Skip to content

Image: intel471.com · rights & removal

Executive Summary

The bulletproof hosting (BPH) landscape is undergoing a significant shift due to the decline of established providers, leading to increased fragmentation among upstart service offerings. BPH historically provided infrastructure used by cybercriminals for various illicit activities, including malware C2 servers, phishing kits, and fraud marketplaces. Long-standing providers like yalishanda, ccweb, and whost were key players, supporting high-profile criminal operations.
Recent law enforcement actions, including sanctions on entities and individuals, have caused disruptions and forced changes among these providers. For example, yalishanda faced sanctions on November 19, 2025, affecting its affiliated companies. Disruptions led to customer migration, with some domains moving to established infrastructure like Cloudflare or Akamai, indicating an attempt by adversaries to maintain operational continuity despite service interruptions.
Newer, upstart providers such as MoreneHost, BEARHOST, AnonHost, OtusCloud, fluxy, and reming have emerged to fill the void. These newer entities often operate with different infrastructure mixes and business models, sometimes leveraging or overlapping with previous BPH services, suggesting an ecosystem where displaced capacity is being rapidly absorbed by new actors.
The overall trend points toward a more fragmented market where operational disruptions lead not to elimination but to redistribution of customer bases, forcing continued evolution in the abuse-resistant infrastructure space.

Facts Only

* BPH providers lease internet infrastructure to cybercriminals.
* BPH providers typically use permissive policies, slow or absent abuse handling, and jurisdictional insulation.
* BPH supports activities such as malware C2 servers, extortion portals, phishing kits, carding shops, spam botnets, and VPN services.
* Long-standing BPH providers include yalishanda, ccweb, and whost.
* yalishanda provided infrastructure for Hancitor, Dridex, and ransomware campaigns.
* ccweb's network hosted LockBit, Conti, and Gozi ISFB campaigns.
* whost facilitated operations linked to Evgeniy Bogachev and Vladimir Drinkman.
* LuxProxy offered various internet protocol proxies (residential, mobile, etc.).
* The BPH ecosystem began in the mid-2000s with pioneers like the Russian Business Network (RBN).
* Cybercriminals now typically rent VPSs leveraging cloud infrastructure for IP rotation and evasion.
* Disruptions occurred between July 2025 and July 2026 due to law enforcement operations.
* On July 1, 2025, the U.S. Treasury sanctioned Aeza Group and its leaders for hosting malware and marketplaces.
* On November 19, 2025, the U.S., U.K., and Australia imposed sanctions against yalishanda and affiliated companies.
* Feelthereal filed a complaint against yalishanda in late April 2026 regarding service downtime.
* The U.S. FBI announced Operation Riptide in June 2026 targeting cybercriminal actors and their infrastructure.
* An indictment was unsealed on July 14, 2026, charging Volosovik and others for malicious cyber activity.
* Fluxy launched the VIP FAST FLUX BPH service in late March 2026.
* Infrastructure impact analysis showed that 80% of yalishanda’s customer domains remained active after the actor's disappearance.
* The top destination for migrating domains was Cloudflare Inc. with 84 domains.

Full Take

The narrative presented suggests that infrastructure disruptions targeting established BPH providers primarily result in operational relocation rather than systemic eradication of malicious activity. The core implication is that law enforcement actions against operators may cause temporary service interruptions but do not dismantle the underlying criminal capacity, as evidenced by the 80% retention rate of customer domains after yalishanda's removal and subsequent sanctions. This points to an ecosystem resilience where actors prioritize continuity over dependence on specific infrastructure.
The shift toward fragmentation, marked by the rise of services like fluxy and reming, demonstrates a dynamic competitive response. These upstarts exploit the vacuum created by established provider instability, effectively redistributing demand among actors who possess existing operational assets or reseller relationships. This suggests that the "demise" of old guard providers accelerates an internal reallocation within the criminal supply chain rather than halting it.
The recommendation to track infrastructure clusters rather than individual IPs directly challenges the traditional focus on single points of failure and moves the analytical lens toward systemic continuity. If disruption is often followed by migration to seemingly legitimate providers like Cloudflare, the analysis must pivot from judging the infrastructure itself as purely malicious to understanding its functional utility within a broader spectrum of risk management. This requires questioning whether the operational effectiveness of law enforcement lies in seizing assets or constraining upstream dependencies, and what responsibility remains when continuity is maintained through alternative channels.
Bridge Questions: If infrastructure disruption often leads to migration to legitimate services, does this shift fundamentally change how authorities should approach tracing criminal intent when physical seizure fails? What mechanisms exist for monitoring the activity on these newly adopted, seemingly benign hosting platforms? How can analysis effectively map ownership and influence across disparate, rotating digital assets that are deliberately obscured?

From the original · Intel 471 Blog

The demise of an old guard of dominant bulletproof hosting providers has given rise to a new era of upstarts — and a more fragmented competitive landscape. Bulletproof hosting providers (BPH) lease internet infrastructure to cybercriminals.
Read the full story at intel471.com

Sentinel — Human

Confidence

This text reads like a detailed forensic report synthesized from investigative work, blending specific incident data with macro-level pattern analysis and actionable recommendations.

Signals Detected
low severity: Sentence length and rhythm show variation typical of analytical writing, not uniform AI cadence.
low severity: The text flows logically from defining the BPH ecosystem to detailing specific incidents, analysis of migration trends, and concluding with recommendations, showing a structured analytical path.
low severity: Specific dates, names (Intel 471, Yalishanda, etc.), sanctions, and observed data points suggest grounded reporting or detailed synthesis rather than simple pattern matching.
medium severity: The dense inclusion of specific, dated law enforcement actions and infrastructure details suggests reliance on sourced intelligence, though the specific dates (July 2025-2026) require external validation.
Human Indicators
The embedded narrative structure that transitions from descriptive facts to forensic analysis and forward-looking recommendations exhibits a characteristic of human-led investigative reporting or deep technical analysis.
The nuanced hedging regarding causation (e.g., 'It is possible the actions against other illicit service providers influenced ccweb’s decision') demonstrates a critical, speculative reasoning process typical of human analysts.
A New Era of Bulletproof Hosting Providers Emerge | Huntaegis