cross-posted from: https://scribe.disroot.org/post/11213684
n a ninth-floor apartment in the central Serbian town of Krusevac, BIRN tracked down Russian-owned web hosting firm eServer.
It was registered in the months following Russia’s full-scale invasion of Ukraine, in April 2022, by 43-year-old Maxim Azarov.
Azarov’s eServer links to several entities that have been sanctioned by Western states, including Aeza Group and another Russian BPH service provider called Stark Industries Solutions.
…
A so-called bulletproof hosting, BPH, service provider, Aeza Group was sanctioned in July last year by the United States, which accused it of supporting cybercriminals in ransomware attacks, stealing US technology, and selling black-market drugs.
Stark Industries Solutions is another Russian bulletproof hosting provider. It was sanctioned by the European Union in May last year for allegedly providing critical digital infrastructure to Russian and Belarusian state-aligned actors involved in cyberattacks and hybrid warfare.
BPH services providers are defined as selling access to specialised servers and other IT infrastructure designed to help cybercriminals evade detection.
…
Following the EU sanctions, Stark Industries Solutions rebranded as PQ Hosting and transferred its IP resources under the umbrella of Dutch WorkTitans.
In May this year, Dutch police arrested the owners of WorkTitans and MIRhosting on suspicion of aiding Stark Industries Solution in circumventing sanctions.
…
BIRN identified at least eight IP ranges that WorkTitans listed as being located in or used from Serbia and Belgrade, with Serbian Open Exchange, an internet traffic exchange point, serving as the internet gateway for all the ranges. These include two previously advertised by eServer.
…
An analysis of the RIPE NCC database shows that numerous IP ranges previously controlled by Azarov have since passed to two providers previously linked to the Russian bulletproof ecosystem and infrastructure used in cyberattacks: Cypriot-registered IT-Hostline and Russia-based Fortis.
IT-Hostline was previously a partner of Stark Industries Solutions and now provides infrastructure to Aeza Group, according to France-based cybersecurity firm Intrinsec, while Fortis’s infrastructure was used by FIN7 hacking group, responsible for mass financial theft and corporate extortion, Insikt Group reported last year.
Former eServer ranges are also now advertised by Global Connectivity Solutions and Global Internet Solutions, both linked to Aeza Group, Insikt Group said, and identified a number of ransomware groups that it said had used their infrastructure.
…
According to RIPE NCC data, among the current users of IP ranges previously held by eServer are: Russian provider Rost, whose infrastructure was also reportedly used in the Doppelganger campaign; Russian Timeweb, where researchers this year found more than 300 active C2 servers – systems used to send instructions to malware-infected devices and steal data; and US-based Baxet Group, whose infrastructure has been linked to cyberattacks by Russia’s military intelligence service, GRU, as reported by Arctic Wolf Networks, an American cybersecurity company, in November 2025.
…
Experts say the expansion of Russian BPH service providers in Europe is part of an effort to conceal the true origin of malicious traffic and bypass Western cybersecurity alerts.
“In most cases, these are small to medium-sized businesses,” said Campbell, the cybersecurity researcher.
“They will not build huge companies that can easily attract attention, so it is much better for them to set up multiple small, quiet organisations that they can simply abandon when it becomes convenient.”
“A fairly large part of Russian infrastructure in Europe is used more for transit and less for the actual attack infrastructure. The aim is to make it look as though the attacks are coming from the European Union.”


