Post

A New Era of Bulletproof Hosting Providers Emerge

A New Era of Bulletproof Hosting Providers Emerge

A New Era of Bulletproof Hosting Providers Emerge

The demise of an old guard of dominant bulletproof hosting providers has given rise to a new era of upstarts – and a more fragmented competitive landscape. Bulletproof hosting providers (BPH) lease internet infrastructure to cybercriminals, allowing them to conduct activity with a low risk of being shut down. BPH providers typically have a combination of permissive policies, slow or absent abuse handling, jurisdictional insulation, reseller layers, frequent infrastructure rotation, and relationships with upstream networks that make takedowns challenging. They provide a key part of the criminal infrastructure supply chain that enhances attacker persistence, complicates attribution, and impedes incident response. BPH services are commonly used to support malware command-and-control (C2) servers, extortion negotiation portals, leak sites, phishing kits, credential-harvesting pages, carding shops, fraud panels, and mass-mailing infrastructure. 🚀

Long-standing BPH providers supporting these activities include yalishanda, ccweb, and whost. Yalishanda – whose real name Intel 471 has known since 2017 to be Alexander Volosovik – has provided infrastructure that hosted payloads for Hancitor, Dridex, and various ransomware campaigns. CCWeb’s fast-flux network hosted LockBit, Conti, and Gozi ISFB campaigns alongside credential-harvesting pages targeting Blockchain. Whost aka Mykhaylo Rytikov facilitated malicious operations for high-profile actors such as Evgeniy Bogachev linked to the GameOver Zeus malware. Cybercriminals now typically rent disposable virtual private servers (VPSs), leveraging cloud infrastructure to blend into legitimate hosting networks and rotate IP addresses to evade blocklists, minimizing downtime for customers. 🌐

Intel 471 investigated and identified several BPH services that experienced disruptions and seizures between July 2025 to July 2026, largely due to a spike in law enforcement operations. On July 1, 2025, the U.S. Treasury Department sanctioned the BPH service provider Aeza Group and its leaders for hosting BianLian ransomware; Lumma, Meduza, and RedLine information-stealing malware. On November 19, 2025, the U.S., U.K., and Australia imposed sanctions against yalishanda’s Media Land and its affiliated companies for supporting LockBit, Black Basta, BlackSuit, and Play ransomware, and for providing infrastructure used in distributed denial-of-service (DDoS) attacks on U.S. critical infrastructure. In late April 2026, yalishanda’s fast-flux BPH service went down, leading to a ban from the Exploit cybercrime forum. A Russian court record dated April 30, 2026, revealed a house arrest order due to criminal proceedings. On July 14, 2026, the U.S. Attorney’s Office unsealed a 2024 indictment charging Volosovik and two other Russian nationals for malicious cyber activity costing victims $62 million in losses. 💼

Although the illicit service provider industry appears to be under pressure, several new BPH services have been advertised since July 1, 2025. Two prominent services are offered by the actors fluxy and reming, both assessed to have some association with yalishanda. The actor reming, an alleged former reseller, launched their own fast-flux proxy service following yalishanda’s reported service outage, supporting HAProxy and Nginx proxy servers. Reming’s infrastructure hosted hundreds of domains, many used for phishing campaigns targeting financial institutions, cryptocurrency platforms, and corporate services. Fluxy launched the VIP FAST FLUX bulletproof hosting (BPH) service in late March 2026, with discovered infrastructure overlap suggesting a possible association or reseller relationship with yalishanda. Most domains registered through fluxy’s service appear to be used for phishing operations. 🔍

Read full article

This post is licensed under CC BY 4.0 by the author.