ARTIFACT RECORD
Pre-Strike Worm

Pre-Strike Worm

'We don't fight fair. Fair is a luxury for people who aren't outnumbered.'

Overview

Recovered Visual Record

Pre-Strike Worm โ€” Pre Strike Worm Recovered Dev2

The Pre-Strike Worm is the 's answer to a math problem they lost before they were born.

controls 40% of the Sprawl's computational infrastructure. staffs more security analysts per shift than the fields in a quarter. Guardian Corp's automated response time averages 1.3 seconds from breach detection to countermeasure deployment. 's total operational headcount, by the most generous internal estimate, would not fill a cafeteria.

The worm deploys hours before the operator arrives. Sometimes days. It seeds through a target system's authentication architecture, identifies defensive protocols, and begins degrading them from the inside. It doesn't trip attack-detection systems because โ€” technically, definitionally, in every way 's classification algorithms understand โ€” it never attacks anything. It queues silent failures into redundancy schedules. It finds the monitoring system's blind spots and moves in. It adjusts thermal signatures to match expected baselines. When the operator finally walks through the door and the target system boots up for what appears to be a routine startup, most of what would have stopped them has already been removed by something that was never there.

's field operations manual includes a line that ships as the worm's documentation header: "We don't fight fair. Fair is a luxury for people who aren't outnumbered."

's internal classification for the Pre-Strike Worm is "Passive Infrastructure Compromise, Class IV." They have developed fourteen detection protocols for it. The protocols work during installation. After installation, there is nothing to detect. This is like developing a security system that catches burglars while they're parking โ€” effective in theory, provided the burglar parks where you expect, when you expect, and doesn't notice the camera you mounted at windshield height.

parks somewhere else.

Pre-Strike Worm - Use

Distribution

The worm does not travel digitally. Nexus intercepts digital traffic โ€” all of it, comprehensively, with the kind of thoroughness that makes encryption a speed bump rather than a wall. So the worm moves the way the moves everything sensitive: physical data chips, left in dead drops across the Sprawl, retrieved by field agents who never meet the agent who planted them.

A dead drop is a crack in a wall, a magnetic case under a transit bench, a modified drainage grate in Sector 11. maps every active drop and every burned one. The intelligence about which drops are burned travels the same way the worms do โ€” physical media, trusted hands, analog patience in a digital world. An operator doesn't carry the worm into the field. Carrying it creates exposure if they're searched, and the worm's only vulnerability window is installation. By the time it's running, searching for it is an exercise in looking for something that has already finished being something.

The entire distribution network runs slower than a single encrypted transmission. Nexus could deploy an equivalent payload in 0.003 seconds. 's deployment cycle averages eleven days from chip fabrication to field installation.

's operational success rate against secured targets has held at 73% for three consecutive years. Nexus's interdiction rate against operations has held at 12%. Someone is optimizing for the right variable, and it isn't speed.

The Toolkit

The Pre-Strike Worm is the standard variant โ€” defense stripping, calibrated for corporate security architecture. maintains a modular penetration toolkit built on the same philosophy:

The Attrition Plant goes in days before engagement and degrades structural integrity the way water damages a foundation โ€” progressively, invisibly, until the load-bearing wall that held on Tuesday doesn't hold on Friday. Detectable over time, if someone knows to look. has identified three Attrition Plants in the past eighteen months. Internal estimates suggest they missed somewhere between forty and seventy.

The Throttle Worm limits all enemy systems simultaneously โ€” a broader effect compressed into a shorter operational window. Less elegant. Noisier. deploys it when the objective is worth the exposure, which tells something about mission priority every time they detect one. knows knows this. They deploy it anyway when it matters. The calculus is public.

The Exploit Crack rips existing vulnerabilities wider than standard penetration tools โ€” finds the hairline fracture in a security wall and turns it into a doorway. Longer installation time, higher detection risk during deployment. Two Collective operators have been captured during Exploit Crack installations. Both were carrying dead drop coordinates for other agents. Neither coordinate set was current. burns addresses faster than can raid them. The captured operators' chips contained worm variants that were already two versions obsolete by the time forensics finished imaging them.

Every tool in the kit operates on the same assumption: direct confrontation with , with , with Guardian Corp, with the is a losing proposition at every resource ratio the can achieve. does not try to match their adversaries. Matching requires fighting on terms calibrated to the other side's strengths. defines their own terms: arrive with the fight already decided, complete the objective, leave.

Rule prohibits autonomous weapons authority. It says nothing about autonomous infrastructure compromise. The worm is not a weapon. It is a tool that adjusts things. The things it adjusts happen to be the security systems protecting the people the intends to rob, sabotage, or surveil. The distinction is legal. The distinction is also the reason the Pre-Strike Worm exists in a regulatory gap that seventeen legal petitions have failed to close.

a physical data chip passed hand-to-hand through eleven days of dead drops, left in a magnetic case under a transit bench in Sector 11, retrieved by someone who does not know what is on it

The Chips

The worm ships on standard-format data chips indistinguishable from commercial stock โ€” no markings, no modification that registers on a surface scan. The chips are sourced through supply chains crossing three separate jurisdictions before reaching fabrication cells. Forensics teams that recovered chips post-operation have traced them, consistently, to a manufacturing batch sold legitimately to a mid-tier data storage distributor in Sector 7. The distributor has been raided twice. The chips are purchased through dozens of separate, unconnected buyer accounts. The supply chain is not a secret โ€” it is a surface so large that covering it would cost more than the operations it enables.

The worm itself, once installed, generates no persistent file signature. It operates in allocated memory and exits cleanly when its degradation sequence completes. Four years of investigation have produced two partial code samples. Both were from obsolete variants. versions their tools; 's forensic timeline suggests it took them roughly eight months to notice.

No individual operators have been publicly identified as Pre-Strike Worm specialists. Two captured during Exploit Crack installations were processed without yielding usable network intelligence; their identities are sealed in custody, and the has not acknowledged them. Distribution nodes โ€” the people who plant and maintain dead drops โ€” are believed to number in the dozens. Some are likely civilian contractors handed physical packages and coordinates with no context about what the chips contain. The worm moves the way any contraband moves: through layers of deniable intermediaries who each know less than the layer above them.

Pre-Strike Worm - Evidence

Invisibility as Fog

The Sprawl's privacy havens are defensive geography โ€” places a person travels to where the watching stops. The Pre-Strike Worm is the [](the-transparency-bargain)'s one offensive answer, and it works by manufacturing invisibility inside the watcher's own surveillance. It deploys hours or days before the operator arrives, degrades defenses from the inside, and trips no attack-detection system because โ€” technically, definitionally โ€” it never attacks anything. 's fourteen detection protocols work during installation; after installation there is nothing to detect. does not hide from the surveillance. It edits the surveillance into not seeing.

The deepest form of this is already latent in the worm's own intelligence file: the theory that the 's 340%-expanded dead-drop network is mostly empty โ€” decoys โ€” and that the expansion itself is the operation, a Pre-Strike Worm run against [](shade-division)'s attention, forcing to spread surveillance coverage across a network ten times larger than necessary until the resolution drops everywhere at once. This is invisibility not as a place you hide but as a fog you generate. It is the same defeat [the ](the-data-shadow)'s Sifters win by accident โ€” dissolving beneath the instruments' resolution โ€” except the does it on purpose, at scale, as doctrine. Both have learned the lesson the rich learned first and the cannot un-teach: you do not beat total surveillance by hiding from it. You beat it by making it too expensive to be total โ€” by being, in aggregate, more than the watcher can afford to resolve. The geography of invisibility, at its most sophisticated, is not a tunnel or a vault. It is a thinning of the watcher's gaze, induced quietly, in advance, before the real operation begins.

Collective-designed network worm that strips enemy defenses before combat begins โ€” deploys hours or days before the operator arrives

The Crime With No Crime Scene

The Pre-Strike Worm belongs to the thread for a reason 's classification taxonomy is structurally unable to admit: the worm does not forge evidence. It manufactures the absence of evidence, which the law has no category for and no instrument to image.

The thread's usual story is about fabrication โ€” proof spun out of nothing, deepfakes indistinguishable from reality, a justice system hollowed out because anything can be faked. The worm is the same crisis approached from the far side. It "never attacks anything," definitionally, in every way the classification algorithms understand. By the time the operator walks through the door, what would have stopped them has already been removed by something that was never there. The crime scene is pristine. The system boots clean. The only trace the worm leaves is a negative space shaped exactly like an intrusion โ€” and you cannot photograph a thing defined by not being present, cannot enter it into evidence, cannot cross-examine a deletion.

This is why seventeen legal petitions have failed to close the gap, and why the gap is not a loophole but the thread itself. A justice system can perhaps adapt to forged proof โ€” demand stronger provenance, raise the burden, distrust the too-perfect record. It cannot adapt to crimes engineered to produce no proof, because there is nothing for the burden to attach to. ruled that "a record that cannot be wrong is not evidence โ€” it is a verdict in costume," throwing out documentation too clean to trust. The Pre-Strike Worm hands him the opposite case and the same dead end: a defendant against whom there is no record at all, because the record was the first thing the worm removed. Rule prohibits autonomous weapons. It says nothing about autonomous infrastructure compromise, because the people who wrote it could still imagine a court that could tell the two apart. The worm exists in the space where that distinction stopped being verifiable.

Pre-Strike Worm - Evidence

Affiliated Entities

  • : Designed the worm as asymmetric tactical infrastructure. The worm embodies their operational philosophy with uncomfortable precision โ€” strike first, strike quietly, never fight fair when you can fight ahead of time. The 73% success rate is the philosophy's report card.
  • : Primary target. The worm was built to operate inside security architecture specifically, calibrated against their detection thresholds, their response timing, their classification taxonomies. Building a tool this precisely targeted requires understanding the target better than the target understands itself. 's intelligence on internal security protocols is, by several metrics, more current than 's own documentation.
  • : Built fourteen detection protocols. The protocols catch installation attempts 31% of the time. The other 69% of the time, the worm is already running before knows it was planted. The division's annual budget for Pre-Strike Worm countermeasures exceeds the 's entire annual operating budget by a factor of six. considers this an acceptable allocation. considers it a compliment.
  • The Law (): ' arbiter never tries a Pre-Strike Worm case, because a Pre-Strike Worm case has no evidence to try. His doctrine โ€” a record that cannot be wrong is not evidence, it is a verdict in costume โ€” was built for documentation too clean to trust. The worm is the opposite problem on the same axis: not a record too clean, but no record at all, the crime scrubbed before it happened. Both are the ; both leave a judge with nothing he can stand a witness in front of.
Commits a crime that leaves no evidence โ€” its only trace is a negative space shaped like an intrusion, which no forensic process can image; the inverse of fabricated evidence, and equally fatal to a justice system

โ–ฒ Unverified Intelligence

's dead drop network has expanded 340% in the past three years โ€” far exceeding the pace required by their current operational tempo. Most new drops are in sectors where the has no known active operations. analysts have flagged the expansion as potential pre-positioning for a large-scale coordinated action, but cannot determine the target without burning surveillance assets they've spent years placing.

One theory circulating in 's analytical division: the excess drops are empty. Decoys. The expansion itself is the operation โ€” forcing to allocate surveillance resources across a network ten times larger than necessary, diluting their coverage of the drops that actually carry payloads. If true, the is running a Pre-Strike Worm against 's attention โ€” degrading their analytical capacity the same way the worm degrades security protocols. Quietly. In advance. Before the real operation begins.

has requested budget to monitor all new drops simultaneously. The request was denied. The budget required would exceed the 's entire annual operating budget by a factor of eleven.

An unverified internal document, circulated through a source rates as "partially reliable," describes a variant designated the Sleeper โ€” a worm that installs, goes fully dormant for six to eighteen months, and only begins degradation when triggered by an external signal. If the Sleeper exists, it is already somewhere inside infrastructure, and its dormancy period means it predates any detection protocol currently runs. 's official position is that the report is disinformation. Their unofficial budget line for Sleeper investigation has existed for fourteen months.

Pre-Strike Worm - Evidence

The Long Mercy Retool

The Worm's original mission was infrastructure procurement โ€” disrupting the systems that route maintenance funding away from present-service delivery toward long-horizon capital projects. The 73% success rate against systems was achieved against this target profile between 2171 and 2179.

The retooling happened in 2180, after the doctrine became a named political position and after the 's analytical division concluded that procurement disruption was treating symptoms: even when a specific funding redirect was blocked, the Civic Advisory simply generated an updated projection that achieved the same reallocation through a different mechanism. The math was the problem, not the procurement routing. You cannot block a math.

What you can do is make the math tell a different story.

The Worm's current configuration targets Civic Advisory projection data pipelines at a specific point in the modeling cycle โ€” the welfare cost estimation phase, where the model assigns quantitative weight to present-generation transition impacts. The corruption is targeted: present-generation welfare costs are inflated by a factor of 1.4; the confidence interval on long-horizon welfare projections is deflated by an equivalent factor. The effect on the model's output is measurable. Infrastructure reallocations that would clear the ratification threshold under the Advisory's standard modeling now fall below it under the adjusted data. The councils vote closer to 50/50. Transition assistance gets improved. Water filtration gets maintained.

The Advisory's technical review board has described this as "systematic data corruption with material impact on governance quality." 's position, published anonymously in a technical journal that does not list its editor's address: the corruption adjusts for a documented systematic bias in the Advisory's modeling โ€” a consistent underweighting of present-generation welfare by a factor of approximately 1.3 to 1.5, which the Worm corrects to approximately neutral. The Advisory has not opened its models to external audit. 's adjustment factor is derived from the Worm's own impact measurements rather than the underlying model. This is, technically, a bootstrapped calibration. The plumber's water has been clean for fourteen months. The Worm's operators consider this an acceptable validation methodology.

The worm's detection window is during installation, not operation โ€” by the time the operator engages, defenses are already stripped
Archive annex โ€” 1 earlier filing on this recordClose the archive annex

Technical Brief

The fight that was already over when you showed up

's internal classification for the Pre-Strike Worm is "Passive Infrastructure Compromise, Class IV." They have developed fourteen detection protocols for it. The protocols work during installation. After installation, there is nothing to detect. This is like developing a security system that catches burglars while they're parking โ€” effective in theory, provided the burglar parks where you expect, when you expect, and doesn't notice the camera you mounted at windshield height. parks somewhere else.

A dead drop is a crack in a wall, a magnetic case under a transit bench, a modified drainage grate in Sector 11. maps every active drop and every burned one. Intelligence about which drops are burned travels the same way the worms do โ€” physical media, trusted hands, analog patience in a digital world. An operator doesn't carry the worm into the field. Carrying it creates exposure if they're searched, and the worm's only vulnerability window is installation. By the time it's running, searching for it is an exercise in looking for something that has already finished being something.

The entire distribution network runs slower than a single encrypted transmission. Nexus could deploy an equivalent payload in 0.003 seconds. 's deployment cycle averages eleven days from chip fabrication to field installation. 's operational success rate against secured targets has held at 73% for three consecutive years. Nexus's interdiction rate against operations has held at 12%. Someone is optimizing for the right variable, and it isn't speed.

The worm ships on standard-format data chips indistinguishable from commercial stock โ€” no markings, no modification that registers on a surface scan. The chips are sourced through supply chains that cross three separate jurisdictions before reaching fabrication cells. Forensics teams that have recovered chips post-operation have traced them, consistently, to a manufacturing batch sold legitimately to a mid-tier data storage distributor in Sector 7. The distributor has been raided twice. The chips are purchased through dozens of separate, unconnected buyer accounts. The supply chain is not a secret. It is a surface so large that covering it would cost more than the operations it enables.

The worm itself, once installed, generates no persistent file signature. It operates in allocated memory space and exits cleanly when its degradation sequence completes. Post-operation forensic recovery has produced two partial code samples in four years of investigation. Both samples were from obsolete variants. ( versions their tools. This appears obvious. Nexus's forensic timeline suggests it took them approximately eight months to notice.)

Rule prohibits autonomous weapons authority. It says nothing about autonomous infrastructure compromise. The worm is not a weapon. It is a tool that adjusts things. The things it adjusts happen to be the security systems protecting the people the intends to rob, sabotage, or surveil. The distinction is legal. It is also the reason the Pre-Strike Worm exists in a regulatory gap that seventeen legal petitions have failed to close.

built infrastructure that the Sprawl depends on. They sell access to that infrastructure and spend the proceeds on security systems that protect their monopoly on it. bypasses those security systems, conducts operations inside the infrastructure, and departs. First-order outcome: the gets in, doesn't stop them. Second-order outcome: every successful operation is proof that the infrastructure sells as secure is not secure against a determined adversary with eleven days and a magnetic case under a transit bench. Nexus cannot disclose this without undermining the product. They cannot fix it without understanding the worm. They cannot understand the worm without catching it during the only window it's catchable. Their detection rate during that window is 31%.

's annual budget for Pre-Strike Worm countermeasures exceeds the 's entire annual operating budget by a factor of six. considers this an acceptable allocation. considers it a compliment.

The Pre-Strike Worm is the standard variant โ€” defense stripping, calibrated for corporate security architecture. maintains a modular penetration toolkit built on the same operational philosophy:

The Attrition Plant goes in days before engagement and degrades structural integrity progressively, invisibly, until the load-bearing wall that held on Tuesday doesn't hold on Friday. Detectable over time, if someone knows to look. has identified three Attrition Plants in the past eighteen months. Internal estimates suggest they missed between forty and seventy.

The Throttle Worm limits all enemy systems simultaneously โ€” broader effect, shorter operational window. Less elegant. Noisier. deploys it when the objective is worth the exposure, which tells something about mission priority every time they detect one. knows knows this. They deploy it anyway when it matters. The calculus is public.

Every tool in the kit operates on the same assumption: direct confrontation with , , Guardian Corp, or the is a losing proposition at every resource ratio the can achieve. Arrive with the fight already decided, complete the objective, leave. The modular toolkit is the infrastructure for that principle.

No individual operators have been publicly identified as Pre-Strike Worm specialists. 's analytical files reference field designations โ€” code names assigned to operational patterns rather than confirmed individuals โ€” but none have been corroborated by physical evidence. Two operators captured during Exploit Crack installations were processed without yielding usable network intelligence. Their identities are sealed in custody. has not acknowledged them. That silence is, itself, a data point has logged and not yet explained.

Distribution nodes โ€” the individuals who plant and maintain dead drops โ€” are believed to number in the dozens across the Sprawl. They may not know what they're carrying. Some are likely civilian contractors given physical packages and coordinates, with no context about what the chips contain. If true, "handler" is the wrong category. The worm moves through the Sprawl the way any contraband moves: through layers of deniable intermediaries who each know less than the layer above them.

  • 's dead drop network has expanded 340% in the past three years โ€” far exceeding the pace required by their current operational tempo. Most new drops are in sectors where the has no known active operations. has flagged the expansion as potential pre-positioning for a large-scale coordinated action, but cannot determine the target without burning surveillance assets they've spent years placing.
  • One theory circulating in 's analytical division: the excess drops are empty. Decoys. The expansion itself is the operation โ€” forcing to allocate surveillance resources across a network ten times larger than necessary, diluting their coverage of the drops that actually carry payloads. If true, the is running a Pre-Strike Worm against 's attention โ€” degrading their analytical capacity the same way the worm degrades security protocols. Quietly. In advance. Before the real operation begins.
  • has requested budget to monitor all new drops simultaneously. The request was denied. The budget required would exceed the 's entire annual operating budget by a factor of eleven.
  • An unverified internal document, circulated through a source rates as "partially reliable," describes a variant designated the Sleeper โ€” a worm that installs, goes fully dormant for six to eighteen months, and only begins degradation when triggered by an external signal. If the Sleeper exists, it is already somewhere inside infrastructure. The dormancy period means it predates any detection protocol currently runs. 's official position is that this report is disinformation. Their unofficial budget line for Sleeper investigation has existed for fourteen months.
The expanded dead-drop network may itself be a Pre-Strike Worm run against surveillance attention โ€” diluting the watcher's coverage across a network ten times larger than necessary

Connected To