Threats Tagged 'bulletproof hosting'
View all threats tagged with 'bulletproof hosting'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'bulletproof hosting'
Click on any threat for detailed analysis and mitigation recommendations
Over five months, four distinct malicious chains operated through the same bulletproof hosting provider, AS202412 registered to OMEGATECH LTD in Seychelles. All chains began with fake CAPTCHA pages (ClickFix technique) that instructed victims to paste commands into Windows Run dialogs. The campaigns used disposable domains with similar naming patterns, compromised legitimate websites, and varied infrastructure including cloud storage, blockchain-resolved C2 addresses, and trojanized installers. Despite different payloads and staging methods, every chain initiated contact through AS202412. The provider expanded from initial allocations to announcing twenty-four /24 prefixes during the observation period. Most browser contacts ended at the lure page without execution, but successful compromises deployed stealers and remote access tools with persistence mechanisms surviving system reboots. Join the discussion | AlienVault OTX General | 09/23/2026, 12:17:14 UTC Added: 09/23/2026, 13:47:50 UTC |
Illegal online gambling infrastructure spans three distinct cybercrime categories that defenders often overlook. First, over 1.7 million Chinese-language casino domains facilitate illegal gambling and transnational money laundering, primarily operated by triad-aligned syndicates. Second, thousands of "scambling" websites target global audiences with rigged games and withdrawal fraud, using deposit bonuses to lure victims. Third, China-aligned APT groups deploy the PeckBirdy malware framework within fake casino and adult websites as command-and-control infrastructure, targeting education, government, finance and technology sectors across Asia. These operations exploit U.S. and European hosting providers through infrastructure laundering while maintaining bulletproof Asian hosting. The campaigns have escalated sharply since 2023, with PeckBirdy domains achieving zero detection rates on VirusTotal. All three types appear visually identical, creating detection challenges for security teams. Join the discussion | AlienVault OTX General | 09/16/2026, 12:31:13 UTC Added: 09/16/2026, 13:01:39 UTC |
A Chinese web-development framework called DCloud Uni-App has become the technical foundation for over 236,000 scam domains since 2022, powering fake cryptocurrency exchanges, pig-butchering operations, wallet drainers, gambling platforms, and brand-impersonation sites. The framework gained prominence after the 2024 RainbowEx cryptocurrency scam in Argentina, which defrauded residents of San Pedro. Similar operations include the Lightning Shared Scooter Co. (LSSC) scam in the United States, which caused millions in losses across multiple states, and the currently-active Yuechi Sharing Technology Ltd. bicycle-sharing investment scam. These operations use legitimate hosting providers, with approximately 6% utilizing bulletproof hosting, particularly CTG Server. The scams target victims globally through WhatsApp, Telegram, and social media, converting victims into recruiters for pyramid-style operations. Enterprise exposure reaches over 985 distinct organizations across 25 industry verticals, with over five m... Join the discussion | AlienVault OTX General | 06/25/2026, 18:43:49 UTC Added: 06/26/2026, 08:31:07 UTC |
0 DriveSurge is a newly identified threat actor operating as an Initial Access Broker using a Pay-Per-Install model to supply victim leads to downstream actors. The actor has compromised thousands of websites, injecting malicious code that redirects visitors through zTDS (Traffic Distribution System) to deliver malware via two primary methods: FakeUpdates, which impersonate browser update prompts for Chrome, Firefox, Edge, Safari, and eight other browsers; and ClickFix, which tricks users into executing malicious PowerShell commands disguised as fixes. DriveSurge leverages sophisticated infrastructure including bulletproof hosting, obfuscated JavaScript injection patterns, and environment-specific targeting including macOS systems. The operation has been active since at least September 2025, utilizing specific technical fingerprints including unique file naming conventions and server configurations that enable detection and tracking of their evolving infrastructure. Join the discussion | AlienVault OTX General | 05/30/2026, 06:07:03 UTC Added: 06/01/2026, 09:48:36 UTC |
MioLab, also known as Nova, is a sophisticated Malware-as-a-Service platform targeting macOS environments, heavily advertised on Russian-speaking underground forums. The platform features extensive data exfiltration capabilities, including browser credential theft, cryptocurrency wallet targeting (supporting over 200 browser extensions and 50+ desktop wallets), and a premium module specifically designed to compromise Ledger and Trezor hardware wallets by intercepting 24-word BIP39 recovery seed phrases. The lightweight C-based payload supports both Intel and Apple Silicon architectures across macOS versions from Sierra to Tahoe. MioLab employs sophisticated social engineering through customizable DMG builders with live preview features, fake system prompts, and ClickFix integration. Recent updates demonstrate rapid development, including Safari cookie grabbing, automated Apple Notes decryption, and universal hardware wallet modules. The operation utilizes bulletproof hosting services and shares infrastruct... Join the discussion | AlienVault OTX General | 04/30/2026, 14:20:46 UTC Added: 05/04/2026, 11:36:22 UTC |
Fibergrid has operated as a bulletproof hosting provider for nearly a decade, currently hosting 16,700 active fraudulent e-commerce sites. The network exploits stolen African IPv4 address space worth $20-25 million, originally acquired through improper AFRINIC registrations. Despite claiming Seychelles-based operations, multilateration analysis reveals infrastructure concentrated in the United States, United Kingdom, Netherlands, Canada, and other Western countries, primarily within Equinix data centers. Fibergrid operates through a complex web of UK and Estonian shell companies using multiple autonomous systems to evade detection and enforcement. Fake shops constitute 70% of malicious activity on this infrastructure, targeting consumers through search engines and social media with counterfeit goods and payment fraud schemes. Disruption opportunities exist through upstream provider intervention, regional internet registry action, domain-level takedowns, and indicator sharing with security providers. Join the discussion | AlienVault OTX General | 04/27/2026, 16:16:01 UTC Added: 04/27/2026, 16:30:05 UTC |
Showing 1 to 6 of 6 results