logo

Abusive Bulletproof Hosting Networks Fuel Global Phishing Campaigns

ID: 96fa076d-227f-5403-8558-f3bae26c6c9e

STIX ID: report--96fa076d-227f-5403-8558-f3bae26c6c9e

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-30

Date Updated: 2026-05-30

Author: Ddos

...
...

Researchers report a large, multi-region phishing campaign distributing obfuscated JavaScript implants and using abusive, bulletproof hosting providers (GHOSTYNETWORKS and OMEGATECH/Virtualine) to host spam and command infrastructure; victims include financial and energy organizations across several countries. The report also documents overlap with other criminal operators (TeamPCP) and a supply-chain compromise of the PyPI LiteLLM package that delivered credential-stealing code, and it recommends blocking known rogue AS prefixes, enforcing application controls, and tightening email gateway protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.