Tech Sentinel
Flat isometric illustration of gold balance scales with two glowing blue pans, standing on a stepped blue plinth against a dark blue dotted background.
threat-intel

Bulletproof Hosting: Why Takedowns Keep Failing

Sanctions and server seizures hit bulletproof hosting through 2025 and 2026, yet the infrastructure keeps returning. What actually degrades it.

By Tech Sentinel Newsroom · · 8 min read

Between February 2025 and May 2026, Western governments ran the most sustained campaign against bulletproof hosting in the history of the category. Three sanctions packages, two large server seizures in the Netherlands, and the first criminal prosecution in Europe aimed at the facilitators rather than the designated entity. Measured by press releases, it was a rout.

Measured by whether the infrastructure went away, it was not. Sanctioned networks reconstituted under new legal entities in weeks. Seized capacity was replaced. The operators who mattered were never in a jurisdiction where an arrest was possible. In November 2025, CISA and its international partners effectively conceded the point by publishing guidance telling network defenders to plan around bulletproof hosting as a permanent condition rather than waiting for enforcement to remove it.

What Bulletproof Hosting Actually Is

A bulletproof hosting provider is an internet infrastructure provider that knowingly leases servers, IP space, or connectivity to criminals and does not act on abuse reports. That last clause is the whole product. The hardware is ordinary. What the customer is buying is a commitment to ignore takedown requests, law enforcement inquiries, and upstream complaints for as long as commercially possible.

The category underwrites nearly every mass-scale crime we cover: ransomware command-and-control, infostealer panels, phishing kit hosting, malware delivery, DDoS coordination, and state-aligned influence operations. Four structural features make these providers hard to remove.

Nested resale. The entity that answers the abuse email is rarely the entity that owns the rack. A criminal customer may sit three or four resale layers below a legitimate European data center that has no visibility into the end user. Prosecuting the visible layer often reaches a company that can plausibly claim ignorance.

ASN and prefix churn. Autonomous system numbers and IP prefixes are administrative objects. They can be transferred between organizations at a regional internet registry in days. A sanctioned network does not need to move a single server to reappear under a new ASN with a clean reputation.

Jurisdictional arbitrage. Company registration, physical hosting, network registration, and beneficial ownership can each sit in a different country. Enforcement authority almost never spans all four.

Front companies in permissive registries. Shell entities in the Seychelles, the UK LP regime, and similar low-disclosure jurisdictions provide a legal wrapper that resets on demand.

The clearest long-run example is the operation founded in 2005 as Ecatel, which has traded over two decades as Novogara, Quasi Networks, and IP Volume, running out of The Hague while registering entities in the UK and later the Seychelles behind anonymous directors. When one sibling was blocked, customers were rerouted to another. Two decades of abuse reporting, rights-holder complaints, and law enforcement interest did not end the network; it renamed it.

The 2025 to 2026 Enforcement Record

Four actions define the campaign, and each one is instructive about a different limit.

February 11, 2025 — Zservers / XHOST. The US, the UK and Australia designated Zservers, a Barnaul-based bulletproof host, on the same day, for leasing IP address space to LockBit ransomware affiliates. The split is instructive about how uneven a “joint” action is in practice: OFAC named the company and two of its employees, the UK’s Foreign, Commonwealth and Development Office named the UK front company XHOST Internet Solutions LP and six employees, and Australia named five individuals. The following day Dutch police seized 127 servers used by the operation, closing an investigation opened roughly a year earlier. This was the model case: coordinated designation plus physical seizure, in the same week.

May 20, 2025 — Stark Industries Solutions. The EU sanctioned Stark Industries Solutions, its affiliate PQ Hosting Plus S.R.L., and the Neculiti brothers who ran it, citing the network’s role in DDoS campaigns, proxy infrastructure for intelligence-linked groups, and hosting for the Doppelganger influence operation.

July 1, 2025 — Aeza Group. OFAC designated Aeza Group, two affiliated Russian companies and four of its leaders, and — in coordination with the UK’s National Crime Agency — its UK branch Aeza International Ltd, which leased IP addresses to cybercriminals. The designation cites bulletproof hosting for the Meduza and Lumma infostealer operators, BianLian ransomware, RedLine infostealer panels, and the BlackSprut darknet drug market. Treasury named the US defense industrial base explicitly among the victim set.

May 18, 2026 — the Dutch arrests. Dutch FIOD investigators arrested two hosting co-owners and seized more than 800 servers, charging them under EU sanctions law with making infrastructure available to designated entities. This was the genuinely new instrument: prosecuting the European connectivity provider that kept a sanctioned network alive, rather than the sanctioned network itself.

The Reconstitution Timeline Is the Whole Problem

The Stark case is the closest thing the field has to a controlled experiment, because Recorded Future’s Insikt Group reconstructed the migration day by day. Infrastructure began moving on April 10, 2025. Prefix transfers off the primary ASN began April 13. A replacement RIPE organization was created on May 13. The primary ASN was transferred on May 16. The EU sanctions were formally announced on May 20 — after the migration was substantially complete. A Netherlands-registered successor created a new RIPE organization on May 28 and 29, and a new ASN was registered in late June.

The designation trailed the migration by roughly six weeks, and the operators appear to have had advance warning. KrebsOnSecurity’s September 2025 investigation then named the Dutch provider that had absorbed the connectivity. The FIOD arrests came eight months after that report.

That asymmetry generalizes. Sanctions designation is a months-long interagency process producing a static list of names. ASN transfer is a form submission. Any enforcement instrument that names entities will lose to an adversary whose entities are disposable.

InstrumentWhat it degradesTypical reconstitution
OFAC / EU designationAccess to Western banking, payment rails, and compliant suppliersWeeks, via a new legal entity and ASN transfer
Server seizureLive capacity and stored evidence, immediatelyWeeks to months, limited by capital rather than law
Facilitator prosecutionWillingness of legitimate providers to carry the trafficYears, if convictions follow
Defender ASN blockingReachability of the criminal infrastructure from your networkImmediate for the operator, but the cost recurs every move

Only the bottom two rows compound. Designation and seizure are events; facilitator liability and defensive blocking change the ongoing economics.

What CISA’s Guidance Actually Asks For

On November 19, 2025, CISA published Bulletproof Defense: Mitigating Risks From Bulletproof Hosting Providers through the Joint Ransomware Task Force, with the NSA, the FBI, the Department of Defense Cyber Crime Center, and the national cyber security centres of Australia, Canada, the Netherlands, New Zealand, and the United Kingdom. It is aimed at internet service providers and network defenders, not at law enforcement, and that choice of audience is the argument.

The core recommendations are unglamorous and durable: curate a list of “high confidence” malicious internet resources from commercial and open-source threat feeds and information-sharing channels; baseline your own traffic and hunt the outliers to supplement that list; review the list automatically and remove resources once they are reallocated to legitimate infrastructure; configure centralized logging to record both ASNs and IP addresses and alert when traffic hits a listed resource; implement filters at the network border; and share findings back through public and private channels.

The honest limitation is collateral damage, and the guidance leads with it rather than burying it: BPH infrastructure is integrated into legitimate internet infrastructure, so ISP and defender actions “may impact legitimate activity.” Bulletproof hosts deliberately co-locate criminal customers alongside legitimate ones so that prefix-level blocking has a cost. Blanket ASN blocks are cheap to apply and occasionally break a customer’s payment processor, which is why the document asks defenders to weigh the impact on malicious and possibly legitimate traffic per resource and to choose a filter granularity — whole ASN, IP range, or single address — from that analysis. Doing that honestly requires per-prefix telemetry most organizations do not currently collect.

Why This Sits Upstream of Everything Else

Hosting is the shared dependency under campaigns that otherwise have nothing in common. The GRU-linked ClickFix CAPTCHA lures against Ukrainian targets and the SVR-attributed hotel Wi-Fi surveillance operation needed staging infrastructure that would not be pulled after the first abuse report. So did the malicious package flood that forced RubyGems to suspend signups, which depended on hosts willing to serve second-stage payloads.

That is what makes ASN-level telemetry a leveraged control rather than a niche one. A single enrichment field on egress logs — the ASN behind every outbound destination — turns unrelated detections into one queue, and it survives the operator’s next rebrand in a way that domain and IP indicators do not.

What Defenders Should Do

  1. Enrich egress logs with ASN and network-owner data. IP indicators expire in days; ASN attribution survives a rebrand and gives you a stable pivot.
  2. Subscribe to and actually ingest the community bulletproof-hosting ASN lists. Several are maintained publicly and updated faster than any sanctions list.
  3. Alert on RIR organization changes for ASNs you already block. A transfer of a blocked ASN to a new organization is the earliest available signal that a network is reconstituting.
  4. Block at prefix granularity, not ASN granularity, where you can. It costs more to maintain and it is the difference between a control you keep and one that gets rolled back after the first false positive.
  5. Add sanctions screening for beneficial ownership to vendor and connectivity onboarding. The Dutch prosecution turns on knowing provision of services, which makes this a legal exposure and not only a security one.
  6. Treat published investigative reporting as notice. Once a provider relationship is named in the public record, the “we did not know” position is materially weaker.
  7. Assume replacement, not removal. Add a standing review after any seizure you depend on, because reconstitution has historically been measured in weeks.

The enforcement campaign of 2025 and 2026 was not wasted. Facilitator prosecution is a genuinely new lever, and it targets the one input the operators cannot manufacture: European providers willing to carry the traffic. But it works on a timescale of years, and the infrastructure moves on a timescale of days. Until those converge, the defensive posture has to assume the hosting is there.

Sources

  1. Bulletproof Defense: Mitigating Risks From Bulletproof Hosting Providers — CISA
  2. Treasury Sanctions Global Bulletproof Hosting Service Enabling Cybercriminals and Technology Theft — U.S. Department of the Treasury
  3. Bulletproof Host Stark Industries Evades EU Sanctions — KrebsOnSecurity
  4. One Step Ahead: Stark Industries Solutions Preempts EU Sanctions — Recorded Future / Insikt Group
  5. IP Volume (Ecatel / Novogara / Quasi Networks) — Wikipedia
#bulletproof-hosting#sanctions#law-enforcement#netherlands#ransomware #threat-intel
Subscribe

Tech Sentinel — in your inbox

Cybersecurity news: breaches, CVEs, ransomware, threat actors, and the patches that matter — delivered when there's something worth your inbox.

No spam. Unsubscribe anytime.

Related