Threat Intelligence

Cybercriminal infrastructure concealed by recycled Windows images

Red Skull Icon Formed From Binary Code on Computer Screen

Bulletproof hosting providers have been reusing the same preconfigured Windows virtual machine images, unintentionally helping cybercriminals hide their infrastructure, reports Cybernews.

Thousands of servers have been deployed by providers without changing default settings, leaving identical computer names or hostnames across many systems, according to Sophos researchers. Analysis showed that over 7,000 servers linked to ransomware activity shared a single hostname, making unrelated criminal groups appear connected. Well known ransomware and malware operations, including ALPHV/BlackCat, LockBit, and Qilin, were traced back to servers created from the same Windows templates.

With the hostnames remaining unchanged, old servers can disappear while new ones appear with the same name but different IP addresses, potentially resulting in wrong assumptions that an activity is coming from one large network instead of many separate actors. According to Sophos, this setup makes tracking, attributing, and shutting down malicious infrastructure much harder, while giving short-lived ransomware operations cover among legitimate systems.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds