Bulletproof Hosting: Map Criminal Infrastructure
Identify bulletproof hosting through ASN, prefix, domain, abuse, migration, and campaign signals without treating an entire network as malicious.

Some criminal services survive because their hosting provider responds slowly to abuse. Bulletproof hosting (BPH) goes further: the infrastructure is designed, marketed or resold to tolerate malicious customers and resist disruption.
For defenders, the difficult question is not “which country is risky?” It is “which networks, tenants and providers repeatedly enable the same abuse, and with what confidence?” Good threat intelligence maps behavior over time without condemning every address in an ASN.
How Bulletproof Hosting Operates
BPH ecosystems may combine front companies, resellers, stolen accounts, leased prefixes, fast-flux nodes and upstream providers. Services can include phishing kits, malware distribution, botnet panels, spam, credential shops and C2.
An older CISA technical review of phishing infrastructure describes hosting advertised as resistant to shutdown. The business model has evolved, but the defensive principle remains: infrastructure persistence and abuse response are observable signals.
Signals of a High-Risk Hosting Cluster
Repeated malicious use
Count independently confirmed phishing, malware, botnet, scanning and spam observations. Weight diverse sources more heavily than duplicated feeds.
Concentration by prefix and tenant
ASN-wide statistics can hide important detail. Compare /24 or smaller operational ranges, routed prefixes, customer assignments and reverse DNS. One abusive reseller should not automatically taint a large upstream network.
Abuse-handling behavior
Track acknowledgement, remediation and reappearance after reports. Consistent non-response or rapid reactivation under related tenants is stronger evidence than one unresolved complaint.
Infrastructure migration
Monitor domains, certificates, nameservers, panel fingerprints and route announcements as services move. Operators often replace IP space while keeping tooling and naming patterns.
Customer and control-plane overlap
Shared contact details, payment identities, SSH keys, certificates or management panels can connect providers. Attribution must distinguish verified fact from analyst inference.
An Investigation Workflow
Begin with a confirmed malicious IP or domain. Use reverse IP lookup and DNS history to find related names. Enrich every address with IP reputation, ASN, prefix, first-seen and last-seen.
Build a timeline:
- first malicious observation;
- domains and certificates associated with the node;
- abuse reports and provider response;
- route or hosting migration;
- reappearance of the same campaign.
Cluster only when several independent features agree. A shared CDN or certificate authority is weak; a reused panel certificate, nameserver set, page kit and migration timing is much stronger.
Turn Intelligence Into Controls
Use response tiers:
- exact IP or domain blocks for confirmed active infrastructure;
- prefix-level monitoring when abuse is concentrated but tenancy is mixed;
- ASN risk as one feature in authentication, fraud and email scoring;
- temporary emergency blocks with explicit expiry during active incidents;
- provider-level escalation and procurement review where relevant.
Never let “bulletproof” become an unreviewable label. Store evidence, confidence, scope and timestamp. IP space changes hands, and old verdicts can harm new legitimate users.
Takedown and Information Sharing
Preserve DNS, certificates, screenshots, headers, malware hashes, timestamps and victim impact. Send precise abuse reports to the host, upstream provider, registrar and relevant authorities. Coordinate through trusted sharing communities when a campaign affects several organizations.
Avoid public attribution that exceeds the evidence. Naming a reseller, upstream network and criminal operator as if they were the same entity can undermine a valid case.
Metrics
Track infrastructure reappearance after blocking, time from migration to rediscovery, confirmed malicious density by prefix, provider response time and false positives from broad controls. Measure how many new campaign assets each infrastructure pivot reveals.
Conclusion
Bulletproof hosting is a resilient service ecosystem, not a country or one permanent ASN. Map it through repeated abuse, provider behavior, prefix concentration and historical relationships. Combine ASN-aware threat intelligence with current domain and IP evidence to disrupt campaigns without turning network reputation into collective guilt.
Frequently asked questions
- What is bulletproof hosting?
- Bulletproof hosting is infrastructure deliberately operated or resold to tolerate abusive customers, ignore complaints, and keep phishing, malware, spam, or C2 services online.
- Is every IP in a bulletproof ASN malicious?
- No. Networks can contain mixed tenants, victims, resellers, and legitimate services. Defenders should use prefix, tenant, domain, time, and behavior evidence rather than a permanent ASN-wide verdict.
- Why does bulletproof infrastructure migrate frequently?
- Operators move between providers, prefixes, shell companies, resellers, and jurisdictions to survive takedowns and reputation damage. Historical infrastructure relationships are therefore essential.
Related articles
Domain Shadowing: Detect Compromised DNS at ScaleDetect domain shadowing by monitoring DNS changes, certificate issuance, subdomain behavior, account security, and infrastructure relationships.
- Reverse IP Lookup: Pivoting on Infrastructure Without Drowning in Shared Hosting
A reverse IP lookup turns one indicator into a cluster — or into a thousand innocent neighbours. Here is how to tell the difference, and how to pivot on hosting infrastructure without generating false positives.
Malicious Infrastructure Clustering: How Passive DNS, TLS Certificates, and ASNs Reveal Shared CampaignsA single C2 IP is a clue; shared signing patterns and DNS co-occurrence are a map. This guide explains how defenders cluster infrastructure without chasing ghosts—and how to document findings for IR, threat intel, and law enforcement handoffs.
Protect Your Infrastructure
Check any IP or domain against our threat intelligence database with indexed records.
Try the IP / Domain Checker