a coordinated browser session that bootstraps proxy routing, leverages an elevated extension, and conditionally triggers ephemeral resource retrieval. Later upgraded into a low-and-slow, traffic-mimetic sleeper that uses legitimate infrastructure for cover, parameter-driven triggering, obfuscation, and self-cleanup. Explicitly positioned for realistic red-team simulation and understanding of next-generation browser-based threats.
L2 VPN Bridge Pivot Theory (January 2026)
Hypothesis of post-breach lateral movement using a Layer-2 VPN bridge (modified OpenVPN TAP or custom WireGuard + bridge) to extend a remote segment into the target LAN so that local broadcasts (NetBIOS, ARP) appear native. Linked to observed traffic patterns and geopolitical timing, framed as rare but high-value tradecraft for stealth recon and focus-shifting.
Living-off-the-Land DNS / Router Hijack & Social Lure Models (January 2026)
Series of threads examining unsolicited Instagram password-reset flows that resolved to legitimate Meta infrastructure. Core theory: the reset itself is a low-profile lure that drives the victim to grant elevated permissions, while upstream router compromise (ACL modification, GRE tunnels, silent persistence) enables the traffic rewriting. Extended into broader discussion of geodata flips, open RDDS/WHOIS abuse, and classic living-off-the-land TTPs.
Attack Ladder / Risk Hierarchy Framing
Conceptual model (later operationalized in the 1,676-IP report) that attackers rarely jump directly to high-signal infrastructure. Medium-risk proxy/VPN/residential ranges handle discovery, testing, and OPSEC; only after validation do operators escalate to high-risk abusive hosting for execution and persistence. This framing underpins the tiered risk products delivered in Q2.
These threads were deliberately public: they tested ideas in the open, invited scrutiny, and demonstrated that the same analytic rigor applied to private protective-intelligence products is also applied to pure concept development. Several of the models (especially Moving Target Defense, session-controller logic, and the attack-ladder hierarchy) moved from theory into working code and report methodology during the same period.
Closing Position
The complete report series validates the systems and methods developed throughout Q1 and Q2. Quantitative Security has demonstrated the ability to move rapidly from raw network telemetry and open-source data to attributed, prioritized, and defensive-ready intelligence products while maintaining consistent engagement with federal agencies and partners. Public long-form delivery on X simultaneously educates the broader community and serves as living proof of operational tempo and analytic quality.