Bulletproof Hosting Providers Leverage Legitimate ISPsystem to Supply Servers for Cybercriminals
ID: 042a6356-eb84-551d-bdcf-dbadc6300fc1
STIX ID: report--042a6356-eb84-551d-bdcf-dbadc6300fc1
Feed Name: cybersecurityNews.com
Late in 2025, attackers rented virtual machines provisioned through ISPsystem/VMmanager and abused static VM templates and "bulletproof" hosting services to launch widespread ransomware campaigns (notably WantToCry, LockBit, BlackCat); analysts traced over 3,000 similarly configured servers across Russia, Europe, and the U.S., highlighting a supply-chain style abuse of legitimate hosting infrastructure and recommending removal of default templates and stronger identifier randomization.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
