Mapping Mesh Infrastructure and Protocol Hijacking

Joseph Goydish II via NANOG <[email protected]>
Newsgroups gmane.org.operators.nanog
Message-ID <Fk-_NahLGLscJ40YbgfB_8S5zYxBL-e3iCV_qu8Ojir0tsrd23PLyq6m4Wl2TCdhe85pqGGBSyZ6s3_VnPeFm2TcV7_C6arqmzzpq_Aw34E=@proton.me>
I’ve been tracking some non-standard networking patterns on iOS that seem to be operating in a blind spot. Detection relies on parsing TraceV3 binary data to actually spot, specifically looking for hex-coded IP patterns in the logs.

A few things I've been seeing:

- Port 5223 (APNs) redirection: System traffic being tossed to non-Apple ASNs.

- Non-standard tunneling: Persistent P2P sync on ports 44 and 522.

- Global reach: Active clusters popping up across Russia, China, the US, Mexico etc.

I put together a live dashboard to track these IPs and ASNs as they're enriched. If anyone else is seeing weird routing anomalies or similar "shadow" egress points at the backbone level, I'd love to hear your thoughts.

Dashboard link: https://www.perplexity.ai/computer/a/ios-threat-tracker-y2BPW5oISauRTNFBcx93Iw

Thank you,
Joseph II
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/[email protected]/message/YDTTFIWTVGTLOUNLUXL6VNKWOIEDJ37Q/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.