What is bulletproof hosting? Recognizing abuse tolerant networks in registry and routing records
Bulletproof hosting is a business posture, not a technology. The servers are ordinary; what is being sold is tolerance: abuse reports go unanswered or answered only for show, takedown requests go nowhere, and when a customer's address burns, the provider hands them a fresh one. Because the posture is commercial rather than technical, it tends to leave traces in the public records anyone can check, and this post is about reading them: what the term means, how the documented operations actually worked and ended, and the pattern an analyst can look for, with the standing caveat that no single trace is proof of anything.
A business posture, not a technology
The institutions that fight this thing define it by behaviour, not by hardware. Europol's IOCTA 2023 glossary calls bulletproof hosting a service that "allows their customers considerable leniency on the content they can upload" and notes such providers "tend not to respond to lawful requests for information". Spamhaus defines it as services "provided with either explicit or tacit actions not to disconnect customers who spam or engage in cybercrime", a wording worth pausing on, because the tolerance can be a sold feature or a cultivated blindness. The US Treasury, in the first of its 2025 sanctions against bulletproof hosters, described providers that "sell access to specialized servers and other computer infrastructure designed to evade detection and defy law enforcement attempts to disrupt these malicious activities".
The behaviour matters because mere slowness is everywhere. In an October 2018 measurement, abuse.ch reported that of the six hundred plus hosting providers its URLhaus project had notified over the preceding two months, only about 16 percent got reported malware content offline within six hours on average, and the same measurement put the overall average reaction above three days. A slow abuse desk is normal. The bulletproof posture is different in kind: the report is not backlogged, it is the thing the customer paid to have ignored. Running an abuse desk shows what the legitimate version of this work looks like.
How the business survives being known
The research literature documents an operation that long ago stopped being a single dirty data centre. Trend Micro's 2015 taxonomy described three models: dedicated servers whose provider knowingly hosts the material, compromised legitimate servers rented onward, and abused cloud accounts at ordinary providers. A 2017 IEEE Security and Privacy paper, Under the Shadow of Sunshine, documented the trend that matters most for record readers: bulletproof services subletting infrastructure inside legitimate lower end providers, migrating between network blocks to defeat address based blocklists; a conservatively trained version of the authors' detector, run across the IPv4 space, flagged roughly 39,000 malicious network blocks. Spamhaus's 2025 analysis of the modern ecosystem adds the registry side: address space leased through broker resellers rather than held directly, shell corporations registered in unobtrusive jurisdictions, predominantly the UK and US, that pass superficial vetting, rapid hops to a new broker when a lease is terminated, occasional operation on hijacked networks, and in at least one case Spamhaus observed in August 2025, a hoster buying outright the prefixes it had previously rented.
The clearest official illustration of the whole posture is in the US Treasury's February 2025 designation of Zservers, a Russia based provider sanctioned jointly with the UK and Australia for supporting LockBit ransomware operations. Per Treasury's statement: after a Lebanese company complained that a Zservers associated address had implemented LockBit in an attack, the two administrators shut the address down; Treasury says one then instructed the other to change the malicious user's IP address, told the complainant the original address was cut off, and assesses that Zservers likely enabled the attacks to continue on the new address. That is an abuse desk as theatre: the report was answered and, on Treasury's assessment, the abuse was rehoused. And when pressure arrives, the response is registry churn. After sanctioning Aeza Group in July 2025, Treasury's follow up action that November stated that Aeza's leadership began a rebranding focused on removing connections between Aeza and its new infrastructure, registering a fresh UK company to move its IP infrastructure and, per Treasury, allegedly standing up capacity through Serbian and Uzbek firms not publicly associated with the brand. Shell companies and re homed prefixes are not a side effect of this business; they are its immune system.
Three endings, on the record
McColo, a San Jose hosting company, was cut off on 11 November 2008 when its two transit providers, Global Crossing and Hurricane Electric, terminated its connectivity after Washington Post reporting presented them with evidence compiled by security researchers. Global spam fell immediately and measurably, though how far depended on where you measured: reports around two thirds circulated widely, while a peer reviewed 2009 study measured 36 percent in the United States and up to 73 percent elsewhere, and the same study documented volumes recovering to pre shutdown levels within months as the botnets rebuilt elsewhere. A year on, the Washington Post reported McColo's own ranges still sat largely unused, poisoned by blocklists. The lesson cuts both ways: cutting the network worked instantly, and it dismantled none of the operations behind the spam.
The Russian Business Network, a St. Petersburg operation documented in 2007 by Verisign iDefense research and Washington Post reporting as hosting phishing, malware and child abuse material, ended without any arrest at all: overnight on 6 to 7 November 2007 the routing for its prefixes under AS40989 simply ceased, with Trend Micro confirming "there is no routing for them any longer". Press coverage inferred, but no provider ever confirmed, that its upstreams had withdrawn transit. Almost everything else told about RBN, its alleged leader, his supposed political connections, the share of world cybercrime laid at its door, rests on anonymous sourcing and vendor estimates that no court ever tested; RBN itself was never prosecuted. It remains the canonical example of an operation whose only reliable biography is its routing record.
CyberBunker is the adjudicated one. In September 2019 several hundred German police raided a former NATO bunker in Traben-Trarbach; in December 2021 the Trier regional court convicted all eight defendants of membership in a criminal organisation, with sentences from one year suspended to five years and nine months, while acquitting them of accessory liability for the roughly 250,000 offences committed through hosted sites, which trial coverage identified as including darknet markets Wall Street Market and Cannabis Road, because they lacked concrete knowledge of the individual crimes. Germany's Federal Court of Justice made the convictions final in September 2023, rejecting the argument that intermediary liability protections covered a service built to conceal crime. That is the legal shape of bulletproof hosting in the one case that ran its full course: the organisation was the crime, even where the individual hosted offences could not be pinned to the operators.
The traces in public records
Most pieces of the posture show up somewhere public, and each has an innocent explanation, which is why the pattern is the finding and no single trace is. The abuse contact: registries publish one for every block, and in the RIPE region the NCC has validated abuse-c mailboxes at least annually since 2019, checking syntax, DNS and that the mailbox technically accepts mail, though legacy space is outside the policy's scope and validation deliberately does not check whether anyone reads the reports. A contact that bounces across validation cycles, or a desk that answers the way Treasury describes Zservers answering, is a different fact from a desk that is merely three days slow. The registration: the adjudicated example of fabricated registrant identity is the Micfo case, where per the Department of Justice a scheme of sham companies with fake officers sought roughly 1.3 million IPv4 addresses from ARIN and obtained the rights to about 758,000 of them, valued near ten million dollars or more; ARIN won revocation in arbitration in 2019, the principal pleaded guilty mid trial in 2021 to twenty counts of wire fraud, was sentenced to five years in 2023, and the conviction became final when the Supreme Court declined the case in January 2026. The routing behaviour: the serial hijacker study at IMC 2019 flagged 934 autonomous systems whose announcements looked like persistent hijackers, with roughly a fifth weeded out on manual review as legitimate operations such as DDoS mitigation, and press coverage of the paper noted flagged networks' announcements lasted under 50 days on average against nearly two years for legitimate ones. Spamhaus's 2019 hijacking explainer documents the dormant space side: derelict allocations revived through forged authority letters and resurrected contact domains. Reading a prefix's routing history is the tutorial for spotting that churn, and hijacked or transferred the procedure when it matters.
One trace deserves an explicit demotion: missing RPKI. As of mid 2026 roughly two thirds of announced prefixes carry valid ROAs per Hurricane Electric's adoption data, which means about a third of the perfectly legitimate internet still has none. A missing ROA by itself indicates nothing. It earns a place on the list only as one more absence in a record that is absent everything else.
Why the single address is the wrong altitude
Everything above explains why defenders who meet this tier stop blocking addresses. Spamhaus's stated rationale for its network level DROP list is precisely that bulletproof hosters either ignore abuse reports or move abusive customers to different addresses to evade targeted listings, and its 2023 rationale for relaunching the AS level list was networks that announce a prefix for hours, spam, and withdraw it. When the adversary's unit of retreat is the prefix, the defender's unit of response has to be at least the prefix, and sizing a block to the evidence is the decision framework for how wide. Researching the ASN is how you find out whether the network behind an address deserves network level treatment. The state has moved to the same altitude: coordinated US, UK and Australian sanctions against named bulletproof providers in 2025, a joint defensive guide from CISA, the NSA, the FBI and five allied cyber centres that November, and a US indictment unsealed in July 2026 charging a provider's operators over more than 62 million dollars in victim losses, allegations the defendants are presumed innocent of, but a marker of where enforcement now aims. For buyers the implication is simpler: space that once lived inside one of these operations is a discounted, difficult asset, which is why checking a range's history before buying and expecting inherited listings are standing advice on this site.
Reading it in a report
On a subnethistory report, this whole post compresses into a handful of places to look. The confirmed tag vocabulary includes bulletproof-hosting itself, alongside the trace level tags this post has been describing: unreachable-abuse, shell-asn, stale-registration, fabricated-registration, frequent-origin-change and dormant-space-revived. Where one of those has been applied, it usually sits on the announcing network rather than the prefix. The abuse contact the report shows is the one the registry chain actually resolves to, walked upward through the enclosing blocks, so you see what a reporter would reach rather than what the holder claims. The Organisation row names the holder, the Type row prints the registry's own status string, and the origin history shows the networks RIS peers have seen announce the space with first and last seen dates, which is where churn becomes visible. Two honest limits close the loop. The traces checklist above is what public records offer any analyst; it is not a description of how our tags are assigned, and a range can wear every innocent explanation at once. And confirmed tags are sparse by design: most networks carry none, so absence of a tag, this site's oldest caveat, is never a finding of innocence.
When an address in your logs traces back to a network you do not recognise, look it up before you decide what it is: the holder and registry status, the abuse contact the chain actually resolves to, any confirmed tags on the announcing network, and the origin history that shows whether the space has lived a settled life or a rotating one. Bulletproof hosting survives by being hard to see one address at a time. The record is where the pattern shows.