Bulletproof hosting providers rent cheap infrastructure to provide virtual machines to ransomware hackers


  • Sophos reports that bulletproof hosting providers are renting VMmanager-based servers to cybercriminals
  • Identical Windows templates leave thousands of vulnerable servers exploited for ransomware and malware campaigns
  • Infrastructure linked to major groups (LockBit, Conti, BlackCat, Qilin, TrickBot, etc.) and sanctioned Russian hosting company

Bulletproof hosting providers are leasing cheap infrastructure to cybercriminals and giving them virtual machines to use in ransomware attacks, new research has found.

A report by Sophos explained how legitimate services were misused to launch attacks on a massive scale without the need to build custom infrastructure.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top