Module 09: Bulletproof Hosting (BPH)
Abuse-resistant hosting backbone. Provides persistent infrastructure to forums, leak sites, loader panels, and service continuity. Node 03 in the EDP Dependency Map, assessed CRITICAL tier with HIGH replace difficulty.
CRITICAL TierNode 03 / M09Phase ADownload PDF
Position in Ecosystem: Node 03, Bulletproof Hosting Open the full ecosystem map ↗
PRIMARY: transit is the dependency whose removal is instant and comprehensive across every hosted service. Insikt Group documented more than a dozen assessed threat activity enablers, sanctioned Aeza included, taking upstream connectivity from aurologic GmbH, with roughly half of Aeza announced prefixes still routing there after designation; when DataCamp terminated Aeza unilaterally, the customer simply moved to aurologic (Confirmed). The 2008 McColo de-peering remains the proof the lever works, and it has not been exercised against a major BPH since (Confirmed).Upstream Transit CarriersUpstream dependencyPRIMARY: address space is what designation survival rides on. RIPE NCC freezes a sanctioned member resources but does not deregister them, and LIR autonomy let Stark move AS44477 to freshly created PQ Hosting Plus S.R.L. days before the EU listing and let Aeza reallocate US-facing space to a new Serbian entity within 24 hours of the OFAC action (Confirmed). Sponsoring LIRs in permissive jurisdictions have repeatedly supplied space to networks that could not obtain it directly (Confirmed).Registries & Sponsoring LIRsUpstream dependencyPRIMARY: every rebrand in the Stark and Aeza records was a formation event. Stark Industries Solutions Ltd (UK, 2022), PQ Hosting Plus S.R.L. (Moldova), WorkTitans B.V. (Netherlands), Smart Digital Ideas DOO (Serbia), Hypercore Ltd and Aeza International Ltd (UK) each inserted a fresh legal entity between operator and infrastructure (Confirmed). The same layer produced the only shell removals to date, strike-offs for false incorporation information rather than sanctions actions (Confirmed).Corporate Formation AgentsUpstream dependencyTOLERANCE: FSB passively tolerates most BPH operators as long as they serve useful actors and avoid domestic targeting. This is non-enforcement, not active shielding, and BPH operators outside the protected core remain reachable through MVD referral without triggering FSB override.FSB ProtectionState protection / toleranceGRU has documented use of criminal-adjacent BPH infrastructure for strategic operations; dual-use hosting overlap creates attribution complexity.GRU Mil. IntelState protection / toleranceBPH keeps Russian-language forums online; upstream registrar, ASN, and transit pressure can fracture trust infrastructure.Underground ForumsPrimary dependencyCrypter vendors depend on abuse-tolerant hosting for panels, payload delivery, and customer continuity.Crypters & PackersPrimary dependencyLoader and botnet C2 infrastructure relies on stable hosting; sinkholing is more durable when paired with BPH pressure.Loaders & BotnetsPrimary dependencyLeak sites depend on the same abuse-resistant hosting backbone; one backbone disruption can hit multiple brands.Leak Site OperationsPrimary dependencyOperators rent the same abuse-resistant backbone their panels, C2, and leak infrastructure run on: OFAC tied Media Land to hosting for LockBit, Black Basta, Play, BlackSuit, and Evil Corp, five operator brands on one supplier, and Zservers served as LockBit primary host (Confirmed). Provider-level action therefore radiates across every brand renting from it, an efficiency no action against a single rebrandable operator can match (Analyst inference).RaaS OperatorPrimary dependencyStealer panels and log markets often use tolerant hosting, but can reconstitute faster than leak sites or loader C2.Stealers & Log MarketsPartial dependencySome IAB infrastructure uses bulletproof hosting for listings, broker comms, or staging, though the dependency is less direct.Initial Access BrokersPartial dependencyAffiliate intrusion, staging, and exfiltration infrastructure sits on the same providers: Sophos documented widely reused Stark VM images carrying LockBit, ALPHV, and Qilin payloads across multiple affiliates and crimeware operators (Credible). The dependency is real but shallower than the operator-side one, since affiliates re-host on commodity VPS inside the historical 1 to 7 day BPH migration window (Analyst inference).RaaS AffiliatesPartial dependencyAbuse-resistant hosting backbone. Provides persistent infrastructure to forums, leak sites, loader panels, and service continuity.BULLETPROOF HOSTINGNode 03 / M09CRITICAL TIER / REPLACE: HIGH
Primary dependency Partial dependency State protection / dual use First-degree connections as assessed in the current ecosystem map (v3.0). Hover any node for the dependency note. Left side: what this node draws on or is protected by. Right side: what depends on it.
FieldValue
Module Number09
Module NameBulletproof Hosting (BPH)
EDP Node ReferenceNode 03 (Bulletproof Hosting Providers) — PRIMARY
Ecosystem LayerCritical Infrastructure / Abuse-Resistant Hosting Foundation
Upstream ConnectionsNode 07 (Underground Forums — recruitment and advertising); Node 15 (Operational Proxy/Anonymization — admin access to BPH panels); upstream ISPs, transit providers, and IP registries (ARIN, RIPE, APNIC)
Downstream ConnectionsNode 06 (Leak-Site Hosting); Node 05 (Botnet/Loader Ecosystems); Node 04 (IAB Markets — access infrastructure); Node 10 (Credential/Stealer-Log Markets); Node 07 (Underground Forums); all modules requiring persistent online infrastructure
Research DateApril 2026 (corrections July 2026)
Primary ResearcherReno
Source Tools UsedPerplexity AI; OFAC/UK NCA/Australia joint sanctions (November 2025); IBM X-Force OSINT Advisory; Intel471; Sophos/Cybernews; Infosecurity Magazine

SECTION 1 — WHAT IT IS

1.1 Definition

Bulletproof Hosting (BPH) refers to internet hosting services that knowingly tolerate or actively facilitate criminal use of their infrastructure by ignoring, delaying, or formally refusing to process abuse complaints and law-enforcement takedown requests. BPH providers supply virtual private servers (VPS), dedicated servers, IP address ranges, and associated network services to cybercrime operators, including ransomware developers, RaaS affiliates, botnet operators, phishing campaign managers, and underground marketplace administrators.

Node 03 in the EDP Dependency Map captures this function and is assessed at CRITICAL tier, HIGH replace difficulty. This is the most broadly cross-cutting infrastructure node in the entire Dependency Map: every other node that requires persistent online presence — leak sites (Node 06), loader ecosystems (Node 05), affiliate panels (Module 07), negotiation portals (Module 07), underground forums (Node 07), credential markets (Node 10), mixing services (Node 08) — depends directly or indirectly on BPH infrastructure for uptime and attribution resistance.

1.2 How BPH Differs from Standard Hosting

Standard commercial hosting providers (AWS, Azure, GCP, OVH, Hetzner) respond to abuse complaints, comply with law-enforcement takedown requests under applicable jurisdiction, enforce terms of service against criminal use, and maintain KYC records tied to payment methods. BPH providers systematically invert these behaviors:

1.3 How It Functions — Step by Step

1.4 Role in the Ecosystem

BPH is the foundational infrastructure layer of the entire ransomware supply chain. It is the node on which all other nodes physically depend. Without BPH, the following EDP functions cannot operate at current scale or with current attribution resistance: ransomware C2 (Module 07), affiliate management panels (Module 07), data-leak sites (Node 06 / Module 08), negotiation portals (Module 07 / Module 15), loader distribution (Module 02 / Node 05), underground forum hosting (Node 07 / Module 10), credential market infrastructure (Node 10 / Module 12), exfiltration staging (Node 14), and botnet coordination infrastructure (Node 05).

This cross-cutting dependency profile is the basis for the CRITICAL tier classification and is the primary justification for placing BPH disruption at Phase A in the EDP Disruption Playbook — before all other nodes. BPH disruption is not a single-node intervention; it is a force multiplier that simultaneously degrades operational capacity across every dependent node.

1.5 BPH Provider Archetypes — Five Models

Archetype 1 — Large Russian BPH Conglomerates (Media Land / Aeza model): High-capacity providers operating under chains of shell companies and related LLCs across multiple jurisdictions. Provide long-lived IP ranges, VPS, and dedicated servers knowingly hosting ransomware infrastructure, leak sites, phishing kits, and markets. Specialize in bulletproof abuse-response policies. Multiple subsidiary brands and ASNs distribute risk. Sanctioned by OFAC/UK/Australia in November 2025. Confidence: CONFIRMED.

Archetype 2 — Mid-Tier Forum-Advertised BPH (Zservers / Yalishanda model): Services that actively market bulletproof VPS, fast-flux proxies, and DDoS-resistant infrastructure on cybercrime forums and Telegram. Bundle services including C2 hosting, phishing sites, carder markets, and basic DLS instances. Provide operational support on traffic routing and infrastructure rotation. Confidence: CONFIRMED.

Archetype 3 — Template-Based VPS / VM Providers Abused as De-Facto BPH: Hosting platforms that deploy pre-configured Windows VM images at scale, creating a pool of fingerprint-identical servers widely used for ransomware C2, exfiltration staging, and DLS. The operator may or may not be aware of criminal use; the template infrastructure functionally serves as BPH regardless of intent. The VM reproduction shortcut has been in use since at least 2021. Confidence: CONFIRMED.

Archetype 4 — Specialized Tor/DLS-Oriented BPH Operators: Providers focused on Tor/onion services and dark-web content hosting. Offer onion hosting, mirrored .onion domains, and Tor-friendly VPS with minimal KYC and crypto-only payments. Host multi-tenant leak platforms (Qilin WikiLeaksV2 model) and cross-service bundles: DLS plus negotiation panel plus exfiltration staging plus backup mirrors. Confidence: CREDIBLE.

Archetype 5 — Selective-Abuse ISPs (Quasi-Legitimate with Tolerated Abuse Sliver): Providers presenting as normal ISPs while quietly tolerating certain classes of criminal activity to retain profitable criminal customers. Use complex routing and fast-flux techniques to absorb takedowns while maintaining plausible deniability. Function as infrastructure for cybercrime-as-a-service ecosystems while avoiding the overt BPH branding that attracts regulatory attention. Confidence: CREDIBLE.

SECTION 2 — KEY ACTORS AND EXAMPLES

2.1 Named BPH Actor Table

Actor / NetworkArchetypeDocumented Services HostedSanction / Attribution StatusConfidence
Media Land LLC / Media Land Technology LLC / Data Center Kirishi LLC / ML.Cloud LLCLarge Russian BPH ConglomerateLockBit ransomware infrastructure, BlackSuit DLS, Play ransomware C2, DDoS attack infrastructure against US critical infrastructure, phishing kits, malware distributionOFAC / UK NCA / Australia joint sanctions November 2025; IBM X-Force entity mappingCONFIRMED
Aeza Group / Aeza InternationalLarge Russian BPH Conglomerate (affiliated)Ransomware C2, fraud infrastructure, cybercrime service hosting across multiple ASNsLinked to Media Land entity structure in IBM X-Force analysis; designated by OFAC in July 2025 and included again in the November 2025 joint actionCONFIRMED
Zservers (zservers.su / zservers.top)Mid-Tier Forum-Advertised BPHBulletproof VPS advertised on cybercrime forums; C2 hosting, phishing, malware distribution; LockBit affiliate infrastructureIntel471 profiling; sanctioned by OFAC in February 2025, a separate action preceding the November 2025 Media Land/Aeza designationCONFIRMED
Yalishanda (Alexander Lyul'ko persona)Mid-Tier Forum-Advertised BPHFast-flux proxy networks; ZLoader/Silent Night banking trojan C2; spammer and malware-distribution hosting; advertised BPH services on cybercrime forums since at least 2010Intel471 persona attribution; named in academic and law-enforcement reporting; not sanctioned as of research dateCREDIBLE
BEARHOST / Underground / Voodoo Servers conglomerateSpecialized Tor/DLS-Oriented BPHQilin WikiLeaksV2 DLS; multiple ransomware DLS instances; dark-web market hosting; negotiation panel infrastructureResecurity attribution; not publicly sanctioned as of research dateCREDIBLE
Template-based VPS providers (unnamed; Sophos fingerprint research)Template-Based De-Facto BPH>7,000 fingerprint-identical servers hosting ransomware C2, DLS, malware distribution, exfil staging, phishing, botnets since at least 2021Sophos/Cybernews technical attribution via VM image fingerprint; provider identity not publicly namedCONFIRMED (infrastructure pattern); CREDIBLE (provider identity)

2.2 Detailed Actor Profiles

Media Land Conglomerate: The most thoroughly documented Russian BPH network in open-source reporting. Media Land operates under at least four named legal entities (Media Land LLC, Media Land Technology LLC, Data Center Kirishi LLC, ML.Cloud LLC) and maintains multiple ASNs and IP ranges. IBM X-Force open-source intelligence reconstructed the entity structure from infrastructure and registration data. The conglomerate hosted LockBit 2.0 affiliate infrastructure on the same IP space for over six months prior to Operation Cronos (Intel471). Joint OFAC/UK NCA/Australian Government sanctions in November 2025 designated Media Land and affiliated entities as key facilitators of ransomware, DDoS, and malware operations worldwide. The 2025 internal data leak (reported by Risky Biz) confirmed active hosting of ransomware DLS, C2 servers, phishing kits, and exfiltration nodes on shared infrastructure.

Zservers: A forum-advertised BPH service with multiple domain iterations (zservers.su, zservers.top) that actively marketed bulletproof VPS to spammers, ransomware operators, and credential thieves on major cybercrime forums including XSS and Exploit.in. Intel471 profiling identified Zservers' IP ranges as supporting LockBit affiliate infrastructure. Sanctioned concurrently with Media Land in November 2025; the joint action against Zservers alongside Media Land established a precedent for parallel sanctioning of both large-scale and mid-tier BPH providers.

Yalishanda / Alexander Lyul'ko: One of the most extensively documented individual BPH operators in open-source intelligence. Active since at least 2010 on Russian-language cybercrime forums. Operated fast-flux proxy networks used by ZLoader and Silent Night banking trojan campaigns (Intel471). Provided "support" services to criminal customers on traffic routing and proxy chain configuration. Represents the mid-tier BPH operator archetype that bridges between forum-visible advertising and the operational support layer.

BEARHOST / Underground / Voodoo Servers: A constellation of BPH brands linked by Resecurity to a common infrastructure owner (the "ghost bulletproof hosting conglomerate" model). Documented as the hosting backbone for Qilin's WikiLeaksV2 DLS and multiple other ransomware DLS instances. Specialized in Tor/onion service hosting and dark-web content. The multi-brand structure mirrors the Media Land multi-entity model and provides similar resilience: disruption of one brand shifts traffic to sibling brands.

2.3 Scale and Documented Impact Table

MetricValuePeriod / ContextSourceConfidence
Ransomware-linked servers from single BPH VM image template>7,000 serversActive since at least 2021; Windows Server 2012 R2 through 2022Sophos / CybernewsCONFIRMED
Media Land infrastructure: ransomware families hostedLockBit, BlackSuit, Play (confirmed); others assessedPre- and post-Cronos period through 2025OFAC/UK/Australia sanctions Nov 2025; Intel471; IBM X-ForceCONFIRMED
LockBit DLS on Media Land/aligned IP space duration>6 months prior to CronosPre-February 2024Intel471CONFIRMED
Media Land legal entities identified4 named entities (Media Land LLC, Media Land Technology LLC, Data Center Kirishi LLC, ML.Cloud LLC)As of Nov 2025 sanctions actionOFAC/IBM X-ForceCONFIRMED
Sanctions jurisdictions acting jointly on BPH3 (US/OFAC, UK/NCA, Australia)November 2025Joint sanctions announcementCONFIRMED
BPH use across cybercrime verticals (Intel471)Forums, MaaS, RaaS, credential/card shops, phishing ops all documented as BPH customersOngoingIntel471CONFIRMED
Yalishanda active period>14 years (2010 to present)2010-2026Intel471CONFIRMED
VM template image versions in useWindows Server 2012 R2, 2016, 2019, and 20222021 to presentSophos / CybernewsCONFIRMED

2.4 Geographic Concentration and Jurisdictional Profile

Russia-based BPH providers dominate the top tier of the market for two structural reasons: Russian jurisdictional insularity from Western law-enforcement process, and established tolerance (whether passive or active) within Russian regulatory and security services for cybercrime infrastructure that targets non-CIS victims.

Confidence: CONFIRMED for Russia as primary BPH market location; CREDIBLE for active Russian state tolerance (as distinct from passive non-enforcement); ANALYST INFERENCE that BPH operators screen customers for CIS-targeting in alignment with ransomware operator practices.

SECTION 3 — INFRASTRUCTURE DEPENDENCIES

3.1 BPH Upstream Dependencies

BPH providers are themselves dependent on upstream infrastructure and commercial relationships that represent the primary structural leverage points for external disruption:

Upstream DependencyRelationshipDisruption Leverage
Transit ISPs and upstream network providersBPH operators source transit connectivity from upstream ISPs; without upstream peering, BPH networks cannot route traffic to the internetHIGH: Upstream provider termination of peering agreements disables BPH network connectivity; most effective single action against large BPH conglomerates; requires upstream provider cooperation or regulatory pressure
IP address registries (ARIN, RIPE, APNIC, LACNIC)BPH operators acquire IP ranges from regional registries or from other providers; shell company chains are used to obscure the ultimate beneficial owner from registry recordsMEDIUM: Registry revocation of IP ranges forces migration; requires demonstrated abuse evidence; RIPE has historically been more responsive than others to abuse-linked revocation actions
Domain registrars and DNS providersBPH-hosted criminal infrastructure uses domain registrations for C2 domains, DLS clearnet mirrors, and phishing infrastructure; registrar-level disruption can disable specific campaignsMEDIUM: Registrar suspension of abuse-linked domains is effective for campaign-level disruption but does not degrade BPH capacity; groups rotate domains rapidly
Data center physical facilitiesSome BPH operators maintain or lease physical rack space in data centers (Data Center Kirishi LLC model); physical facility operators represent an upstream leverage pointLOW-MEDIUM: Physical facility eviction requires local-jurisdiction cooperation; Russia-based facilities are not accessible to Western LE; third-country data centers are more actionable
Underground forums (Node 07)BPH providers advertise on underground forums and Telegram channels to recruit criminal customers; forum visibility is essential to mid-tier BPH business modelLOW (against BPH directly): Forum disruption degrades BPH advertising but providers are established enough that existing customer relationships sustain operations without active advertising

3.2 BPH Downstream Customers (All Dependent EDP Nodes)

Downstream Customer / NodeEDP NodeBPH Service UsedImpact if BPH Disrupted
Ransomware C2 infrastructureModule 07 (RaaS Operators)VPS/dedicated server for key management, payload delivery, affiliate coordinationOperator loses C2 capability; deployed ransomware cannot receive commands or validate payments; affiliate operations fail
Affiliate management panelsModule 07 (RaaS Operators)VPS hosting admin console, victim tracking, build generationAffiliate deployment rate drops; operators cannot distribute builds or track victims
Data-leak sites and negotiation portalsNode 06 / Module 08Tor-accessible VPS for DLS hosting, countdown timers, staged data releaseDouble-extortion mechanism degrades; victims lose DLS-derived pressure; operator credibility with affiliates damaged
Botnet and loader C2Node 05 / Module 02C2 servers for loader command-and-control, bot management, malware update deliveryLoader operators lose botnet management; infected systems stop receiving ransomware payloads; affiliate deployment pipeline stalls
IAB market infrastructureNode 04 / Module 05Hosting for access listing sites, escrow services, communication channelsIAB market availability degrades; affiliates lose access acquisition channel; deployment rates fall
Underground forum hostingNode 07 / Module 10Forum web server, database hosting, communication infrastructureForum downtime disrupts affiliate recruitment, reputation management, and ecosystem coordination
Credential and stealer-log marketsNode 10 / Module 01Market web hosting, download infrastructure, payment portalsCredential market access disrupted; stealer-log availability reduced; downstream attack supply degrades
Exfiltration staging serversNode 14VPS for temporary storage of exfiltrated data before DLS postingExfiltrated data becomes inaccessible for DLS escalation; reduces operator leverage in active negotiations
Crypto mixing servicesNode 08 / Module 11Web-facing mixing service infrastructure, transaction processing serversMixer availability reduced; payment obfuscation capability degrades; financial tracing becomes easier

3.3 Critical Chokepoints

ChokepointWhy CriticalDisruption OwnerBackfire Risk
Upstream transit ISP peering relationshipBPH cannot route traffic without upstream connectivity; peer termination by upstream ISP immediately disables BPH network across all hosted services simultaneouslyFVEY LE + regulatory bodies + private sector (upstream ISP engagement); US DOJ Section 1030 enforcement against upstream US-based providersLOW
IP range source / RIPE/ARIN registrationBPH IP ranges are allocated from registries via shell company chains; registry revocation or blocking denies BPH ability to acquire new address space and degrades routing for existing rangesRIPE/ARIN/APNIC abuse processes; FVEY LE supporting documentationLOW
VM template distribution sourceThe Sophos-identified template provisioning pipeline enables industrial-scale ransomware infrastructure from a single image; disrupting template distribution prevents new server provisioning at scaleFVEY IC + private sector (cloud providers, VPS marketplaces); template fingerprint-sharing programLOW
BPH corporate entity banking relationshipsBPH operators require banking or crypto payment processing to receive customer payments; financial isolation via OFAC designation disrupts business model and payment collectionTreasury/OFAC; financial institutions (correspondent banking); crypto exchanges (designation compliance)LOW
Multi-entity shell company legal chainMedia Land-type operators distribute infrastructure across multiple legal entities to resist seizure; identifying and designating the full entity chain simultaneously removes legal insulationTreasury/OFAC; DOJ (civil forfeiture); foreign jurisdiction cooperationLOW
BPH-as-a-Service advertised on underground forumsMid-tier BPH providers depend on forum advertising for customer acquisition; forum disruption combined with BPH takedown removes both the service and the primary replacement-discovery channel simultaneouslyFVEY LE (joint action against BPH + forum)LOW

3.4 Multi-Entity Conglomerate Structure (Media Land Model)

The Media Land entity structure illustrates the defensive architecture of major Russian BPH conglomerates. Key structural features:

3.5 Cross-Module Linkages

EDP ModuleLinkage TypeDescription
Module 01 — StealersDownstream CustomerStealer log market infrastructure and C2 for stealers hosted on BPH; BPH disruption degrades stealer log availability.
Module 02 — LoadersCritical DownstreamLoader C2 infrastructure and malware distribution hosted on BPH; BPH disruption is the primary loader infrastructure disruption lever.
Module 03 — Crypters/PackersDownstream CustomerCrypter service delivery infrastructure hosted on BPH; crypter service disruption follows from BPH disruption.
Module 05 — IABsDownstream CustomerIAB market hosting on BPH; access listing and escrow infrastructure depends on BPH uptime.
Module 07 — RaaS OperatorsCritical DownstreamAll operator-facing infrastructure (C2, affiliate panels, payment portals, negotiation) hosted on BPH; BPH disruption is the primary operator infrastructure lever.
Module 08 — Leak Site OperationsCritical DownstreamAll DLS infrastructure hosted on BPH; BPH backbone disruption is identified in Module 08 as the highest-leverage DLS disruption method.
Module 10 — Underground ForumsDownstream CustomerForum hosting on BPH; forum disruption requires or benefits from BPH-level action.
Module 11 — Crypto MixersDownstream CustomerMixer web infrastructure hosted on BPH; mixer availability tied to BPH uptime.
Module 12 — OTC BrokersDownstream Customer (partial)OTC broker communication and escrow infrastructure may use BPH for operational security; less direct dependency than other modules.
Module 15 — Negotiation ServicesDownstream CustomerThird-party negotiation service communication infrastructure hosted on BPH for attribution resistance.

SECTION 4 — DISRUPTION LEVERAGE POINTS

4.1 Primary Disruption Levers

LeverMechanismOwnerBest MethodExpected EffectBackfire
Upstream ISP peering terminationIdentify the upstream transit ISPs providing connectivity to BPH networks; engage or compel those providers to terminate peering or transit agreements for BPH-linked ASNsFVEY LE + regulatory bodies (FCC, OFCOM equivalents); private sector upstream provider engagementDocumented abuse evidence package to upstream providers; OFAC designation creating compliance obligation; DOJ engagement with US-nexus upstream providersMost impactful single action: immediately severs all BPH-hosted services across all downstream nodes simultaneously; forces full infrastructure migrationLOW
OFAC / joint multilateral financial designationDesignate BPH entities and individuals under sanctions frameworks (OFAC SDN, UK OFSI, Australia DFAT); trigger compliance obligations for all financial institutions, crypto exchanges, and payment processors dealing with designated entitiesTreasury/OFAC + UK NCA + Australia (joint action model demonstrated November 2025); crypto exchanges and OTC brokers (compliance)Full entity-chain designation (all shell companies simultaneously); concurrent crypto wallet cluster designation; coordination with FVEY financial partnersCuts off BPH payment processing; forces business model disruption; creates legal liability for customers knowingly using designated infrastructure; established effective precedent with Media LandLOW
IP range / ASN blocking at regional registry levelEngage RIPE/ARIN/APNIC with documented abuse evidence; seek revocation of IP range allocations to shell company chains; request ASN-level routing blocks from upstream providersFVEY LE (evidence provision) + regional registries (RIPE, ARIN); upstream ISPs (routing blocks)Comprehensive abuse documentation package; RIPE NCC Community Projects Fund precedent; law-enforcement evidence sharing with registry abuse teamsDegrades BPH ability to acquire new IP space; routing blocks degrade existing range usability; forces migration to less reputable upstream providersLOW
VM template fingerprint blocking (private sector)Share Sophos-identified Windows VM image fingerprints with major cloud providers (AWS, Azure, GCP), VPS marketplaces, and hosting registries as a threat-intelligence feed; providers proactively block provisioning of template-matched VMsPrivate sector (Sophos, cloud providers); CISA/NCSC as coordination mechanism; no LE operation requiredFormalized threat-intelligence sharing program; fingerprint database maintained and updated by private sector researchers; cloud provider policy engagementPrevents provisioning of 7,000+ fingerprint-matched servers; proactive disruption before deployment rather than reactive takedown; highest ROI-per-analyst-hour action available against BPH infrastructureLOW
Full multi-entity chain designation (simultaneous)Identify all legal entities in BPH conglomerate corporate chain (IBM X-Force reconstruction model); designate all entities simultaneously to prevent migration between sibling entities post-actionTreasury/OFAC (full entity chain); DOJ civil forfeiture (US-nexus assets); FVEY partners (foreign-entity chains)Complete entity mapping prior to public action; simultaneous designation of all identified entities; concurrent infrastructure seizure where physically accessibleEliminates the conglomerate resilience mechanism; prevents post-designation migration to sibling entities; most comprehensive single action against conglomerate-model BPHLOW
Criminal referral and prosecution of BPH operatorsIdentify, indict, and seek extradition or prosecution of BPH operators (Yalishanda model); impose personal legal consequences that deter continued operationFVEY LE (FBI, NCA, Europol); DOJ Grand JuryGrand jury indictment + INTERPOL Red Notice + public unsealing; extradition request or in absentia prosecution for deterrence signalingIndividual deterrence; forces operational security changes; sets precedent for BPH operator accountability; limited by Russia non-extradition defaultMEDIUM (individual attribution requires Dark Covenant screening for Russia-based operators)

4.2 The Intel471 Cost-Effectiveness Finding

Intel471 has assessed that targeting and blocking BPH IP ranges and ASNs is among the most cost-effective defensive actions available against the ransomware ecosystem. The analytical basis for this assessment:

4.3 Compounding Actions

SECTION 5 — RESILIENCE AND REPLACE DIFFICULTY

5.1 Replace Difficulty Assessment

LevelAssessmentRationale
Individual BPH server or IP addressVERY LOWTrivially replaced within hours from the same provider's IP pool; address-level disruption has no meaningful effect on BPH operational capacity.
Single BPH entity or brandLOW-MEDIUMDisruption of one entity (e.g., Zservers designation) can be partially absorbed by migration to sibling entities or alternative providers within days to weeks. Criminal customers are lost during migration but most re-establish on alternative infrastructure.
Full BPH conglomerate (all entities simultaneous)MEDIUM-HIGHSimultaneous disruption of all conglomerate entities (full Media Land chain) forces complete infrastructure migration with no internal fallback. Estimated weeks to months for full operational reconstitution on alternative infrastructure.
BPH function for Russia/CIS operators (market depth)MEDIUMThe Russian BPH market has sufficient provider depth that disruption of Media Land and Zservers simultaneously would create temporary pressure but not eliminate BPH availability. Estimated 5-10 major Russian BPH providers serve the top-tier ransomware market; full market disruption requires action against all simultaneously.
VM template provisioning pipelineHIGHIndustrial-scale VM template provisioning (7,000+ servers from a single image) requires specific technical infrastructure and BPH operational capability that cannot be immediately replicated after disruption of the template source.
BPH function globally (all providers, all jurisdictions)VERY HIGHEliminating BPH availability globally is not achievable with current tools; tolerant jurisdictions (Russia, Belarus, certain Central Asian states) will always provide a refuge for BPH operations that cannot be compelled to comply with Western enforcement requests.

5.2 Redundancy and Structural Resilience

5.3 Historical Reconstitution Patterns

Disruption EventBPH ImpactReconstitution TimeOutcome
OFAC designation of Media Land and Aeza Group (November 2025); Zservers designated separately (February 2025)Financial isolation; compliance obligations for US-nexus upstream providers; customer legal exposureAssessment pending (recent as of research date); structural impact expected over 6-12 monthsDesignation is the most significant BPH enforcement action documented in open reporting; long-term operational impact under assessment
Operation Avalanche / Avalanche takedown (2016)Disruption of fast-flux proxy infrastructure used by multiple banking trojan and ransomware operations; not a direct BPH provider takedownFast-flux network reconstituted under different operators within monthsIllustrates that infrastructure-level disruption produces temporary effect; criminal operators migrate to alternative BPH without the specific disrupted network
Lolita City and Freedom Hosting takedowns (2011-2013)Dark-web hosting provider disruptions affecting criminal content hosting broadlyHosting function reconstituted across multiple successor providers within monthsEstablished the pattern that BPH function is highly resilient; individual provider disruption displaces rather than eliminates criminal hosting
ISP/upstream depeering actions (various)When upstream providers have terminated BPH networks (e.g., Hurricane Electric depeering of McColo 2008), effect was immediate and comprehensiveMcColo reconstitution failed; global spam volume dropped 75% for weeksHistorical precedent: upstream depeering is the most effective single action against BPH; McColo case remains the benchmark for BPH infrastructure disruption impact

5.4 Durability Assessment

FactorRatingNotes
Russian jurisdictional insularityVERY HIGHPrimary structural resilience factor; cannot be addressed through legal process alone.
Multi-entity corporate architecture resilienceHIGHDeliberate design; requires full entity-chain simultaneous action to overcome.
IP range and ASN portfolio depthHIGHSufficient range diversity to absorb partial blocking; requires comprehensive ASN-level action.
VM template provisioning resilienceHIGHIndustrial-scale capability; disruption of template pipeline is highest-leverage technical action.
Market depth (number of viable Russian BPH providers)MEDIUMEstimated 5-10 top-tier providers; disruption of 1-2 degrades market but does not eliminate it.
Financial and payment resilience (crypto payments)MEDIUM-HIGHOFAC designation creates compliance obligation; crypto-only payment model complicates financial isolation but does not prevent it.
Overall BPH function durabilityHIGHNode 03 is correctly assessed at HIGH replace difficulty; this module confirms that rating is accurate and potentially understated given jurisdictional insularity.

SECTION 6 — INDICATORS AND KPIs

6.1 Health Indicators — Normal vs. Under Pressure

IndicatorNormal / Stable StateUnder Pressure
BPH provider forum advertising activityActive advertising on XSS, Exploit.in, RAMP, and Telegram channels for bulletproof VPS and DLS hostingAdvertising volume declining; providers going dark or advertising under new names after enforcement action
Known BPH ASN uptimeMedia Land, Zservers, and equivalent ASNs routing continuously with stable IP rangesExtended routing outages; ASN depeering events; IP range revocation notices at RIPE/ARIN
VM template-matched server count>7,000 fingerprint-matched servers activeDecline in fingerprint-matched server count indicates template-blocking program is effective
Criminal infrastructure uptime on known BPH rangesSustained uptime for C2, DLS, and affiliate panel infrastructure on documented BPH IP rangesIncreased migration frequency; shorter IP lifetime on known BPH ranges; increased use of proxy chains
BPH customer acquisition (new operator onboarding)Active new customer advertising and onboarding visible in forum posts and Telegram channelsDecline in new-customer advertising; operators reporting difficulty acquiring BPH hosting on forums
Ransomware infrastructure hosting concentrationMajor RaaS operators concentrated on 3-5 identified BPH networksInfrastructure dispersing across more providers; increased rotation frequency; lower concentration per provider
OFAC-designated BPH entity list growthDesignated list growing with new entities following enforcement actionsStable or declining list could indicate enforcement fatigue; growing list indicates sustained pressure

6.2 Disruption KPIs

KPIBaselineDisruption Target (18-month)Collection Method
Fraction of top-tier BPH providers under OFAC/UK/AU designation2 providers sanctioned (Media Land, Zservers) as of Nov 2025Top-5 Russian BPH providers all under designation or enforcement actionTreasury OFAC SDN list; UK OFSI; AUSTRAC designations
Upstream ISP depeering actions against BPH ASNs0 documented depeering actions against major Russian BPH in 2024-20251 documented depeering event against a designated BPH ASN within 12 monthsBGP routing monitoring; upstream provider engagement tracking
VM template fingerprint block rate0% (no program operational as of research date)50%+ of Sophos-identified template fingerprints blocked by major cloud/VPS providersCoordinated tracking with Sophos and cloud providers; fingerprint database updates
Ransomware infrastructure migration frequency (known BPH ranges)Stable, long-lived hosting (LockBit on same IP space >6 months)Average IP lifetime for ransomware C2 on BPH <30 days (indicates continuous blocking pressure)Threat intelligence platform C2 tracking; Intel471 / Recorded Future infrastructure monitoring
BPH-dependent node uptime (proxy metric)DLS, affiliate panels, and C2 maintain >99% uptime on BPHDocumented 48-hour+ outages for major DLS and affiliate panel infrastructure per quarterDLS availability monitoring; C2 tracking platforms
Criminal operator reports of BPH difficulty on forumsInfrequent complaints; providers meeting service-level expectationsIncreasing forum discussion of BPH availability problems; operators requesting alternative provider recommendationsForum monitoring (Intel471, Flashpoint)

6.3 Collection Methods

6.4 Baseline Data

MetricValuePeriodSource
Ransomware-linked servers from single VM template>7,000 serversActive since 2021Sophos / Cybernews
Windows Server image versions used in template provisioningServer 2012 R2, 2016, 2019, 20222021 to presentSophos / Cybernews
Media Land legal entities identified4 (Media Land LLC, Media Land Technology LLC, Data Center Kirishi LLC, ML.Cloud LLC)As of Nov 2025OFAC / IBM X-Force
Jurisdictions jointly designating Media Land3 (US/OFAC, UK/NCA, Australia)November 2025Joint sanctions announcement
Ransomware families confirmed hosted on Media LandLockBit, BlackSuit, PlayPre- and post-CronosOFAC; Intel471; IBM X-Force
LockBit infrastructure on aligned BPH IP space duration>6 monthsPre-Cronos (pre-Feb 2024)Intel471
Yalishanda active BPH period>14 years (2010 to 2026)2010 to presentIntel471
BPH customer verticals documentedForums, MaaS, RaaS, credential/card shops, phishing, spam, DDoSOngoingIntel471; Infosecurity Magazine

6.5 Alert Thresholds

Threshold EventTrigger LevelRecommended Action
New major BPH provider emergenceNew provider advertising bulletproof hosting for RaaS infrastructure on major forums within 60 days of an enforcement action against existing providerImmediate profiling; corporate entity mapping (IBM X-Force model); upstream ISP identification; OFAC pipeline initiation
BPH market consolidation (fewer providers hosting more)Single BPH network identified as hosting >50% of known active RaaS C2 and DLS infrastructurePrioritize that network for multi-track disruption: OFAC designation + upstream depeering engagement + RIPE revocation simultaneously
VM template variant emergenceNew template fingerprint identified producing 500+ servers within 60 daysImmediate fingerprint distribution to cloud providers; alert to Sophos and Intel471 for validation; include in blocking feeds
Designated BPH operator continuing operationsOFAC-designated entity identified as routing new IP ranges under different ASN within 90 days of designationExpand designation to new entity; upstream provider re-engagement; escalate to Treasury for enhanced designation action
Upstream provider enabling designated BPHUS-nexus upstream provider identified as providing transit to OFAC-designated BPH ASN post-designationDOJ referral for potential OFAC violation; FCC/regulatory engagement; direct provider notification with legal exposure briefing

SECTION 7 — SOURCES AND CONFIDENCE

7.1 Primary Sources

Enforcement and Designation Actions:

Infrastructure Intelligence:

Contextual and Ecosystem Analysis:

7.2 Gaps and Uncertainties

7.3 Confidence Notes

Claim / FindingConfidenceBasis
Media Land entity structure (4 named entities)CONFIRMEDOFAC designation + IBM X-Force reconstruction; independent corroboration
Media Land hosting LockBit, BlackSuit, Play infrastructureCONFIRMEDOFAC sanctions designation; Intel471 IP analysis; IBM X-Force corroboration
Zservers hosting LockBit affiliate infrastructureCONFIRMEDIntel471 profiling + OFAC/UK designation
VM template fingerprint: >7,000 servers from single imageCONFIRMEDSophos primary research; Cybernews reporting; technical reproducibility
Yalishanda / fast-flux BPH network identity and operationsCONFIRMEDIntel471 persona attribution; >14-year documented forum history
BEARHOST as hosting backbone for Qilin WikiLeaksV2CREDIBLEResecurity single-source; strong infrastructure correlation; not independently corroborated
Russian state passive tolerance of BPH operationsCREDIBLEJurisdictional insularity evidence; CIS filter analogs; selective enforcement patterns (REvil 2022)
VM template provider identity (specific BPH operator)CREDIBLEIP range and ASN correlation with known BPH providers; not publicly named
Active Russian state direction of BPH operatorsNOT SUPPORTED IN OPEN REPORTINGTolerance model is supported; active direction requires IC-level evidence not available in open sources
5-10 viable Russian BPH providers serving top-tier ransomware marketANALYST INFERENCEMarket depth inference from forum advertising volume and provider documentation; no systematic count available

SECTION 8 — ANALYST ASSESSMENT

8.1 Key Takeaway

Bulletproof hosting is the single most cross-cutting infrastructure node in the EDP ecosystem. Every other node that requires persistent online presence is either directly hosted on BPH or depends on services that are. This makes Node 03 qualitatively different from all other EDP nodes: it is not a service consumed by ransomware operators; it is the substrate on which the entire ecosystem operates. The CRITICAL tier classification in the Dependency Map is accurate, but the strategic implications of that classification are not fully reflected in current disruption planning.

The November 2025 joint OFAC/UK/Australia designation of Media Land and Aeza Group (Zservers having been designated separately in February 2025) is the most significant BPH enforcement action in the history of the sector and establishes a replicable multi-jurisdictional model. The designation is necessary but not sufficient: financial isolation without concurrent upstream ISP depeering allows designated entities to continue routing traffic and hosting infrastructure. The McColo 2008 precedent — upstream depeering that immediately disabled a major criminal hosting network and reduced global spam volume by 75% — remains the benchmark for what effective BPH disruption actually looks like. No comparable upstream action has been taken against a major Russian BPH network in the period covered by this module.

The Sophos VM template finding represents a currently underexploited disruption vector. The ability to proactively block 7,000+ servers before deployment, through a private-sector threat-intelligence-sharing mechanism that requires no law-enforcement operation, is an asymmetric advantage that has not been operationalized. This module recommends immediate formalization of a fingerprint-sharing program as the highest-ROI-per-analyst-hour action available.

8.2 Priority Recommendations

Recommendation 1 — Pursue Upstream ISP Depeering as the Primary BPH Disruption Method: OFAC designation alone does not disable BPH infrastructure; it creates compliance obligations that depend on upstream provider enforcement. The McColo precedent (Hurricane Electric depeering, 2008) demonstrates that upstream provider action is immediate and comprehensive. The OFAC designations of Media Land (November 2025) and Zservers (February 2025) create legal exposure for any US-nexus provider maintaining transit relationships with those ASNs. The priority action is converting that legal exposure into operational depeering: identifying all US-nexus upstream providers currently transiting Media Land and Zservers ASNs, and providing them with a formal legal exposure briefing and enforcement timeline. DOJ engagement with the relevant DOJ Computer Crime and Intellectual Property Section is the appropriate mechanism.

Recommendation 2 — Operationalize the VM Template Fingerprint Program: The Sophos VM template finding should be converted from a research finding into an operational disruption program: formalize a threat-intelligence sharing relationship between Sophos, CISA/NCSC, and major cloud and VPS providers (AWS, Azure, GCP, Hetzner, OVH) under an existing information-sharing framework (CISA's Joint Cyber Defense Collaborative or UK NCSC's equivalent). The deliverable is a maintained, automatically-updated feed of BPH VM template fingerprints that participating providers use to block provisioning of fingerprint-matched VMs. This is the closest available analog to proactive BPH disruption that does not require international legal cooperation or Russian jurisdiction access.

Recommendation 3 — Apply IBM X-Force Entity-Reconstruction Methodology to All Known BPH Conglomerates: The IBM X-Force reconstruction of the Media Land entity chain was the analytical precondition for the November 2025 designation. The same methodology should be applied systematically to BEARHOST/Underground/Voodoo Servers, Aeza Group, and any other BPH conglomerate supporting active ransomware operations. The output of each reconstruction exercise is a full entity chain designation package for OFAC pipeline submission. Completing this analysis for the top-5 Russian BPH providers within 12 months establishes the evidentiary foundation for comprehensive Phase A BPH designation actions.

Recommendation 4 — Sequence BPH Disruption Before Individual RaaS Operator Actions: Actions against specific RaaS operator infrastructure (Module 07) should be sequenced after or concurrent with BPH backbone disruption, not before. Operator disruption without BPH backbone disruption allows reconstitution on the same infrastructure within days (LockBit post-Cronos precedent). Operator disruption following BPH backbone disruption forces reconstitution on degraded infrastructure, compresses reconstitution timelines by weeks, and increases the probability that affiliate diaspora exceeds ecosystem absorption capacity. The Phase A-before-Phase-C sequencing in the EDP Playbook reflects this logic; this recommendation operationalizes it as an explicit pre-condition for future RaaS operator enforcement actions.

8.3 Connection to EDP Disruption Playbook

Summary implication: BPH is the node where Phase A investment produces cascading Phase B and Phase C effects. The EDP Playbook Phase sequencing should explicitly identify BPH as the highest-leverage Phase A target specifically because its disruption compounds the effect of all subsequent phase actions.

8.4 Node 03 Dependency Map Assessment

Current Dependency Map assessment for Node 03:

This module's analysis supports the existing assessment with the following refinements:

DimensionCurrent Map AssessmentModule 09 Refined AssessmentBasis
Backfire RiskLOW-MEDIUMLOW for infrastructure and financial actions (OFAC designation, upstream depeering, VM template blocking); MEDIUM for individual BPH operator attribution and prosecution of Russia-based operators (Dark Covenant screening required for personal attribution). The LOW-MEDIUM aggregate should be disaggregated by action type.Section 4.1 disruption lever table; Dark Covenant 3.0 framework
Primary Owner framingFVEY IC + LE + upstream providers (ISPs, registrars, CDN)Recommend adding Treasury/OFAC as an explicit primary owner (November 2025 designation demonstrates OFAC as the most effective single actor against BPH); also add private sector (cloud providers, Sophos) for the VM template disruption vector. Current framing underweights financial designation and overweights IC relative to operational utility.November 2025 sanctions action; VM template program recommendation
Replace DifficultyHIGHHIGH confirmed for full conglomerate disruption; VERY HIGH for complete market elimination (jurisdictional insularity ensures BPH function cannot be fully eliminated). Recommend noting the jurisdictional ceiling explicitly in the Dependency Map.Section 5.1-5.4 resilience analysis; jurisdictional insularity assessment

8.5 Follow-On Research Priorities

Research QuestionPriorityRationaleSuggested Source / Method
Full entity-chain reconstruction for BEARHOST / Underground / Voodoo Servers conglomerateHIGHBEARHOST is documented as hosting multiple active ransomware DLS (Qilin, others); full entity chain is prerequisite for OFAC designation pipeline initiation.Resecurity technical attribution + corporate registry cross-reference; IBM X-Force entity reconstruction methodology applied to BEARHOST IP ranges
Full entity-chain reconstruction for Aeza GroupHIGHAeza linked to Media Land entity structure in IBM analysis but not separately designated; may represent the primary fallback infrastructure post-Media Land designation.IBM X-Force methodology; RIPE routing data; corporate registry cross-reference for Aeza ASNs
Identification of the VM template provisioning provider (Sophos unnamed)HIGHVM template fingerprint blocking program cannot be fully operationalized without knowing which BPH provider is deploying the template; provider identity is the missing operational link.Sophos technical collaboration; ASN/IP range correlation with known BPH providers; IC collection
Post-November 2025 designation operational impact assessmentHIGHMedia Land and Zservers designation is recent; operational impact (infrastructure migration, customer dispersal, upstream provider compliance) requires 6-12 month monitoring assessment.BGP routing monitoring; DLS uptime tracking; forum monitoring for customer migration discussions
Russian BPH market depth: full population of viable providersMEDIUMMarket depth assessment (5-10 providers) is ANALYST INFERENCE; systematic enumeration is required for comprehensive Phase A planning.Intel471 and Flashpoint forum advertising data; IP range cluster analysis; law-enforcement operational intelligence
Upstream ISP compliance with OFAC-designated BPH ASN peeringHIGHDesignation is only effective if upstream providers comply; identifying which US-nexus providers are still transiting designated ASNs is prerequisite for depeering engagement.BGP routing monitoring (BGPmon, RIPE RIS); RouteViews AS path analysis for designated ASNs

8.6 Module 09 Assessment Summary

Node 03 (Bulletproof Hosting) is the foundational infrastructure node of the EDP ecosystem and the highest-leverage Phase A target. The November 2025 joint designation of Media Land and Aeza Group is the most significant BPH enforcement action documented in the sector and establishes a replicable model. The gap between that designation and full operational disruption is the upstream ISP depeering step that converted the 2008 McColo action into a decisive infrastructure takedown. Closing that gap — by converting OFAC designation compliance obligations into actual upstream depeering of designated BPH ASNs — is the single highest-impact follow-on action available to the EDP framework. Update July 2026: the criminal-prosecution complement to designation has now landed. On 14 July 2026 DOJ unsealed an indictment of three Russian nationals (Aleksandr Volosovik, known as Yalishanda; Kirill Zatolokin; Yulia Pankova) and the Media Land and ML Cloud companies for more than 62 million USD in victim losses, paired with a 10 million USD Rewards for Justice offer. This is the named-operator accountability model this module recommends, executed against the sector's highest-priority conglomerate.

Concurrently, the Sophos VM template fingerprint program represents an asymmetric private-sector disruption capability that can proactively prevent industrial-scale ransomware infrastructure provisioning without law-enforcement operations or international legal coordination. Operationalizing this capability through CISA or NCSC-mediated threat-intelligence sharing is a low-cost, high-yield action that should not require additional analysis cycles before implementation.