Security1 distinct publisher3 min readUpdated
Intel 471 says sanctions thinned the top tier of criminal hosting and upstarts filled the gap. The practical effect is that each takedown and each ASN block now covers less of the market.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Intel 471 reports that a year of sanctions and arrests has thinned the old guard of bulletproof hosting providers, and that the space they occupied has been taken by upstarts rather than left empty [1][15]. That changes the arithmetic behind every blocklist entry and every disruption operation: the same effort now covers a smaller share of a more fragmented market [21].
Bulletproof hosting providers lease infrastructure to criminals with a low risk of being shut down, using permissive policies, slow or absent abuse handling, jurisdictional insulation, reseller layers, frequent infrastructure rotation, and upstream relationships that make takedowns hard [2][3]. The customer workloads are the familiar ones: malware command-and-control, extortion negotiation portals and leak sites, phishing and credential-harvesting pages, carding shops and fraud panels, spam botnets, proxy and VPN services, and payload staging [4].
The incumbents had long records. Intel 471 says it has known yalishanda's real name since 2017 as Alexander Volosovik, and that his infrastructure hosted payloads for Hancitor, Dridex and various ransomware campaigns [6]. ccweb's fast-flux network hosted LockBit, Conti and Gozi ISFB activity plus credential-harvesting pages targeting Blockchain [7]. whost, also known as Mykhaylo Rytikov, served actors including Evgeniy Bogachev of GameOver Zeus and Vladimir Drinkman, linked to the Heartland Payment Systems and NASDAQ breaches [8]. Those three sat at the top tier [5].
Enforcement then landed in a cluster. On July 1, 2025 the U.S. Treasury sanctioned Aeza Group and its leaders over hosting for BianLian ransomware, the Lumma, Meduza and RedLine stealers, and the BlackSprut marketplace [16]. On November 19, 2025 the U.S., U.K. and Australia sanctioned yalishanda's Media Land along with ML Cloud, Media Land Technology and Data Center Kirishi, four named entities in one action, over support for LockBit, Black Basta, BlackSuit and Play [17][20]. The two actions fell 141 days apart [18].
What replaced them is more numerous and less legible. Intel 471 names MoreneHost, BEARHOST and AnonHost as newer providers that carved out market share, plus LuxProxy, selling HTTP and SOCKS proxies across residential, mobile, ISP/static, shared data center and data center IPv4 pools [9][10]. That is four named newer entrants against three named incumbents [19]. The write-up does not quantify total criminal hosting capacity, so the honest reading is displacement rather than proven reduction [23].
Fragmentation compounds a tenancy model that already defeats static indicators. Where the mid-2000s ecosystem, pioneered by the Russian Business Network, ran physical servers in weak-law jurisdictions, criminals now rent disposable virtual private servers, blend into legitimate cloud networks, and rotate IP addresses specifically to evade blocklists [11][12]. That rotation also lets them reroute traffic after a seizure with minimal customer downtime [13]. Intel 471 describes resilience through law enforcement action as a defining characteristic of leading providers, while noting they are not invulnerable and remain high-priority targets [14].
The detection consequence is that provider identity is the transient attribute and rotation is the durable one [22]. Inventories keyed to named providers and their ASNs decay as tenants move; behavioral signals such as rotation cadence, reseller-layer reuse and abuse-response latency survive the rename [3][22].
Watch whether sanctioned customers surface under new ASNs within weeks, and whether the next actions in the July 2025 to July 2026 window target upstream network relationships rather than individual providers [15][17].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Intel 471 states that the demise of an old guard of dominant bulletproof hosting providers has given rise to a new era of upstarts and a more fragmented competitive landscape.
Bulletproof hosting providers lease internet infrastructure to cybercriminals, allowing them to conduct activity with a low risk of being shut down.
BPH providers typically combine permissive policies, slow or absent abuse handling, jurisdictional insulation, reseller layers, frequent infrastructure rotation and relationships with upstream networks that make takedowns and disruptive action challenging.
BPH supports malware command-and-control servers, extortion negotiation portals and leak sites, phishing kits and credential-harvesting pages, carding shops, fraud panels, fake marketplaces and forums, spam botnets and mass-mailing infrastructure, proxy/VPN/anonymization services, and payload staging and malware download servers.
Long-standing BPH providers include yalishanda, ccweb and whost, described as the top tier of the market.
Intel 471 says it has known since 2017 that yalishanda's real name is Alexander Volosovik, and that his infrastructure hosted payloads for Hancitor, Dridex and various ransomware campaigns.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed vendor reporting, single publisher, no independent corroboration
The cluster contains one source: a threat-intelligence vendor blog with named providers, real-name attributions held since 2017, hosted malware families, two precisely dated multilateral sanctions actions and a dated court record. That is specific and internally consistent, but nothing is corroborated by a second publisher, primary designation documents are not in the cluster, and the central defensive conclusion about blocklist coverage is derived rather than measured.
Four observed market events; downstream market share unquantified
Real-world movement is observable: two sanctions actions, ccweb withdrawing to a private offering, and yalishanda's fast-flux service collapsing with customers abandoning it in April 2026. Named upstarts (MoreneHost, BEARHOST, AnonHost, LuxProxy) are said to have taken share. What is missing is any measure of how much capacity moved, where displaced customers landed, or what fraction of criminal hosting the new entrants now carry.
Slightly overstated: fragmentation asserted, not measured
The reporting is restrained by category standards — dated actions, explicit caveats that providers are resilient but not invulnerable, and an admission that ccweb's motives are unconfirmed. Still, the era-defining framing ('a new era', old guard demised) outruns the underlying data, which names three incumbents and four upstarts and never quantifies market share or hosting capacity. A modest positive gap reflects narrative reach exceeding measurement, not fabrication.
Vendor-owned channel with direct commercial stake in provider tracking
The sole publisher is a commercial threat-intelligence vendor publishing on its own blog, and the content — named provider inventories, actor real names, campaign linkage, an enforcement timeline — is the demonstration surface for the products it sells. The post does not disclose that interest. The incentive is toward emphasizing the difficulty of tracking fragmented providers, which is precisely the problem the vendor monetizes; it does not by itself imply the facts are wrong.
Moderate: specific and dated, but single-sourced and partly unverifiable
Confidence is held down by the single-publisher cluster, the vendor's commercial incentive, and reliance on non-public underground-forum and court-record observations that cannot be checked against the supplied material. It is held up by date-specific, externally checkable sanctions actions and by the vendor's willingness to flag its own uncertainty. The operational conclusions about behavioral detection remain unverified within the cluster.
security
New Zealand adds 33 names, including two Cyber Army of Russia Reborn operators1 distinct publisher
invest
Treasury moved $742 billion in a week. The price was a 5.216% thirty-year.1 distinct publisher
invest
IRS gives syndicated easements a permanent desk, and takes the settlement clock away1 distinct publisher
invest
IRS Swaps In FS-2026-14, Resetting The Working Text On The 163(j) Interest Cap1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026