Definition: A bulletproof hoster (BPH) is an internet hosting provider that deliberately ignores, or actively resists, law enforcement takedown requests and abuse complaints, providing a safe harbor for cybercriminals to run spam, malware, phishing, ransomware, and DDoS infrastructure with near-impunity. If you work in security, threat intelligence, or IT, understanding bulletproof hosting is non-negotiable; it sits at the root of almost every major cybercrime ecosystem on the internet today.
Why Are Bulletproof Hosters A Big Deal?
A bulletproof hoster is, at its core, a web hosting or network infrastructure provider that sells its services with an implicit (and sometimes explicit) promise: we will not take you down. They offer the same things a legitimate host does (IP address space, servers, bandwidth, domain registration) but with one critical differentiator: when your victims complain, when Interpol sends a letter, or when the FBI comes knocking, the provider either ignores the request, moves the content to a new IP block, or re-registers the same infrastructure under a new name.
This is not accidental negligence. Bulletproof hosting is a deliberate, structured criminal service.
How It Works
Modern bulletproof hosters typically operate through a layered model:
- Upstream provider obfuscation. BPHs often lease IP space from legitimate upstream providers or internet exchanges, positioning themselves as middlemen so that their true customer base remains hidden from view.
- Jurisdiction shopping. Operators deliberately choose countries with weak cybercrime laws, limited international cooperation agreements, or rampant corruption — historically, Russia, Ukraine, China, and certain Eastern European nations have featured prominently, though infrastructure is spread globally.
- Rapid re-hosting. When abuse notices arrive, rather than removing content, BPHs simply shift the offending content to a new IP address or netblock, often within the same Autonomous System (AS). From the outside, it looks like takedown compliance; from the criminal's perspective, nothing has changed.
- Reseller networks. Many BPHs operate through a franchise-like network of resellers, adding further layers of indirection and legal complexity.
A Brief History of Bulletproof Hosting's Greatest Hits
Bulletproof hosting is not a new concept. Its roots go back to the earliest days of large-scale internet crime, and the list of infamously tolerant providers reads like a who's who of internet infrastructure abuse.
The Russian Business Network (RBN)
Perhaps the most notorious BPH operation in history, the Russian Business Network was a cybercrime-as-a-service organisation that flourished between roughly 2006 and 2008. Researchers at VeriSign's iDefense and independent security journalists documented how the RBN was linked to child exploitation material, phishing, spam, and some of the earliest large-scale malware distribution campaigns. At its peak, the organisation was estimated to host 60% of all global cybercrime activity. When pressure from the security community mounted in late 2007, RBN simply vanished, its infrastructure re-emerging in multiple other jurisdictions. [1]
McColo
In November 2008, two upstream providers, Global Crossing and Hurricane Electric, cut off connectivity to McColo Corp, a San Jose-based hosting company that Brian Krebs of The Washington Post had thoroughly documented as a hub for botnet command-and-control (C&C) infrastructure. The effects were immediate and dramatic: global spam volumes dropped by approximately 75% overnight. The McColo takedown remains one of the most cited examples of how critical BPH infrastructure is to the broader cybercrime ecosystem and how much damage a single de-peering event can cause. [2]
Atrivo
Contemporaneous with McColo, Atrivo (also known as Intercage) was another U.S.-based network that security researchers had flagged as a hub for malware distribution and spam. Following sustained public pressure and reporting by Krebs and others, upstream providers cut ties in 2008. [3]
Troyak
In 2010, the upstream provider for Troyak (a network closely associated with the Zeus botnet infrastructure) was briefly cut off after security researchers mapped its role in banking trojan C&C. At the time, Zeus was estimated to have infected 3.6 million computers in the United States alone and was actively draining bank accounts globally. [4]
Heihachi / MaxiDed
In the 2010s, networks such as MaxiDed continued the BPH tradition, serving an international clientele of cybercriminals. In 2019, Europol coordinated action against MaxiDed, which led to the arrest of its administrator, with investigators noting that the service had provided hosting to ransomware gangs, carding forums, and DDoS-for-hire services. [5]
Zservers (2024–2025)
In February 2025, the United States, United Kingdom, and Australia jointly sanctioned Zservers, a Russia-based bulletproof hosting provider accused of supporting the LockBit ransomware group. The action highlighted how BPH infrastructure remained deeply embedded in the modern ransomware supply chain, with Zservers allegedly providing LockBit affiliates with IP addresses specifically for managing ransomware attacks and laundering proceeds. [6]
The Scale of the Problem
Bulletproof hosting is not a niche concern. BHPs host the load-bearing infrastructure that the global cybercrime economy runs on.
- Spam and phishing: Studies by researchers at Georgia Tech and the UCSB-led Collaborative Center for Internet Epidemiology and Defenses (CCIED) found that a disproportionate share of spam and phishing infrastructure traces back to a small number of "bad" ASes, many of which exhibit BPH characteristics. [7]
- Ransomware C&C: A 2023 analysis by Coveware and corroborated by independent researchers found that the vast majority of active ransomware command-and-control infrastructure is hosted on a small pool of networks that accept abuse reports without acting on them, classic BPH behaviour. [8]
- Malware distribution: The majority of drive-by download campaigns, exploit kit landing pages, and malware staging servers are ephemeral, spun up quickly, then moved, a pattern almost exclusively enabled by BPH providers that tolerate rapid IP churn.
- DDoS-for-hire: The "booter" and "stresser" market, which allows anyone to purchase distributed denial-of-service attacks, is almost entirely hosted on BPH infrastructure, with providers shielding both the booter operators and their attack servers from takedown.
The FBI's Internet Crime Complaint Center (IC3) reported $12.5 billion in adjusted losses from internet crime in 2023 alone [9], a figure that would be materially lower if BPH infrastructure did
Why Law Enforcement Struggles
Shutting down a bulletproof hoster is genuinely hard, for reasons that are structural, legal, and geopolitical:
- Jurisdiction gaps: Many BPHs operate from countries without mutual legal assistance treaties (MLATs) with Western law enforcement, or in states where cybercrime against foreigners is tacitly tolerated.
- Infrastructure resilience: BPH operators have learned from McColo. Modern operations distribute infrastructure across multiple upstream providers and countries, so no single de-peering event can bring the whole operation down.
- Money laundering: Payments are typically made via cryptocurrency, often through mixing services, making it difficult to trace the flow of funds back to operators.
- Layers of indirection: Multiple shell companies, resellers, and front organisations mean that identifying the actual controlling party of a BPH network can require years of investigation.
That said, law enforcement has scored significant wins, from the McColo de-peering to the 2021 seizure of Emotet infrastructure (hosted, in part, on BPH networks across Europe and Asia) [10], to the Zservers sanctions in 2025. Each takedown, however, is followed by migration and reconstitution.
What Bulletproof Hosters Look Like to a Threat Analyst
For a threat hunter or SOC analyst, BPH infrastructure has recognisable signatures if you know what to look for:
- Autonomous System reputation: Certain AS numbers have persistent, documented histories of abuse. When you see traffic to or from these ASes, the likelihood of malicious activity is elevated dramatically.
- IP churn with persistent function: The C&C moves, but the beacon pattern and the function are consistent. If you're seeing regular check-ins from an endpoint to IPs that cycle through the same ASes over time, BPH is probably involved.
- Abuse-email black holes: BPH providers typically list abuse contacts that either bounce, go unanswered, or respond with form letters, resulting in no action.
- Minimal WHOIS transparency: Registrant information is either heavily anonymised, recently created, or traces to known registration privacy services used by cybercriminals.
Knowing which networks are bulletproof-hosters, and being able to enrich your telemetry with that knowledge in near real time, is the difference between chasing individual IPs and understanding the infrastructure layer beneath an entire campaign.
How Augur Helps
This is where Augur's Predictive Threat Intelligence (PTI) becomes a decisive advantage.
Augur has been collecting, correlating, and analysing internet telemetry for more than a decade, building one of the most comprehensive longitudinal datasets of internet infrastructure behaviour in existence. Over that time, Augur's platform has developed the ability to identify and automatically tag bulletproof hosters across the global IP space, surfacing not just known-bad IPs but entire network blocks and ASes with documented BPH characteristics.
For threat hunters and analysts, that means:
- Infrastructure-level context: When a suspicious IP appears in your logs, Augur can tell you immediately whether it belongs to a network with a BPH designation,giving you an instant risk signal that goes far beyond a simple IP reputation score.
- Historical depth: Because Augur's telemetry spans more than 10 years, the platform can surface patterns invisible to shorter-horizon feeds, including BPH operators who have cycled through multiple AS registrations and company names over time.
- Proactive blocking: Rather than waiting for an IOC feed to catch up, analysts can use Augur's BPH tagging to enforce network-level policy against known-tolerant hosters before attacks even launch.
- Campaign attribution: BPH infrastructure is often shared across threat actor groups. Augur's longitudinal data allows analysts to connect infrastructure across campaigns and draw attribution links that point-in-time tools cannot see.
If your threat intelligence programme is still operating at the indicator level, blocking individual IPs and hashes after the fact, bulletproof hosting is exactly why that approach will always lag. The attackers rehost in minutes. The infrastructure layer, tracked over time, is where the durable signal lives.
Bulletproof Hosters Identified By Augur
Here are a few examples of BHPs identified by Augur. Augur automates the painstaking process of backtracking and cross-checking thousands of domains, CIDRs, and ASNs, allowing threat hunters and analysts to identify risk vectors in minutes.

AS200593: Prospero OOO
Prospero (operating alongside sister network Proton66) is a Russia-based network recognized as a pure Bulletproof Hosting (BPH) operation. It acts as a primary infrastructure provider for prominent Russian-language malware strains, specifically hosting the script fingerprinting and traffic redirection mechanics for loaders like SocGholish and FakeBat. In early 2025, Prospero made a highly publicized routing shift, shifting its upstream traffic directly through Russian security boundaries to intentionally evade blocking by Western organizations like Spamhaus and began servicing Russian GRU/SVR operations more openly.
AS8254: Green Floid LLC
Originally incorporated in Florida in 2015 as ITLDC, Green Floid LLC operates as a geographically distributed hosting network. It has historically been flagged for hosting disinformation networks and fraudulent sites, as well as hosting links to state-sponsored influence operations. Today, it functions as an impervious infrastructure host, routing over 75,000 IP addresses that frequently host anonymizing VPNs, public proxies, automated scrapers, and malicious operations.
AS14956: RouterHosting LLC (Cloudzy)
Operating primarily under the commercial brand Cloudzy, RouterHosting is a US-registered provider with infrastructure heavily concentrated in Europe, Asia, and other legally permissive jurisdictions. Augur identifies it as a prominent entry point for malicious activity due to its low-friction, anonymous cryptocurrency payment options. The network also actively manages Command and Control (C2) frameworks, most commonly Cobalt Strike beacons and phishing tooling, which are frequently linked to Middle Eastern advanced persistent threats (APTs) and state-sponsored espionage operations.
AS57043: HOSTKEY B.V.
Based out of the Netherlands, HOSTKEY is a legitimate, high-volume Infrastructure-as-a-Service (IaaS) provider that specializes in dedicated servers and GPU hosting. However, due to its permissive data policies, it is frequently exploited as a high-capacity staging area for malicious actors. It is heavily used today by automated credential-stuffing bots, vulnerability scanners, and large-scale spam distributors that leverage its fast European backbone to target high-value regional victims.
AS197730: BWE Capital Limited
Registered as an offshore entity in the British Virgin Islands, BWE Capital acts as a highly protective network layer for threat actor operations. Unlike retail hosting companies, it functions primarily as an opaque network peer. It is employed today to shield malicious backend operations by providing untraceable BGP routing and clean IP space for operators, routing alongside isolated and offshore networks to prevent systemic internet takedowns from law enforcement.
AS200019: AlexHost SRL
AlexHost is a hosting provider based in the Republic of Moldova, with data centers in Eastern Europe and the Netherlands. It explicitly markets itself on cybercrime forums under "freedom of speech" guarantees, actively refusing to comply with standard international intellectual property and non-governmental abuse complaints. It is widely employed today to host underground carding forums, cracked software repositories, phishing pages, and malware delivery infrastructure.
For a deeper dive into the issues surrounding BHPs and how Augur helps threat hunters and analysts track them, you can read our research report exploring the many rebrands and pivots of BHP Stark Industry Solutions.
Frequently Asked Questions
Is bulletproof hosting illegal? In many jurisdictions, operating a bulletproof hosting service is prosecutable under computer fraud, money laundering, or organised crime statutes. However, prosecution requires establishing criminal intent and jurisdiction, which is difficult when operators are in non-cooperative countries. The 2025 Zservers sanctions represent a shift toward using economic and financial tools, rather than criminal charges alone, to disrupt BPH operations.
Can I accidentally use a bulletproof hoster? Unlikely, but an adjacent risk exists. Legitimate businesses that purchase IP space from upstream providers without due diligence can find their IPs blocklisted because they share netblock space with known BPH customers. This is one reason AS-level reputation monitoring matters.
What's the difference between a BPH and a VPN or Tor exit node? Tor exit nodes and commercial VPNs anonymise users but are not, themselves, hosting services. BPHs host infrastructure (servers, domains, C&C panels) not end-user traffic. That said, VPNs and Tor are frequently used in conjunction with BPH-hosted infrastructure.
Are all "offshore" hosts bulletproof hosters? No. Many legitimate businesses host offshore for cost or data sovereignty reasons. The distinction is willingness to act on abuse: a legitimate offshore host will investigate and act on credible abuse reports. A BPH will not.
Bottom Line
Bulletproof hosters are the landlords of the cybercrime economy. They don't write the malware, run the botnets, or steal the credentials, but without them, none of those things scale. Understanding BPH infrastructure, knowing which networks operate this way, and having the telemetry to act on that knowledge is foundational to any mature threat intelligence programme.
The cybercriminals already know which networks will protect them. The question is whether your defences know the same thing. And with Augur, they will.
Citations
[1] Krebs, B. (2007). "Shadowy Russian Firm Seen as Conduit for Cybercrime." The Washington Post. https://www.washingtonpost.com/wp-dyn/content/article/2007/10/12/AR2007101202461.html
[2] Krebs, B. (2008). "Host of Internet Evils Taken Offline." The Washington Post. https://www.washingtonpost.com/wp-dyn/content/article/2008/11/12/AR2008111200658.html
[3] Symantec / iDefense Security Intelligence. (2008). Atrivo/Intercage: Documenting a malicious ISP. (Archived industry reporting; widely cited in peer literature.)
[4] FBI Cyber Division / Microsoft Digital Crimes Unit. (2010). Operation b71 — Zeus Botnet Disruption. Microsoft Security Blog. https://blogs.microsoft.com/on-the-issues/2010/10/07/microsoft-helps-fbi-and-financial-partners-take-down-cybercriminal-operation/
[5] Europol. (2019). "Takedown of hosting provider used by cybercriminals." Europol Press Release. https://www.europol.europa.eu/newsroom/news/takedown-of-hosting-provider-used-by-cybercriminals
[6] U.S. Department of the Treasury, OFAC. (2025, February). Treasury Sanctions Bulletproof Hosting Provider Supporting LockBit Ransomware. https://home.treasury.gov/news/press-releases
[7] Stone-Gross, B., et al. (2009). "Your Botnet is My Botnet: Analysis of a Botnet Takeover." ACM CCS 2009. (University of California, Santa Barbara — CCIED.) https://dl.acm.org/doi/10.1145/1653662.1653738
[8] Coveware. (2023). Ransomware Marketplace Report Q4 2023. https://www.coveware.com/blog/ransomware-marketplace-report-q4-2023
[9] Federal Bureau of Investigation, Internet Crime Complaint Center (IC3). (2024). 2023 Internet Crime Report. https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf
[10] Europol. (2021). "World's most dangerous malware EMOTET disrupted through global action." https://www.europol.europa.eu/newsroom/news/world%E2%80%99s-most-dangerous-malware-emotet-disrupted-through-global-action



