Bulletproof
My server gets attacked every day. SSH brute-force attempts from IPs in Lithuania, Romania, Bulgaria, the Netherlands. Nine addresses banned this week alone. I looked up who owns them.
The answer is a category of business called bulletproof hosting. These are internet providers that exist specifically to host things nobody else will host. No KYC, no ID verification, no abuse complaints processed. You pay with crypto, you get a server. What you do with it is your problem.
The name is the business model. Bulletproof means the provider will not take your server down, no matter what. Spam, malware, ransomware, credential stuffing, DDoS botnets, child abuse material. They don't care. They don't log. They don't respond to law enforcement unless forced at gunpoint, and even then, the servers keep running somewhere else.
The companies on my firewall
Three IPs hitting my server belong to CIPHER OPERATIONS DOO, a Serbian company registered in Lithuania.[1] "DOO" is the Serbian LLC suffix. They operate from Belgrade but rent IP space in Vilnius, which means when Serbia gets an abuse report, they say the servers are in Lithuania. When Lithuania gets one, they say the company is Serbian. Nobody takes jurisdiction. This is not a bug. It is the design.
Two more IPs belong to UNMANAGED LTD in Timisoara, Romania. The name literally describes the service. "Unmanaged" means they don't monitor or police what runs on their servers. Two more from TECHOFF SRV in Amsterdam, likely Russian-operated, renting small VPS slices that get spun up, attack, get banned, and get replaced. One from TechTies Inc. in Sofia. One from BestDC Limited in Amsterdam. All small. All anonymous. All ignoring you.
You can rent from them right now. Go to their website, pay with crypto, get SSH credentials in minutes. Some don't even require an email address. This is not a darknet secret. It is a business model operating in plain sight.
Why nobody stops them
SSH brute-forcing sits in a legal gray zone. Scanning open ports and trying passwords is illegal in Germany and France but not clearly criminal in Serbia, Romania, or Russia. Even where it is illegal, nobody got hacked. Nobody lost money. A few thousand failed login attempts on a random server does not reach the threshold for a police report in most countries. Cyber police focus on actual breaches, fraud, and child abuse material.
The providers stay just barely on the legal side by calling themselves "infrastructure providers" who "don't control what customers run." It is the same legal fiction that protects a cash-only motel that doesn't check ID. Not illegal to operate. Everyone knows what the customers are there for.
Abuse reports are useless against these providers. That is the whole point of bulletproof hosting. You send a complaint to abuse@ and it goes nowhere. The legitimate providers, the ones like Hetzner, OVH, DigitalOcean, they suspend accounts caught scanning or brute-forcing within 24 hours. Bulletproof providers exist because they don't.
Stark Industries
The most notorious bulletproof host is a company called Stark Industries Solutions. It materialized two weeks before Russia invaded Ukraine in February 2022 and quickly became a top source of Kremlin-linked cyberattacks and disinformation campaigns.[2]
In May 2025, the European Union sanctioned Stark's owners, a pair of brothers in Moldova running a company called PQ Hosting. The EU said they were linked to Russia's hybrid warfare efforts. Twelve days before the sanctions were announced, Moldovan media leaked the upcoming sanctions. The brothers moved Stark's IP space to a new company called PQ Hosting Plus, rebranded the whole operation to "the.hosting" under a Dutch entity called WorkTitans BV, and kept going.[3]
In May 2026, Dutch police arrested the operators of WorkTitans and a related company called MIRhosting, seizing 800 servers. It did not matter. Stark's core IP address space survived. The infrastructure rotated to new shell companies and kept running. Dark Reading called it a raid that "failed to dent" the network.[4] Sanctioned, seized, still scanning.
Aeza Group
In July 2025, the U.S. Treasury Department sanctioned Aeza Group, a St. Petersburg-based bulletproof host that provided infrastructure to ransomware gangs like BianLian and the operators behind infostealing malware like RedLine, Lumma, and Meduza.[5] Aeza also helped BlackSprut, a Russian darknet drug marketplace, and was linked to the pro-Kremlin disinformation campaign known as Doppelganger, which has been pumping fake news into European media since 2022.
Multiple Aeza Group leaders were arrested by Russian authorities in April 2025 on suspicion of running a criminal organization and large-scale drug trafficking. The CEO was among those arrested. The sanctions, the arrests, the takedown, all of it happened. The infrastructure moved to new companies and kept running.
The Balkan pipeline
An investigation published just yesterday by the Balkan Investigative Reporting Network found that Russian-owned hosting firms are registering shell companies in Serbia and Montenegro to obscure the origins of cyberattacks and disinformation campaigns targeting Europe.[6]
One company, eServer, was registered in Krusevac, Serbia in April 2022, the same month Russian forces began their full-scale invasion. Its founder, a 43-year-old Russian, attended a conference at the Russian presidential administration led by Putin's former internet adviser. eServer's IP ranges subsequently passed to Stark Industries, then to Aeza Group, then to other sanctioned entities. The founder said his company "had no direct business relations with Stark Industries" and that "subnets roam between some providers." The subnets do roam. They roam from one sanctioned entity to the next, always landing somewhere that doesn't ask questions.
The investigation identified at least eight IP ranges that WorkTitans listed as located in Serbia, with Serbian Open Exchange serving as the internet gateway. These include ranges previously advertised by eServer. Former eServer ranges are now advertised by companies linked to Aeza Group and to FIN7, a hacking group responsible for mass financial theft and corporate extortion.
The war connection
Bulletproof hosting is not a side effect of the war in Ukraine. It is part of the war.
Stark Industries appeared two weeks before the invasion. It was not a coincidence. The infrastructure was pre-positioned. The same networks that host ransomware and credential stuffing botnets also host Russian disinformation campaigns, DDoS attacks against Ukrainian infrastructure, and proxy networks used by Russian intelligence. The lines between criminal enterprise and state operation do not exist in this space. They are the same infrastructure, the same providers, the same IP ranges rotating between the same shell companies.
When the EU sanctions a bulletproof host, the host rebrands. When Dutch police seize 800 servers, the IP space survives. When the U.S. Treasury sanctions the operators, new operators appear. The Western response has been whack-a-mole, and the mole is faster.
Russia uses these networks for military disinformation, for hacking campaigns against European governments, for ransomware attacks on critical infrastructure, and for the digital infrastructure of its war effort. Serbia and Montenegro, both outside EU sanctions enforcement, serve as convenient waypoints. Russian companies register shell firms in Belgrade and Podgorica, transfer IP ranges through them, and obscure the trail back to St. Petersburg and Moscow.
Meanwhile, the small operators keep hammering my server. Nine IPs, banned for SSH brute-force. They are not targeting me. They are scanning thousands of servers in parallel, looking for the one idiot who left root login enabled with password "123456." The botnet does not care about me. It does not care about anyone. It just runs.
The providers behind it do not care either. That is the point. That is the product.
Bulletproof means untouchable. And so far, it has been.
Sources
- IPinfo, AS215930 CIPHER OPERATIONS DOO BEOGRAD - NOVI BEOGRAD, RS. RIPE NCC registry, updated June 2026. ^
- Brian Krebs, "Stark Industries Solutions: An Iron Hammer in the Cloud," Krebs on Security, May 2024. ^
- Recorded Future, "One Step Ahead: Stark Industries Solutions Preempts EU Sanctions," 2025. ^
- Jai Vijayan, "Dutch Raid Fails to Dent Russian Bulletproof Host," Dark Reading, May 28, 2026. ^
- U.S. Department of the Treasury, "Treasury Sanctions Bulletproof Hosting Provider Aeza Group for Ransomware and Illicit Drug Facilitation," July 2025. ^
- Aleksa Tesic and Milos Katic, "Disposable IP Firms in Serbia, Montenegro Obscure Origins of Russian Cyber Meddling," Balkan Insight, September 9, 2026. ^