Module 4: Hosting, Networks, Investigation, and Disruption

Bulletproof Hosting in the TDS Ecosystem

Understand what bulletproof hosting provides, how it differs from ordinary hosting abuse, and which named providers were publicly designated.

In this lesson, you will learn to:

  • Differentiate a TDS from bulletproof hosting.
  • Map BPH dependencies and interpret named provider evidence responsibly.

Bulletproof Hosting in the TDS Ecosystem

Covers abuse tolerance, address space, ASNs, datacenters, upstream carriers, front companies, DDoS protection, and official 2025–2026 examples including Aeza Group, ZServers, and XHost.

BPH keeps infrastructure available; a TDS routes traffic

Spamhaus defines bulletproof hosting as DNS, web, mail, or other service provided with explicit or tacit refusal to disconnect customers engaged in spam or cybercrime. A BPH provider may supply servers, virtual machines, IP addresses, DNS, connectivity, DDoS protection, and rapid replacement. A TDS classifies and routes visitors. One criminal operation can use both, but they are not the same layer.

A TDS might run on ordinary compromised infrastructure, a public cloud account, shared hosting, or a BPH. Its landing pages or payload servers might use different providers. Conversely, a BPH can host botnet command-and-control, leak sites, phishing, marketplaces, or malware panels without operating a TDS. Name the observed service and role separately.

The host depends on a supply chain

A hosting operation needs physical datacenters, servers, IP address space, an Autonomous System or a network willing to announce routes, upstream carriers, domain and DNS services, and payment. Some BPH providers own parts of this stack; others lease them, use front companies, or hide a real datacenter behind remote DDoS protection. IPv4 scarcity makes address suppliers and network connectivity important chokepoints.

An ASN is an identifier for a routing domain, not a verdict about every address or customer. Investigate registration and routing history, upstreams, announced prefixes, geolocation limits, abuse contacts, customer density, and changes over time. BPH operators can move prefixes or downstream arrangements. Provider attribution requires more than one malicious IP; look for sustained abuse, re-provisioning, advertised services, corporate links, and authoritative actions.

Named 2025 cases illustrate evidence standards

In July 2025, the U.S. Treasury designated Aeza Group as a BPH provider and said it supported Meduza and Lumma infostealers, BianLian ransomware, RedLine panels, and the BlackSprut marketplace. Treasury identified Aeza International as a UK branch used to lease IP addresses, plus Aeza Logistic and Cloud Solutions as subsidiaries. These are official allegations and sanctions findings with a date and jurisdiction.

In February 2025, the United Kingdom sanctioned ZServers, six members, and XHost Internet Solutions LP, describing ZServers as BPH used by LockBit affiliates and XHost as a company supporting and obscuring that activity. These examples teach attribution through corporate, operational, and government evidence. They do not establish that these providers hosted every TDS in this course. Keep BPH case links separate unless a source directly connects them.

Resources