logo

Bulletproof Hosting Providers Exploit Legitimate ISPs to Power Cybercrime Servers

ID: 3f34b2d0-10f6-5a7a-88c6-bb6f772c60df

STIX ID: report--3f34b2d0-10f6-5a7a-88c6-bb6f772c60df

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-06

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive summary:** Researchers discovered that ISPsystem VMmanager's default Windows hostnames are identical across thousands of servers; many of these machines are concentrated at abuse-tolerant "bulletproof" hosting providers and have been used as infrastructure by major ransomware gangs (WantToCry, LockBit, BlackCat/ALPHV, Conti, Qilin), creating both a useful fingerprint for detection and a large, anonymized pool that criminals exploit.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.