Cyber Security News

Russian Hackers Using Russia-Based Bulletproof Network to Switch Network Infrastructure

Russian-aligned hacking groups UAC-0050 and UAC-0006 have been observed switching their network infrastructure through bulletproof hosting providers, enabling persistent campaigns against Ukrainian entities and their international allies.

These threat actors conducted financially-motivated and espionage operations throughout late 2024 and early 2025, primarily targeting organizations in Ukraine’s energy sector, governmental institutions, and critical infrastructure.

The malicious campaigns employ sophisticated social engineering techniques, delivering payloads through phishing emails with weaponized attachments.

In one notable campaign in January 2025, attackers deployed NetSupport Manager remote access tools through JavaScript downloaders hosted on compromised infrastructure.

The attacks typically begin with emails containing PDF documents that redirect victims to malicious JavaScript files hosted on services like 4sync.

Intrinsec researchers noted a significant tactical shift in early 2025, when UAC-0050 transitioned from using Remcos and sLoad to predominantly leveraging NetSupport Manager for their operations.

This shift coincided with migration to new network infrastructure hosted on bulletproof providers that specialize in evading detection and legal consequences.

Network Infrastructure

The infrastructure supporting these operations reveals a complex web of bulletproof hosting providers operating through offshore shell companies.

The primary provider, Global Connectivity Solutions LLP (AS215540), is a UK-based autonomous system routing traffic through Stark Industries (AS44477), a network that cybersecurity researchers have linked to Russian intelligence operations.

Analysis of network infrastructure reveals a deliberate strategy to obscure attribution and evade sanctions.

IPv4 prefixes previously announced by sanctioned bulletproof hosting provider Zservers were systematically transferred to newly created autonomous systems including AS213194, AS61336, and AS213010.

These networks are registered to seemingly unrelated entities but share peering agreements and technical characteristics with known malicious infrastructure.

The network traffic patterns reveal communications between infected systems and command and control servers hosted on IP addresses like 185.157.213[.]71 and 147.45.44[.]255, which resolve to domains owned by shell companies registered in offshore jurisdictions like Seychelles.

The complex hosting arrangements provide these threat actors with resilient infrastructure that complicates attribution and frustrates takedown efforts, allowing them to maintain persistent access to compromised systems even as individual infrastructure components that are identified and blocked.

Are You from SOC/DFIR Team? - Try Free Malware Research with ANY.RUN - Start Now

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…

11 minutes ago

OpenAI Releases GPT-5.1-Codex-Max that Performs Coding Tasks Independently

OpenAI has launched GPT-5.1-Codex-Max, a specialized coding model designed to handle complex development tasks autonomously. The…

13 minutes ago

Authorities Sanctioned Russia-based Bulletproof Hosting Provider for Supporting Ransomware Operations

The U.S. Department of the Treasury, Australia, and the United Kingdom have announced coordinated sanctions…

20 minutes ago

Salesforce Confirms that Customers’ Data Was Accessed Following the Gainsight Breach

Salesforce has issued a critical security alert identifying "unusual activity" involving Gainsight-published applications connected to…

2 hours ago

Oracle Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

The notorious Clop ransomware gang has listed Oracle on its dark web leak site, alleging…

3 hours ago

Critical Windows Graphics Vulnerability Lets Hackers Seize Control with a Single Image

A critical remote code execution flaw in Microsoft's Windows Graphics Component allows attackers to seize…

14 hours ago