Tech Sentinel
Dutch FIOD agents seizing racks of bulletproof-hosting servers tied to sanctioned Russian-linked cyberattack infrastructure
threat-intel

Netherlands Seizes 800 Servers Over Russian-Linked Hosting

Dutch FIOD agents seized more than 800 servers and arrested two hosting co-owners over EU sanctions tied to the Stark Industries Solutions network.

By Tech Sentinel Newsroom · ·Updated August 18, 2026 · 11 min read

Dutch authorities arrested two co-owners of Netherlands-based hosting companies on May 18, 2026, and seized more than 800 servers, charging the men with violating EU sanctions law by making IT infrastructure available to entities linked to Russian-directed cyberattacks and influence operations inside the European Union.

The enforcement action dismantled a hosting footprint that investigators say absorbed the operational infrastructure of Stark Industries Solutions after the EU sanctioned that company in 2025. It is the first European case to prosecute the facilitators rather than the designated entity itself, and it landed in the same month as the edge-device exploitation wave rounded up in this month in security: May 2026.

The Arrests

The FIOD, the Dutch Fiscal Information and Investigation Service, executed simultaneous raids across five locations: three business premises in Enschede and Almere, and two data centers in Dronten and Schiphol-Rijk. More than 800 servers were seized, along with laptops and mobile phones.

The two men in custody are Andrey Nesterenko, 39, a Russian national and founder of MIRhosting, and Youssef Zinad, 57, an Amsterdam resident. Together they co-own MIRhosting, WorkTitans BV, and a third company trading as the[.]hosting. Dutch authorities did not publicly name the suspects in the FIOD announcement; their identities were established through investigative reporting by KrebsOnSecurity and The Record.

The charge is violating EU Council Regulation 269/2014 and Dutch implementing sanctions legislation, specifically making economic resources available to sanctioned entities. No software vulnerability or breach of a victim’s systems underlies the case. The prosecution turns on whether the defendants knowingly continued to serve sanctioned customers after the EU designations took effect.

The scale of the seizure reflects how embedded the operation was in Dutch internet infrastructure. This was not a fly-by-night setup but a functioning commercial hosting business with a data center presence at Schiphol-Rijk, adjacent to Amsterdam’s main international airport.

Stark Industries and Its Orbit

The EU sanctioned Stark Industries Solutions and its affiliate PQHosting Plus S.R.L. on May 20, 2025, citing both as staging grounds for attacks tied to Russian intelligence services and for “aiding Russia’s hybrid warfare efforts.” Stark was incorporated on February 10, 2022, two weeks before Russia’s invasion of Ukraine, by Ivan and Iurie Neculiti, brothers who operated PQHosting out of Moldova. The company was registered in the United Kingdom but operated through a constellation of infrastructure providers.

Within months of incorporation it had become a preferred bulletproof hosting platform for Russian state-linked and state-adjacent activity: DDoS campaigns, proxy and anonymization infrastructure used by intelligence-affiliated hacking groups, and hosting for the Doppelganger influence network’s disinformation operations targeting EU member-state elections. Stark’s IP ranges provided infrastructure to NoName057(16), a pro-Russia hacktivist group that recruits volunteers for DDoS attacks via a gamified Telegram tool called DDoSia. Stark-adjacent address blocks also traced back to Russia’s Federal Guard Service, the successor to the KGB’s Ninth Directorate. Hosting is the shared dependency underneath the operator-level campaigns Tech Sentinel has covered since, from GRU-linked ClickFix CAPTCHA lures against Ukrainian targets to the SVR-attributed hotel Wi-Fi surveillance campaign.

Nesterenko had previously confirmed to researchers that Stark Industries was a colocation customer of MIRhosting, characterizing the relationship as “purely provider-customer.” Dutch prosecutors’ theory of the case appears to be that the relationship was materially deeper.

The Sanctions-Evasion Playbook

The sanctions did not end Stark Industries’ operations. They displaced them.

According to Recorded Future’s Insikt Group, the Stark network began migrating infrastructure roughly six weeks before the EU formally announced the Neculiti sanctions, suggesting the operators received advance warning. The sequence was precise and fast:

  • April 10, 2025: Migration of Russian infrastructure to UFO Hosting LLC begins.
  • April 13, 2025: IP prefix transfers begin from Stark Industries’ primary ASN (AS44477) to the new entity.
  • May 8, 2025: European media, citing leaked documentation, reports the forthcoming EU sanctions package by name.
  • May 13, 2025: A new RIPE-registered organization, PQ Hosting Plus S.R.L., is created.
  • May 16, 2025: AS44477 is transferred to PQ Hosting Plus S.R.L.
  • May 20, 2025: EU sanctions formally designate Stark Industries, Ivan and Iurie Neculiti, and PQHosting.
  • May 28 to 29, 2025: WorkTitans B.V., a Netherlands-registered company, creates a new RIPE organization; the public rebrand to “the[.]hosting” is announced.
  • June 23 to 24, 2025: A new ASN, AS209847, is registered under THE/WorkTitans B.V.

The result was a functioning heir to Stark’s connectivity, built from Dutch internet infrastructure, that the original EU sanctions package had not named. Recorded Future assessed the activity as “a strategic effort to obfuscate ownership and sustain hosting services under new legal and network entities.”

The piece that bridged the Neculiti network into its post-sanctions incarnation was MIRhosting, run by Nesterenko. When KrebsOnSecurity published an investigation in September 2025 identifying MIRhosting as the surviving connection to Stark, the company was providing upstream connectivity to WorkTitans B.V. and effectively sustaining the operational infrastructure the EU believed it had cut off. Research by KrebsOnSecurity and Recorded Future indicated that MIRhosting’s infrastructure accounted for 84 percent of the communications used in NoName057(16) DDoS campaigns during that period.

Zinad’s company, WorkTitans BV, provided internet connectivity and held the RIPE registrations for the new ASN. Together the two companies kept Stark’s functional capabilities alive for more than twelve months after the initial EU designation.

Nesterenko’s involvement in Russian-associated hosting operations predates the current investigation by nearly two decades. His earlier company, Innovation IT Solutions Corp., founded in 2004, hosted stopgeorgia[.]ru, a website used to coordinate cyberattacks against Georgian government and media infrastructure during Russia’s August 2008 military campaign in South Ossetia. Dutch prosecutors are reportedly incorporating that history into the evidentiary record.

What the Infrastructure Was Used For

The seized servers supported three distinct categories of malicious activity, according to the FIOD announcement and prior reporting.

DDoS campaigns. NoName057(16) has run persistent DDoS campaigns against European government agencies, military websites, and political institutions since 2022, relying heavily on Stark and MIRhosting infrastructure for command-and-control and bot coordination. The Swiss cyber authority previously documented that NoName057(16) traffic originated from Russian IP addresses, from MIRhosting’s networks, and from Stark Industries, treating the three as effectively interchangeable routing options. The group is assessed as operating with at least tacit coordination with Russian state interests, though its formal organizational relationship to Russian intelligence remains the subject of ongoing analysis.

Election interference. FIOD documentation cited DDoS attacks against targets connected to Danish municipal elections held November 13 to 19, 2025. That campaign hit local government infrastructure in an EU member state during an active electoral cycle, placing it directly in scope for the EU’s hybrid warfare sanctions framework. MIRhosting contested the allegation: “Based on our preliminary findings, there are no indications that the services over which we exercise control were actually used to influence the Danish elections.” The company did not address the broader sanctions-evasion charge.

Disinformation operations. The Doppelganger influence network, which combines fake news sites, cloned legitimate media domains, and social media amplification to spread pro-Kremlin narratives inside EU member states, used infrastructure associated with the Stark and Reliable Recent News ecosystem for hosting and coordination. The network has been attributed by EU institutions, Meta, and independent researchers to entities operating on behalf of the Russian government. Disinformation infrastructure of this type increasingly relies on AI-generated content at scale, a dimension tracked in depth at ai-alert.org’s AI incident tracker.


Analysis: Why Sanctions Alone Cannot Win This Fight

The Netherlands operation represents something genuinely new in European enforcement against cyber-enabling infrastructure, but understanding why requires confronting the structural problem that made MIRhosting possible in the first place.

Sanctions displace infrastructure, they do not dismantle it. When the Council designates an entity, the named company loses access to EU financial systems and EU-registered parties must cease dealings with it. But the physical infrastructure, meaning servers, fiber, and IP address blocks registered through RIPE, can be transferred to a new legal entity in days. The Stark migration timeline documented by Insikt Group shows the entire transfer sequence completed in roughly six weeks, beginning before the sanctions were even public.

This is not unique to EU sanctions. The same dynamic appears in U.S. Treasury OFAC designations against hosting providers: named entities rebrand, transfer ASNs, and reconstitute under new registrations within weeks. Sanctions are an instrument built to exert economic pressure on nation-states and large corporations where asset freezing has durable effect. Applied to a loosely structured hosting operation with distributed physical infrastructure and jurisdictional flexibility, they function more like a temporary inconvenience.

The Stark case provides a controlled experiment. The May 2025 sanctions wave successfully disrupted the Neculiti brothers’ ability to operate under their own names inside the EU. Within two weeks, functionally equivalent infrastructure was running under new names via WorkTitans and MIRhosting, with Dutch legal entities and Dutch internet connectivity. The named actors were inconvenienced; the operational capability was not materially degraded.

The missing enforcement layer is facilitator liability. What the Netherlands operation adds, and what is largely absent from prior EU sanctions enforcement against cyber infrastructure, is criminal prosecution of the people and companies that knowingly provided connectivity to post-sanction successor entities.

Nesterenko and Zinad did not operate Stark Industries. They provided internet connectivity and hosting to entities that were themselves operating in apparent violation of EU sanctions. The Dutch case treats that knowing provision of services as a sanctionable act in its own right. If the prosecution succeeds, it establishes that European internet service providers face criminal liability when they continue to serve entities identified in the public record as sanctions-circumvention vehicles. Because investigative reporting had publicly named the connection in September 2025, the published report functions as a public notice that removes the “we did not know” defense.

The obvious counter-argument: the principals are untouched. Arresting Nesterenko and Zinad does not arrest anyone in Moscow. The actual threat actors face no consequence from a Dutch prosecution, and their infrastructure is disrupted only until replacement hosting is found. Stark has already migrated multiple times; there is no reason to believe the post-MIRhosting network stays dark.

That objection is correct as far as it goes, but it sets the wrong success criterion. The goal is not to arrest the officer who ordered a DDoS campaign against a Danish municipal election. The goal is to raise the operational cost of running persistent cyberattack and disinformation infrastructure inside the EU by shrinking the pool of willing European hosting providers.

The journalism-to-prosecution pipeline. KrebsOnSecurity published the first major Stark investigation in May 2024. When EU sanctions in May 2025 missed MIRhosting as the surviving connection, Krebs published a follow-on in September 2025 explicitly naming MIRhosting and Nesterenko. The Dutch FIOD arrested Nesterenko eight months later. That gap is not a failure; it is the time required to investigate, build a case under Dutch law, and coordinate a multi-location raid. The reporting provided the intelligence lead, the agency provided the legal authority, and neither could have produced the outcome alone.

The structural risk that remains. The arrests address the Dutch node. They do not address the broader condition: most bulletproof hosting infrastructure serving Russian offensive operations is registered in jurisdictions with no meaningful sanctions enforcement capacity. The Stark network routed through Moldova, Russia, and the United Kingdom before landing in the Netherlands, and only the Dutch node was actionable for Dutch prosecutors.

Nor do the arrests address the speed problem. The gap between the initial Stark exposure in May 2024 and EU sanctions in May 2025 was twelve months. The gap between sanctions and the infrastructure migrating to MIRhosting was measured in days. Enforcement institutions are structurally slower than the infrastructure they are attempting to disrupt. Closing that gap requires either faster designation processes or standing frameworks that make sanctions-evasion infrastructure presumptively unlawful independent of a specific designation. Both reforms are politically available within EU institutions. Neither is currently on the Commission’s immediate legislative calendar.

What Defenders Should Do

The seizure affects live hosting infrastructure. Organizations with dependencies on IP ranges linked to MIRhosting, WorkTitans BV, or the[.]hosting may encounter unexpected connectivity disruptions. Bulletproof-hosting operations have historically reconstituted under new autonomous system numbers within weeks of law enforcement seizures, so monitoring for reactivation is warranted. The full enforcement record since February 2025, and the CISA guidance that now treats these providers as a permanent condition rather than a removable one, is in bulletproof hosting: why takedowns keep failing.

  1. Within 48 hours: block and monitor the successor ASNs. AS209847 (WorkTitans B.V. / the[.]hosting) and AS33993 (UFO Hosting LLC) were the primary successor ASNs documented by Insikt Group. Cross-reference these and MIRhosting’s ranges against egress-allow lists, firewall rules, and threat-intel block lists. Their presence in outbound traffic may indicate compromised systems contacting C2 infrastructure.
  2. Within 7 days: audit DDoS mitigation dependencies. Review traffic-scrubbing configurations for any reliance on upstream IP ranges now under FIOD control, and confirm upstream provider scrubbing agreements are active and tested.
  3. Update threat-intel feeds with Stark successor ranges. The seizure of 800 servers does not guarantee complete takedown. Insikt Group documented IP ranges including 45.15.178.0/24, 94.131.10.0/24, and 176.120.67.0/24 under the WorkTitans and THE umbrella; add these to block and alert lists pending further attribution.
  4. Scan historical logs. Search for connections to ASNs associated with Stark Industries, PQHosting, and MIRhosting. Community-published blocklists covering this infrastructure have been available since mid-2024.
  5. Treat NoName057(16) as an ongoing threat. Its DDoS campaigns predate MIRhosting and will continue after it. Organizations in European government, critical infrastructure, financial services, and political institutions should review DDoS mitigation posture accordingly.
  6. Monitor for Doppelganger successor infrastructure. The influence operations associated with the Stark network use domains that closely mimic legitimate European news outlets. Monitor outbound DNS resolution for lookalike domains.
  7. Review relationships with unknown Netherlands-based hosting resellers. The Stark network operated through a chain of legitimate-looking Dutch commercial entities. Cloud providers and CDN operators should ensure due-diligence processes include sanctions screening for the beneficial owners of connectivity customers.
  8. If operating in Denmark or adjacent EU jurisdictions: flag the election-period attack allegation to legal and compliance teams, since regulatory inquiries may follow.

Both men remain in custody pending further Dutch criminal proceedings. No trial date has been set.

Sources

  1. Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks — KrebsOnSecurity
  2. Stark Industries Solutions: An Iron Hammer in the Cloud — KrebsOnSecurity
  3. Bulletproof Host Stark Industries Evades EU Sanctions — KrebsOnSecurity
  4. Dutch authorities arrest men suspected of providing infrastructure for Russian cyber operations — The Record
  5. One Step Ahead: Stark Industries Solutions Preempts EU Sanctions — Recorded Future / Insikt Group
#bulletproof-hosting#netherlands#eu-sanctions#russia#ddos#law-enforcement
Subscribe

Tech Sentinel — in your inbox

Cybersecurity news: breaches, CVEs, ransomware, threat actors, and the patches that matter — delivered when there's something worth your inbox.

No spam. Unsubscribe anytime.

Related