Dutch Raid Fails to Dent Russian Bulletproof Host
A Dutch law enforcement operation targeting THE.Hosting, a bulletproof hosting network linked to Russian cybercrime, resulted in the seizure of 800 servers and arrests of two operators but failed to significantly disrupt the network's malicious activity. The network, which has repeatedly shifted its infrastructure and ASN to evade sanctions, continues to be used for activities such as botnet creation, cryptocurrency mining, and attacks on critical infrastructure, including ICS. This highlights the resilience of sophisticated cybercriminals and their ability to utilize complex network strategies to avoid takedown efforts.
On May 18, 2025, the Dutch Ministry of Finance’s fiscal crime service (FIOD) executed a raid resulting in the seizure of over 800 servers and the arrest of two individuals connected to THE.Hosting, a hosting provider identified as facilitating cybercriminal activity within the European Union. Despite this operation, the network’s scanning activity has remained largely unchanged, indicating a significant level of operational resilience. The operation targeted a bulletproof hosting network, a service that knowingly provides infrastructure to cybercriminals, often operating across multiple jurisdictions and ignoring abuse complaints. This type of infrastructure is frequently used to host malware, run botnets, and conduct attacks while avoiding detection and takedown efforts.
The network’s history is marked by a series of strategic shifts to evade sanctions, beginning with a Russian individual registrant, followed by transfers to Stark Industries Solution and PQ Hosting Plus S.R.L., ultimately rebranding as THE.Hosting and relocating to a new network, AS209847, under WorkTitans B.V. Threat intelligence firm ELLIO noted this behavior resembles a "relay race" designed to stay ahead of regulatory scrutiny. Recent scanning activity associated with THE.Hosting is particularly concerning due to its targeting of databases (MongoDB, Redis, PostgreSQL, Oracle) and industrial control systems (DNP3, EtherNet/IP), suggesting a potential threat to critical infrastructure sectors. Furthermore, the operators have been linked to DDoS attacks on European infrastructure and disinformation campaigns, including activity attributed to NoName057(16) and attacks on Danish government systems. The operation’s limited impact underscores the challenges faced by law enforcement in combating sophisticated, globally distributed cybercrime operations.
