Dutch Police shut down bulletproof hosting provider Zservers and seized 127 servers

Dutch police seized 127 servers of the bulletproof hosting service Zservers/XHost after government sanctions.

On February 11, 2025, the US, UK, and Australia sanctioned a Russian bulletproof hosting services provider and two Russian administrators because they supported Russian ransomware LockBit operations.

Alexander Igorevich Mishin and Aleksandr Sergeyevich Bolshakov are the two Russian nationals and administrators of Zservers.  

Zservers, headquartered in Barnaul, Russia, has advertised BPH services on known cybercriminal forums to evade law enforcement investigations and takedowns, as well as scrutiny from cybersecurity firms. Zservers has provided BPH services, including leasing numerous IP addresses, to LockBit affiliates, who have used the hosting services to coordinate and launch ransomware attacks.” reads the announcement published by the US Treasury. “During a 2022 search of a known LockBit affiliate, Canadian law enforcement uncovered a laptop operating a virtual machine that was connected to a Zservers’ subleased IP address and running a programming interface used to operate LockBit malware. In 2022, a Russian cybercriminal purchased IP addresses from Zservers, almost certainly for use as Lockbit chat servers to discuss ransomware operations. In 2023, Zservers leased infrastructure, including a Russian IP address, to a Lockbit affiliate”

bulletproof hosting service Zservers

Bulletproof hosting services enable global cybercrime by providing safe havens for threat actors. Weak laws in the Netherlands make shutting them down difficult, highlighting the need for stricter regulations like KYC policies.

A few days later, Dutch police announced it took 127 servers associated with the bulletproof hosting service Zservers/XHost offline. The law enforcement revealed that Zservers’ servers were in Amsterdam, and cybercrime groups like Conti and LockBit used the platform.

“The Cybercrime Team of the Amsterdam police has, after an investigation of over a year, dismantled a bulletproof hoster on the Paul van Vlissingenstraat in Amsterdam. During the raid on February 12, 127 servers were taken offline and seized.” reads the press release published by Dutch Police. “During the operation, a server was found with hacking tools from Conti and Lockbit. They are known as the most productive and damaging ransomware groups in the world”

The investigation began one year ago and is still ongoing, the police are analyzing the data stored on the seized servers.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Zservers)

Leave a Reply

Your email address will not be published. Required fields are marked *

Subscribe to our Newsletter