Bulletproof hosting providers have been reusing the same preconfigured Windows virtual machine images, unintentionally helping cybercriminals hide their infrastructure, reports Cybernews.Thousands of servers have been deployed by providers without changing default settings, leaving identical computer names or hostnames across many systems, according to Sophos researchers. Analysis showed that over 7,000 servers linked to ransomware activity shared a single hostname, making unrelated criminal groups appear connected. Well known ransomware and malware operations, including ALPHV/BlackCat, LockBit, and Qilin, were traced back to servers created from the same Windows templates.With the hostnames remaining unchanged, old servers can disappear while new ones appear with the same name but different IP addresses, potentially resulting in wrong assumptions that an activity is coming from one large network instead of many separate actors. According to Sophos, this setup makes tracking, attributing, and shutting down malicious infrastructure much harder, while giving short-lived ransomware operations cover among legitimate systems.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds




