This is highly likely CrazyRDP :)
16.11.2025 19:58 β π 2 π 0 π¬ 0 π 0@lawrencesec.bsky.social
π¬π§ Threat Research @ Recorded Future. I Like Tracking ASNs and ISPs for some reason...
This is highly likely CrazyRDP :)
16.11.2025 19:58 β π 2 π 0 π¬ 0 π 02/ ASNs believed to be utilised by CrazyRDP were reportedly downstream of aurologicβ¦.. lowendspirit.com/discussion/c...
15.11.2025 12:08 β π 0 π 0 π¬ 0 π 01/ Reports indicating that CrazyRDP is the bulletproof hoster behind this seizure in the Netherlands. nltimes.nl/2025/11/14/d...
15.11.2025 12:07 β π 2 π 1 π¬ 1 π 03/ metaspinner net GmbH (Hamburg, Germany) has no affiliation with #AS209800, Virtualine Technologies, or any related malicious activity associated with that network.
12.11.2025 21:52 β π 0 π 0 π¬ 0 π 02/ A falsified RIPE end-user agreement provided to Insikt Group highlights how a basic verification check against publicly accessible company registration documents could have prevented the fraudulent registration.
12.11.2025 21:52 β π 0 π 0 π¬ 1 π 01/ [UPDATE] As of November 10, 2025, metaspinner net GmbH has provided substantial evidence confirming Insikt Groupβs original assessment that their identity was unlawfully and fraudulently used in the registration of #AS209800.
12.11.2025 21:51 β π 1 π 1 π¬ 1 π 0German ISP aurologic GmbH Identified as Key Hub for Malicious Hosting Infrastructure gbhackers.com/german-isp-a...
09.11.2025 15:24 β π 1 π 1 π¬ 0 π 0Malicious Infrastructure Finds Stability with aurologic GmbH
07.11.2025 11:24 β π 1 π 1 π¬ 0 π 0German ISP Aurologic GmbH has Become a Central Nexus for Hosting Malicious Infrastructure
08.11.2025 00:41 β π 2 π 3 π¬ 0 π 0/10 Dive into the full report βMalicious Infrastructure Finds Stability with Aurologic GmbHβ for the data, analysis, and context behind this ecosystem: www.recordedfuture.com/research/mal...
06.11.2025 11:34 β π 3 π 0 π¬ 0 π 09/Aeza Group continues to rely on aurologic for a large share of its connectivity, announcing roughly half of its IP space, despite recent sanctions by the US and the UK.
06.11.2025 11:33 β π 4 π 0 π¬ 1 π 08/ Femo IT Solutions was allocated a /24 prefix from a /17 network registered to the Iranian Research Organization for Science and Technology (IROST), the same origin seen in allocations to other TAEs such as Global Connectivity Solutions and Aeza Group.
06.11.2025 11:33 β π 3 π 1 π¬ 1 π 07/ Femo IT Solutions Ltd #AS214351 is a UK-registered network with close operational ties to self-proclaimed bulletproof hoster βDefhostβ, who offer βGermany-onlyβ abuse-resilient services on underground forums.
06.11.2025 11:32 β π 2 π 0 π¬ 1 π 06/ Virtualine Technologies is a Russia-linked TAE with operational ties to multiple organizations used to register and control IP space, masking ownership and maintaining operational control through networks like Railnet.
06.11.2025 11:32 β π 2 π 0 π¬ 1 π 05/ Railnetβs elevated abuse levels followed the transfer of Metaspinner Net IP space to Lanedonet, networks assessed with high probability to have impersonated legitimate companies, under the control of actors tied to Virtualine Technologies.
06.11.2025 11:31 β π 2 π 0 π¬ 1 π 04/ Railnet LLC #AS214943 is one of the largest sources of malicious infrastructure observed by Insikt Group, with over 80 validated C2 servers currently active on the network.
06.11.2025 11:31 β π 2 π 0 π¬ 1 π 03/ Among the highest risk networks are: The recently sanctioned Aeza Group #AS210644, Railnet LLC #AS214943, Global-Data System IT Corp aka SWISSNETWORK02 #AS42624, and Femo IT Solutions #AS214351.
06.11.2025 11:30 β π 4 π 1 π¬ 1 π 02/ RecordedFuture network intelligence identified persistent malicious infrastructure across more than 20 networks receiving upstream transit from aurologic, several of which are assessed with high probability to operate as Threat Activity Enablers (TAEs).
06.11.2025 11:30 β π 2 π 0 π¬ 1 π 01/ New report from myself and @whoisnt.bsky.social: βMalicious Infrastructure Finds Stability with aurologic GmbH.β
We uncover how German ISP aurologic GmbH has become a central nexus for high-risk hosting networks, sustaining large concentrations of malicious infrastructure.
Recorded Future just published Dark Covenant 3.0, revealing how global crackdowns and shifting Russian enforcement are reshaping the cybercriminal underground, exposing ties to state actors and turning cybercrime into a geopolitical tool: www.recordedfuture.com/research/dar...
22.10.2025 14:26 β π 7 π 7 π¬ 0 π 0Great work by my colleague, @lawrencesec.bsky.social ! He dives deep into the systemic flaw where "neutral" internet governance lets sanctioned ISPs evade restrictions and continue supporting #cyberattacks and #disinformation. A must-read on the infrastructure gap. π
21.10.2025 08:45 β π 5 π 1 π¬ 0 π 0Great opinion piece by my colleague @lawrencesec.bsky.social on an extremely timely and important topic!
21.10.2025 08:59 β π 2 π 2 π¬ 0 π 0π¨ My latest research for @bindinghook is out!
I explore how sanctions against #Aeza and #StarkIndustries reveal the limits of current policy, and how #ThreatActivityEnablers exploit RIR policy and company registration frameworks to maintain infrastructure and support ongoing cyber operations.
In his latest for Binding Hook, @lawrencesec.bsky.social looks at how internet service providers work within the system to evade sanctions and enable #cyberattacks and #disinformation campaigns: bindinghook.com/neutral-inte...
21.10.2025 07:19 β π 6 π 2 π¬ 0 π 3#Surveillance has become central to #counterterrorism in democracies, but its spread into daily life raises a key question: how much monitoring can a free society absorb without losing trust? bindinghook.com/why-democrac...
16.10.2025 11:19 β π 1 π 1 π¬ 0 π 0π Don't miss the first Colloquium session tomorrow!
π Mythical Beasts and Where to Find Them: Diving into the Depths of the Global Spyware Market
π‘ Jen Roberts (@cyberstatecraft.bsky.social) & @julianferdinand.bsky.social (Recorded Future)
ποΈ October 2, 2025
π 16:00 β 17:00 CET
First public report at Recorded Future by yours truly is out! RedNovember (formerly TAG-100, a.k.a. Storm-2077) is a Chinese state-sponsored threat group focused on intelligence collection, especially on flashpoint issues of strategic interest to China. www.recordedfuture.com/research/red...
24.09.2025 18:57 β π 21 π 14 π¬ 2 π 01/ Hi, I'm TProphet. I write the Telecom Informer for @2600.com. A lot of people have been asking me about www.nbcnews.com/politics/nat... given that I'm somewhat knowledgeable in the area.
Here's my take: I'm kind of astonished that this is public, and it isn't normal that it would ever be.