Security1 publisher3 min readPublished
Bulletproof hosting got smaller, not scarcer: what fragmentation costs your blocklist
Intel 471 says sanctions thinned the top tier of criminal hosting and upstarts filled the gap. The practical effect is that each takedown and each ASN block now covers less of the market.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Intel 471 states that the demise of an old guard of dominant bulletproof hosting providers has given rise to a new era of upstarts and a more fragmented competitive landscape.
- Bulletproof hosting providers lease internet infrastructure to cybercriminals, allowing them to conduct activity with a low risk of being shut down.
- BPH providers typically combine permissive policies, slow or absent abuse handling, jurisdictional insulation, reseller layers, frequent infrastructure rotation and relationships with upstream networks that make takedowns and disruptive action challenging.
- BPH supports malware command-and-control servers, extortion negotiation portals and leak sites, phishing kits and credential-harvesting pages, carding shops, fraud panels, fake marketplaces and forums, spam botnets and mass-mailing infrastructure, proxy/VPN/anonymization services, and payload staging and malware download servers.
- Long-standing BPH providers include yalishanda, ccweb and whost, described as the top tier of the market.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Intel 471 reports that a year of sanctions and arrests has thinned the old guard of bulletproof hosting providers, and that the space they occupied has been taken by upstarts rather than left empty [1][15]. That changes the arithmetic behind every blocklist entry and every disruption operation: the same effort now covers a smaller share of a more fragmented market [21].
Bulletproof hosting providers lease infrastructure to criminals with a low risk of being shut down, using permissive policies, slow or absent abuse handling, jurisdictional insulation, reseller layers, frequent infrastructure rotation, and upstream relationships that make takedowns hard [2][3]. The customer workloads are the familiar ones: malware command-and-control, extortion negotiation portals and leak sites, phishing and credential-harvesting pages, carding shops and fraud panels, spam botnets, proxy and VPN services, and payload staging [4].
The incumbents had long records. Intel 471 says it has known yalishanda's real name since 2017 as Alexander Volosovik, and that his infrastructure hosted payloads for Hancitor, Dridex and various ransomware campaigns [6]. ccweb's fast-flux network hosted LockBit, Conti and Gozi ISFB activity plus credential-harvesting pages targeting Blockchain [7]. whost, also known as Mykhaylo Rytikov, served actors including Evgeniy Bogachev of GameOver Zeus and Vladimir Drinkman, linked to the Heartland Payment Systems and NASDAQ breaches [8]. Those three sat at the top tier [5].
Enforcement then landed in a cluster. On July 1, 2025 the U.S. Treasury sanctioned Aeza Group and its leaders over hosting for BianLian ransomware, the Lumma, Meduza and RedLine stealers, and the BlackSprut marketplace [16]. On November 19, 2025 the U.S., U.K. and Australia sanctioned yalishanda's Media Land along with ML Cloud, Media Land Technology and Data Center Kirishi, four named entities in one action, over support for LockBit, Black Basta, BlackSuit and Play [17][20]. The two actions fell 141 days apart [18].
What replaced them is more numerous and less legible. Intel 471 names MoreneHost, BEARHOST and AnonHost as newer providers that carved out market share, plus LuxProxy, selling HTTP and SOCKS proxies across residential, mobile, ISP/static, shared data center and data center IPv4 pools [9][10]. That is four named newer entrants against three named incumbents [19]. The write-up does not quantify total criminal hosting capacity, so the honest reading is displacement rather than proven reduction [23].
Fragmentation compounds a tenancy model that already defeats static indicators. Where the mid-2000s ecosystem, pioneered by the Russian Business Network, ran physical servers in weak-law jurisdictions, criminals now rent disposable virtual private servers, blend into legitimate cloud networks, and rotate IP addresses specifically to evade blocklists [11][12]. That rotation also lets them reroute traffic after a seizure with minimal customer downtime [13]. Intel 471 describes resilience through law enforcement action as a defining characteristic of leading providers, while noting they are not invulnerable and remain high-priority targets [14].
The detection consequence is that provider identity is the transient attribute and rotation is the durable one [22]. Inventories keyed to named providers and their ASNs decay as tenants move; behavioral signals such as rotation cadence, reseller-layer reuse and abuse-response latency survive the rename [3][22].
Watch whether sanctioned customers surface under new ASNs within weeks, and whether the next actions in the July 2025 to July 2026 window target upstream network relationships rather than individual providers [15][17].