detection
confidence: medium
public
The online-config repo defines Flink topologies literally named "vpn-recommend" and "app-recommend" (both keyed on a config named RECOMMENDATION-APP-CIP, i.e. client-IP-based app/VPN recommendation) alongside a family of "ip-learning-spark" Spark jobs (including an "ip-learning-spark-subid-only" variant tying IP-learning to a subscriber ID) — evidence of an automated, cross-site VPN/app client-IP classification-and-learning pipeline distinct from, but conceptually similar to, the Pakistan-specific CyberNarrator vpn-thwarting IP-harvesting capability documented elsewhere.
flink/NC/topology/vpn-recommend/config/RECOMMENDATION-APP-CIP ; ip-learning-spark-subid-only.jar
Defense implications
- A dedicated 'vpn-recommend' pipeline plus subscriber-ID-aware 'ip-learning' Spark jobs suggest VPN-classified client IPs feed an automated recommendation/scoring system across TSG deployments generally, not only the Pakistan CyberNarrator site — assume newly observed circumvention client IPs can be auto-flagged network-wide within the ETL refresh cadence, reinforcing the need for IP-rotation / ephemeral-egress designs as standard practice rather than a defense against one customer.
extracted_by: claude-sonnet-5 · added 2026-08-26 · id: 2026-vpn-recommend-iplearn-1170e6