Advertisement

U.S. Sanctions Russian Bulletproof Internet hosting Supplier for Supporting Cybercriminals Behind Ransomware


Thank you for reading this post, don't forget to subscribe!

Jul 02, 2025Ravie LakshmananCybercrime / Darkish Internet

Russian Bulletproof Hosting

The U.S. Division of the Treasury’s Workplace of International Property Management (OFAC) has levied sanctions towards Russia-based bulletproof internet hosting (BPH) service supplier Aeza Group to help menace actors of their malicious actions and concentrating on victims within the nation and the world over.

The sanctions additionally prolong to its subsidiaries Aeza Worldwide Ltd., the U.Okay. department of Aeza Group, in addition to Aeza Logistic LLC, Cloud Options LLC, and 4 people linked to the corporate –

  • Arsenii Aleksandrovich Penzev, CEO and 33% proprietor of Aeza Group
  • Yurii Meruzhanovich Bozoyan, basic director and 33% proprietor of Aeza Group
  • Vladimir Vyacheslavovich Gast, technical director who works intently with Penzev and Bozoyan
  • Igor Anatolyevich Knyazev, 33% proprietor of Aeza Group who manages the operations within the absence of Penzev and Bozoyan
Cybersecurity

It is price noting that Penzev was arrested in early April 2025 on expenses of main a prison group and enabling large-scale drug trafficking by internet hosting BlackSprut, a bootleg medication market on the darkish internet. Bozoyan and two different Aeza staff, Maxim Orel and Tatyana Zubova, had been additionally detained.

“Cybercriminals proceed to rely closely on BPH service suppliers like Aeza Group to facilitate disruptive ransomware assaults, steal U.S. know-how, and promote black-market medication,” mentioned Appearing Beneath Secretary of the Treasury for Terrorism and Monetary Intelligence Bradley T. Smith.

“Treasury, in shut coordination with the U.Okay. and our different worldwide companions, stays resolved to show the important nodes, infrastructure, and people that underpin this prison ecosystem.”

BPH providers have been godsend for menace actors as they’re recognized to intentionally ignore abuse experiences and regulation enforcement takedown requests, usually working in international locations with weak enforcement or deliberately imprecise authorized requirements. This makes them a resilient possibility for attackers to host their malicious infrastructure, together with phishing websites and command-and-control (C2) servers, with out disruption or penalties.

Headquartered in St. Petersburg, Aeza Group is accused of leasing its providers to varied ransomware and data stealer households, equivalent to BianLian, RedLine, Meduza, and Lumma, a few of which have been used to focus on U.S. protection industrial base and know-how corporations and different victims worldwide.

What’s extra, a report printed by Correctiv and Qurium final July detailed using Aeza’s infrastructure by the pro-Russian affect operation dubbed Doppelganger. One other menace actor that has availed the providers of Aeza is Void Rabisu, the Russia-aligned menace actor behind RomCom RAT.

Cybersecurity

The event comes practically 5 months after the Treasury sanctioned one other Russia-based BPH service supplier named Zservers for facilitating ransomware assaults, equivalent to these orchestrated by the LockBit group.

Final week, Qurium additionally linked a Russian website hosting and proxy supplier named Biterika to distributed denial-of-service (DDoS) assaults towards two Russian unbiased media shops IStories and Verstka.

These sanctions kind a part of a broader effort to dismantle the ransomware provide chain by concentrating on important enablers like malicious internet hosting, C2 servers, and darkish internet infrastructure. As menace actors shift techniques, monitoring sanctioned entities, IP popularity scores, and abuse-resilient networks is changing into central to trendy menace intelligence operations.

Discovered this text fascinating? Comply with us on Twitter and LinkedIn to learn extra unique content material we put up.