Bulletproof Hosting Providers Exploit Legitimate ISPs to Power Cybercrime Servers
ID: 3f34b2d0-10f6-5a7a-88c6-bb6f772c60df
STIX ID: report--3f34b2d0-10f6-5a7a-88c6-bb6f772c60df
Feed Name: GBHackers
Threat Score
**Executive summary:** Researchers discovered that ISPsystem VMmanager's default Windows hostnames are identical across thousands of servers; many of these machines are concentrated at abuse-tolerant "bulletproof" hosting providers and have been used as infrastructure by major ransomware gangs (WantToCry, LockBit, BlackCat/ALPHV, Conti, Qilin), creating both a useful fingerprint for detection and a large, anonymized pool that criminals exploit.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
