Ransomware brands die constantly. LockBit was seized. RansomHub went dark overnight. Black Basta collapsed. Every few months a leak site disappears and a press release declares a win.
Meanwhile, one hosting provider sanctioned in late 2025 had been serving attackers since at least 2015. Ten years. It outlived most of the gangs that rented from it, and it would have kept going if governments had not finally decided to sanction the landlord instead of chasing the tenants.
That gap tells you where the real durability in cybercrime sits. Not in the malware, and not in the brand, but in two support layers that almost never make headlines: the infrastructure that keeps criminal operations online, and the network of accounts and people that moves the money out afterwards. Bulletproof hosting is the first. The money mule ecosystem is the second. Together they bracket every ransomware attack, every phishing campaign, and every investment scam you have read about.
This article covers both, because understanding either one alone gives you half a picture. Let me start with where the operation lives.
Figure 1: The visible attack chain gets the coverage. The two layers that bracket it are where the ecosystem is most durable, and most disruptible.
Part One: Bulletproof Hosting
What it actually is
Bulletproof hosting, usually shortened to BPH, is a hosting service that deliberately ignores abuse complaints and takedown requests. That is the entire product. A normal hosting provider that receives a credible complaint about a phishing page will typically suspend the account within hours. A bulletproof provider will not forward the complaint, will not act on it, and in many cases will help the customer move the content somewhere else on their network and keep operating.
Everything else follows from that core promise. These providers tend to operate from jurisdictions where foreign takedown notices carry little legal weight, accept cryptocurrency so that billing cannot be traced to an identity, require no know-your-customer verification, and provision new servers within minutes of payment. Some advertise resistance to law enforcement directly. Others use softer language about "resilience against complaint-driven interruptions," which means the same thing dressed for a website.
What runs on it is the machinery of the rest of the ecosystem: malware command-and-control servers, phishing pages, ransomware leak sites, infostealer panels, and the distribution points for the credential dumps that feed the whole underground economy.

Figure 2a: The complaint goes in. Nothing comes back out. That silence is the entire product.
An honest note on the grey zone
There is a nuance that most explainers skip, and skipping it makes the topic easier to write about but harder to understand.
Not everything marketed as bulletproof hosting is criminal infrastructure. Offshore hosting that ignores foreign takedown notices is also used by journalists in hostile media environments, whistleblower platforms, political dissidents, and privacy advocates who have legitimate reasons to want their content resistant to takedown pressure. Tor relay and exit node operators use it, since running an exit node generates abuse complaints by design. Several providers in this space enforce hard limits on child abuse material and terrorism content while refusing to act on copyright and speech complaints.
So the honest line is not "offshore hosting equals crime." The line is between abuse tolerance and an abuse-driven business model. When a provider's customer base is predominantly criminal, when staff actively help clients evade detection, and when the operator is knowingly selling immunity to victims' complaints, it has crossed from grey into the thing governments have started sanctioning. Analysts who cannot hold both ideas at once end up either dismissing real threats or flagging journalists as criminals.
The 2025 and 2026 crackdown
For years, the enforcement response to cybercrime focused on the gangs. That changed, and the change is recent enough that most security teams have not fully absorbed it.
Figure 2: A coordinated year. Note the final panel, which is the pattern that matters most for analysts.
The sequence ran roughly like this. In February 2025, the United States, United Kingdom, and Australia jointly sanctioned Zservers over its support for LockBit. In May, the European Union sanctioned Stark Industries Solutions. In July, the US Treasury designated Aeza Group, a St. Petersburg operation whose infrastructure had been tied to the Lumma, Meduza, and RedLine infostealers, BianLian ransomware, and a dark web drug marketplace. Then in November 2025 came the largest coordinated action yet, against Media Land, whose infrastructure had been used by LockBit, BlackSuit, and Play, alongside three of its executives and three affiliated companies.
Two details from that November action deserve attention.
The first is that the same day, CISA, the NSA, and the FBI published joint mitigation guidance with agencies from Australia, Canada, the Netherlands, New Zealand, and the United Kingdom. The stated goal was to reduce the effectiveness of bulletproof infrastructure and push criminals back onto legitimate providers that actually respond to complaints and legal process. That is a meaningful shift in strategy: not "take this server down," but "make this whole category of service less useful."
The second detail is the more instructive one. Aeza Group, sanctioned in July, had already rebranded and rebuilt. The November action named Hypercore, a UK-registered front company Aeza was using to evade the earlier designation, along with additional shells in Serbia and Uzbekistan and a new set of executives. Sanctioning a bulletproof host does not end the operation. It starts a race between designation and reincorporation, and the ecosystem has become very good at that race.
Why sanctions work differently from takedowns
It would be easy to read the Hypercore story as proof that none of this works. That reading is too quick.
A takedown removes servers, and servers are cheap to replace. Sanctions attack something harder to rebuild: the ability to do business. A designated provider loses access to Western payment processors, upstream transit relationships, and any customer who cares about legal exposure. Legitimate infrastructure partners have to cut ties or face secondary consequences themselves. As one threat intelligence analyst put it after the Media Land action, this is not the same as a takedown, but it makes it materially harder for these actors to keep operating and serving customers.
The longevity point cuts both ways too. A provider that has been running since 2015 has accumulated a decade of infrastructure, relationships, and reputation. That is exactly what makes it valuable to criminals, and exactly what makes it expensive to rebuild from scratch under a new name with sanctioned executives.
Part Two: The Money Mule Ecosystem
If bulletproof hosting keeps the operation online, the mule ecosystem is what turns a successful attack into money the criminal can actually spend. Stolen funds sitting in a traceable account are not proceeds. They are evidence.
What a money mule is
A money mule is a person who receives and transfers illicit funds on someone else's behalf, usually for a commission. Some are fully complicit. Many are not, having been recruited through a fake job, a romance scam, or a plausible-sounding request from someone they trust. Europol has consistently attributed the overwhelming majority of money mule transactions to cyber-enabled crime, which is what makes this a threat intelligence topic rather than purely a banking one.
The mechanics are simple by design. Stolen funds are deposited into a mule account. The mule transfers them onward, sometimes across borders, sometimes withdrawing cash, sometimes converting to cryptocurrency. Each hop adds distance between the money and its origin. Do it enough times through enough accounts and the trail becomes economically impractical to follow.
Who gets recruited, and how
The recruitment picture in 2026 is broader and more uncomfortable than the stereotype suggests.
Young people remain the primary target. Banking industry research consistently finds 18 to 24 year olds are the most likely to have been approached, and cases have involved mules as young as twelve. The scale can be substantial: in Ireland, a violent organized crime network recruited people aged roughly 17 to 22 and moved on the order of 84 million euros through Irish bank accounts. Recruitment reaches them through fake job advertisements promising easy money for "payment processing," through social media and gaming platforms, and increasingly through Telegram channels that read like gig-economy listings.
But the demographic is widening. Lloyds Bank reported a 73 percent rise in mule accounts held by people over forty, driven largely by romance and investment scams where the victim is simultaneously being defrauded and used as a laundering node. The FBI has documented cases of elderly romance scam victims who became mules without ever understanding what they were participating in.
Regionally, the pressure is intensifying fastest where digital banking has grown quickest. Industry reporting on Latin America documented a 324 percent increase in account takeover and synthetic identity attacks in Mexico between 2024 and mid-2026, with related fraud categories climbing on a similar curve.

Figure 3a: Job ads, gaming chats, romance messages, social posts. Different doors, same funnel.
The industrialization: Mule-as-a-Service
Here is the development that changes the shape of the problem. Laundering capacity is now a product you rent, the same way malware and phishing kits are.
Figure 3: The structural shift is in the caption at the bottom. The mule increasingly does not need to be a willing participant, or a person.
Research by KELA and others describes a tiered supply chain. At the base, account manufacturers open or acquire accounts using real, stolen, or entirely synthetic identities, with AI-generated documents and deepfakes used to clear know-your-customer verification at scale. In the middle, brokers aggregate those accounts and sell them in blocks, largely through Telegram channels and underground forums, sorted by country, bank, balance, and verification level. Business accounts with an established transaction history command premium prices, for obvious reasons. At the top, end buyers, meaning business email compromise crews, romance and investment scam networks, ransomware affiliates, and crypto fraud syndicates, purchase in bulk and layer funds across the accounts until the trail breaks.
These marketplaces come with tiered pricing, customer support, and replacement guarantees if an account is frozen. If that sounds familiar, it is the same commercial pattern documented in the initial access broker ecosystem and in ransomware-as-a-service. Every layer of cybercrime has converged on the same business model.
The structural consequence is significant. The traditional mule was a recruited human being, which meant recruitment was a bottleneck and a point of failure. Purchasing verified accounts built on synthetic identities removes that bottleneck. The mule no longer needs to be persuaded, and no longer needs to exist.
For a sense of how much of the banking system this touches, industry estimates put roughly 0.3 percent of all accounts at US financial institutions under mule control. That sounds small until you multiply it out.
The crypto layer
The cash-out increasingly runs through cryptocurrency, and one category now dominates it.
Chainalysis reported in its 2026 Crypto Crime Report that Chinese-language money laundering networks, operating largely through Telegram, processed 16.1 billion dollars in 2025 alone, roughly 44 million dollars per day, across more than 1,799 active wallets. That makes them approximately 20 percent of all known cryptocurrency money laundering activity and the single largest laundering channel in the ecosystem. Their growth has been extraordinary, with inflows expanding thousands of times faster than flows to centralized exchanges over the same period.
What is notable for analysts is the internal specialization. Chainalysis identified distinct service types within these networks based on on-chain behavior, including brokers who serve as the entry point for illicit funds, coordinated groups of mule accounts that move value in formation, informal over-the-counter services, and gambling-based laundering. This is the same division of labor seen everywhere else in cybercrime, expressed in wallets instead of job titles.

Figure 4a: One deposit, then layer after layer of transfers, until the trail is not worth following.
These networks also connect to the Telegram marketplace ecosystem and, uncomfortably, to the Southeast Asian scam compounds where much of the fraud that feeds them originates.
Where the Two Layers Meet
Put them side by side and the shared characteristics become obvious.
Both are rented rather than owned. Both are shared infrastructure, used simultaneously by unrelated criminal groups who may be competitors. Both are commercially structured, with pricing tiers and customer support. Both have quietly outlasted every headline-grabbing gang that depended on them. And both are, for exactly that reason, the highest-value targets in the entire ecosystem.
That last point is the strategic argument, and it is one that firms tracking the ransomware economy have been making with increasing force. The service layer generally operates with weaker operational security than the ransomware crews themselves, because running a hosting company or a mule account marketplace requires visible commercial infrastructure: incorporation, banking relationships, upstream providers, advertising. That visibility is a vulnerability. Disrupting the plumbing scales better than chasing one leak site at a time, because the plumbing serves everyone.
What This Means for CTI Analysts
There is specific, practical tradecraft here.
Hosting infrastructure is trackable, and it is durable intelligence. Because criminal groups cluster on a small number of providers, mapping autonomous system numbers, netblocks, and hosting relationships gives you detections that survive malware changes. When an actor rotates payloads weekly but keeps the same hosting provider for years, the hosting is the better indicator. Sanctions designations are a gift here: they publish specific entities, individuals, and sometimes cryptocurrency addresses that you can pivot from.
Watch for the rebrand, not just the designation. The Hypercore pattern is the lesson. When a provider is sanctioned, the analytical question is not "is it gone" but "where did it reappear, under whose name, in which jurisdiction." Front companies leave paper trails in corporate registries, and infrastructure reuse leaves technical fingerprints.
Mule marketplaces are collectable. Advertisements for verified accounts in a specific country or bank are a leading indicator of where fraud pressure is heading next, in the same way access broker listings precede ransomware. For any organization with a financial services angle, monitoring for your own institution's name in mule account listings is a genuine early-warning capability.
Treat both layers as part of one picture. An investigation that maps the hosting but not the cash-out, or the money movement but not the infrastructure, tends to end at the boundary of the analyst's own comfort zone rather than the boundary of the operation.
This is exactly the kind of ecosystem literacy CTI Academy's Hunter track is built to develop. Our NullBase environment lets you practice reading underground listings and tracking actor personas in a simulated forum, which is the skill this work depends on, and LeakLens puts you inside the credential and breach data that feeds the fraud these networks monetize. A SOC simulator and a phishing simulator are also on the CTI Academy roadmap, adding the operational detection reps alongside the intelligence work. If you want to learn to read the support layer the way an analyst has to, start with the Hunter track.
Common Misconceptions
"Bulletproof hosting is just offshore hosting." No. Offshore hosting that resists foreign takedown notices has legitimate users, including journalists and privacy platforms. The distinction is whether the business model is built on selling immunity to victims of crime, and whether the operator knowingly serves criminal customers.
"Sanctioning a host shuts it down." No. It degrades the business and cuts off legitimate commercial relationships, but operators rebrand through front companies, as Aeza demonstrated within months. The value is in raising cost and friction, not in a clean kill.
"Money mules are all willing criminals." No. A large share are recruited through fake jobs or are simultaneously victims of romance and investment scams. Prosecution policy varies, but the human picture is far messier than the label suggests.
"This is a banking problem, not a security problem." No. Europol attributes the overwhelming majority of mule activity to cyber-enabled crime, and mule marketplaces now operate on the same underground platforms as access brokers and malware vendors. It is one ecosystem.
Frequently Asked Questions
What is bulletproof hosting?
Bulletproof hosting is a web hosting service that deliberately ignores abuse complaints, takedown requests, and law enforcement pressure. Providers typically operate from permissive jurisdictions, accept cryptocurrency, require no identity verification, and keep malicious content online. It hosts malware command-and-control, phishing pages, ransomware leak sites, and infostealer panels.
Is bulletproof hosting illegal?
The hosting itself sits in a grey area, since offshore hosting that resists foreign takedown notices also serves journalists, whistleblower platforms, and privacy advocates. What has drawn sanctions is the abuse-driven business model, where a provider knowingly serves criminal customers and helps them evade detection. Several providers have had executives imprisoned and companies sanctioned.
Which bulletproof hosting providers have been sanctioned?
Between February and November 2025, coordinated actions targeted Zservers, sanctioned by the US, UK, and Australia over LockBit support, Stark Industries Solutions, sanctioned by the EU, Aeza Group, designated by the US Treasury, and Media Land, sanctioned alongside its executives and subsidiaries. Aeza subsequently rebranded through a UK front company called Hypercore, which was also designated.
What is a money mule?
A money mule is someone who receives and transfers illicit funds on behalf of criminals, usually for a commission. Some are fully complicit, but many are recruited unwittingly through fake job offers, romance scams, or social media advertisements. Each transfer through a mule account adds distance between stolen money and its origin.
What is Mule-as-a-Service?
Mule-as-a-Service is the industrialized version of money muling, where laundering capacity is rented rather than recruited. Account manufacturers create accounts using stolen or synthetic identities, brokers sell them in blocks on Telegram sorted by country, bank, and verification level, and end buyers such as fraud and ransomware crews purchase in bulk. Listings often include replacement guarantees.
How are money mules recruited?
Primarily through fake job advertisements promising easy money for payment processing, social media and gaming platforms, Telegram channels, and romance or investment scams where the victim is defrauded and used as a laundering node simultaneously. People aged 18 to 24 are most commonly approached, though mule accounts held by people over forty have risen sharply.
How do criminals cash out stolen funds in cryptocurrency?
Increasingly through specialized laundering networks. Chainalysis reported that Chinese-language money laundering networks operating largely via Telegram processed 16.1 billion dollars in 2025, around 20 percent of all known crypto laundering, using specialized roles including entry brokers, coordinated mule wallet groups, informal over-the-counter services, and gambling-based laundering.
Why do analysts focus on bulletproof hosting and money mules?
Because they are the most durable and most disruptible parts of the ecosystem. Ransomware brands collapse and rebrand within weeks, but hosting providers and laundering networks serve many groups over many years. They also operate with weaker operational security, since running a hosting company or account marketplace requires visible commercial infrastructure.
Sources
- US Department of the Treasury, Treasury Sanctions Global Bulletproof Hosting Service Enabling Cybercriminals
- The Record, US, allies sanction Russian bulletproof hosting services for ransomware support
- CyberScoop, Five Eyes just made life harder for bulletproof hosting providers
- Elliptic, US cracks down on Russian bulletproof hosting services
- Chainalysis, 2026 Crypto Crime Report
- KELA, Exposing the Underground Mule-as-a-Service Economy
- Europol, European Money Mule Action results
- Sumsub, What Is a Money Mule? Red Flags, Examples, and Prevention in 2026