Security News

Cybersecurity news aggregator

⚔️
HIGH Attacks Reddit r/netsec

A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate

The threat is a sanctioned Russian bulletproof hosting network, operating through a relay of shell companies and ASNs to evade sanctions and provide infrastructure for cyberattacks, disinformation, and influence operations targeting the EU. The attack vector involves the network providing high-capacity connectivity and colocation services to malicious actors, as evidenced by its continued scanning activity even after the seizure of its physical servers. The article does not provide details on a specific software vulnerability, CVSS score, affected versions, a fixed version, or a workaround.
Read Full Article →

Blog Threat/Vulnerability News Sanctioned, Seized, Still Scanning: Inside a Russian Bulletproof Hosting Network Targeting the EU May 27, 2026 7 min read ELLIO Threat Research Lab On 18 May 2026, Dutch investigators seized more than 800 servers and broke up a hosting operation that prosecutors say powered Russian cyberattacks across the EU. We had spent the previous year watching the same network from the other side. After the seizure, the scanning did not stop. The Takedown On 18 May 2026, the Dutch fiscal crime service FIOD seized more than 800 servers, along with laptops, phones and administrative records, in raids on data centres in Dronten and Schiphol-Rijk and searches of businesses in Enschede and Almere. Two people were arrested: a 57-year-old company director from Amsterdam, and a 39-year-old from The Hague who ran a separate firm supplying internet connectivity. De Volkskrant, which had been investigating the network , described them memorably as a consultant and a concert pianist. The target was a hosting operation that prosecutors say helped Russia run cyberattacks, influence operations and disinformation inside the European Union. The Dutch front was WorkTitans B.V., trading as THE.Hosting. A second Dutch company, Mirhosting in Almere, provided the colocation and the high-capacity connectivity into the Amsterdam and Frankfurt internet exchanges, the transport layer that carried the traffic into Europe. Danish authorities have tied the infrastructure to the pro-Russian hacktivist group NoName057(16) and to attacks on Danish government bodies during the November 2025 municipal elections. If those brand names look like a shell game, that is because they are. We had spent the previous year watching the same operation from the other side: the ELLIO deception network was logging the reconnaissance and mass-exploitation attempts coming from it, and not only from it. Here is what the takedown looked like from the inside, and the part that should worry defenders most. One operator, a parade of names The company history reads like a relay race run to stay ahead of sanctions: Stark Industries Solutions appeared two weeks before Russia invaded Ukraine and became a notorious bulletproof host. The EU sanctioned it, and the Moldovan Neculiti brothers behind it, on 20 May 2025. PQ Hosting Plus S.R.L. , a Moldovan entity, took over Stark's main network number just four days before the sanctions landed. THE.Hosting , announced nine days after the sanctions, runs on a brand-new autonomous system operated by the Dutch company WorkTitans B.V. In our honeypot telemetry, this corporate relay shows up cleanly as a migration across autonomous systems, the numbered networks that announce IP address space to the internet. + ---------- + -------------------------- + -------------------------------------------------------------- + | ASN | Organization | Role | + ---------- + -------------------------- + -------------------------------------------------------------- + | AS44477 | Pq Hosting Plus S . r . l . | the original Stark network , relabelled to PQ after sanctions | | AS209847 | WorkTitans B . V . | THE . Hosting , the post - sanction primary | | AS213999 | WorkTitans B . V . | THE . Hosting , a secondary | | AS33993 | UFO Hosting LLC ( Moscow ) | a steady , 100 percent Russia - based side channel | + ---------- + -------------------------- + -------------------------------------------------------------- + When we saw each one, and the handoff The honeypot data gives precise first and last sightings. AS44477 was already active when our tracking window opened, so its true start is older than the dates shown here. + ------------------------ + ------------------ -+ -------------- -+ -------------------------- -+ | ASN | First seen | Last activity | Last 90 days | + ------------------------ + ------------------ -+ -------------- -+ -------------------------- -+ | AS44477 ( Stark / PQ ) | before 2025 - 01 - 01 | October 2025 | nothing | | AS209847 ( THE . Hosting ) | 2025 - 08 - 05 | 2026 - 05 - 26 | active , ~ 107 distinct IPs | | AS213999 ( THE . Hosting ) | 2026 - 03 - 29 | 2026 - 04 - 25 | dormant | | AS33993 ( UFO , Moscow ) | 2025 - 04 - 16 | 2026 - 05 - 24 | low | + ------------------------ + ------------------ -+ -------------- -+ -------------------------- -+ The old Stark/PQ network ( AS44477 ) carried the scanning all through the summer of 2025, then threw one last enormous punch: on 30 August 2025, more than 7,300 distinct addresses from AS44477 swept our sensors in a single day, mostly on web and SSH ports. Within weeks it went quiet. By November its primary run was over, and we have seen nothing genuine from it since. Its address blocks did not vanish, though. At almost the same moment, the new THE.Hosting network ( AS209847 ) woke up. It first touched our sensors on 5 August 2025, then climbed fast, peaking in November and December 2025 at over two million scanning sessions a month. The baton passed in plain ...

Share this article