Spamhaus: Prospero, a notorious provider of abuse-friendly “bulletproof” hosting for cybercriminals, is routing its operations through Kaspersky Lab's networks
One of the most notorious providers of abuse-friendly “bulletproof” web hosting for cybercriminals has started routing … Bluesky: @abuse-ch . Mastodon: @briankrebs@infosec.exchange Bluesky: @abuse-ch : BGP suggests that @kasperskylab.bsky.social is providing internet connectivity to a large Russian cybercrime outfit called Prospero 👀. Both, Securehost and BEARHOST are hosting their infra on Prospero, selling bulletproof hosting services in cyebrcrime forums 🇷🇺🕵️ … Mastodon: BrianKrebs / @briankrebs@infosec.exchange : New, from me: — One of the most notorious providers of abuse-friendly “bulletproof” web hosting for cybercriminals has started routing its operations through networks run by the Russian antivirus and security firm Kaspersky Lab, KrebsOnSecurity has learned. Kaspersky did not respond to multiple requests for comment. …
Context & Ripple Effects
The report shifts attention from abuse-friendly hosting itself to the upstream connectivity that can keep that ecosystem reachable. It follows a prior enforcement example in which authorities took down the Lolek bulletproof-host operation, underscoring that disruption at one hosting provider need not eliminate the underlying service model.
Prospero sits beneath customer-facing services including Securehost and BEARHOST, making the reported routing relationship consequential beyond a single operator. The account is about network routing, not a finding that Kaspersky intentionally supported criminal activity.
First-order effects
- Prospero and the services it hosts, including Securehost and BEARHOST, gain an observed connectivity path through Kaspersky Lab-run networks; defenders can use that routing signal in monitoring and blocklist decisions.
- Kaspersky Lab faces an immediate abuse-handling and reputational test: it will need to assess whether the reported route reflects an authorized customer, a reseller relationship, or another network-path arrangement.
Second-order effects
- Organizations that consume Kaspersky-associated network intelligence or connectivity may scrutinize relevant routes more closely, while other upstream providers may review exposure to bulletproof-host customers and resellers.
- Disrupting a hosting operation becomes less durable when its operators can change upstream paths; enforcement and threat-response teams must track the hosting customers as well as the networks carrying them.
Third-order effects
- If such routing changes remain a common response to takedowns and blocking, accountability for cybercrime infrastructure will increasingly extend from hosting brands to transit, reseller, and routing relationships.
- The later shift reported toward residential proxies that disguise malicious traffic suggests a broader adaptation pattern: abuse services can move between infrastructure layers when one layer becomes more visible or vulnerable to disruption.
The trend: Cybercrime infrastructure is becoming more modular, forcing defenders to trace abuse across hosting, reseller, and connectivity layers rather than treating any one provider as the whole operation.