    <?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>surveillance &#8211; Mark E. Jeftovic is The Bombthrower</title>
	<atom:link href="https://bombthrower.com/tag/surveillance/feed/" rel="self" type="application/rss+xml" />
	<link>https://bombthrower.com</link>
	<description>Blowing up the Clown World.</description>
	<lastBuildDate>Sun, 05 Jul 2026 00:01:20 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://bombthrower.com/wp-content/uploads/2021/01/favicon.jpg</url>
	<title>surveillance &#8211; Mark E. Jeftovic is The Bombthrower</title>
	<link>https://bombthrower.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Honeypot Probes: Government-Linked Network Activity, Link-Local Addresses, and Immediate Suspicious Reactions</title>
		<link>https://bombthrower.com/honeypot-probes-government-linked-network/</link>
					<comments>https://bombthrower.com/honeypot-probes-government-linked-network/#respond</comments>
		
		<dc:creator><![CDATA[Chris]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 09:00:48 +0000</pubDate>
				<category><![CDATA[Bitcoin]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Clown World]]></category>
		<category><![CDATA[Cryptocurrencies]]></category>
		<category><![CDATA[Disruption]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[CSIS]]></category>
		<category><![CDATA[Equibit]]></category>
		<category><![CDATA[Five Eyes]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[nasa]]></category>
		<category><![CDATA[surveillance]]></category>
		<category><![CDATA[zersetzung]]></category>
		<guid isPermaLink="false">https://bombthrower.com/?p=12380</guid>

					<description><![CDATA[If you are new to the Equibit story, please read The Assassination of Equibit, originally released in 2023. By December 2020 CSIS was deep in default of filing its defense, and Chris Horlacher suspected they would attempt to undermine the lawsuits via other means. After experiencing persistent and strange internet behaviors Horlacher deployed a honeypot named “Equibit-Dev” on [&#8230;]]]></description>
										<content:encoded><![CDATA[<div style="margin-top: 0px; margin-bottom: 0px;" class="sharethis-inline-share-buttons" ></div><p><img fetchpriority="high" decoding="async" class="alignnone wp-image-12413 size-full" src="https://bombthrower.com/wp-content/uploads/2026/06/honeypot-probes.jpg" alt="" width="1168" height="784" srcset="https://bombthrower.com/wp-content/uploads/2026/06/honeypot-probes.jpg 1168w, https://bombthrower.com/wp-content/uploads/2026/06/honeypot-probes-300x201.jpg 300w, https://bombthrower.com/wp-content/uploads/2026/06/honeypot-probes-1024x687.jpg 1024w, https://bombthrower.com/wp-content/uploads/2026/06/honeypot-probes-768x516.jpg 768w, https://bombthrower.com/wp-content/uploads/2026/06/honeypot-probes-600x403.jpg 600w" sizes="(max-width: 1168px) 100vw, 1168px" /></p>
<p><em>If you are new to the Equibit story, please read <a href="https://bombthrower.com/the-assassination-of-equibit/">The Assassination of Equibit</a>, originally released in 2023.</em></p>
<p class="wp-block-paragraph">By December 2020 CSIS was deep in default of filing its defense, and Chris Horlacher suspected they would attempt to undermine the lawsuits via other means. After experiencing persistent and strange internet behaviors Horlacher <a href="https://github.com/mattymcfatty/HoneyPi">deployed a honeypot</a> named “Equibit-Dev” on his home network while still residing in Canada on a Rogers internet connection. The purpose was straightforward: to observe and document any targeted probing of his systems.</p>
<p class="wp-block-paragraph">What followed was a series of events that remain among the most technically and behaviorally revealing in the Equibit case.</p>
<h1 class="wp-block-heading">Chronology of Events</h1>
<p class="wp-block-paragraph"><strong>December 2020 – Initial Probe</strong></p>
<p class="wp-block-paragraph">Shortly after the honeypot was activated, it received an immediate probe from the link-local IP address <strong>169.254.15.240</strong>. This address returned several times over the ensuing weeks and eventually self-identified on the local network as “<strong>Equibit-Dev.local</strong>” — using the exact naming convention of Horlacher’s honeypot.</p>
<div class="wp-block-image">
<figure class="aligncenter size-full"><img decoding="async" class="wp-image-1850 aligncenter" src="https://equibitlawsuit.com/wp-content/uploads/2026/06/image-1.png" alt="" width="579" height="445" /></figure>
</div>
<p class="wp-block-paragraph">Link-local addresses (169.254.0.0/16 range) are not publicly routable and are typically used for automatic communication within a local network segment. In this context, the appearance of such a probe strongly suggests activity originating from within the local network — most plausibly the router itself, which Chris already suspected had been subjected to ISP-level interception under a Federal Court warrant.</p>
<p class="wp-block-paragraph"><strong>Controlled Disclosure</strong></p>
<p class="wp-block-paragraph">Horlacher performed a controlled disclosure, informing Marc Godard (long-time friend, former CTO and CEO of Equibit Group, and primary suspect for being a CSIS Officer) and IT-security professional George Plytas (a highly-accomplished CISO whom Chris had worked with at several companies) about the probe. For the purpose of the test, he referred to it as the “NASA” probe (the actual address was one digit off from a known NASA range, 169.154.15.240).</p>
<div class="wp-block-image">
<figure class="aligncenter size-full"><img decoding="async" class="wp-image-1199 aligncenter" src="https://equibitlawsuit.com/wp-content/uploads/2026/05/image.png" alt="" width="976" height="183" /></figure>
</div>
<p class="wp-block-paragraph">Marc Godard quickly downplayed the finding. George Plytas, a seasoned cybersecurity expert with whom Horlacher had a long professional relationship, immediately ceased all communication and has not been heard from since.</p>
<p class="wp-block-paragraph"><strong>January 3, 2021 &amp; May 30, 2021 – Confirmed Government-Linked Probes</strong></p>
<p class="wp-block-paragraph">Several weeks after the initial link-local probe, the honeypot was contacted by the IP address <strong>168.254.7.38</strong>. This address belongs to <strong>ASN BHN-33363</strong>, officially registered to <strong>Charter Communications, Inc.</strong> (formerly Bright House Networks). Charter is one of the largest cable and internet service providers in the United States, operating under the Spectrum brand in many regions.</p>
<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" class="wp-image-1851 aligncenter" src="https://equibitlawsuit.com/wp-content/uploads/2026/06/image-2.png" alt="" width="575" height="454" /></figure>
</div>
<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" class="wp-image-1849 aligncenter" src="https://equibitlawsuit.com/wp-content/uploads/2026/06/image.png" alt="" width="954" height="170" /></figure>
</div>
<p class="wp-block-paragraph">Sources:</p>
<ul class="wp-block-list">
<li><a href="https://search.arin.net/rdap/?query=AS33363" target="_blank" rel="noreferrer noopener">ARIN WHOIS Record for AS33363</a></li>
<li><a href="https://bgp.tools/as/33363" target="_blank" rel="noreferrer noopener">BGP.tools ASN Details</a></li>
</ul>
<p class="wp-block-paragraph">While Charter Communications is a commercial ISP, large U.S. telecommunications providers like Charter are frequently used by government agencies for data interception, handoffs, and operational cover. IP ranges from major carriers are commonly seen in government and law enforcement activity due to warrants served on the ISP.</p>
<p class="wp-block-paragraph">The 168.254.7.38 address probed the honeypot once on January 3, 2021, and then three separate times on May 30, 2021. The repetition on May 30 is particularly noteworthy, as it suggests deliberate, targeted reconnaissance rather than random scanning.</p>
<h1 class="wp-block-heading">Analysis and Implications</h1>
<p class="wp-block-paragraph">The combination of these probes is significant:</p>
<ul class="wp-block-list">
<li>The <strong>link-local probe</strong> (169.254.15.240) suggests local network compromise or router-level monitoring, consistent with lawful interception authorized by a Federal Court warrant served on Rogers.</li>
<li>The <strong>BHN-33363 probes</strong> represent <strong>external interest</strong> from a major U.S. telecommunications ASN with documented government ties. The timing of these probes — shortly after honeypot deployment and again during sensitive litigation periods — strengthens the pattern of coordinated surveillance.</li>
</ul>
<p class="wp-block-paragraph">Together, they indicate targeted technical surveillance during a period when Horlacher was actively preparing to confront CSIS in discovery.</p>
<p class="wp-block-paragraph">The behavioral reactions remain particularly telling. Marc Godard’s rapid dismissal and George Plytas’s complete withdrawal of contact occurred immediately after disclosure. In intelligence and counter-intelligence contexts, such abrupt changes in behavior are often interpreted as signs of recognition or operational sensitivity.</p>
<h2 class="wp-block-heading">Conclusion</h2>
<p class="wp-block-paragraph">While the most dramatic initial probe was link-local rather than a direct external NASA connection, the overall pattern — local router-level activity combined with probes from a major government-linked ASN, timed with litigation milestones, and followed by highly suspicious reactions from key individuals — remains deeply concerning.</p>
<p class="wp-block-paragraph">This incident forms part of a broader technical surveillance picture that has been meticulously documented and will be included in the full Factum of Equibit Group.</p>
<p class="wp-block-paragraph"><em>The watchers were active.</em></p>
<p class="wp-block-paragraph"><strong>Some of their reactions suggested they did not appreciate being watched in return.</strong></p>
<p><em>Stay tuned to <a href="http://equibitlawsuit.com/">equibitlawsuit.com</a> for more updates on the Equibit lawsuits against CSIS and related actors.</em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://bombthrower.com/honeypot-probes-government-linked-network/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>DNS Man-in-the-Middle Attack Exposed: Targeted Internet Surveillance on Chris Horlacher’s Network</title>
		<link>https://bombthrower.com/dns-man-in-the-middle-attack-exposed-targeted-internet-surveillance-on-chris-horlachers-network/</link>
					<comments>https://bombthrower.com/dns-man-in-the-middle-attack-exposed-targeted-internet-surveillance-on-chris-horlachers-network/#respond</comments>
		
		<dc:creator><![CDATA[Chris]]></dc:creator>
		<pubDate>Tue, 26 May 2026 09:00:04 +0000</pubDate>
				<category><![CDATA[Bitcoin]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Clown World]]></category>
		<category><![CDATA[Cryptocurrencies]]></category>
		<category><![CDATA[Disruption]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[CSIS]]></category>
		<category><![CDATA[dns mitm]]></category>
		<category><![CDATA[Equibit]]></category>
		<category><![CDATA[Five Eyes]]></category>
		<category><![CDATA[surveillance]]></category>
		<category><![CDATA[zersetzung]]></category>
		<guid isPermaLink="false">https://bombthrower.com/?p=12376</guid>

					<description><![CDATA[If you are new to the Equibit story, please read The Assassination of Equibit, originally released in 2023. In one of the clearest examples of technical surveillance in his case, Chris Horlacher discovered and documented a DNS-based Man-in-the-Middle (MITM) attack that was intercepting and potentially monitoring his internet traffic. Discovery of the DNS Hijack While investigating persistent [&#8230;]]]></description>
										<content:encoded><![CDATA[<div style="margin-top: 0px; margin-bottom: 0px;" class="sharethis-inline-share-buttons" ></div><p><img loading="lazy" decoding="async" class="alignnone wp-image-12374 size-full" src="https://bombthrower.com/wp-content/uploads/2026/05/dns-mitm.jpg" alt="" width="1168" height="784" srcset="https://bombthrower.com/wp-content/uploads/2026/05/dns-mitm.jpg 1168w, https://bombthrower.com/wp-content/uploads/2026/05/dns-mitm-300x201.jpg 300w, https://bombthrower.com/wp-content/uploads/2026/05/dns-mitm-1024x687.jpg 1024w, https://bombthrower.com/wp-content/uploads/2026/05/dns-mitm-768x516.jpg 768w, https://bombthrower.com/wp-content/uploads/2026/05/dns-mitm-600x403.jpg 600w" sizes="auto, (max-width: 1168px) 100vw, 1168px" /></p>
<p><em>If you are new to the Equibit story, please read <a href="https://bombthrower.com/the-assassination-of-equibit/">The Assassination of Equibit</a>, originally released in 2023.</em></p>
<p>In one of the clearest examples of technical surveillance in his case, Chris Horlacher discovered and documented a DNS-based <a href="https://en.wikipedia.org/wiki/Man-in-the-middle_attack">Man-in-the-Middle</a> (MITM) attack that was intercepting and potentially monitoring his internet traffic.</p>
<h2 class="wp-block-heading">Discovery of the DNS Hijack</h2>
<p>While investigating persistent connectivity problems and router compromises in 2025, Chris noticed that DNS queries were resolving through unexpected Akamai servers located in the United States, even when he manually configured trusted public resolvers such as Cloudflare (1.1.1.1).</p>
<p>He engaged an independent, experienced cybersecurity professional to conduct a thorough forensic investigation. The expert worked directly with Chris as he performed extensive testing across multiple devices, configurations, and networks. The results confirmed anomalous DNS behavior consistent with interception or manipulation, primarily affecting the home Telmex network.</p>
<h2 class="wp-block-heading">Controlled Disclosure Test</h2>
<p>At the time the DNS MITM was still active, Chris made a deliberate controlled disclosure. He shared specific details about discovering and isolating the attack with only one person — Ilya Fadeev, a minor shareholder and former lead wallet developer at Equibit Group — who was known to be in communication with Marc Godard, a co-founder, former CTO, and lead suspect in Chris’s investigation of the sabotage and entrapment efforts that had been levelled against him.</p>
<p>Within hours of this limited disclosure, the most obvious signs of the DNS manipulation disappeared. Follow-up testing confirmed that DNS queries were now resolving normally through trusted servers.</p>
<h2 class="wp-block-heading">Expert Analysis and Evidence</h2>
<p>The cybersecurity specialist produced a detailed report documenting the investigation, test methodology, and findings. This report included extensive DNS leak tests, nslookup results, and comparative analysis across networks.</p>
<p><strong>Download: <a href="https://equibitlawsuit.com/wp-content/uploads/2026/05/Fiverr_Chris_18August2025.pdf">Expert Report (August 18, 2025)</a></strong></p>
<p>Screenshots of the DNS tracing tests are available upon request to competent researchers or journalists.</p>
<p>Notably, this was the same expert report that Chris later witnessed being <strong>spontaneously moved to his desktop</strong> through apparent remote access via his Microsoft OneDrive account.</p>
<h2 class="wp-block-heading">Strategic Context: “Control the Battlefield”</h2>
<p>Had Chris remained in Canada, such a MITM attack might have been unnecessary. Canadian authorities could simply serve a warrant directly to the ISP for full traffic access. By relocating to Mexico, Chris deliberately removed one of the most powerful tools from his adversaries’ arsenal — forcing them to resort to more complex technical attacks like router compromises via TR-069 and DNS manipulation.</p>
<p>This forms part of Chris’s broader “Control the Battlefield” strategy, which comes from Sun Tzu’s <em>Art of War</em>: denying easy institutional access and forcing any surveillance into more detectable, and legally questionable methods.</p>
<h2 class="wp-block-heading">Implications</h2>
<p>A DNS Man-in-the-Middle attack at the router or ISP level is extremely invasive. It enables:</p>
<ul class="wp-block-list">
<li>Logging of every website visited</li>
<li>Undetectable traffic redirection to spoofed websites</li>
<li>Monitoring of communications (even HTTPS to a limited degree)</li>
</ul>
<p>The precision, persistence, and rapid response to the controlled disclosure strongly suggest a targeted operation by sophisticated actors.</p>
<p>This incident adds to the growing body of technical evidence of digital harassment that includes router compromises, Microsoft ecosystem intrusions, and other documented attacks.</p>
<p><strong>Further Reading:</strong></p>
<ul class="wp-block-list">
<li><a href="https://equibitlawsuit.com/router-sabotage-exposed/">Router Sabotage</a> via TR-069</li>
<li><a href="https://equibitlawsuit.com/microsoft-under-fire/">Microsoft Unauthorized Access</a> Incidents</li>
<li>Complete <a href="https://equibitlawsuit.com/category/media/">Media section</a></li>
</ul>
<p>These attacks highlight the vulnerabilities of modern connected infrastructure and the challenges faced by individuals seeking accountability from powerful institutions.</p>
<p>If you value digital privacy and the right to due process, please share this post.</p>
<p><em>Stay tuned to <a href="http://equibitlawsuit.com/">equibitlawsuit.com</a> for more updates on the Equibit lawsuits against CSIS and related actors.</em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://bombthrower.com/dns-man-in-the-middle-attack-exposed-targeted-internet-surveillance-on-chris-horlachers-network/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
