threat_intelligence2349 wordsRead on Arc Codex

A New Era of Bulletproof Hosting Providers Emerge

A New Era of Bulletproof Hosting Providers Emerge The demise of an old guard of dominant bulletproof hosting providers has given rise to a new era of upstarts — and a more fragmented competitive landscape. Bulletproof hosting providers (BPH) lease internet infrastructure to cybercriminals. BPH allows cybercriminals to conduct their activity with a low risk of being shut down. BPH providers typically have a combination of permissive policies, slow or absent abuse handling, jurisdictional insulation, reseller layers, frequent infrastructure rotation and relationships with upstream networks that make takedowns and disruptive action challenging. They provide a key part of the criminal infrastructure supply chain that enhances attacker persistence, complicates attribution and impedes incident response. They are commonly used to support a broad array of cybercrime products and services, including: - Malware command-and-control (C2) servers. - Extortion negotiation portals and leak sites. - Phishing kits and credential-harvesting pages. - Carding shops, fraud panels, fake marketplaces and underground forums. - Spam botnets and mass-mailing infrastructure. - Proxy, virtual private network (VPN) and anonymization services. - Payload staging and malware download servers. Long-standing BPH providers supporting these activities include yalishanda, ccweb, and whost. yalishanda — whose real name Intel 471 has known since 2017 to be Alexander Volosovik — has provided infrastructure that hosted payloads for Hancitor, Dridex and various ransomware campaigns. ccweb’s fast-flux network hosted LockBit, Conti and Gozi ISFB campaigns alongside credential-harvesting pages targeting Blockchain. whost aka Mykhaylo Rytikov facilitated malicious operations for high-profile actors such as Evgeniy Bogachev linked to the GameOver Zeus malware and Vladimir Drinkman linked to the Heartland Payment Systems and NASDAQ breaches. A newer service named LuxProxy offered HTTP/socket secure (SOCKS) internet protocol proxies including residential, mobile, internet service provider (ISP)/static, shared data center and data center IPv4 proxies. Bulletproof hosting overview The BPH ecosystem has been around since the mid-2000s when pioneers such as the Russian Business Network (RBN) first gained global attention. In the early days, illicit service providers relied on physical servers housed in data centers in jurisdictions with weak cyber laws. Cybercriminals now typically rent disposable virtual private servers (VPSs), leveraging cloud infrastructure to blend into legitimate hosting networks and rotate IP addresses to evade blocklists. This allows them to avoid the risks associated with physical servers and quickly reroute traffic in the event of a seizure, minimizing downtime for customers. While the tactics, techniques and procedures (TTPs) have evolved over that time, the core players — those with positive reputations for reliability — largely remained the same. Among this top tier are yalishanda, ccweb and whost, while newer providers such as MoreneHost, BEARHOST and AnonHost carved out portions of the market for themselves. A defining characteristic of leading BPH providers is their resilience, with many prominent operators surviving law enforcement actions and infrastructure disruptions. However, because their services enable a wide range of cybercriminal activity, they remain persistent high-priority targets for authorities. BPH providers are also not invulnerable. Disruptions evolve the criminal hosting landscape Intel 471 investigated and identified several BPH services that experienced disruptions and seizures over between July 2025 to July 2026. Disruptions were largely due to a spike in law enforcement operations, with numerous sanctions and arrests executed globally in that time frame. Since July 1, 2025, we observed the following services impacted by law enforcement actions: On July 1, 2025, the U.S. Treasury Department sanctioned the BPH service provider Aeza Group and its leaders for hosting BianLian ransomware; Lumma, Meduza and RedLine information-stealing malware; and the BlackSprut marketplace, among other underground services. On November 19, 2025 the U.S., U.K. and Australia imposed sanctions against yalishanda’s Media Land, and its affiliated companies ML Cloud, Media Land Technology and Data Center Kirishi. The companies have supported the LockBit, Black Basta, BlackSuit and Play ransomware and are also implicated in providing infrastructure used in distributed denial-of-service (DDoS) attacks on U.S. critical infrastructure. In late April 2026, the actor Feelthereal filed a complaint on the Exploit cybercrime forum against yalishanda claiming the actor's fast-flux BPH service had been down for several days. yalishanda was subsequently banned from the forum. Further investigation revealed a Russian court record dated April 30, 2026, pertaining to an appeal to a house arrest order a Moscow district court imposed on the actor due to criminal proceedings concerning illegal circulation of payment instruments and related financial fraud activity. The sudden collapse of yalishanda’s fast-flux infrastructure triggered widespread anxiety and speculation, with consistent customers of yalishanda abandoning the actor’s infrastructure. We also observed ccweb change the actor’s offering during this period. To our knowledge, the actor was not impacted directly by any of the law enforcement actions. However, ccweb’s infrastructure appeared to change in late June 2025 or early July 2025, possibly signaling an adjustment in the actor’s business. The reasoning behind ccweb’s decision to go private remains unclear but aligns with the actor’s history of robust operational security (OPSEC) practices. It is possible the actions against other illicit service providers influenced ccweb’s decision; however, this theory remained unconfirmed at the time of this report. Figure 1: Some of the most prominent BPH service providers, their historical offerings and their current status of operations as of July 28, 2026. In June 2026, the U.S. FBI announced Operation Riptide, which was described as an ongoing, coordinated law enforcement campaign targeting cybercriminal actors and the key services they rely on including their infrastructure, tools and services, communications platforms and money. The FBI stated the announcement marked the beginning of a “focused, sustained 60-day national effort.” Based on our observations and the announcement, we anticipate additional illicit service providers likely will be targeted by international authorities in the near future. On July 14, 2026, the U.S. Attorney’s Office for the Northern District of Ohio unsealed a 2024 indictment charging Volosovik and fellow Russian nationals Kirill Zatolokin and Yulia Pankova for their roles in malicious cyber activity affecting 21 states costing victims $62 million in losses. The State Department also offered a $10 million reward for information about the three. And on July 13, 2026, the EU sanctioned Volosovik, Media Land and ML Cloud. Upstarts fill the void Although the illicit service provider industry appears to be under pressure, we identified several new BPH services advertised since July 1, 2025. One such offering is OtusCloud by the actor Otus who provides a Telegram-based service where actors could place orders for VPSs and domain registration services through a Telegram bot. Although first advertised in December 2023, Otus began to give more routine advertisements and updates in late 2025. Two additional prominent services are those offered by the actors fluxy and reming, who we assessed have some sort of association with yalishanda. The actor reming previously was an alleged reseller for yalishanda’s BPH service but appeared to launch their own fast-flux proxy service following yalishanda’s reported service outage. reming’s service allegedly supports both HAProxy and Nginx proxy servers and was marketed as providing better uptime for the same price as previous offerings in the market. The service is priced at US $80 for one domain name, with additional offerings such as VPS rental and anonymous domain registration in multiple domain zones. The actor’s infrastructure hosted hundreds of domains, many of which were used for phishing campaigns targeting financial institutions, cryptocurrency platforms and corporate services. fluxy launched the VIP FAST FLUX bulletproof hosting (BPH) service in late March 2026. We discovered an overlap in fluxy’s and yalishanda’s infrastructure, which suggests fluxy possibly was an associate or reseller similar to reming, although it is also possible the actors are unrelated and fluxy just used yalishanda’s infrastructure. The VIP FAST FLUX service is managed through a dedicated administrative panel, allowing for streamlined management of fast-flux services and SSL certificate generation. As of April 20, 2026, users could register domain names for free via a support representative, with plans to further automate this process through an API. The service uses multiple hosting providers and DNS servers — typical of fast-flux networks — and most domains registered through the service appear to be used for phishing operations. Customers migration trends after yalishanda disappears Intel 471 conducted an infrastructure impact analysis on yalishanda following the actor’s disappearance in late April 2026 and subsequent ban from the Exploit cybercrime forum. To establish an operational baseline, we evaluated 2,240 customer domains active prior to the shutdown, which dynamically resolved across 179 IP addresses — a small subset of all the infrastructure we tracked over the past nine years — attributed to yalishanda’s fast-flux service. We cross-referenced WHOIS records, hosting data and passive domain name server (pDNS) records to track possible post-disappearance infrastructure shifts and identify key customer migration trends. To maintain the fast-flux infrastructure, the actor leveraged 19 distinct hosting providers, regularly rotating front-end proxies in and out of service. Host distribution leaned heavily toward a select few entities, such as Sprinthost.ru LLC with 29 tracked hosts, while other providers had only a single host rented. We evaluated customer domain activity across yalishanda’s baseline infrastructure while fully operational in April 2026 against the subset of domains that remained active through June 2026. From the initial list of 2,240 tracked domains, the count narrowed to 1,439 active domains in June 2026, with 1,156 domains or about 80% of active domains still responding to known yalishanda infrastructure. These findings support the assessment that the disruption was only partially effective, as a substantial volume of customer domains remained active and resolved directly to known yalishanda infrastructure well into June 2026. Notably, the top destination for migrating domains was Cloudflare Inc. with 84 domains, ranking it 5th overall in the top 20 hosting providers supporting the active domains. Other top destinations for migrating domains were Great Flower and Reg[.]ru. The migration to Cloudflare Inc. is significant, as it indicates that at least a portion of yalishanda’s customers decided to host their infrastructure on a well-established company, risking detection rather than continuing with underground providers. Other well-known providers identified during this migration included Akamai, Amazon, DigitalOcean and Vercel. This migration should not be interpreted as evidence these companies knowingly support BPH activity; instead, it illustrates adversaries’ ability to use legitimate or mixed-use infrastructure to maintain availability and complicate attribution. Outlook — A more fragmented market Recent disruptions of established BPH providers appear to have accelerated the ecosystem’s transition from a market dominated by veteran operators toward a more fragmented and competitive landscape. Arrests, sanctions and infrastructure seizures have created opportunities for junior providers, former resellers and newly branded services to absorb displaced customers, redistributing rather than eliminating demand for abuse-resistant infrastructure. Continued law enforcement pressure likely will cause further service interruptions, rebranding and customer migration, while established providers may increasingly adopt private, referral-only models similar to ccweb’s apparent approach. Emerging services such as those operated by reming, fluxy and Otus demonstrate how quickly displaced capacity can be replaced, particularly by actors with existing infrastructure, customers or reseller relationships. These less-established services may initially have weaker resilience and OPSEC, creating additional opportunities for infrastructure mapping and disruption. The disruption of yalishanda’s operation appears to have been more actor-focused rather than an infrastructure seizure, as a substantial portion of the actor’s previously identified fast-flux infrastructure and customer domains — about 80% — remained operational after yalishanda’s disappearance and ban from the Exploit forum. This indicates law enforcement actions pertaining to yalishanda possibly interrupted the service’s management or availability to customers but did not comprehensively dismantle its underlying technical capacity. The continued operation of this infrastructure raises the possibility another actor is maintaining at least part of the service while yalishanda deals with the actor’s reported legal issues or otherwise remains unable to operate publicly. Another possible explanation includes customers continuing to use previously configured services without active operator involvement. Our research determined some infrastructure formerly associated with yalishanda appears to have migrated toward Cloudflare, Great Flower and Reg.ru, showing that disrupting a provider or removing an operator does not necessarily deactivate the underlying malicious operations. Observed forum interactions revealed some of yalishanda’s customers expressed intent to move away from the actor’s infrastructure, possibly due to a diminishing level of confidence in the actor rather than technical outages. Additionally, some domains possibly moved to previously unidentified yalishanda infrastructure, although available telemetry does not definitively establish continued actor control. The BPH ecosystem likely will remain volatile but operational, with sustained law enforcement impact depending on authorities’ ability to disrupt upstream hosting relationships, domain registration, payments and trusted intermediaries in addition to the individual providers themselves. Operations that remove or constrain an actor without seizing or disabling the associated infrastructure likely will produce temporary disruption followed by customer migration, delegated management or rebranding rather than lasting degradation of the broader BPH market. Recommendations Intel 471 recommends the following: - Track infrastructure clusters, not individual IP addresses. Use passive DNS, certificate, autonomous system, name server and domain registration data to identify related infrastructure that may persist after IP rotation or provider migration. - Prioritize recently migrated assets. Domains and IP addresses formerly associated with disrupted BPH services may remain malicious after moving to new providers or being placed behind reverse-proxy services. - Monitor emerging providers and resellers. Track advertisements, service names, operator handles, contact details, payment methods and infrastructure associated with newer offerings such as fast-flux, VPS and proxy services. - Do not block entire hosting providers based solely on association. Cloud and mixed-use providers can host both legitimate and malicious activity; apply domain-, IP-, certificate- and behavior-based controls supported by additional evidence. - Strengthen detection for fast-flux behavior. Alert on rapid DNS changes, unusually low time-to-live values, large rotating IP pools, frequently changing autonomous systems and shared name server infrastructure. - Preserve historical infrastructure data. Retain DNS resolutions, certificates, WHOIS records, hosting relationships and telemetry so analysts can identify migrations, rebranding and continuity following disruptions. - Coordinate abuse reporting and takedowns. Share complete evidence packages with registrars, hosting providers, computer emergency response teams and law enforcement, including domains, IP addresses, time stamps and related malicious activity. - Expect displacement rather than permanent removal. Following enforcement actions, increase monitoring for replacement infrastructure, referral-only services and rebranded offerings operated by former resellers or associates.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.