EDP / Research / The Enablement Layer
The Enablement Layer
How and why bulletproof hosting is allowed to exist: the commercial infrastructure chain above the provider, and the legal architecture that makes non-intervention the default behaviour of every actor in it.
Cross-Cutting Analysis

Executive Summary

12+
Threat Enablers on One Upstream
~50%
Aeza Prefixes via aurologic
0
RIR Revocations for Sanctions
24 hrs
OFAC to Reallocation (Aeza)
2008
Last Full BPH De-peering
5 of 7
Profiles with Western Upstream

Every bulletproof hosting provider profiled in this library depends on a chain of commercial services it does not own: transit connectivity, IP address allocations, physical rack space, corporate registration, and payment rails. Each link in that chain is operated by a company that is, in most cases, entirely lawful, frequently European, and under no legal obligation to look at what its customer is doing.

This page addresses the question the individual provider profiles do not: not who the operators are, but why the service is permitted to remain reachable. The state protection question, the Russian security services relationship and the tolerated safe harbour model, is assessed separately in Section 07 of each provider profile. This analysis covers the other half of the problem, which sits almost entirely inside Western and EU jurisdictions.

Central Finding

Bulletproof hosting persists less because of Russian protection than because the commercial layer above it has no legal duty to act, no reputational cost for inaction, and a well-established business rationale for neutrality. Russian tolerance explains why operators are not arrested. Western intermediary liability law explains why their servers stay online. Analyst Inference

Key Findings

FindingDetailConfidence
Upstream concentration is the single largest structural vulnerability Recorded Future's Insikt Group identified more than a dozen assessed threat activity enablers taking upstream connectivity from one German carrier, aurologic GmbH, including sanctioned Aeza. Several downstream networks route exclusively through it, creating single points of failure that have never been exercised. Confirmed
Registry policy freezes resources but does not reclaim them RIPE NCC freezes registration of number resources held by sanctioned parties but does not deregister them or terminate membership, on guidance from the Dutch Ministry of Foreign Affairs. Sanctioned providers retain their allocations and can move them to new, unsanctioned legal entities. Confirmed
EU intermediary liability law makes inaction legally correct Under the Digital Services Act mere conduit provisions and the German DDG, transit providers carry no general monitoring obligation and incur liability only on actual knowledge. Providers structure their terms of service around this, acting only on formal notice. Confirmed
Sanctions designate the entity, not the infrastructure Aeza reallocated US-facing IP resources to a newly registered Serbian entity within 24 hours of the July 2025 OFAC designation, and to a new UK entity within three days. Stark Industries migrated resources weeks before the May 2025 EU listing and rebranded to THE.Hosting under a Dutch company. Confirmed
Company registry integrity powers have outperformed sanctions authority against the shells Hypercore Ltd was struck off in December 2025 and Aeza International Ltd in March 2026, both for false or misleading incorporation information rather than under sanctions authority. This is the one enabling layer where an existing, unglamorous power has actually removed entities. Confirmed
The upstream lever is not available against every provider Five of seven published profiles have at least one upstream inside an EU, UK, or US jurisdiction, and two of them depend on the same German carrier. Media Land and Bearhost/PROSPERO route through Russian carriers and, in the Bearhost case, a Russian security vendor's ASN, placing them outside the reach of Western transit pressure. Credible
Upstream termination works when it is used, and it is almost never used The November 2008 McColo de-peering by Global Crossing and Hurricane Electric removed the network within a day and cut global spam volume by two thirds or more. No comparable voluntary upstream action against a major BPH has been documented since. Confirmed
ScopeCommercial and governance infrastructure sitting above bulletproof hosting providers. Excludes state protection, which is covered per-profile in Section 07.
Providers referencedAeza Group, Bearhost / PROSPERO, DEDBROPRO, Media Land, Stark / THE.Hosting, Virtualine / Railnet, ZServers / XHost
Enabler jurisdictionsGermany, Netherlands, Bulgaria, United Kingdom, United States, Russia, Montenegro, Serbia, Seychelles, Turkey
Governing legal instrumentsEU Digital Services Act (Regulation 2022/2065) Article 4; German Digitale-Dienste-Gesetz (DDG); RIPE NCC Standard Service Agreement; EU restrictive measures regulations
Primary evidence baseRecorded Future Insikt Group (Nov 2025); Spamhaus Project (Jun 2026); Binding Hook / Virtual Routes (Oct 2025); KrebsOnSecurity; Qurium; RIPE NCC published policy and transparency reporting
Last reviewed31 July 2026

The Enablement Stack

A bulletproof host is not a self-contained business. It is an assembly of purchased dependencies, each obtainable from a limited number of suppliers, and each representing a distinct point at which the service could be denied. The two panels below show that position as the ecosystem map records it: what feeds the hosting layer, and what the hosting layer feeds.

Ecosystem Map, Filtered View
Two inbound mechanisms, one node
Open the full map ↗
Derived from the live ecosystem map data. Node and edge definitions, confidence, tier, and replaceability values are read from the same file that drives the full map, filtered to the six nodes with a direct relationship to bulletproof hosting. Hover any node or arrow for the underlying assessment.
Ecosystem Map, Filtered View
What the enablement layer keeps online
Open the full map ↗
The same node, viewed downward. Colours are the ecosystem layer each dependent node belongs to, matching the full map. This is the blast radius of a single upstream termination: one action against the hosting layer reaches six ecosystem layers at once, which is why Section 08 assesses transit as the highest-yield single lever available.

The five dependencies in full

The map models the enablement layer as three nodes, because those are the three that can be given a distinct owner and a distinct disruption pathway. The full dependency chain has five links. The list below expands the three that appear in the panels above, and adds the two the map does not model separately: physical facilities, which are covered by the hosting jurisdiction rather than by a supplier relationship, and payment rails, which are treated as a financial node elsewhere in the map.

Read downward. The ordering is by disruption leverage, highest first, and it is not the order in which enforcement has actually been attempted.

Layer 1Upstream transit carriersConfirmed
Without a transit provider announcing its routes, a bulletproof host is unreachable regardless of how many servers it owns. Transit is the only dependency whose removal is instant, comprehensive, and effective across every hosted service simultaneously.
Leverage: HIGH. Requires voluntary carrier action or regulatory compulsion. No general legal duty exists to compel it in the EU.
Layer 2Regional internet registries and sponsoring LIRsConfirmed
IP address space and autonomous system numbers come from RIPE NCC, ARIN, or APNIC, directly as a local internet registry or indirectly through a sponsoring LIR that assigns sub-allocations. Sponsoring LIRs in permissive jurisdictions have been repeatedly used to obtain space for networks that could not obtain it directly.
Leverage: MEDIUM. Registry policy permits deregistration for falsified information or non-payment, but not for sanctions designation.
Layer 3Datacenters and colocation facilitiesConfirmed
Physical rack space, power, and cross-connects. Where the facility is in an EU or NATO jurisdiction, it is subject to search, seizure, and asset freezes, as demonstrated in Amsterdam in February 2025 and May 2026. Where it is in Russia, it is not.
Leverage: HIGH where jurisdiction permits, NONE where it does not. Entirely determined by the hosting jurisdiction.
Layer 4Corporate formation and registration agentsConfirmed
Registry membership requires a legal entity. Formation agents supply one within hours, typically with a virtual office address. This is the layer that converts a sanctions designation from a terminal event into a paperwork exercise, at least in the short term.
Leverage: MEDIUM, and rising. Both Hypercore Ltd (December 2025) and Aeza International Ltd (March 2026) were ultimately struck off the UK register for false or misleading incorporation information, not by sanctions authority. UK identity verification from November 2025 may compound this; effect not yet measurable.
Layer 5Payment and settlement railsCredible
Cryptocurrency processing, high-risk merchant acquiring, and exchange off-ramps. Covered in detail in Section 05 of each provider profile and in the exchange node library.
Leverage: MEDIUM. Degrades revenue and improves financial tracing, but does not take infrastructure offline.
Why the ordering matters

Enforcement activity to date has concentrated on Layers 3, 4, and 5, which are the layers where legal authority is clearest. Layer 1, which carries the highest disruption value, has been almost untouched because it depends on voluntary commercial decisions by companies that are not themselves accused of wrongdoing. Analyst Inference

Upstream Transit: The Intermediary Layer

Cross-profile upstream dependency map

Upstream chains as documented in Section 04 of each published profile. Jurisdiction here refers to the transit provider, not the bulletproof host. This table and every count derived from it are generated from a shared data file, so a newly published profile appears here as soon as it is registered there.

ProviderDocumented upstream chainReachable jurisdictionTransit lever
Analytic Implication

Transit pressure is a jurisdiction-dependent tool, not a universal one. It is available against Aeza, Stark, ZServers, DEDBROPRO and Virtualine, and unavailable against Media Land and Bearhost. Disruption planning that assumes a uniform upstream lever will misallocate effort against exactly the two providers where seizure and designation are the only options. Analyst Inference

Case study: aurologic GmbH as concentration point

Recorded Future's Insikt Group published the most detailed available assessment of upstream concentration on 6 November 2025. The findings establish that the concentration problem is not theoretical. Confirmed

Concentration Within This Library

The concentration is visible without leaving this profile set. Two of the seven providers profiled here, Aeza and Virtualine, depend on aurologic as their primary upstream, and Virtualine routes roughly 95 percent of its backbone traffic through it. One of those two is designated by three authorities and the other by none, yet both are carried by the same German company, over the same period, with no distinction in treatment. A single termination decision at one carrier would reach two of the seven providers in this library at once. Analyst Inference

Aeza's dependence on aurologic was itself the product of an earlier upstream decision. After Qurium published its Doppelganger investigation in July 2024, UK provider DataCamp Limited (AS60068) terminated its contract with Aeza. Aeza publicly stated it then partnered with aurologic to continue operations. One upstream acted; the customer moved to another that did not. Confirmed

The stated rationale for non-intervention

The aurologic CEO's public position, documented across forum posts, an interview with the German investigative outlet CORRECTIV, and the company's own terms of service, is consistent: action follows formal legal notice, and neutrality is a principled stance rather than a commercial convenience.

aurologic CEO, quoted by CORRECTIV, June 2024 interview
"I can kick everyone out, but then at some point I won't make any sales."
aurologic CEO, responding to Spamhaus on X, April 2025
Neutrality described as "the art of being impartial"; the company asserted it has "no considerable history of bulletproof hosting" and that staff "react according to applicable law" on receipt of abuse reports.

Insikt Group's own framing of the resulting problem is that the distinction between negligence and complicity becomes meaningless from the perspective of the victim, because the outcome is identical: the malicious infrastructure remains globally reachable. Confirmed

Note on Attribution

No public reporting alleges that aurologic knowingly facilitates crime, and the company has not been sanctioned, charged, or named in any enforcement action. The assessment here concerns structural position and demonstrated behaviour, not criminal intent. The same analytic caution applies to Hetzner, Hurricane Electric, Zayo, Belcloud, Hostkey, and MIRhosting, each of which appears in a documented upstream chain above.

Registry Governance: Freeze, Not Revoke

Address space is the second dependency and the one that determines whether a designated provider can reconstitute. RIPE NCC's position, developed in consultation with the Dutch Ministry of Foreign Affairs, is that registration of internet number resources constitutes an economic resource for sanctions purposes, which requires freezing, but that deregistration is not required and will not be performed. Confirmed

TriggerRIPE NCC actionPractical effect on the provider
EU sanctions designationRegistration frozen. No new allocations, no transfers. Membership retained. Resources not reclaimed.Existing space keeps routing. Provider retains its ASNs and prefixes.
Falsified or incorrect information supplied to the registryPermanent deregistration of number resources available under RIPE NCC closure and deregistration procedure RIPE-858.Terminal, where detected and pursued.
Non-payment of membership feesDeregistration available.Terminal, where it occurs.
Dutch court orderDeregistration available under RIPE-858 section B.1.Terminal, but requires litigation in the Netherlands.
Documented abuse or criminal hostingNo specific policy trigger.None.
The Enforcement Asymmetry

A member sanctioned by the European Union for enabling cyber operations faces a freeze. A member that submits incorrect paperwork can be fully deregistered. As long as fees are paid and records are accurate, the use of registry resources to support state-aligned cyber operations does not put those resources at risk. RIPE NCC has publicly stated that internet resources should be kept separate from political disputes and has said it will continue to investigate the possibility of a blanket exemption for number resources from EU sanctions regulation. Note the counterpoint: this same integrity power, applied through the UK company register rather than RIPE, is what ultimately removed both Hypercore Ltd and Aeza International Ltd. Confirmed

Local internet registry autonomy as the reconstitution mechanism

Bulletproof providers that hold LIR status can assign prefixes to customer organisations and update registry records themselves. That autonomy is the mechanism by which designation is survived: register a new entity, assign the space to it, update the record. Each step is procedurally ordinary and none of it breaches registry policy.

Weeks before 20 May 2025
Stark Industries Solutions migrates key IP resources to a separate legal entity ahead of the EU designation, following media leaks of the pending listing. Confirmed
1 July 2025, within 24 hours
Following the OFAC designation, Aeza begins reallocating US-facing IP resources to Smart Digital Ideas DOO, a Serbian entity registered hours after the announcement. Confirmed
3 to 7 July 2025
Hypercore Ltd is registered in the UK and receives a prefix from Smart Digital Ideas created the previous day. Smart Digital Ideas is then assigned its own ASN, sponsored by Aeza International Ltd. Confirmed
19 September 2025
The UK designates Aeza International Ltd. The company remains registered at Companies House for a further six months. Confirmed
23 December 2025
Hypercore Ltd is dissolved, struck off under section 1002A of the Companies Act 2006 for false or misleading information supplied on incorporation. The corporate registry route, not the sanctions route, removes the entity. Confirmed
24 March 2026
Aeza International Ltd is dissolved at Companies House, roughly six months after the UK designation and nine months after the OFAC action. Registration integrity enforcement, again, rather than sanctions enforcement. Confirmed
October 2025
Twelve prefixes announced under a fraudulently registered ASN impersonating a legitimate Hamburg software company are re-allocated to a newly created Amsterdam-registered organisation at a serviced-office address, at the peak of observed malicious activity on that space. Confirmed

Why routing security is not the lever it appears to be

A reader familiar with BGP will ask the obvious question: if the registry issues the cryptographic certificates that networks use to validate route announcements, why not revoke a designated provider's certificates and let route filtering do the work? The answer is that this does not function as an off switch, for three separate reasons.

A freeze does not reach the certificates. RIPE NCC's certification terms give an exhaustive list of revocation triggers: inconsistency with the registration records, technical or security compromise, violation of the terms, and voluntary termination. Sanctions designation is not among them, and the certification practice statement omits it as well. Because a freeze preserves the registration record rather than altering it, the inconsistency trigger never fires. Whether a frozen member retains day-to-day access to manage its own route origin authorisations is undocumented, and no published RIPE NCC position addresses it. Confirmed

Revocation would not remove reachability. A prefix is treated as invalid only when a valid authorisation covers it and the announcement fails to match. Revoking a member's certificate destroys all of that member's authorisations at once, so nothing covers the prefix and its status falls back to unknown, which every network accepts, including those that discard invalid routes. Certificate revocation therefore strips a provider of protection against hijacking rather than taking it offline. Prefixes only become invalid once the space is deregistered and reallocated to a different holder who authorises it to a different network, a sequence that runs on months to years. Confirmed

The community has already considered and rejected the idea. A March 2022 multistakeholder statement on internet sanctions, circulated on the RIPE list and signed by senior figures including a then member of the RIPE NCC Executive Board, examined manipulating routing security attestations as a sanctions instrument and concluded that it "could risk the withdrawal of networks from the system entirely" and constituted an unacceptable risk. The reasoning is that a security mechanism repurposed for enforcement stops being one that operators voluntarily adopt. Confirmed

Assessment

This is the strongest form of the counterargument to this page's central claim. The registry layer's refusal to act is not simple inertia at this particular point: it reflects a documented judgement that converting routing security into an enforcement tool would degrade the security system itself. That judgement is defensible on its own terms, and it further narrows the registry lever to the falsified-data route described above, which bites slowly and through reallocation rather than through anything sudden. Analyst Inference

Sponsoring LIR abuse

Where a network cannot or will not become an LIR itself, it obtains space through a sponsoring LIR. Insikt Group documented a Turkish LIR sponsoring several suspicious ASNs all created during 2025, and prefixes sub-allocated from Iranian and Omani registrants appearing under UK-incorporated shells routing exclusively through a German carrier. Identity verification at the point of registration is the control that failed in these cases: at least one registration used a falsified end-user agreement that a basic check against public company records would have caught. Confirmed

Corporate Formation and Jurisdictional Arbitrage

Registry membership, transit contracts, and datacenter agreements all require a legal entity. The speed and low cost of obtaining one determines how quickly a designated provider reconstitutes. Applying the jurisdictional separation discipline used in the provider profiles, the enabling jurisdictions divide as follows.

Entity registration
United Kingdom, Netherlands, Serbia, Estonia, Seychelles, US states
Chosen for formation speed and low verification. UK entities recur most frequently across profiles, often at shared virtual office addresses.
Infrastructure hosting
Germany, Netherlands, Bulgaria, Russia, Moldova, Finland
Determines whether physical seizure is possible. The Amsterdam actions of February 2025 and May 2026 are the demonstration cases.
Assessed operator location
Russia, Moldova, Netherlands
Determines whether arrest is possible. Only the Netherlands-resident operators in the Stark cluster have been arrested by a Western authority.

A recurring pattern across Insikt Group reporting is the reuse of a small number of London virtual office addresses by multiple assessed threat activity enablers, and the impersonation of legitimate companies during ASN registration. In at least two documented 2025 cases, the name of a real, unrelated European business was used to register an autonomous system that then announced substantial malicious infrastructure. Confirmed

UK Companies House identity verification for directors and persons of significant control began rolling out from 18 November 2025. Whether it materially raises the cost of shell formation depends on the treatment of formation agents, and no measurable effect has yet been published. Credible

Datacenters and Internet Exchanges

Physical facilities are the layer where Western enforcement has been most effective, because the legal authority is unambiguous and does not depend on a commercial partner's willingness to act.

Internet exchange points occupy an ambiguous position. Stark-linked infrastructure reached AMS-IX and DE-CIX Frankfurt through its Netherlands colocation provider. No public reporting documents an exchange disconnecting a member in response to a sanctions designation, and no exchange policy requiring it has been identified. This is an unresolved question rather than a negative finding. Analyst Inference

Seizure Without De-peering

Both Amsterdam actions removed hardware while leaving the routing relationships and address allocations intact. In both cases the provider or its successor continued announcing prefixes afterwards. Physical seizure degrades capacity; it does not remove reachability. Analyst Inference

When the Backbone Acts

What upstream termination actually does

One distinction the field tends to blur. Transit is a smaller network paying a larger one to carry its traffic to the rest of the internet. Peering is two networks exchanging traffic directly, usually without money changing hands. The term de-peering is commonly applied to both, but the action that removes a bulletproof host is termination of transit.

A network is reachable because its upstream carrier announces to everyone it connects to that traffic for a given set of addresses should be sent through it. That announcement propagates outward until every major network on the internet knows the path. End the contract, the carrier stops making the announcement, and the route drains out of the global routing table within seconds to a few minutes.

Nothing is confiscated. The servers keep running, the disks still hold the data, and the operator can still reach the machines locally. The addresses simply cease to exist as far as the rest of the internet is concerned. It is not a seizure, it is a refusal to carry, and that is precisely why it outperforms every other instrument available: it takes minutes rather than months, it reaches every hosted service at once rather than one brand at a time, it requires no warrant, and it avoids the jurisdictional problem entirely because the carrier is only deciding who its own customers are. Confirmed

The evidentiary case for this lever rests on a small number of instances, because upstream action is rare. Those instances are consistent.

EventDateActionOutcome
McColo November 2008 Upstream providers Global Crossing and Hurricane Electric terminated connectivity on 11 November 2008. Immediate. Global spam volume fell by two thirds or more. A brief reconnection via a backup peer on 19 November 2008 was cut off again; spam volumes did not recover to pre-takedown levels until around April 2009. Confirmed
Aeza and DataCamp Disclosed Aug 2024 UK provider DataCamp Limited terminated its contract with Aeza following the Qurium Doppelganger report of July 2024. Aeza disclosed the termination in August 2024; the termination date itself is not stated in the source. Partial. Aeza publicly stated it moved to aurologic and continued operating. Effect displaced rather than eliminated. Confirmed
Media Land post-designation Nov 2025 to Jul 2026 No upstream action taken by any of the four observed peers. All four peers remained in place across the latest BGP snapshot, through sanctions, indictment, and EU designation. Confirmed
Aeza post-designation Jul 2025 to date No upstream de-peering by aurologic. Routing continued after US, UK, and Australian designations. Approximately half of announced prefixes still routed via the same German upstream at last published assessment. Confirmed
Assessment

Upstream termination is the highest-yield single action available against a bulletproof host, and the evidence that it works is eighteen years old because it has essentially not been attempted since at comparable scale. Where a single upstream has acted in isolation, the customer has relocated to a more permissive carrier within weeks. This suggests the effective form of the lever is coordinated rather than unilateral: simultaneous refusal by the realistic set of alternative carriers, not termination by one. Analyst Inference

Why the lever is not pulled

The instrument is fast, cheap, and effective, and it sits unused. That is not an oversight. Every incentive acting on a transit carrier points away from using it.

DisincentiveMechanism
The law rewards inaction A carrier that does not inspect what it carries has no liability for it, and no obligation to go looking. Acting on suspicion rather than formal notice moves the carrier out of that shelter. Doing nothing is not merely permitted, it is the legally optimal position.
The customer holds a contract Terminating a paying customer without a clear breach or a legal instrument invites a breach of contract claim. Carriers want an instrument that makes disconnection safe: a court order, a designation naming that specific customer, or a formal law enforcement notice.
The designated entity is usually not the customer Sanctions name a legal person; the carrier's contract is frequently with a different legal person one or two steps removed. This is the documented aurologic position on Aeza, where the public defence was that the designated entity was not the contractual customer. Accurate as stated, and it dissolves the obligation.
Revenue High-abuse customers are often high-margin customers, and a carrier known for disconnecting on suspicion loses legitimate business as well. The aurologic CEO stated the trade-off publicly and without embarrassment.
Whoever moves first pays for nothing A carrier acting alone bears the entire cost, in lost revenue, legal exposure, and public argument, while the customer relocates to a more permissive carrier within weeks. DataCamp terminated Aeza and Aeza moved to aurologic. The first mover produces displacement rather than disruption and subsidises a competitor.
Nobody owns the decision Sanctions authorities designate entities; they do not route traffic. No regulator is tasked with directing a carrier to disconnect a customer, so the action falls between institutions and rests on a voluntary commercial judgement by a company that has not itself been accused of anything.
The neutrality objection is genuine Carriers making judgements about who deserves connectivity establishes that carriers can make such judgements, which is the precedent an authoritarian government wants. This is the same reasoning the RIPE community used to reject routing security as a sanctions instrument in 2022. It serves as convenient cover, and it is also a position held in good faith.
The Structural Trap

The disincentives are not equally weighted. Most could be overcome by a determined carrier, but the first mover problem cannot be overcome by any carrier acting alone, because it is a property of the market rather than of the firm. Unilateral action is, from the carrier's own perspective, correctly identified as pointless: it costs real money and achieves relocation rather than removal. That is the finding with the clearest policy implication on this page, and it means that appeals to individual carriers to behave responsibly are aimed at the wrong unit of analysis. Analyst Inference

What would change the calculation

The facilitator model

Spamhaus published its own formulation of this argument in June 2026, framing IP address brokers, network carriers, and datacenters as facilitators whose services are essential, difficult to obtain independently, and available from a finite number of sources. Its stated position is that pursuing individual bulletproof hosts without pursuing facilitators treats symptoms rather than causes. The mechanism Spamhaus describes is escalation of SBL listing against the facilitator's own network, combined with the observation that clustering bulletproof customers increases a facilitator's attractiveness to law enforcement. Reputational cost is a consequence of that approach rather than the stated lever. Confirmed

Leverage Points and Measurable Indicators

Leverage pointOwnerActionAssessed yieldConstraint
Coordinated upstream refusalTransit carriers, prompted by regulators and industry bodiesSimultaneous termination by the realistic alternative carrier set, not one carrier aloneHIGHVoluntary. No legal duty exists to compel it in the EU.
Registry policy reformRIPE NCC membershipExtend deregistration triggers to sanctions designation, or tighten sponsoring LIR verificationHIGHRequires community policy change against a stated neutrality position.
Registration integrity enforcementRIPE NCCDeregister resources obtained through falsified end-user agreements or corporate impersonation, using existing SSA powersMEDIUM-HIGHAlready permitted under current policy. Requires detection capacity, not new rules.
Designating the enabler, not only the hostOFAC, EU Council, UK FCDOExtend designations to upstream carriers and sponsoring LIRs with demonstrated repeat knowledgeHIGHPolitically significant. Would set precedent affecting lawful European carriers.
Formation agent verificationUK Companies House and equivalentsExtend identity verification to formation agents and beneficial ownersMEDIUMRollout began November 2025. Effect unmeasured.
Physical seizureNational law enforcementDatacenter raids and asset seizure in cooperating jurisdictionsMEDIUMProven and repeatable, but degrades capacity without removing reachability.

Indicators to track

Intelligence Gaps

Complete upstream chains for Bearhost/PROTON66 and ZServers

PROTON66 transit is undocumented in open sources, and ZServers transit beyond Hostkey is unknown. Both require historical BGP analysis or network operator community records. Priority: HIGH, because the presence or absence of a Western upstream determines which disruption tool applies.

Internet exchange policy on sanctioned members

No published AMS-IX or DE-CIX policy on disconnecting designated entities has been identified, and no instance of an exchange doing so has been documented. Whether this reflects absence of policy or absence of reporting is unresolved.

Whether any transit provider has quietly terminated a BPH customer

Voluntary terminations are commercially sensitive and rarely announced. The DataCamp and Aeza case became public only because Aeza itself disclosed it. The true rate of upstream action is likely higher than the documented rate, by an unknown margin.

Effect of UK Companies House identity verification

Rollout began 18 November 2025. No published assessment of whether it has slowed shell formation by these networks. Measurable from mid-2026 onward.

RIPE NCC policy trajectory

RIPE NCC stated in November 2021 that it would continue to investigate the possibility of a blanket exemption for internet number resources from EU sanctions regulation, after the Dutch Ministry of Foreign Affairs indicated there was no legal basis for one. If such an exemption were ever granted, the freeze mechanism weakens further. Status as of July 2026 not confirmed in this pass.

Whether a frozen member retains routing security management access

No published RIPE NCC position states whether a member under a sanctions freeze can still create or modify route origin authorisations. A 2020 board announcement described frozen members as unable to access RIPE NCC services, which would imply they cannot, but every transparency report since 2022 defines the freeze narrowly and never mentions the certification service. No one in the RIPE community appears to have asked. Low operational significance given the analysis in Section 04, but it is an open question that a direct request to RIPE NCC would settle.

Non-RIPE registry exposure

This analysis is RIPE-weighted because the profiled providers are RIPE-region. ARIN and APNIC policy on sanctioned members has not been assessed to the same depth.

Sources

[1]Recorded Future Insikt Group, "Malicious Infrastructure Finds Stability with aurologic GmbH," 6 November 2025. recordedfuture.com
[2]Lawrence Stowe, "'Neutral' internet governance enables sanctions evasion," Binding Hook / Virtual Routes, 21 October 2025. bindinghook.com
[3]RIPE NCC, "How Sanctions Affect the RIPE NCC," RIPE Labs. labs.ripe.net
[4]RIPE NCC, "EU Sanctions and Our Russian Membership," RIPE Labs. labs.ripe.net
[5]RIPE NCC, "The RIPE NCC and Ukraine/Russia," member support guidance. ripe.net
[6]Jonas Arnold, "Bulletproof Hosting: Cutting off the facilitators," The Spamhaus Project, 11 June 2026. spamhaus.org
[7]The Spamhaus Project, "The anatomy of bulletproof hosting: past, present, future." spamhaus.org
[8]KrebsOnSecurity, "Stark Industries Solutions: An Iron Hammer in the Cloud," May 2024. krebsonsecurity.com
[9]KrebsOnSecurity, "Bulletproof Host Stark Industries Evades EU Sanctions," September 2025. krebsonsecurity.com
[10]Recorded Future Insikt Group, "One Step Ahead: Stark Industries Solutions Preempts EU Sanctions." recordedfuture.com
[11]Qurium Media Foundation, "Exposing the Evil Empire of Doppelganger disinformation." qurium.org
[12]CORRECTIV, "Inside Doppelganger: how Russia uses EU companies for its propaganda," 22 July 2024. correctiv.org
[13]US Department of the Treasury, "Treasury Sanctions Global Bulletproof Hosting Service Enabling Cybercriminals and Technology Theft," 1 July 2025. home.treasury.gov
[14]Regulation (EU) 2022/2065 (Digital Services Act), Article 4, mere conduit. eur-lex.europa.eu
[15]Digitale-Dienste-Gesetz (DDG), Federal Republic of Germany. gesetze-im-internet.de
[16]UK Government, "Companies House confirms identity verification rollout from 18 November 2025." gov.uk
[17]Wikipedia, "McColo" (Global Crossing and Hurricane Electric de-peering, 11 November 2008; two thirds or greater reduction in global spam volume; brief reconnection 19 November 2008). en.wikipedia.org
[18]BleepingComputer, "Netherlands seizes 800 servers of hosting firm enabling cyberattacks," May 2026. bleepingcomputer.com
[19]Virtual Routes, "Sanctions on bulletproof hosting (Aeza Group)," ransomware countermeasures tracker. virtual-routes.org
[20]EDP BPH provider profiles, Section 04 upstream transit chains: Aeza, Bearhost, DEDBROPRO, Media Land, Stark Industries, ZServers. research.therenoproject.org
[21]EDP Module 09, Bulletproof Hosting Providers, and its Intelligence Annex (internal corpus, Node 03 upstream dependency and chokepoint analysis).
[22]UK Companies House register, Aeza International Ltd (company 15109642, dissolved 24 March 2026) and Hypercore Ltd (company 16558658, dissolved 23 December 2025 under s1002A Companies Act 2006). find-and-update.company-information.service.gov.uk
[23]RIPE NCC, RIPE-858, "Closure of Members, Deregistration of Internet Resources and Legacy Internet Resources" (certificate revocation on closure and deregistration). ripe.net
[24]RIPE NCC Certification Service Terms and Conditions, Article 5.2 (exhaustive revocation triggers) and Article 3.11 (removal of signed objects on termination). ripe.net
[25]RIPE NCC, RIPE-549, Certification Practice Statement for the Resource Public Key Infrastructure, section 4.9 (revocation circumstances, processing times, and CRL publication). ripe.net
[26]Packet Clearing House and co-signatories, "Multistakeholder Imposition of Internet Sanctions," March 2022, section on manipulation of routing security attestations; circulated on the RIPE list. ripe.net
[27]APNIC Labs, RPKI route origin validation adoption statistics (share of networks discarding invalid routes). stats.labs.apnic.net