AEZA GROUP
St. Petersburg-based bulletproof hosting provider // successor to MskHost // OFAC / UK / AU sanctioned // core leadership arrested in Russia // infrastructure migrated to Hypercore (AS211522) post-sanctions
Degraded

Executive Summary and Provider Overview

Sanctioned and Indicted Operators - Escalated Module
Arsenii A. Penzev
CEO / 33% owner (OFAC)
DOB: 27 Oct 2002 (age 21 at arrest)
Location: Pre-trial detention, Moscow
Charges: RF Arts. 210 & 228.1
Tax ID: 780721423242 (RU)
OFAC · UK - Jul/Sep 2025 RU Detention - Apr 2025
Yurii M. Bozoyan
General Director / 33% owner (OFAC)
DOB: 30 Jan 1992
Location: Pre-trial detention, Moscow
Prior: Founder of MskHost (~2019)
Tax ID: 780538991581 (RU)
OFAC · UK - Jul/Sep 2025 RU Detention - Apr 2025
Vladimir V. Gast
Technical Director (OFAC)
DOB: 6 May 1999
Location: Detained (Apr 2025)
Role: Internal network; DDoS/botnet lead
Tax ID: 860243420832 (RU)
OFAC · UK - Jul/Sep 2025 RU Detention - Apr 2025
Igor A. Knyazev
33% owner / acting director (OFAC)
DOB: 26 Jul 1986
Location: At large (Russia)
Status: Not criminally charged in RU
Tax ID: 780532513677 (RU)
OFAC · UK - Jul/Sep 2025
Maksim V. Makarov
New Director (post-arrest)
DOB: 23 Mar 1989
Location: At large (Russia)
Role: Directed sanctions-evasion decisions
Tax ID: 244309586068 (RU)
OFAC · UK - Nov 19, 2025
Ilya V. Zakirov
Associate (successor infrastructure)
DOB: 20 Nov 1999
Location: At large (Russia)
Role: New companies / payment channels
Tax ID: 165504427793 (RU)
OFAC - Nov 19, 2025
Degraded
Operational Status
AS210644
Primary Delivery ASN
~100k+
IPv4 (Ecosystem)
3
Sanctioning Authorities
6
Individuals Sanctioned
3
Founders Detained (RU)
ASN-DROP
Spamhaus (AS210644)
2019
Lineage Origin (MskHost)

Quick-Reference Attributes

Common NamesAeza; Aeza Group; AezaNet; aeza.net / aeza.ru; ООО АЕЗА ГРУПП
Node TypeBulletproof Hosting Provider
StatusDegraded - core brand offline post-July 2025 sanctions; three founders in RU pre-trial detention; infrastructure migrated to Hypercore (AS211522) and successor shells; assessed partially operational in Europe as of December 2025. [1][2][10][14]
Entity Registration JurisdictionRussia (RU) - Aeza Group LLC, TIN 7813654490, St. Petersburg (parent). United Kingdom (UK) - Aeza International Ltd (Co. 15109642) and Hypercore Ltd (Co. 16558658). Also Serbia (Smart Digital Ideas DOO) and Uzbekistan (Datavice MCHJ) as successor shells. [1][2][3]
Infrastructure Hosting JurisdictionPrimary European footprint in Sweden, Netherlands, and Germany (aurologic GmbH data center, Langen; Hetzner resale); directly controlled nodes in Moscow and St. Petersburg, Russia. [10][11][14][15]
Assessed Operator LocationRussia - all six designated operators are Russian nationals; three are in Moscow pre-trial detention, three at large in Russia. [1][2][3]
Active PeriodAeza Group LLC incorporated 17 Jun 2021 (marketed launch 26 Dec 2021); predecessor MskHost ~2019 to Sep 2021. [15]
Primary ASNsAS210644 (Aeza International, primary European delivery); AS216246 (Aeza Group LLC, RU); AS211522 (Hypercore Ltd, post-sanctions successor). [10][16]
Upstream TransitAS30823 aurologic GmbH (Germany, primary European upstream + colocation); AS24940 Hetzner (server resale); AS6939 Hurricane Electric; AS8218 Zayo. [11][14]
Abuse Contactabuse@aeza.net / abuse@aeza.ru (RIPE record, AS210644); support via @aezasupport_bot (Telegram). [16]
SanctionsSANCTIONED OFAC SDN (1 Jul 2025 and 19 Nov 2025); UK FCDO/OFSI (19 Sep 2025 and 19 Nov 2025); Australia DFAT (19 Nov 2025). EU: no designation as of December 2025. [1][2][5][14]
Blocklist StandingSpamhaus ASN-DROP: AS210644 LISTED ("under control of cyber-criminals"); 3,000+ ThreatFox IOCs on AS210644 over 12 months. [16][23]
Designated CryptoTU4tDFRvcKhAZ1jdihojmBWZqvJhQCnJ4F (TRON), OFAC-designated 1 Jul 2025; $350k+ received; Garantex pathway. [3][7][8]
State Nexus TierProbable Cooperation (Tier 3 of 4) - assessed; based on confirmed bulletproof hosting for the Social Design Agency (SDA) / Doppelgänger and ~4 years of non-enforcement in Russia. [5][12][13]

Overall Assessment

Aeza Group is a St. Petersburg-based bulletproof hosting (BPH) provider that presented publicly as a low-cost, high-performance VPS/VDS and dedicated-server business while functioning as core infrastructure for ransomware, infostealer, darknet-market, and Russian state-aligned disinformation operations. OFAC, which designated the group on 1 July 2025, described Aeza as a BPH service that "allows cybercriminals to avoid law enforcement while renting IP addresses, servers and domains" and specifically named the Meduza and Lumma infostealer operators, BianLian ransomware, RedLine infostealer panels, and the BlackSprut darknet drug marketplace as hosted activity. [1]

The provider is the assessed successor to MskHost, a predecessor BPH brand founded circa 2019 by Yurii Bozoyan and taken offline by hacktivists in September 2021. Aeza Group LLC was incorporated in June 2021 with Bozoyan, Arsenii Penzev, and Igor Knyazev each holding 33%. Its business model deliberately routed criminal clients through a downstream reseller chain (LetHost, ZeroHost, and others), which advertised the "bulletproof" property to end users while Aeza maintained plausible deniability at the core ASN level. [1][14][15]

Aeza is assessed as Degraded rather than defunct. Russian authorities arrested Penzev, Bozoyan, and Gast in February/April 2025 (charged with narcotics and organized-crime offenses tied to BlackSprut, not cybercrime), and OFAC/UK/Australia sanctions followed. Within nineteen days of the July 2025 OFAC action, Silent Push detected roughly 2,100 IP addresses migrating from AS210644 to the newly registered AS211522 (Hypercore Ltd), and the November 2025 tri-lateral action designated Hypercore plus Serbian and Uzbek successor shells and two additional operators (Makarov, Zakirov). The European Union imposed no sanctions, and Recorded Future described Aeza as "one of the most significant sources of malicious infrastructure" as recently as November 2025. The single largest structural leverage point remains the group's dependency on German upstream aurologic GmbH for its European footprint. [2][10][11][14]

Lineage and Organizational Heritage

Predecessor and Sibling Analysis

Aeza is assessed as the direct successor to MskHost (MSK.host), a bulletproof and abuse-tolerant hosting provider founded circa 2019 by Yurii Bozoyan and known for launching DDoS attacks against competing hosts. MskHost was taken offline by hacktivists "who had enough" in September 2021, per researcher compilation at aeza-gang.com and corroborating forum records. The same operator pool, principally Bozoyan and Penzev, incorporated Aeza Group LLC on 17 June 2021 and marketed a public launch date of 26 December 2021. [15]

MskHost → Aeza Lineage: CONFIRMED

Confirmed Four independent evidentiary pillars support this lineage: (1) Infrastructure continuity - shared server hardware patterns (Threadripper 3990X, later i9-14900K) appearing at MskHost-linked LetHost; (2) Personnel continuity - Bozoyan confirmed as founder of both, Penzev present at Aeza founding; (3) Forum corroboration - multiple LowEndTalk / searchengines.guru participants stated "mskhost стал aeza" (MskHost became Aeza), and one user told Aeza directly in 2024 "I lost a lot of money because of your past project MskHost"; (4) Client migration - MskHost clients migrated to Aeza. [15][18][19]

Brand, Entity, and Sibling Structure

Entity / BrandJurisdiction / IdentifierRoleActive WindowConfidence
MskHost (MSK.host)RussiaPredecessor BPH brand; owner Bozoyan~2019 – Sep 12, 2021Confirmed
Aeza Group LLC (ООО АЕЗА ГРУПП)Russia; TIN 7813654490; AS216246Russian parent entityJun 17, 2021 – presentConfirmed
Aeza International LtdUK; Co. 15109642; AS210644UK front; leases IP to cybercriminals per OFACSep 1, 2023 – presentConfirmed
Aeza Logistic LLCRussia; TIN 7810965578100%-owned subsidiarySep 27, 2024 – presentConfirmed
Cloud Solutions LLC (Облачные Решения)Samara, Russia; TIN 6312219617100%-owned subsidiaryJul 23, 2024 – presentConfirmed
Hypercore LtdUK; Co. 16558658; AS211522Post-sanctions successor infrastructure vehicleJul 2025 – present (designated Nov 19, 2025)Confirmed
Smart Digital Ideas DOOBelgrade, Serbia; TIN 113294246Successor shell2025 (designated Nov 19, 2025)Confirmed
Datavice MCHJTashkent, Uzbekistan; TIN 312252645Successor shellJul 2025 (designated Nov 19, 2025)Confirmed
Shelter LLCRussia; TIN 5049025855; AS211409Ecosystem-linked; hosted Lumma/Meduza/Mystic C2Researcher-identifiedCredible
TNSecurity LtdUK; Co. 15103352Reseller/distributor; "prefix swapping with AEZA"; owner Anastasija Berezina (Latvia)Researcher-identifiedCredible
Liber SystemsUK; Co. 11405895Managed 2nd-level domains for Doppelgänger networkResearcher-identifiedCredible
LetHost / ZeroHostRussiaDownstream resellers on Aeza hardware; advertised "bulletproof"~2022 – 2024Credible

Additional UK entities identified by researchers as part of the network include AEZA GROUP LIMITED (Co. 15065828), AEZATRADE LIMITED (Co. 15172068), and QWINS LTD (Co. 16072422). Researcher-identified sibling ASNs include AS210352 (Partner LLC), AS211409 (Shelter LLC), AS209224 (CYBERHUB-AS), and AS216319 (CHROMIS IT LTD). [15]

Operator Profiles

Six individuals have been sanctioned across the July and November 2025 actions; three were arrested by Russian law enforcement in early 2025. All are Russian nationals. The escalated operator module appears above the fold in Section 01. Detailed profiles follow.

2.1 Yurii Meruzhanovich Bozoyan

Handles / Aliases"Yuri Bozoyan"; general director; no confirmed public pseudonym
DOB / Nationality30 January 1992; Russian
Current LocationPre-trial detention, Moscow (since April 2025)
RoleGeneral Director; 33% owner; founder of predecessor MskHost (~2019)
Legal StatusArrested April 2025; charged under RF Articles 210 (organized criminal group) and 228.1 (drug trafficking); faces up to 20 years
SanctionsOFAC SDN 1 Jul 2025 (Tax ID 780538991581); UK 19 Sep 2025. OFAC basis: "helped manage the finances of Aeza Group and was similarly arrested for his involvement in Blacksprut."
NotesBefriended Penzev 2018–2019 when the then-16-year-old Penzev proposed renting servers; invested 400,000 rubles as founding partner. Court published photos of Bozoyan in a detention cell.

2.2 Arsenii Aleksandrovich Penzev

Handles / Aliases"Arseny Penzev"; email aezagroup@gmail.com; domain aezadns.com
DOB / Nationality27 October 2002; Russian (age 21 at arrest)
Current LocationPre-trial detention, Moscow (since April 2025)
AddressLeninskiy str. 64, 1, A, 766, St. Petersburg 198335, Russia
RoleCEO; 33% owner
Legal StatusArrested April 2025; charged under RF Articles 210 and 228.1
SanctionsOFAC SDN 1 Jul 2025 (Tax ID 780721423242); UK 19 Sep 2025. OFAC basis: "has been involved in multiple bulletproof hosting and illicit drug marketplace businesses"; arrested for placement of BlackSprut onto Aeza infrastructure.
NotesYoungest operator; publicly represented Aeza as legitimate and apolitical in the mid-2024 VSquare interview and claimed the group responded to all complaints.

2.3 Vladimir Vyacheslavovich Gast

Handles / AliasesNone confirmed (myrotvorets.center profile exists)
DOB / Nationality6 May 1999; Russian
Current LocationDetained (arrested April 2025)
RoleTechnical Director; manages internal network; DDoS/botnet lead
Legal StatusArrested April 2025; charged
SanctionsOFAC SDN 1 Jul 2025 (Tax ID 860243420832); UK 19 Sep 2025. OFAC basis: "manages Aeza Group's internal network and oversaw the technical details of placing Blacksprut on Aeza Group infrastructure."
NotesDescribed by researchers as "the key link" in Aeza DDoS operations; "together with Penzev … created and use botnets." DDoS attacks attributed to Aeza reportedly continued after his arrest, indicating other accomplices remain active.

2.4 Igor Anatolyevich Knyazev

Handles / AliasesNone confirmed
DOB / Nationality26 July 1986; Russian
Current LocationAt large (Russia)
Role33% owner; acting director during absence of Bozoyan and Penzev
Legal StatusNot criminally charged in Russian proceedings (per available information); OFAC-designated
SanctionsOFAC SDN 1 Jul 2025 (Tax ID 780532513677); UK 19 Sep 2025. OFAC basis: "is managing the company during the absence of Penzev and Bozoyan."
NotesHeld operational control during the critical post-arrest period before the July 2025 sanctions.

2.5 Maksim Vladimirovich Makarov

Handles / AliasesNone confirmed
DOB / Nationality23 March 1989; Russian
Current LocationAt large (Russia)
RoleNew Director of Aeza (installed after original leadership arrested)
SanctionsOFAC SDN 19 Nov 2025 (Tax ID 244309586068; Passport 772555187); UK 19 Nov 2025. OFAC basis: "new director of Aeza" who "made key decisions regarding Aeza Group's attempt to evade sanctions."

2.6 Ilya Vladislavovich Zakirov

Handles / AliasesNone confirmed
DOB / Nationality20 November 1999; Russian
Current LocationAt large (Russia)
RoleAssociate; established successor companies and payment channels
SanctionsOFAC SDN 19 Nov 2025 (Tax ID 165504427793). OFAC basis: "helped establish new companies and payment methods to obfuscate Aeza's continuing activity."

Non-Designated Front Persons

Marat Timurov (Uralsk, M. Ihsanov str. 45, Kazakhstan) is identified by researchers as the nominal front person for Aeza International Ltd (UK Co. 15109642); not OFAC-designated as of the record date. Separately, open reporting attributes the registration of Hypercore Ltd to a "Patryk Drozda" two days after the July 2025 sanctions. [SINGLE SOURCE] This registrant name should be treated as CREDIBLE pending Companies House corroboration; it does not appear in the OFAC designation text. [15]

Disputed Assessments

Penzev publicly disputed the Doppelgänger and state-nexus allegations (see Section 03 verbatim copy), and Aeza's official agent characterized reseller connections (LetHost/ZeroHost) as mere IP-transit relationships terminated after complaints. These claims are contradicted by (a) OFAC's finding that Bozoyan and Penzev "began to provide Blacksprut with services in 2023," and (b) forum evidence of identical server hardware appearing simultaneously at Aeza and the resellers. The name "Yuri" vs. "Yurii" for Bozoyan varies between OFAC (Yurii) and secondary reporting; treated as the same individual. [1][14][15]

Operational and Business Model

Service Model

Aeza publicly marketed itself as a high-performance, affordable VPS/VDS and dedicated-server provider for legitimate customers, developers, and VPN users. Advertised products included KVM VPS on AMD Ryzen 9 7950X3D/9950X with NVMe storage from roughly €4.94/month, dedicated Threadripper and i9-class servers from about €200/month, anti-DDoS on all plans, and locations spanning Moscow, St. Petersburg, Stockholm, Helsinki, Amsterdam, Vienna, Paris, Frankfurt/Falkenstein, London, Hong Kong, and Los Angeles. Behind this commercial face, OFAC assessed Aeza as a de facto BPH provider that "allows cybercriminals to avoid law enforcement while renting IP addresses, servers and domains used for disseminating malware, supporting darknet markets and carrying out other tasks related to fraud and cyberattacks." [1]

Plausible deniability was maintained by routing malicious clients through a downstream reseller chain rather than direct onboarding (see reseller chain below). This architecture is the primary mechanism by which Aeza insulated its core ASNs from direct attribution. [1][14]

Verbatim Advertising Copy

LowEndTalk - official Aeza promotional thread, ~March 2024 [18]
"We are pleased to present you fast, powerful and premium virtual (VPS/VDS) and dedicated servers."
"Our advantages: Activation within 60 seconds of payment; 24/7/365 chat support; AntiDDoS protection on all servers; Hourly rate option from 0.02€/hour."
"Available payment methods: Bank cards of any country (Visa/Mastercard/World and others); Cryptocurrency (Bitcoin, Litecoin, Dogecoin, BTC Cash, USDT and others); E-wallets (YouMoney, PerfectMoney and others)."
LowEndTalk - Aeza official agent response to Doppelgänger allegations, July 2024 [19]
"This is an absolute fabrication that has nothing to do with reality. We do not work with governments and are completely independent."
"More than 80% of our clients use the servers for VPN, to bypass blocking and get access to independent information."
"We have not received any complaints about 'twin sites'. And those AS that were served through us we have switched off, but even during their work we received almost no complaints."
"We have nothing illegal located on our site, and we always respond to all complaints."
VSquare / Investigace.cz interview with co-founder Arseny Penzev, mid-2024 [14]
"If we receive a complaint from Roskomnadzor [the Russian censorship authority], we forward it to the client. That is where our mission ends."
Aeza Telegram channel, February 2025 (pre-raid satire post, cited in VSquare) [14]
"The police storm our office … Look online, without SMS and registration" [with a link to an ironic video featuring an actor in Soviet military uniform]. Later described as having "unwanted prophetic" significance after the April 2025 raids.
Note on "Bulletproof" Marketing

Aeza did not openly market itself as "bulletproof" in its own storefronts. Its resellers (LetHost, ZeroHost, and others on Aeza infrastructure) advertised "bulletproof" services to end criminal customers. The VSquare investigation confirmed: "Aéza's resellers advertised its services as 'bulletproof.'" [14]

Pricing (Documented Examples)

TierConfigPrice
Standard VPS (shared, Ryzen 9 9950X)2 GB / 1 core / 30 GB NVMe€4.94/mo
Standard VPS8 GB / 4 cores / 120 GB€19.77/mo
Standard VPS32 GB / 16 cores / 480 GB€79.09/mo
Dedicated VDS (dedicated CPU)2 GB / 1 core / 30 GB€7.07/mo
Dedicated serversThreadripper / i9-classfrom ~€200/mo
Entry hourly rateadvertised on LowEndTalk€0.02/hr
Historical promo (Aug 2022)1 core / 8 GB / 20 GB / 100 Mbps99 RUB/mo (~€1.60)

Onboarding

Aeza operated an open-signup model with no identity verification. A third-party review site documented that "the service supports anonymous registration, no real-name verification, and accepts cryptocurrency payments." Penzev framed equal treatment of all clients (including censorship-evading and opposition-linked projects) as a neutral, apolitical posture; no vetting of client intent was performed. [14]

Downstream Reseller Chain

Russian IT-law specialists consulted by investigace.cz noted that "legal liability may extend to the original hosting providers, not just the resellers." [14]

Abuse Handling and LE Posture

Stated posture: "We always respond to all complaints" (Aeza agent, July 2024); Penzev: "If we receive a complaint from Roskomnadzor, we forward it to the client." Documented behavior contradicts this: Aeza hosted BlackSprut for roughly two years before Russian action; Spamhaus flagged LetHost/ZeroHost-linked subnets; and OFAC found Bozoyan and Penzev "began to provide Blacksprut with services in 2023." Penzev's claim that Aeza terminated the BlackSprut reseller "because of the large number of reports we received from Spamhaus" is directly contradicted by the OFAC finding. Support ran via a 24/7 Telegram bot (@aezasupport_bot), a ticket panel, and RIPE abuse contacts abuse@aeza.net / abuse@aeza.ru. [1][14]

OPSEC

Multi-jurisdiction incorporation (RU LLC, UK Ltd, plus post-sanctions Serbia and Uzbekistan shells), reseller abstraction, anonymous crypto/e-wallet payments, and separation between Russian-controlled hardware and European delivery infrastructure. The principal OPSEC failure was operator concentration in Russia: all six designated operators are Russian nationals, and three founders were arrested domestically. [1][2][14]

Technical Capabilities and Infrastructure Footprint

Autonomous Systems

ASNRegistered NameReg. CountryActive WindowNotes
AS216246Aeza Group LLC (RU-AEZA-AS)Russia (RIPE)Sep 27, 2023 – active~12,032 IPv4; ~6,643 hosted domains (2025); registered Ul. Zolnaya d.15 str.1, St. Petersburg 193318
AS210644Aéza International Ltd (AEZA-AS)Russia (RIPE) / UK (corporate)2021 – active (migrating)~90,112 IPv4 announced; primary European delivery; Spamhaus ASN-DROP listed; tech org: Aeza International LTD, 311 Shoreham Street, Sheffield S2 4FA, UK
AS211522Hypercore LtdUKJul 10, 2025 – activePost-sanctions successor; 2,100+ IPs migrated from AS210644 starting Jul 20, 2025; shares 83.147.192.0/24 with AS210644

RIPE abuse contact (AS210644): abuse@aeza.net. Registration verification: AS210644, AS216246, and AS211522 registrations and the AS210644→AS211522 IP migration are corroborated across Silent Push, bgp.tools, IPinfo, and RIPEstat references. Registered technical organization for AS210644 is Aeza International LTD (Sheffield, UK). [10][16][24]

IP Ranges and Geographic Footprint

Physical data centers: Europe (primary) - aurologic GmbH facility, Robert-Bosch-Str. 25, 63225 Langen, Germany; Russia - Moscow and St. Petersburg nodes (directly controlled). European servers are primarily sourced through Hetzner resale and aurologic colocation. [11][15]

Upstream Transit Provider Chain

UpstreamRelationshipDe-peering Status
AS30823 aurologic GmbH (Langen, DE)Primary European upstream + colocationNOT terminated as of Nov 2025; Recorded Future noted aurologic "defended" the relationship; Qurium: Aeza "enabled by connectivity suppliers such as Aurologic in Germany continue operating malicious infrastructure"
AS24940 Hetzner Online GmbH (DE)Server resale ("All our European VPS are hosted on servers from Hetzner," Aeza, Jul 2024)No confirmed de-peering event documented
AS6939 Hurricane Electric (US)Transit peer (RIPE BGP data)No de-peering documented
AS8218 Zayo Infrastructure FranceTransit peerNo de-peering documented
DataPacketFormer European transitReplaced by aurologic ("they just moved from DataPacket to Aurologic")
Upstream De-peering History

Following the 2024 Qurium/CORRECTIV investigations, "several transit providers decided to terminate connection to the exposed structures" (Qurium via detector.media, April 2025); specific providers were not named. The most significant documented disruption was not a de-peering but the post-sanctions IP migration from AS210644 to AS211522 (Hypercore) beginning 20 July 2025, nineteen days after the OFAC designation. aurologic continued to provide transit through at least November 2025. This subsection is retained per schema even where de-peering evidence is partial. [10][11]

Resilience Techniques

Hosted Activity Types

ActivityEvidence BasisStatusIOCs / Examples
Meduza Stealer C2OFAC; TRM Labs; ThreatFox IOC 1368443Confirmed147.45.78[.]8:80 (AS210644, first seen 2024-12-25)
Lumma Stealer C2OFAC; Qurium/CORRECTIV; The RecordConfirmedAttributed via Qurium analysis
RedLine infostealer panelsOFAC press release; CyberScoopConfirmedHosted RedLine panels
Rhadamanthys Stealer C2AbuseIPDB; ThreatFoxConfirmed91.103.252[.]25 (AS210644), reported 39×
RecordBreaker C2ThreatFox IOC 842374Confirmed89.208.103[.]4 (AS210644, 2022-08-10)
BianLian ransomwareOFAC press release; CyberScoopConfirmedHosted BianLian infrastructure
BlackSprut darknet drug marketOFAC; RU court; Mash/Fontanka; QuriumConfirmedHosted 2023–2025; BS2site.at
Doppelgänger disinformation (SDA)Qurium/EU DisinfoLab; CORRECTIV; The Record; UK sanctionsConfirmed300+ prefixes, 100,000+ IPs; Liber Systems domains
Cobalt Strike C2Recorded Future / Insikt (Nov 2025 aurologic report)CredibleVia aurologic-hosted Aeza infra
DarkComet / QuasarRAT C2Recorded Future / Insikt (Nov 2025)CredibleAeza-associated networks on aurologic
Botnet / DDoSForum records; aeza-gang.com; OFAC (implied)ConfirmedGast/Penzev botnets; DDoS since MskHost era
Mystic Stealer C2 (via Shelter LLC)aeza-gang.com; Shelter LLC attributionCredibleShelter LLC (AS211409)

Blocklist Standing

BlocklistStatusDetail
Spamhaus ASN-DROP (AS210644)Listed"This ASN should not be routed or peered with. It is under control of cyber-criminals." Confirmed via ThreatFox ASN report and Spamhaus DROP. [16][23]
Spamhaus ASN-DROP (AS216246)UnknownNot explicitly confirmed in available sources; likely but unverified.
Spamhaus SBLListed (per-IP)Individual AS210644 IPs listed; LetHost/ZeroHost subnets flagged pre-2024.
ThreatFox (abuse.ch)Listed3,000+ IOCs mapped to AS210644 over 12 months; Meduza, Rhadamanthys, RecordBreaker and others. [16]
URLhaus (abuse.ch)Listed (per-IP)Individual AS210644 IPs; no aggregate ASN figure confirmed.
Feodo Tracker (abuse.ch)Not ApplicableFeodo datasets largely empty post-Operation Endgame; tracks Emotet/Dridex/QakBot, not the stealers Aeza hosts.
MalwareBazaar (abuse.ch)Not ConfirmedNo aggregate ASN-level linkage confirmed in this pass.
Firehol Level 1 / 2ProbableLikely given ASN-DROP status; not directly confirmed.
AbuseIPDBListed (per-IP)91.103.252[.]25 confirmed; tagged C2/stealer.

Delisting history: No documented delisting attempts or successful delistings. Aeza's stated position was that complaints were forwarded to clients; no documented engagement with Spamhaus delisting procedures for the ASN-DROP entry. [16]

Known Weaknesses and Single Points of Failure

Financial Infrastructure

Payment Methods

Advertised methods included Bitcoin, USDT (TRC20/BEP20/ERC20/TON), Litecoin, Dogecoin, BTC Cash, ETH, SOL, BNB, TRX, TON, USDC; bank cards ("of any country"); PayPal (via support); and the Russian e-wallets QIWI, YouMoney (formerly Yandex.Money), and PerfectMoney. WebMoney and SteamPay were observed in third-party reviews. Forum users noted that Russian-only payment methods carried low fees while international methods carried ~10% fees, interpreted as evidence that operations were financially centered in Russia. [18][14]

Designated Cryptocurrency Address

TRON (TRX) AddressTU4tDFRvcKhAZ1jdihojmBWZqvJhQCnJ4F
Designated1 July 2025 (OFAC SDN List)
AttributionOFAC; Chainalysis; TRM Labs
Volume receivedOver $350,000 USD

Three-Phase Laundering Model

Source: Chainalysis and TRM Labs analyses of the designated TRON address (1 July 2025). [7][8]

Phase 1 - Acquisition: Aeza used an intermediary payment processor to receive hosting fees, obscuring direct traceability. The designated TRON address functioned as an administrative/cash-out wallet rather than the primary customer-facing deposit address, so total inflow is likely larger than the $350,000 visible. Direct payments from infostealer vendors matched Aeza service pricing; regular payment pathways ran through Garantex (per TRM Labs).

Phase 2 - Layering: Funds routed through intermediary addresses before cash-out. Garantex (OFAC-sanctioned March 2025, disrupted by US/Germany/Finland) served as a layering node. Chainalysis also noted connections to "an escrow service used for selling items on a popular gaming platform," an unusual pattern that may represent deliberate obfuscation using legitimate-seeming transaction flows.

Phase 3 - Extraction: Regular cash-out points to global cryptocurrency exchanges and payment-service providers. Chainalysis Reactor graphs showed deposit addresses receiving funds from multiple sources including Garantex and an infostealer vendor. No OTC broker relationships were specifically documented in available public sources.

Internal Data

Internal Internal data reviewed for this profile is consistent with the published Chainalysis/TRM structure, in particular the Garantex layering pathway and the administrative-wallet role of the designated TRON address. No independent internal payment or victim dataset is attributed by name in this profile.

Post-sanctions payment infrastructure: per OFAC (19 Nov 2025), Ilya Zakirov "helped establish new companies and payment methods to obfuscate Aeza's continuing activity." Specific successor addresses are not yet publicly documented. [2]

Sanctions and Risk Designations

Client Profile and Hosted Operations

Crimeware Verticals by Evidence Tier

Client CategoryEvidence BasisClassification
Meduza Stealer operatorsOFAC; TRM Labs; ThreatFox (147.45.78[.]8)Confirmed
Lumma Stealer operatorsOFAC; Qurium; The Record; CORRECTIVConfirmed
RedLine Stealer operatorsOFAC; CyberScoopConfirmed
Rhadamanthys Stealer operatorsThreatFox; AbuseIPDB (91.103.252[.]25)Confirmed
BianLian ransomwareOFAC; CyberScoopConfirmed
BlackSprut darknet drug marketOFAC; RU court; Qurium; mediaConfirmed
Doppelgänger disinformation (SDA client)UK sanctions; Qurium; CORRECTIV; EU DisinfoLabConfirmed
DDoS operations (Aeza-originated)Forum records; aeza-gang.comConfirmed
Cobalt Strike C2Recorded Future / Insikt (Nov 2025)Credible
DarkComet / QuasarRAT C2Recorded Future / Insikt (Nov 2025)Credible
Mystic Stealer C2 (via Shelter LLC)aeza-gang.comCredible
Carding / RAT hosting (via LetHost/ZeroHost)LowEndTalk; researcher accusation ("Dessgun")Credible

Client Geography and Target Profile

Aeza's infrastructure was physically distributed across Western Europe (Germany, Sweden, Netherlands, Finland, Austria) while operator leadership was exclusively Russian (St. Petersburg), creating a deliberate jurisdictional split: European server locations gave reduced latency for European/US-targeted campaigns while operator liability remained in Russia, where enforcement was absent until 2025. No confirmed CIS exclusion policy is documented, though Aeza's marketing emphasized service to Russian users evading censorship. [1][14]

Notable Hosted Cases

Case 1 - BlackSprut Darknet Drug Market (2023–2025)

Primary infrastructure host and anti-DDoS backbone. BlackSprut was described as one of the world's largest darknet marketplaces; Jan–Sep 2025 transaction volume was estimated at $1.85 billion. OFAC: "Aeza Group has also hosted … BlackSprut, a Russian darknet marketplace for illicit drugs." Gast "oversaw the technical details of placing Blacksprut on Aeza Group infrastructure." Bozoyan and Penzev were arrested Feb/Apr 2025 and charged under Articles 210 and 228.1 (up to 20 years). [1]

Case 2 - Meduza and Lumma Infostealers (2023–2025)

C2 hosting and IP provisioning via Aeza International (UK). OFAC: these operators "used the hosting service to target the U.S. defense industrial base and technology companies." Lumma infected ~10 million systems before its May 2025 takedown. IOC: 147.45.78[.]8:80 (Meduza C2, AS210644). OFAC: "Aeza International serves as a front company to lease IP addresses to cybercriminals, including Meduza infostealer operators." [1]

Case 3 - Doppelgänger Disinformation (2022–2025)

Core European infrastructure hub hosting fake sites impersonating Der Spiegel, The Guardian, Le Monde and others across 10+ countries. The Record (July 2024): "At the core of Doppelgänger's operation in Europe and Russia is a company called Aeza." UK FCDO designated Aeza for "provision of 'bulletproof hosting services' to the Social Design Agency (SDA)." Qurium scale: 300+ prefixes, 100,000+ IPs, ~€5M market value, ~€50,000/month leasing cost - "can only be sustained by serious financial support from external actors." [5][12][13]

Case 4 - BianLian Ransomware

Infrastructure host for the double-extortion group. Confirmed by OFAC and CyberScoop; no specific IPs or timeframes documented in open sources. [1][22]

State Nexus Assessment

Entity Registration Jurisdiction
Russia (parent) + UK
Aeza Group LLC (RU, TIN 7813654490); Aeza International Ltd and Hypercore Ltd (UK); successor shells in Serbia and Uzbekistan.
Infrastructure Hosting Jurisdiction
Germany / Sweden / NL + Russia
European delivery via aurologic (Langen, DE) and Hetzner resale, footprint concentrated in Sweden/NL/DE; directly controlled nodes in Moscow and St. Petersburg.
Assessed Operator Location
Russia
All six designated operators are Russian nationals; three in Moscow pre-trial detention, three at large in Russia.
Assessed Tier: Probable Cooperation (Tier 3 of 4)

The evidence supports Tier 3. The state is assessed to have been aware of operations, to have benefited from the Doppelgänger campaign, and to have refrained from enforcement of the cyber/disinformation functions for an extended period. The documented bulletproof-hosting relationship with the Social Design Agency (SDA), a Kremlin-directed entity, constitutes deliberate enablement beyond passive tolerance. Overall confidence: MODERATE-HIGH.

Positive Evidence

Negative Evidence and Limitations

Nexus TierAssessment
Direct ControlNot assessed - no evidence
Probable CooperationASSESSED - SDA relationship confirmed; Doppelgänger scale; ~4-year non-enforcement
Tolerated Safe HarborApplicable as baseline - authorities demonstrably aware and non-reactive to cyber/disinfo functions
No NexusRejected - the SDA relationship alone eliminates this

Law Enforcement and Regulatory Response

February 2025
Undercover Russian police operation: a pawnbroker sells mephedrone to officers; Aeza linked; raids follow. Bozoyan and Penzev linked to BlackSprut. [14]
April 1, 2025
~30 economic-police officers raid Aeza's St. Petersburg offices. [14]
April 4, 2025
Meshchansky District Court (Moscow) orders pre-trial detention for Bozoyan, Penzev, Gast, Lavrukhin, and two businessmen. [14]
July 1, 2025
OFAC designates Aeza Group LLC, Aeza International Ltd, Aeza Logistic LLC, Cloud Solutions LLC, and four individuals (E.O. 13694/14144/14306); UK NCA designates the UK front company. [1][5]
July 10, 2025
Hypercore Ltd allocated AS211522 (registered in the UK) as successor infrastructure vehicle. [10]
July 20, 2025
Silent Push detects ~2,100 IPs migrating from AS210644 to AS211522, nineteen days post-sanctions. [10]
September 19, 2025
UK FCDO separately sanctions Aeza Group LLC. [5]
November 19, 2025
OFAC (with UK and Australia) expands designations to Hypercore Ltd, Smart Digital Ideas DOO (Serbia), Datavice MCHJ (Uzbekistan), Maksim Makarov, and Ilya Zakirov. UK designates Aeza under Russia (Sanctions)(EU Exit) Regulations 2019, citing BPH services to the SDA. [2][5][9]
December 2025
VSquare/Investigace.cz: Aeza remains operational in Europe; EU has imposed no sanctions. [14]
Jan–Jul 2026
No new EU designation, arrest, indictment, or seizure specific to Aeza identified in open sources during this follow-on pass. Status assessed unchanged from December 2025.

Arrests, Sanctions, and Seizures

Three founders (Bozoyan, Penzev, Gast) were arrested and remain in Russian pre-trial detention on narcotics/organized-crime charges. Sanctions span three authorities (US, UK, Australia) across two rounds. No infrastructure seizure by any EU member state has been documented; European servers at aurologic/Hetzner facilities remained partially accessible as of December 2025. [1][2][5][14]

Post-Disruption Client Migration

The dominant post-disruption pattern was provider-side infrastructure migration rather than client dispersal: AS210644 IP space shifted to Hypercore's AS211522 within days of sanctions, and successor shells were stood up in Serbia and Uzbekistan. Recorded Future characterized Aeza as "one of the most significant sources of malicious infrastructure" as recently as November 2025, indicating clients largely followed the migrated infrastructure rather than abandoning it. [10][11]

Connected Groups and Ecosystem Relationships

Each connected-entity claim carries two independent confidence tiers: Tier 1 (infrastructure relationship: did Aeza host their infrastructure?) and Tier 2 (operational relationship: did the Aeza operator know the client's identity or coordinate operationally?). Aeza's no-KYC, reseller-mediated model makes most Tier 2 assessments inference-level, with the notable exceptions of BlackSprut and the SDA, where OFAC/UK evidence indicates operator-level knowledge.

Social Design Agency (SDA) / Doppelgänger
Kremlin-directed influence entity; Doppelgänger disinformation campaign
Two-Tier Confidence Assessment
Tier 1 - Infrastructure Relationship:Confirmed
Tier 2 - Operational Relationship:Credible
Tier 1 CONFIRMED: UK FCDO explicitly designated Aeza for providing bulletproof hosting to the SDA; Qurium/CORRECTIV/The Record independently attribute Doppelgänger's European hub to Aeza. Tier 2 CREDIBLE: the UK sanctions basis and the ~€50,000/month, 300+-prefix scale imply a knowing, sustained provider relationship rather than an anonymous transaction, but direct evidence of operator-level coordination (versus reseller-mediated provisioning via Liber Systems/TNSecurity) is not fully public.
Corroborating: UK FCDO, Qurium, EU DisinfoLab, CORRECTIV, The Record Not assessed: Mandiant, CrowdStrike (no formal Aeza-specific assessment)
BlackSprut Darknet Drug Marketplace
Major Russian darknet drug market
Two-Tier Confidence Assessment
Tier 1 - Infrastructure Relationship:Confirmed
Tier 2 - Operational Relationship:Confirmed
Tier 1 CONFIRMED and Tier 2 CONFIRMED: uniquely among Aeza clients, OFAC and Russian court proceedings establish operator-level knowledge. OFAC found Bozoyan and Penzev "began to provide Blacksprut with services in 2023," Gast "oversaw the technical details of placing Blacksprut on Aeza Group infrastructure," and all three were arrested specifically for this. Penzev's framing of BlackSprut as "a client of our reseller" is contradicted by these findings.
Corroborating: OFAC, Russian courts, Qurium, Mash/Fontanka
Meduza / Lumma / RedLine / Rhadamanthys Infostealer Operators
Commodity infostealer ecosystems; targeted US defense industrial base and tech firms
Two-Tier Confidence Assessment
Tier 1 - Infrastructure Relationship:Confirmed
Tier 2 - Operational Relationship:Analyst Inference
Tier 1 CONFIRMED: OFAC named Meduza and Lumma operators as Aeza clients; ThreatFox/AbuseIPDB IOCs place Meduza (147.45.78[.]8), Rhadamanthys (91.103.252[.]25), and RecordBreaker C2 on AS210644. Tier 2 ANALYST INFERENCE: OFAC states Aeza International was used "to lease IP addresses to cybercriminals, including Meduza infostealer operators," but the no-KYC, reseller-mediated model means operator-level knowledge of any specific stealer client cannot be confirmed from public evidence.
Corroborating: OFAC, TRM Labs, abuse.ch ThreatFox, AbuseIPDB
BianLian Ransomware
Double-extortion ransomware group
Two-Tier Confidence Assessment
Tier 1 - Infrastructure Relationship:Confirmed
Tier 2 - Operational Relationship:Analyst Inference
Tier 1 CONFIRMED via the OFAC press release and CyberScoop, though no specific IPs/timeframes are public. Tier 2 ANALYST INFERENCE for the same no-KYC reasons. Tier 1 rests primarily on OFAC/CyberScoop; no independent IOC published
Corroborating: OFAC, CyberScoop
Cobalt Strike / DarkComet / QuasarRAT operators (via aurologic-hosted infra)
Commodity C2 frameworks and RATs
Two-Tier Confidence Assessment
Tier 1 - Infrastructure Relationship:Credible
Tier 2 - Operational Relationship:Analyst Inference
Tier 1 CREDIBLE: attributed by Recorded Future's Insikt Group (November 2025) via Aeza infrastructure on aurologic; single-vendor at present. Tier 2 ANALYST INFERENCE. [SINGLE SOURCE: Recorded Future]
Corroborating: Recorded Future / Insikt Group Not assessed: other major vendors

Vendor Attribution Summary

Corroborating vendors across the profile: OFAC, UK FCDO, Australia DFAT, Chainalysis, TRM Labs, Silent Push, Recorded Future/Insikt, Qurium, EU DisinfoLab, CORRECTIV, The Record, abuse.ch (ThreatFox/URLhaus), AbuseIPDB. No public vendor has issued an assessment materially disagreeing with the Aeza-BPH attribution. Vendors that have not published a formal Aeza-specific assessment in this pass: Mandiant, CrowdStrike, Secureworks, Microsoft MSTIC, Team Cymru.

Trajectory Assessment

Infrastructure Churn

Churn is assessed HIGH and deliberate. The defining event was the rapid post-sanctions migration of ~2,100 IPs from AS210644 to the newly allocated AS211522 (Hypercore) within nineteen days, described by Silent Push as "unusually rapid," accompanied by shared-prefix announcement (83.147.192.0/24) confirming continuity. Successor shells were stood up across three jurisdictions (UK, Serbia, Uzbekistan). [10]

Market Position

Aeza was a large-scale, established BPH operator (~100,000+ IPs at peak) serving a broad portfolio spanning infostealers, ransomware, a major darknet market, and state-aligned disinformation. Recorded Future's November 2025 characterization as "one of the most significant sources of malicious infrastructure" indicates it retained material market weight even after sanctions. [11]

Disruption History

Three disruption vectors converged in 2025: Russian criminal arrests (Feb/Apr), tri-lateral sanctions (Jul and Nov), and infrastructure exposure by researchers (Silent Push, Recorded Future, Qurium). None fully terminated operations; the group adapted via migration and rebranding. The EU imposed no sanctions and no server seizures are documented.

Assessed Trajectory: Degraded but Persistent

Aeza is assessed as degraded rather than defunct. Sanctions froze US-nexus assets and blocked its designated wallet; three founders are detained; the core brand is offline. Yet successor infrastructure (Hypercore/AS211522) and shells continued operating through at least December 2025, aurologic upstream persisted, and no EU action materialized. Absent EU designation or aurologic de-peering, the most likely trajectory is continued operation under successor branding with periodic ASN/shell rotation.

Mandatory Intelligence Gaps

Full reseller chain

Identities and scale of downstream resellers beyond LetHost, ZeroHost, and TNSecurity are unknown.

Post-sanctions payment infrastructure

Specific crypto addresses and payment methods established by Zakirov after November 2025 are not publicly identified.

Successor operational status (July 2026)

Whether Hypercore, Smart Digital Ideas, and Datavice remain operational and client-serving is not confirmed in open sources.

EU-jurisdiction server status

No EU member state has seized Aeza-associated servers; current status of hardware at aurologic/Hetzner is undocumented.

Knyazev current status

The non-arrested 33% owner's whereabouts and legal status post-sanctions are unconfirmed.

SDA-to-Aeza funding flows

SDA's state-funded status is confirmed, but the specific funding flows to Aeza are not publicly documented.

Hypercore registrant identity

Open reporting names "Patryk Drozda" as Hypercore's registrant; this is single-source and not corroborated against Companies House or the OFAC record in this pass.

AS216246 blocklist history

Only AS210644 is explicitly confirmed ASN-DROP listed; per-IP SBL history for AS216246 is unconfirmed.

Recent Reporting

Follow-On Verification (July 2026)

Verification Pass Summary

This profile's core claims were verified against primary sources during a July 2026 follow-on pass. The OFAC July 2025 press release (SB0185) was confirmed verbatim for hosted-activity attributions (Meduza, Lumma, RedLine panels, BianLian, BlackSprut) and personnel roles. The November 2025 tri-lateral action (SB0319) was confirmed to have designated Hypercore Ltd plus Serbian/Uzbek successors and operators Makarov and Zakirov (note: SB0319 also designated the separate Media Land / Yalishanda BPH network, which is a distinct EDP node). The AS210644→AS211522 migration and AS211522 allocation date were corroborated via Silent Push and BGP data.

No Post-December-2025 Escalation Identified

No EU designation, additional arrest, indictment, or infrastructure seizure specific to Aeza was identified in open sources for January–July 2026. The EU's continued non-action (despite European hosting) remains the most notable outstanding anomaly. Status is assessed unchanged from the December 2025 VSquare reporting.

Single-Source Flag: Hypercore Registrant

Secondary reporting attributes Hypercore Ltd's registration to "Patryk Drozda" two days after the July 2025 sanctions. This name does not appear in the OFAC designation text and is treated as CREDIBLE / single-source pending Companies House corroboration. The researcher-named front person for Aeza International Ltd is separately identified as Marat Timurov (Kazakhstan), also non-designated.

Sources

[11]
Malicious Infrastructure Finds Stability with aurologic GmbH - Recorded Future / Insikt Group, November 2025
[12]
Doppelgänger Investigation - Qurium / EU DisinfoLab, September 2022