The Containment Era is here. →Explore

Executive Summary

In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA), together with the NSA, FBI, Department of Defense Cyber Crime Center, and international partners, released comprehensive guidance to combat risks posed by Bulletproof Hosting Providers (BPHs). BPHs are infrastructure providers that knowingly lease servers and networking resources to cybercriminals, enabling ransomware, phishing, malware distribution, and denial-of-service attacks at scale. The guidance urges Internet Service Providers and network operators to apply blocklists, traffic analysis, intelligence sharing, and stronger vetting to prevent malicious actors from exploiting BPH resources, aiming to bolster the digital resilience of critical infrastructure sectors globally.

The ongoing proliferation of cyberattacks leveraging BPH infrastructure underscores the urgency of these recommendations. With threat actors increasingly turning to anonymized, resilient hosting to evade law enforcement and detection, proactive mitigation by ISPs is crucial to limiting damage and strengthening industry-wide cybersecurity defense.

Why This Matters Now

Bulletproof Hosting Providers remain a key enabler for organized cybercrime, supplying resilient infrastructure for ransomware, malware, and phishing operations. As defenders modernize their controls, attackers shift to more sophisticated BPH services, making urgent coordinated action critical to disrupt criminal operations and protect critical systems.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Bulletproof Hosting Providers offer infrastructure to cybercriminals, knowingly enabling malware distribution, phishing, and ransomware operations by evading takedown and law enforcement.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Applying Zero Trust network segmentation, workload isolation, egress policy enforcement, inline threat detection, and encrypted traffic controls would have limited attacker movement, prevented command-and-control, and reduced the likelihood and blast radius of both exfiltration and ransomware impact.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Malicious inbound traffic is detected and blocked at the perimeter.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Lateral privilege escalation paths are minimized through strict segmentation.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic monitoring and controls detect and prevent unauthorized lateral movement.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Known malicious C2 destinations are blocked; risky egress channels are restricted.

Exfiltration

Control: Inline IPS (Suricata)

Mitigation: Anomalous exfiltration is detected and can be stopped in real-time.

Impact (Mitigations)

Malicious or anomalous behaviors trigger near-real-time alerts and automated response.

Impact at a Glance

Affected Business Functions

  • Internet Service Provision
  • Network Security Operations
  • Critical Infrastructure Management
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive customer data due to cybercriminal activities facilitated by bulletproof hosting providers.

Recommended Actions

  • Enforce Zero Trust segmentation to restrict both north-south and east-west traffic, containing attacker movement post-compromise.
  • Deploy centralized, multi-cloud-aware firewall and intrusion prevention controls to block traffic from known malicious and bulletproof hosting sources.
  • Apply granular egress filtering and policy enforcement to prevent unauthorized outbound connections and data exfiltration.
  • Enhance threat detection and automated response capabilities to rapidly identify and contain emerging threats, including ransomware and exfiltration events.
  • Maintain real-time visibility, baselining, and logging across hybrid/cloud environments to quickly detect anomalies and support investigations.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image