home.social

#bulletproofhosting — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bulletproofhosting, aggregated by home.social.

fetched live
  1. 🚨 New entrant alert: Stark Industries Solutions debuts at #2 for newly observed botnet C&Cs between Jan and Jun 2026, with 931 detections in just six months. This 🇬🇧 UK-registered host is widely assessed to be 🇷🇺 Russian-operated bulletproof hosting, and it's now on Spamhaus's DROP and ASN-DROP lists.

    Network operators: treat traffic to/from this ASN accordingly ⚠️

    Read the full report👇
    spamhaus.org/resource-hub/botn

    #BotnetCC #BulletproofHosting #ThreatIntel #InfoSec #CyberSecurity

  2. 👉️ IPv4 address brokers are a critical chokepoint for bulletproof hosters
    👉️ Carrier and broker responses to SBL listings reveal a lot about their intentions
    👉️ Clustering internet badness at specific facilitators makes them attractive to law enforcement
    👉️ Evasion tactics from miscreants signal that the pressure is actually working

    In case you missed it, read the full post here:
    spamhaus.org/resource-hub/bull

    #BulletproofHosting #ThreatIntel #InfoSec #Cybercrime #IPv4 #DNSAbuse #NetSec

  3. 💡 NEW BLOG | Bulletproof hosting doesn't operate in a vacuum, it depends on a network of facilitators: IP address brokers, carriers, data centers, and more. Cut off the facilitators, and you cut off the criminals.

    Here we dig into how we hold these enablers accountable and how this approach, however slow and methodical, is steadily "draining the swamp".

    Read the full post here ⤵️
    spamhaus.org/resource-hub/bull

    #Cybersecurity #BulletproofHosting #ThreatIntelligence #InfoSec #InternetAbuse

  4. The anatomy of bulletproof hosting has changed significantly, and if you're working in threat intelligence or network abuse, it's worth understanding how.

    In this post we cover the decline of monolithic bulletproof hosts, the shift toward separation of liabilities, and the growing abuse of trusted, legitimate services to conceal criminal infrastructure.

    Read the post here:

    👉 spamhaus.org/resource-hub/bull

    #Cybersecurity #BulletproofHosting #ThreatIntelligence #InfoSec #InternetAbuse

  5. The lack of proper vetting of UK corporations' officers details has long been exploited by miscreants (and criticized by investigators).

    Thanks to recently strengthened regulation, find-and-update.company-inform proudly notes Davletshin's identity has been verified successfully. What remains to be sorted is the ability of bulletproof hosting operators to successfully establish shell corporations in the UK at all. 🧐

    #OSINT #BulletproofHosting #Cybercrime #UK

  6. BIG TECH IS EVIL

    Afgelopen woensdag (8 april 12:53) ontving ik weer eens een bunq phishingmail met daarin de volgende link:

    https:⧸⧸bunq.x24hr.com/nD5Wpy

    Die "doorstuursite" (en dat is vast niet de enige) stuurde toen door naar de volgende phishingsite:

    https:⧸⧸bunq-web.duckdns.org

    Die site antwoordt nu niet meer. Zojuist bleek de eerdergenoemde "doorstuursite" mijn browser nu door te sturen naar:

    https:⧸⧸bunq-portaal.duckdns.org (screenshot linksboven)

    Ook de Duitse hoster SYNLINQ is medeplichtig aan cybercrime.

    @DigitaleOverheid : blocklists werken niet, je blijft achter de feiten aanlopen.

    Druk op een plaatje om te vergroten.

    #BigTechIsEvil #InfoSec #CyberCrime #BulletProofHosting #SYNLINQ #bunqPhishing #bunq #SantanderPhishing #Santander #Odido #OdidoDataLek

  7. These are IP netblocks that shouldn’t be trusted ❌

    If you’re not automatically ingesting DROP and/or ASN-DROP, now’s the time to fix that:
    👉 spamhaus.org/blocklists/do-not

    Be proactive. Block the worst of the worst IP traffic.

    #ThreatIntel #SOC #ThreatHunting #BGP #NetworkSecurity #BulletproofHosting #Infosec

  8. Its current uplink is a familiar name, seen in conjunction with bulletproof hosting and IP hijacking before: 🇩🇪 Pfcloud UG (AS51396) - You always meet twice in life, indeed.

    Corporate register data suggest the legitimate owners of 160.65.0.0/16 and 143.222.0.0/16 seem still active. We ask them to investigate, and secure their networks.

    #Cybercrime #OSINT #BulletproofHosting

  9. 🥰 Show your network some love: Get Spamhaus’ free DROP lists to block known malicious IP ranges before they reach your network - access the lists here 👉 spamhaus.org/blocklists/do-not

    #ThreatIntel #NetworkSecurity #BulletproofHosting

  10. 🎯 New Year’s resolution: Get Spamhaus’ free DROP lists to block known malicious IP ranges before they ever reach your network.

    Start the year protected - access the list here 👇
    spamhaus.org/blocklists/do-not

    #DROP #IPs #ThreatIntel #NetworkHygiene #BulletproofHosting

  11. Kosten, naar verluidt: € 1,17. Resultaat: de bankrekening achter uw creditcard maximaal in het rood.

    Geen dank aan Let's Encrypt voor het certificaat.

    En de hele IP-reeks is crimineel (158.94.208.0 - 158.94.211.255, servers waarschijnlijk in Nederland). De nep KPN-inlog website aldaar gehost is ook nog steeds live (screenshots in todon.nl/@ErikvanStraten/11546).

    #Phishing #CyberCrime #BulletProofHosting #LANEDONET #LetsEncryptIsEvil

  12. This week, everywhere you look, bulletproof hosting (BPH) is in cyber news headlines. From the CrazyRDP takedown, to sanctions against entities adjacent to Aeza, and most recently Media Land LLC and ML[.]Cloud] LLC (do these measures actually move the needle?), to new CISA guidance on mitigating BPH activities.🛡️

    It’s clear the spotlight is firmly on one of cybercrime’s most persistent enablers. And for a good reason. Few infrastructures have enabled so much criminal activity, for so long, with such resilience.

    Spamhaus has tracked BPH operators and their evolving tactics for decades. 🕵️ We've watched the ecosystem shift from monolithic BPHs to layered and complex business structures.

    So, amid the sensational headlines, we’ve compiled a grounded look at the topic, covering: the history, the current landscape, and where the threat landscape is likely to head next.

    Read it in full here 👉 spamhaus.org/resource-hub/bull

    #Bulletproofhosting #Cybercrime

  13. On November 12, around 250 physical servers were seized by the Dutch police at two datacenters in the Netherlands 👉 politie.nl/nieuws/2025/novembe

    We assess the unnamed #bulletproofhosting provider (BPH) is CrazyRDP, a major #cybercrime hub previously operating front companies such as 🇺🇸 Delis LLC (AS211252), 🇺🇸 Limenet LLC (AS394711) and, most recently, 🇺🇸 Sovy Cloud Services (AS401110) and its downstreams (all incorporated in 🇺🇸 as well): ... ⤵️ 1/2

  14. Like all other internet abuse, bulletproof hosting does not just happen - it is enabled by facilitators such as network carriers, datacenter operators, IP brokers and domain registrars. Sometimes, malicious infrastructure agglomerates in the internet vicinity of such facilitators - why not join the show if your criminal competitors thrive there already?🧐

    A particularly prolific example is 🇩🇪aurologic GmbH (regular readers might recognize the name), as highlighted by Recorded Future in a report published on November 6 ⤵️
    recordedfuture.com/research/ma

    #Cybercrime #BulletproofHosting #ThreatIntel #HostingProviders

  15. This is traffic you DO NOT want to connect with. ✋

    🔥 Get FREE access to this additional layer of protection here ⬇️ ⬇️
    spamhaus.org/blocklists/do-not

    #DROP #IPs #BulletproofHosting #ThreatIntel

  16. DROP is free to use, giving you an extra layer of protection against the worst IP space on the internet.

    Access it here ⬇️ ⬇️
    spamhaus.org/blocklists/do-not

    #DROP #IPs #BulletproofHosting #ThreatIntel

  17. (🇺🇸 49.3 Networking LLC), a bulletproof hosting provider we've previously reported on. The sole network it propagates follows a similar hosting pattern than those currently announced by AS213441. Both ASNs share the same uplink, corroborating the suspicion that they might be part of the same cybercriminal operation.

    Finished your meal? Have some mint DROPs to take away the phish 👉 spamhaus.org/blocklists/do-not and protect your network. Enjoy!

    #BulletproofHosting #Phishing #Cybercrime #OSINT

    3/3

  18. 🔥 Spamhaus provides FREE access to anyone who wants to add this layer of protection.

    Get it here ➡️ spamhaus.org/blocklists/do-not

    Remember, this is traffic you do not want to connect with. Not ever. DROP it now.

    #DROP #IPs #BulletproofHosting #ThreatIntel

  19. a russian hosting service that takes payment in crypto, Aeza Group, was just hit with #OFAC sanctions.

    they've sent funds to a bunch of the shadiest crypto exchanges - #Cryptomus, #MEXC, #Binance, and (of course) #HTX, the crypto exchange run by the business partner of the president of the united states.

    also looks like they took payment in #Tether, the #stablecoin whose money is managed by america's secretary of commerce howard lutnick.

    * OFAC press release: ofac.treasury.gov/recent-actio
    * Wallet: intel.arkm.com/explorer/addres

    #JustinSun #threatintel #threatassessment #DNS #bulletproofhosting #cybersecurity #infosec #justinSun #howardlutnick #ransomware #russia #putin #vladimirPutin #ukraine #aeza #aezagroup