{"id":10470,"date":"2026-02-07T10:04:30","date_gmt":"2026-02-07T10:04:30","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/07\/bulletproof-hosting-providers-leverage-legitimate-ispsystem-to-supply-servers-for-cybercriminals\/"},"modified":"2026-02-07T10:04:30","modified_gmt":"2026-02-07T10:04:30","slug":"bulletproof-hosting-providers-leverage-legitimate-ispsystem-to-supply-servers-for-cybercriminals","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/07\/bulletproof-hosting-providers-leverage-legitimate-ispsystem-to-supply-servers-for-cybercriminals\/","title":{"rendered":"Bulletproof Hosting Providers Leverage Legitimate ISPsystem to Supply Servers for Cybercriminals"},"content":{"rendered":"<p>    Bulletproof Hosting Providers Leverage Legitimate ISPsystem to Supply Servers for Cybercriminals<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>In the constantly shifting landscape of online threats, cybercriminals have found a new way to strengthen their attacks by hiding behind legitimate technology. <\/p>\n<p>Late in 2025, a series of ransomware incidents revealed that attackers were using virtual machines provisioned through ISPsystem, a popular platform used by hosting companies to manage their servers. <\/p>\n<p>By renting these virtual computers, criminals gained access to powerful infrastructure that appeared trustworthy, allowing them to launch attacks without triggering immediate alarms. <\/p>\n<p>This abuse of commercial infrastructure highlights a growing sophistication in how threat actors procure their resources, shifting from compromised home computers to high-bandwidth data center assets.<\/p>\n<p>These virtual machines became the launchpad for some of the most dangerous ransomware variants, including WantToCry, LockBit, and <a href=\"https:\/\/cybersecuritynews.com\/seiko-data-breach\/\" id=\"38103\" target=\"_blank\" rel=\"noreferrer noopener\">BlackCat<\/a>. <\/p>\n<p>The attackers utilized these servers to establish remote connections, distribute malicious software, and control infected networks from a safe distance. <\/p>\n<p>Since the servers were hosted on legitimate networks, they bypassed many standard security blocks that typically flag suspicious traffic. <\/p>\n<p>This method provided a stable and reliable base of operations, making it difficult for defenders to shut them down quickly. <\/p>\n<p>The integration of commodity malware delivery mechanisms further complicates the defensive posture for affected organizations, requiring more advanced detection strategies.<\/p>\n<p>Sophos analysts <a href=\"https:\/\/www.sophos.com\/en-us\/blog\/malicious-use-of-virtual-machine-infrastructure\" id=\"https:\/\/www.sophos.com\/en-us\/blog\/malicious-use-of-virtual-machine-infrastructure\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> this malicious activity after observing a distinct pattern in the network identifiers of the attacking machines. <\/p>\n<p>They discovered that thousands of these servers shared the exact same computer names, derived from the hosting software\u2019s default templates. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFO_zO5IJy0xXCTchTBSP_yUQi7U29tI4XpX5rsGlwuGP4jLXiNGsB5xpGYhVWgqM1oVDV3BKiPnUfgcBHo1bdqYWuARx30Kq-CHZreYLZ8A-I27iFvtQtRdFSrXR_8AMcYfb4x26XRuyx0CmHSLDBycQzLlIR7tEPVY6p7xPENEAgeNfZPR38sCx_Kpg\/s16000\/Locations%2520of%2520devices%2520using%2520these%2520hostnames%2520based%2520on%2520associated%2520IP%2520address%2520%28Source%2520-%2520Sophos%29.webp?ssl=1\" alt=\"Locations of devices using these hostnames based on associated IP address (Source - Sophos)\"><figcaption class=\"wp-element-caption\">Locations of devices using these hostnames based on associated IP address (Source \u2013 Sophos)<\/figcaption><\/figure>\n<\/div>\n<p>This oversight allowed researchers to trace the widespread infrastructure, identifying over 3,000 active devices in regions including Russia, Europe, and the United States. <\/p>\n<p>The sheer volume of these machines suggests a highly organized effort to maintain a resilient network for criminal operations.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-exploiting-static-configuration-templates\"><strong>Exploiting Static Configuration Templates<\/strong><\/h2>\n<p>The persistence of this threat relies heavily on how these virtual environments are sold. <\/p>\n<p>Service providers like \u201cMasterRDP,\u201d operating as rdp.monster, have built a business model around selling these pre-configured servers. <\/p>\n<p>They market these services on underground forums as \u201cbulletproof,\u201d promising that the servers will remain online despite abuse reports. <\/p>\n<p>These providers act as a critical supply chain link, offering affordable access to dedicated hardware that facilitates large-scale malicious <a href=\"https:\/\/cybersecuritynews.com\/evolving-phishing-campaigns\/\" id=\"107132\" target=\"_blank\" rel=\"noreferrer noopener\">campaigns<\/a>. <\/p>\n<p>By purchasing these resources, attackers can bypass the complex technical challenges of building their own botnets.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEixD_9OAkGIoDqo2g5jU4VOinThhqm2zZFVb_EUJqUaKwVTm7aPSyX-KSdwkbtpeDjZuDuJCXKmzl84cClftHPl9Ubwmex18H0r_ZKFn9s7tmgnjjUIo1RiCOCl2lPdY2aYT95WS2CoN3O1XdebKB4rsl_F5NuWaa-WA4YpsbdXW7o7nSDiKozXIroXts4\/s16000\/Virtual%2520machine%2520services%2520offered%2520by%2520rdp.monster%2520%28Source%2520-%2520Sophos%29.webp?ssl=1\" alt=\"Virtual machine services offered by rdp.monster (Source - Sophos)\"><figcaption class=\"wp-element-caption\">Virtual machine services offered by rdp.monster (Source \u2013 Sophos)<\/figcaption><\/figure>\n<\/div>\n<p>The technical mechanism enabling this scale is the use of static templates within the VMmanager software. <\/p>\n<p>When a new virtual machine is set up using these default templates, it retains specific system identifiers instead of creating unique ones. <\/p>\n<p>This lack of randomization means that every server spawned from the same template looks identical at a system level. <\/p>\n<p>This feature simplifies management for <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-exploiting-legitimate-software\/\" id=\"78092\" target=\"_blank\" rel=\"noreferrer noopener\">legitimate<\/a> administrators but inadvertently provided cybercriminals with a standardized, mass-produced fleet of attack servers ready for immediate deployment. <\/p>\n<p>Recommendations include avoiding default templates and implementing stricter randomization protocols to prevent such uniform exploitation.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/bulletproof-hosting-providers-leverage-legitimate-ispsystem\/\">Bulletproof Hosting Providers Leverage Legitimate ISPsystem to Supply Servers for Cybercriminals<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/bulletproof-hosting-providers-leverage-legitimate-ispsystem\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Bulletproof Hosting Providers Leverage Legitimate ISPsystem to Supply Servers for Cybercriminals In the constantly shifting landscape of online threats, cybercriminals have found a new way to strengthen their attacks by hiding behind legitimate technology. Late in 2025, a series of ransomware incidents revealed that attackers were using virtual machines provisioned through ISPsystem, a popular platform [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-10470","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10470"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10470"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10470\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10470"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10470"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10470"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}