# Cloud ASN Risk Watchlist: methodology and changelog

Evidence and routing snapshot **2026-10-09**. Bundle generated 2026-10-09.

Canonical page, which is always more current than a copy of this file:
<https://blog.infostruction.com/research/cloud-asn-risk-watchlist/>

Licensed CC BY 4.0. Use it, build on it, say where it came from.

## What this is

A tiered catalog of hosting, VPS, VPN, proxy, bulletproof-hosting and
campaign infrastructure, built to prioritise unusual Entra ID and
Microsoft 365 employee sign-ins while keeping shared-cloud false
positives under control.

## What an ASN match means, and what it does not

An autonomous system number is a risk feature. It is not attribution.
An actor using a provider does not make the provider complicit, and the
country an ASN is registered in does not identify the actor, the
employee, or the place a sign-in came from.

Every tier in this catalog is built on that distinction. T1 does not mean
block, it means look now. Nothing here supports an ASN-only verdict.

## Counts

| Measure | Value | What it means |
|---|---|---|
| Catalog ASNs | 1151 | Every researched autonomous system in the current standalone catalog. |
| Enabled for monitoring | 559 | Rows switched on by default. The rest are disabled pending tenant validation. |
| T1 Critical | 403 | Highest-priority identity and infrastructure risk. |
| T2 High | 60 | Direct campaign, commercial anonymizer, or strong provider evidence. |
| T3 Context | 107 | Hosting and VPS context that needs a corroborating anomaly. |
| T4 Review | 581 | Broad cloud, access ISP and lifecycle-review rows, disabled by default. |
| On Spamhaus ASN-DROP | 431 | Current membership in the ASN-DROP snapshot for this build. |
| Published indicators | 511 | Exact IPs, CIDRs, domains, hashes and application IDs with observation dates. |
| Detection patterns | 29 | Identity and post-authentication patterns, each tied to its event sources. |
| Cited sources | 159 | Every tiering decision resolves to one of these source records. |
| Holder countries represented | 82 | RIR holder registration, which is not where a sign-in came from. |
| Review-only rows | 592 | Candidates examined and left disabled, with the reason recorded. |

## Tiers

| Tier | Default | What puts an ASN here | How to handle a match | False-positive risk |
|---|---|---|---|---|
| T1 Critical | Enabled | Current high-confidence risk plus direct identity, BPH, or local critical evidence | Immediate triage of successful interactive sign-ins. Validate dependencies before deny actions. | Medium |
| T2 High | Enabled | Direct credential campaign, commercial anonymizer, or strong threat-infrastructure evidence | High-severity alert on success or failed-to-success sequence. | High |
| T3 Context | Enabled | Commodity VPS, hosting, or point-IOC provider context | Require identity, device, session, travel, MFA, or exfiltration corroboration. | High to very high |
| T4 Review | Disabled | Broad cloud, access ISP, uncertain continuity, or non-originating allocation | Tenant-specific review only. Never use as an ASN-only verdict. | Very high |

### Effective enablement

The `Effective Enabled` column is what decides whether a row is live. In this snapshot 559 of 1151 rows are enabled.

T1 and T2 are enabled throughout. T3 is enabled with a small number of
exceptions where the evidence did not survive review. T4 is disabled
throughout, because it holds broad cloud networks, access ISPs, uncertain
ownership continuity and allocations that are not currently originating
routes. Those are the rows where an ASN-only match is most likely to be
an employee on a phone rather than an intruder.

The research workbook this bundle is generated from also carries a local
override layer, so an analyst can force a row on or off for one tenant and
record why. That layer is tenant-specific and is removed from every file
here. What you get is the researched default. Build your own override
column on top of it; do not edit the defaults in place, or the next
refresh will silently revert your decisions.

## Holder country against event-time geolocation

`RIR Country Code` is where the ASN holder is registered. It is useful for
filtering provider ownership context and useless for deciding where a
sign-in came from.

Use event-time IP geolocation for that, and apply the
`Event-Country Policy` column in the country summary to it rather than to
the holder country. A US-registered network can carry a foreign operator's
exit traffic, and a foreign-registered server can be a compromised host
belonging to anyone.

## Operating rules

**Purpose.** Prioritize unusual Entra ID and Microsoft 365 employee sign-ins from hosting, VPS, anonymizer, bulletproof-hosting, and high-abuse networks while controlling shared-cloud false positives.

**Core distinction.** An ASN is a risk feature, not attribution. Provider use by an actor does not prove complicity. RIR country does not identify the actor, employee, or event location.

**Country fields.** ASN Catalog records the current holder-registration country and scope. Apply Country Summary policy to event-time IP geolocation. A US exit may be used by a foreign actor, and a foreign server may be compromised by anyone.

**Country policy.** Set Event-Country Policy to Expected, No Employees, or Prohibited. Correlate a match with user history, managed-device state, anonymizer use, impossible travel, and authentication method.

**T1 handling.** Triage successful interactive employee sign-ins immediately. Correlate preceding failures, unfamiliar device, token or session changes, MFA or passkey registration, mailbox changes, and user confirmation.

**T2 handling.** Generate a high-severity alert on successful interactive sign-in or a failed-to-success pattern. Validate the identity and endpoint promptly.

**T3 handling.** Use only as a risk multiplier with at least one corroborating anomaly. Commodity VPS and hosting providers belong here unless direct evidence supports a higher tier.

**T4 handling.** Keep disabled by default. T4 contains broad cloud, access ISP, uncertain continuity, and lifecycle-review candidates that need tenant-specific validation.

**Published indicators.** Use exact IPs, CIDRs, domains, and hashes within their observation window. Current ASN mapping is separate because addresses and prefixes move.

**Community feeds.** Use IPsum, Data-Shield, public proxy lists, ransomware.live, and similar sources for current exact-IP context. Check lineage and freshness. Cross-list counts do not automatically raise an ASN tier.

**Clouvider and PacketHub.** Clouvider AS62240 and PacketHub rows distinguish observed actor use from provider complicity. PacketHub is treated as commercial VPN and anonymizer infrastructure, not automatically as bulletproof hosting.

**Lifecycle.** 29 high-confidence obsolete or reassigned ASNs were removed. 7 allocated but non-originating rows remain disabled for review. Do not carry historical reputation to a new holder.

**Refresh cadence.** Refresh machine-readable feeds at least weekly, recheck holder and route status monthly, and revalidate campaign and provider research quarterly or when ownership changes.

**Known limits.** BYOIP, suballocation, residential proxies, anycast, compromised legitimate hosts, and provider size can all obscure control or create false positives. Maintain workload, vendor, SASE, VPN, and admin-jump-host allowlists.

**Campaign watch.** Networks named in published identity or VPN-authentication campaigns, but not persistently abusive, are on a ladder. One campaign: T3 Context for 180 days from the newest report. Two or more independent campaigns within 12 months: T2 High for 180 days, then T3 for 180 more. Without a new report a row then steps down to T4 Review, disabled, as 'Campaign watch ended; retained for history'. Each step is dated in Analyst Notes and the changelog, a new report moves the row back up, and no row is deleted for this reason. Rows with ASN-DROP, bulletproof-hosting or local evidence keep the tier that evidence gives them.

## What changed in this refresh

**Refresh record 2026-10-09.** Catalog 1,148 to 1,151. Routing re-verified for all 1,148 prior catalog ASNs against RIPEstat; every difference was confirmed on a second pass. AS209425 is originating again. AS262909 and AS402170 stopped originating and are held for lifecycle review, not removed. AS212238, AS13335, AS16509 and AS20940 timed out or did not answer on one or both passes and are recorded as unresolved, not changed (AS9009 and AS20940 answered on retry with no change). RIR delegation files for all five registries show AS401109, AS401110, AS401116, AS401120 and AS262909 as reserved with no RDAP object; they stay in the catalog at T4 for lifecycle review because the status is new this week. No new published reporting changed any tier since 2026-10-07. Abuse percentages, IPsum and community feed counts were not re-pulled, and RIPEstat, Spamhaus and RDAP answered while some news sites refused automated requests.

**ASN-DROP delta 2026-10-09.** Spamhaus changed from 427 to 431 ASNs. Added: AS14956 (ROUTERHOSTING, already catalogued, moved T2 to T1), AS198636 (CAPSULA-AS), AS199457 (SolidCore), AS199804 (TFES-AS), the last three newly catalogued as T1 Critical. Removed: none. Delisting is not exoneration.

**Evidence expansion 2026-10-09, campaign ladder applied.** Campaign watch is now a ladder: one campaign holds T3 for 180 days, two or more separate campaigns within 12 months hold T2 for 180 days and then T3 for 180 more, then T4 for history. Applied to every row whose only basis is campaign reporting. 21 rows step down to T4: 17 whose newest Akira, Fog or Proofpoint campaign is more than 180 days old and 4 whose cited reporting is exploitation or C2 rather than sign-in abuse. 8 rows are on the ladder at T3: tzulo, Hydra, FranTech and Hivelocity from T2, the three HZ Hosting ASNs on the family's three campaigns, and Global Connectivity Solutions from T4. Datacamp stays T2 as commercial VPN egress. No row was removed.

**Refresh record 2026-10-07.** Catalog 1,130 to 1,148. Routing re-verified for all catalog ASNs on two passes; AS16509 did not answer either pass and is recorded unchanged. Four rows stopped originating: AS36680, AS209896 and AS209946 (T1 Critical, tiers held pending lifecycle review) and AS215462 (T4). Abuse percentage, IPsum and community feed counts were not re-pulled, and new rows carry none.

**ASN-DROP delta 2026-10-07.** Spamhaus changed from 430 to 427 ASNs. Added: AS211443, catalogued as T1 Critical. Removed: AS401109, AS401110, AS401116 and AS401120, all non-originating since 2025, moved to T4 Review for lifecycle review. Delisting is not exoneration.

**Evidence expansion 2026-10-07, campaign watch added.** New 120-day campaign watch tier rule. Eight ASNs enter at T3 Context: LSHIY AS32167 (Entra ID password spray, June 2026); AS213250 and AS19318 (Storm-3168 service principal abuse); AS212171, AS213929, AS210328, AS201002 and AS267784 (FortiBleed FortiGate SSL-VPN brute force, FBI and USSS advisory of 2026-10-06).

**Evidence expansion 2026-10-07, campaign history added.** Nine ASNs named in identity campaigns more than 120 days ago were missing and are added at T4 Review, disabled, for history: Railway AS400940 and HZ Hosting AS61046 (device-code phishing); AS43350, AS215929 and AS211632 (GlobalProtect brute force); AS214238, AS204957 and AS215540 (Tycoon 2FA logins); AS35758 (Iran-nexus password spray).

**Evidence expansion 2026-10-07, indicators.** 24 indicators added: the 20 FortiBleed IPs, the INC ransomware AnyDesk C2 213.111.185.108 and C2 domain throughoutes.net, the LSHIY range 2a0a:d683::/32, and Railway 162.220.234.41. Six sources added (N58 to N63).

**Refresh record 2026-10-02.** Per-row routing re-verification against RIPEstat for all 1,130 catalog ASNs. No ASNs were added, removed or re-tiered. Spamhaus ASN-DROP membership was unchanged at 430. Five rows changed routing state: AS209946, AS47945, AS42505 and AS9164 resumed origination after a dormant period and remain T1 Critical and ASN-DROP listed; AS265410 lost its origin on 2026-09-30 and is held for lifecycle review. 1,123 of 1,130 ASNs resolved on the first pass and the remaining 7 are large cloud and CDN networks whose announced state was unchanged.

**Refresh record 2026-10-02, not re-verified.** Abuse percentage, IPsum and community feed counts were not re-pulled, so this cycle re-verified routing and RIR state only.

**Refresh record 2026-09-29.** 17 ASNs were added and 3 were removed from the active catalog. Lifecycle removals: AS211736, AS213832, AS205759. Each removal met reserved registration, missing direct RDAP object, and no qualifying origin; this is not a claim of permanent retirement.

**ASN-DROP delta 2026-09-29.** Spamhaus changed from 437 to 430 ASNs. Added: AS218732, AS403005. Removed: AS20724, AS27463, AS61003, AS62563, AS63023, AS211736, AS213474, AS213832, AS215462. Delisting is not exoneration; retained tiers use current routing and independent evidence.

**Ownership and anomalies 2026-09-29.** AS401661 is now labeled EMBNEX, LLC in the United States. AS213474, AS215462, and AS265410 are reserved registrations with observed origins; they are normalized to Unknown holder-country context and remain disabled for review.

**Evidence expansion 2026-09-29.** 487 published indicators, 29 detection patterns, and 152 cited sources now cover current bulletproof-hosting, fast-flux, credential-phishing, cloud-token, SonicWall, FortiGate, ransomware, and post-compromise tradecraft.

## Community feeds, and why list volume does not promote a tier

Public indicator feeds are used for exact-IP enrichment and short-lived
hunting, not for tiering. Their inputs are not independent of each other,
so an address appearing on four lists is frequently one observation
reported four times. Cross-list overlap is not corroboration, and the
number of listed addresses in a network does not raise its tier.

| Feed | Snapshot | Indicators | State | Where it falls short |
|---|---|---|---|---|
| IPsum | 2026-09-29 | 121838 | Tue, 29 Sep 2026 03:00:38 +0200 | Inputs are not independent. 47,278 IPs overlap Data-Shield, including 14,466 IPsum score >=3 addresses. |
| mzyui HTTP proxy list | 2026-08-29 | 63797 | Rejected: stale and unvalidated | Byte-identical for 31.8 days with 143 consecutive updater failures. |
| Data-Shield IPv4 Blocklist | 2026-09-29 | 92896 | 2026-09-29 20:05:41 | Large overlap with IPsum prevents treating cross-list presence as independent evidence. |
| Cisco Talos April 2024 brute-force IOCs | 2024-04-16 | 3926 | Historical snapshot | Keep campaign-time attribution separate from current routing. Source IPs can be reassigned; no ASN-wide provider implication. |
| Ransomware.live IoCs | 2026-09-29 | 2564 | Dynamic page checked 2026-09-29 | Network rows mix bare IP, IP:port, and CIDR and lack reliable per-row observation dates/original references. Revalidate exact indicators; never promote an ASN from presence alone. |
| Current community-feed union | 2026-09-29 | 218847 | Mixed; see individual rows | Cross-list overlap is not independent corroboration. Feed volume alone does not support ASN-level malicious attribution. |

**Exact-IP use.** Enrich listed IPs to the event-time ASN and retain the feed snapshot date. Do not turn a transient IP hit into permanent ASN-wide reputation.

**Overlap.** IPsum and Data-Shield share substantial source lineage. A hit in both is not automatically independent corroboration.

**Freshness.** Proxy lists require age and validation checks. A stale updater or untested endpoint should not drive blocking.

**Cloud volume.** Large cloud ASNs can dominate raw counts while serving legitimate customers. Treat count as exposure context, not maliciousness.


## Limitations

These are the reasons a row here can be wrong, and they are not rare.

- **BYOIP and suballocation.** The network announcing a prefix is not
  always the party controlling the address.
- **Residential and mobile proxies.** Traffic exits through addresses
  that carry none of the signals this catalog is built on.
- **Anycast.** One address, many physical locations.
- **Compromised legitimate hosts.** A hosting provider's customer being
  breached looks identical to a hosting provider being abused.
- **Provider size.** A large network generates more abuse reports because
  it is large. Counts here are not normalised by provider size.
- **Ownership change.** Reputation does not transfer to a new holder, and
  reassignment is why rows get removed rather than retired.
- **Delisting is not exoneration.** A network leaving a feed snapshot is a
  change in that feed, not a finding about the network.

Maintain allowlists for your own workloads, vendors, SASE egress, VPN
concentrators and admin jump hosts before any of this goes near an
enforcement decision.

## Provider complicity

Several networks in this catalog belong to legitimate hosting, transit and
commercial VPN businesses. They are listed because published reporting or
local incident evidence placed activity on their infrastructure, which is
a statement about observed use and nothing else.

Where the research has a position on a provider's role it is recorded in
the `Provider Role Assessment` column, and for most rows that position is
that infrastructure use was observed and no provider-complicity claim is
made. Do not read a tier as an accusation.

## Sources (159)

Every tiering decision resolves to one of these. Each entry records what
it supports and what it does not.

- **S01** Spamhaus, ASN-DROP (2026-10-09). <https://www.spamhaus.org/drop/asndrop.json> Limits: Membership and allocations can change. Neither list membership nor removal establishes every address/customer intent or login-source attribution. Update regularly before enforcement.
- **S02** CISA, NSA, FBI and international partners, Bulletproof Defense: Mitigating Risks From Bulletproof Hosting Providers (2025-11-19). <https://media.defense.gov/2025/Nov/19/2003826020/-1/-1/0/CSI_BULLETPROOF_DEFENSE_MITIGATING_RISKS_FROM_BULLETPROOF_HOSTING_PROVIDERS.PDF> Limits: Warns that whole-ASN blocking can affect legitimate users and that BPH providers cycle infrastructure.
- **S03** ipapi.is, Most Abusive ASNs (2026-09-29). <https://ipapi.is/most-abusive-asn.html> Limits: Vendor methodology and labels are prioritization signals, not malicious-login probability. Absence from the top 1,000 is not zero abuse; tied 100% ranks make rank-only movement weak evidence.
- **S04** Proofpoint, Cloud Credential Compromise from Russian Infrastructure (2022-03-03). <https://www.proofpoint.com/us/blog/cloud-security/cloud-credential-compromise-campaign-originating-russian-affiliated> Limits: Proofpoint published IPs, provider labels and domains, not ASNs or CIDRs. ASN mapping is historical analyst enrichment and does not imply provider complicity.
- **S05** RIPE NCC, RIPEstat AS Overview (2026-09-15). <https://stat.ripe.net/docs/data-api/api-endpoints/as-overview/> Limits: Registry identity and routing status can change; country is not actor nationality.
- **S06** RIPE NCC, RIPEstat Routing History (2026-09-15). <https://stat.ripe.net/docs/data-api/api-endpoints/routing-history/> Limits: BGP origin establishes routing at a point in time, not ownership, intent or provider complicity.
- **S07** Microsoft, ACTINIUM targets Ukrainian organizations (2022-02-04). <https://www.microsoft.com/en-us/security/blog/2022/02/04/actinium-targets-ukrainian-organizations/> Limits: Actor infrastructure and C2 evidence, not Microsoft 365 login-source evidence. Microsoft describes REG.RU as legitimate.
- **S08** Palo Alto Networks Unit 42, Gamaredon (Primitive Bear) Russian APT Group Actively Targeting Ukraine (2022-02-03). <https://unit42.paloaltonetworks.com/gamaredon-primitive-bear-ukraine-update-2021/> Limits: Mostly malware C2/downloader telemetry, not authentication-source evidence. Large shared providers create ASN-wide false positives.
- **S09** U.S. Department of the Treasury, Treasury Sanctions Global Bulletproof Hosting Service Enabling Cybercriminals and Technology Theft (2025-07-01). <https://home.treasury.gov/news/press-releases/sb0185> Limits: The press release names the entity but not ASNs; ASN linkage comes from technical research and current registry data.
- **S10** U.S. Department of the Treasury, United States, Australia, and the United Kingdom Jointly Sanction Key Infrastructure that Enables Ransomware Attacks (2025-02-11). <https://home.treasury.gov/news/press-releases/sb0018> Limits: The release names the entity, not a complete current ASN inventory.
- **S11** U.S. Department of Justice, Three Russian Nationals and Two Companies Indicted for International Cybercrimes Resulting in More Than $62M in Victim Losses (2026-07-14). <https://www.justice.gov/opa/pr/three-russian-nationals-and-two-companies-indicted-international-cybercrimes-resulting-more> Limits: Criminal charges are allegations until proven. The release is not a complete ASN or prefix feed.
- **S12** Recorded Future Insikt Group, One Step Ahead: Stark Industries Solutions Preempts EU Sanctions (2025-08-27). <https://www.recordedfuture.com/research/one-step-ahead-stark-industries-solutions-preempts-eu-sanctions> Limits: Infrastructure was already shifting; revalidate current routing and ownership before enforcement.
- **S13** GreyNoise, The Stark Industries Shell Game (2025-11-17). <https://www.greynoise.io/blog/stark-industries-shell-game> Limits: Observed scanning does not make every customer or sign-in malicious.
- **S14** Silent Push, IOFA Detects Aeza Group Infrastructure Shift Following OFAC Sanctions (2025-07-24). <https://www.silentpush.com/news/iofa-detects-aeza-group-infrastructure/> Limits: Use the source date and routing snapshot; provider infrastructure can move.
- **S15** Intel 471, Zservers: Bulletproof Hosting for Crime (2025-03-11). <https://www.intel471.com/blog/zservers-bulletproof-hosting-for-crime> Limits: Historical technical snapshot. AS197414 is currently unannounced in this workbook enrichment.
- **S16** Team Cymru, Exploring Seychelles: Team Cymru’s Tech Adventure (2022-09-10). <https://www.team-cymru.com/post/exploring-seychelles> Limits: Historical family mapping; current routing and current feed membership are shown separately.
- **S18** Microsoft, Midnight Blizzard: Guidance for responders on nation-state attack (2024-01-25). <https://www.microsoft.com/en-us/security/blog/2024/01/25/midnight-blizzard-guidance-for-responders-on-nation-state-attack/> Limits: Publishes no ASN list.
- **S19** Google Cloud Mandiant, APT29 Continues Targeting Microsoft 365 (2022-08-18). <https://cloud.google.com/blog/topics/threat-intelligence/apt29-continues-targeting-microsoft> Limits: Publishes no ASN list; behavior supports combining network and identity signals.
- **S20** Team Cymru, Operationalizing OFAC Sanctions for Financial Defense: MediaLand AS206728 (2026-02-04). <https://www.team-cymru.com/post/ofac-sanctions-compliance-active-risk-medialand-as206728> Limits: Treat current routes and exact resources as time-sensitive.
- **X001** Rapid7, Ongoing Social Engineering Campaign Refreshes Payloads (2024-08-12). <https://www.rapid7.com/blog/post/2024/08/12/ongoing-social-engineering-campaign-refreshes-payloads/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X002** Silent Push, USPS Phishing on a Bulletproof Hosting Network (2024-08-12). <https://www.silentpush.com/blog/usps-phishing-on-a-bulletproof-hosting-network/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X003** Recorded Future, Malicious Infrastructure Finds Stability with aurologic GmbH (2025-11-06). <https://assets.recordedfuture.com/insikt-report-pdfs/2025/cta-2025-1106.pdf> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X004** Excedo, How cybercriminals abuse ASN for bulletproof hosting (2026-09-15). <https://www.excedo.se/en/blog-articles/how-cybercriminals-are-abusing-autonomous-system-numbers-asn-for-bulletproof-hosting> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X005** bgp.tools, bgp.tools AS215208 current registration (2025-05-01). <https://bgp.tools/as/215208> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X006** bgp.tools, bgp.tools AS215240 current registration (2025-05-01). <https://bgp.tools/as/215240> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X007** Team Cymru, How Virtual Offices Enable a Facade of Legitimacy (2025-05-01). <https://www.team-cymru.com/post/how-virtual-offices-enable-a-facade-of-legitimacy> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X008** Huntress, No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack (2026-07-15). <https://www.huntress.com/blog/lshiy-password-spray-attack> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X009** bgp.tools, bgp.tools AS207569. <https://bgp.tools/as/207569> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X010** urlhaus.abuse.ch, URLhaus malware URL database. <https://urlhaus.abuse.ch/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X011** global.ptsecurity.com, Lazarus Group Recruitment: Threat Hunters vs Head Hunters (2024-08-19). <https://global.ptsecurity.com/en/research/pt-esc-threat-intelligence/lazarus-recruitment/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X012** urlhaus.abuse.ch, URLhaus ASN report for AS26496 (2024-08-19). <https://urlhaus.abuse.ch/hoster/AS26496/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X013** bgp.he.net, Hurricane Electric BGP Toolkit AS214943 (2025-10-27). <https://bgp.he.net/AS214943> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X014** rdap.arin.net, ARIN RDAP lookup (no current object). <https://rdap.arin.net/registry/autnum/11331> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X015** bgp.tools, bgp.tools AS11938. <https://bgp.tools/as/11938> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X016** halcyon.ai, Update: Cloudzy Command and Control Provider Report (2026-07-24). <https://www.halcyon.ai/blog/update-cloudzy-command-and-control-provider-report> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X017** cloudzy.com, Cloudzy Official Statement, August 2023 (2026-07-24). <https://cloudzy.com/news/official-statement-august-2023/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X018** jumpsec.com, Inside a DPRK BlueNoroff ClickFix Kit (2026-07-24). <https://www.jumpsec.com/inside-a-dprk-bluenoroff-clickfix-kit/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X019** bgp.tools, bgp.tools AS22295. <https://bgp.tools/as/22295> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X020** threatfox.abuse.ch, ThreatFox ASN report for AS22295. <https://threatfox.abuse.ch/asn/22295/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X021** rdap.arin.net, ARIN RDAP lookup (no current object). <https://rdap.arin.net/registry/autnum/22801> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X022** bgp.tools, bgp.tools AS26701. <https://bgp.tools/as/26701> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X023** rdap.arin.net, ARIN RDAP lookup (no current object). <https://rdap.arin.net/registry/autnum/27524> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X024** rdap.arin.net, ARIN RDAP lookup (no current object). <https://rdap.arin.net/registry/autnum/32177> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X025** rdap.arin.net, ARIN RDAP lookup (no current object). <https://rdap.arin.net/registry/autnum/32558> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X026** bgp.tools, bgp.tools AS42624 successor context (2025-11-06). <https://bgp.tools/as/42624> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X027** bgp.tools, bgp.tools AS35346. <https://bgp.tools/as/35346> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X028** bgp.tools, bgp.tools AS35718. <https://bgp.tools/as/35718> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X029** bgplookingglass.com, List of Autonomous System Numbers - 2 (historical identity reference) (2026-09-15). <https://www.bgplookingglass.com/list-of-autonomous-system-numbers-2> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X030** ipinfo.io, IPinfo AS41947 historical ASN summary (2026-09-15). <https://ipinfo.io/AS41947> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X031** Recorded Future, Malicious Infrastructure Finds Stability with aurologic GmbH (2026-04-23). <https://www.recordedfuture.com/research/malicious-infrastructure-finds-stability-with-aurologic-gmbh> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X032** bgp.he.net, Hurricane Electric BGP Toolkit: AS42624 (2026-04-23). <https://bgp.he.net/AS42624> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X033** ipinfo.io, IPinfo AS43094 ASN summary (2026-09-15). <https://ipinfo.io/AS43094> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X034** x.com, Spamhaus researcher report on suspicious AS44317/AS21738 announcements (2024-05-16). <https://x.com/spamhaus/status/1791118679645593845> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X035** peeringdb.com, PeeringDB historical entry: AS44317 Mercury Telecom LLC (2024-05-16). <https://www.peeringdb.com/asn/44317> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X036** krebsonsecurity.com, Stark Industries Solutions: An Iron Hammer in the Cloud (2026-05-29). <https://krebsonsecurity.com/2024/05/stark-industries-solutions-an-iron-hammer-in-the-cloud/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X037** augursecurity.com, European Union Sanctions Force Stark Industries Solutions Ltd. to Rebrand Again (2026-05-29). <https://www.augursecurity.com/post/european-union-sanctions-force-stark-industries-solutions-ltd-to-rebrand-again> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X038** bgp.he.net, Hurricane Electric BGP Toolkit: AS44477 (2026-05-29). <https://bgp.he.net/AS44477> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X039** bgp.tools, BGP.Tools: AS44589 (2026-09-15). <https://bgp.tools/as/44589> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X040** ipinfo.io, IPinfo AS44774 historical ASN summary (2025-05-20). <https://ipinfo.io/AS44774> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X041** Silent Push, Infrastructure Laundering: Silent Push Exposes Cloudy Behavior Around FUNNULL CDN Renting IPs from Big Tech (2026-03-25). <https://www.silentpush.com/blog/infrastructure-laundering/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X042** greynoise.io, Ghost Fleet: Half of All New Scanning IPs Last Week Geolocated to Hong Kong (2026-03-25). <https://www.greynoise.io/blog/ghost-fleet-half-new-scanning-ips-geolocated-to-hong-kong> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X043** peeringdb.com, PeeringDB: AS45753 (2026-03-25). <https://www.peeringdb.com/asn/45753> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X044** ipinfo.io, IPinfo AS47500 ASN summary (2026-09-15). <https://ipinfo.io/AS47500> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X045** Team Cymru, Team Cymru: Jingle Shells - How Virtual Offices Enable a Facade of Legitimacy (2026-09-15). <https://www.team-cymru.com/post/jingle-shells-how-virtual-offices-enable-a-facade-of-legitimacy> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X046** threatfox.abuse.ch, ThreatFox AS49042 tag (2026-09-15). <https://threatfox.abuse.ch/browse/tag/AS49042/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X047** urlhaus.abuse.ch, URLhaus ASN report for AS49042 (2026-09-15). <https://urlhaus.abuse.ch/asn/49042/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X048** bgp.tools, BGP.Tools historical profile for AS49042 (2026-09-15). <https://bgp.tools/as/49042> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X049** threatfox.abuse.ch, ThreatFox AS49217 tag (2026-09-15). <https://threatfox.abuse.ch/browse/tag/AS49217/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X050** bgp.tools, BGP.Tools historical profile for AS49217 (2026-09-15). <https://bgp.tools/as/49217> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X051** alfa-inet.net, Alfa-inet ISP website (2026-09-15). <https://alfa-inet.net/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X052** rasvtv.md, RASV-TV official website (2026-09-15). <https://rasvtv.md/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X053** pfcloud.io, Pfcloud official service catalog (2026-09-15). <https://pfcloud.io/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X054** urlhaus.abuse.ch, URLhaus ASN report for AS51396 (2026-09-15). <https://urlhaus.abuse.ch/asn/51396/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X055** rootlayer.net, RootLayer network and hosting page (2026-09-15). <https://rootlayer.net/network/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X056** ip2location.com, IP2Location current AS51490 status (2026-09-15). <https://www.ip2location.com/as51490> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X057** Recorded Future, Recorded Future 2022 Adversary Infrastructure Report (2026-09-15). <https://www.recordedfuture.com/research/2022-adversary-infrastructure-report> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X058** bgp.tools, BGP.Tools profile for AS57678 (2026-09-15). <https://bgp.tools/as/57678> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X059** innetra.com, INNETRA official service catalog (2026-09-15). <https://innetra.com/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X060** peeringdb.com, PeeringDB AS58349 profile (2026-09-15). <https://www.peeringdb.com/asn/58349> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X061** xserver.cloud, XServer official VPS and dedicated-server site (2026-09-15). <https://xserver.cloud/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X062** bgp.tools, BGP.Tools AS48031 profile (2026-09-15). <https://bgp.tools/as/48031> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X063** docs.hetzner.com, Hetzner official documentation (2026-09-15). <https://docs.hetzner.com/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X064** peeringdb.com, PeeringDB AS213230 profile (2026-09-15). <https://www.peeringdb.com/asn/213230> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X065** learn.microsoft.com, Microsoft Learn: Internet peering and AS8075 (2026-09-15). <https://learn.microsoft.com/en-us/azure/internet-peering/internet-peering-vs-peering-service> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X066** azure.microsoft.com, Microsoft Azure official site (2026-09-15). <https://azure.microsoft.com/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X067** serveroffer.lt, Serveroffer official hosting page (2026-09-15). <https://serveroffer.lt/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X068** m247.com, M247 official service catalog (2026-09-15). <https://m247.com/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X069** urlhaus.abuse.ch, URLhaus ASN report for AS9009 (2026-09-15). <https://urlhaus.abuse.ch/asn/9009/> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X070** Recorded Future, GrayBravo's CastleLoader Activity Clusters Target Multiple Industries (2025-12-09). <https://www.recordedfuture.com/research/graybravos-castleloader-activity-clusters-target-multiple-industries> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X071** infosec.exchange, Spamhaus: 49.3 Networking bulletproof-host investigation (2025-09-26). <https://infosec.exchange/@spamhaus/115270763024502133> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X072** infosec.exchange, Spamhaus: Bearhost's bulletproof-hosting comeback (2026-04-29). <https://infosec.exchange/@spamhaus/116488118532640901> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X073** infosec.exchange, Spamhaus: Netiface bulletproof-hosting infrastructure (2026-08-24). <https://infosec.exchange/@spamhaus/117150614554456244> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X074** infosec.exchange, Spamhaus: AS219067 phishing and prefix-hopping infrastructure (2026-08-24). <https://infosec.exchange/@spamhaus/117150614533611970> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X075** infosec.exchange, Spamhaus: Virtualine bulletproof hosting (2025-09-18). <https://infosec.exchange/@spamhaus/115225449245944633> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **X076** infosec.exchange, Spamhaus: infrastructure facilitating bulletproof-host proliferation (2026-08-24). <https://infosec.exchange/@spamhaus/117150614543659573> Limits: Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- **N01** RIPE NCC, RIPEstat AS Overview, RIR registration, and routing status (2026-10-07). <https://stat.ripe.net/docs/data-api/> Limits: RIR country is holder-registration metadata, not user or IP geolocation. A non-originating result can be transit-only, dormant, or below the RIPE visibility threshold; opaque RIR IDs are not stable ownership identifiers.
- **N02** stamparm, IPsum threat-intelligence feed (2026-09-29). <https://github.com/stamparm/ipsum> Limits: Underlying lists are not statistically independent. Score and ASN concentration are context, not automatic provider-tier evidence.
- **N03** mzyui, HTTP proxy list (2026-08-29). <https://github.com/mzyui/proxy-list> Limits: Artifact remained byte-identical and about 31.8 days stale after 143 consecutive updater failures when checked 2026-09-29; two invalid endpoint rows are excluded.
- **N04** duggytuxy, Data-Shield IPv4 Blocklist (2026-09-29). <https://github.com/duggytuxy/Data-Shield_IPv4_Blocklist> Limits: Large overlap with IPsum prevents treating cross-list presence as independent corroboration. Use exact-IP context and short review TTLs.
- **N05** CAIDA, RouteViews Prefix-to-AS dataset (2026-09-13). <https://www.caida.org/catalog/datasets/routeviews-prefix2as/> Limits: Origin-AS mappings change over time and MOAS routes require separate handling.
- **N06** Arctic Wolf, July 2025 Uptick in Akira Ransomware Activity Targeting SonicWall SSL VPN (2025-08-04). <https://arcticwolf.com/resources/blog/arctic-wolf-observes-july-2025-uptick-in-akira-ransomware-activity-targeting-sonicwall-ssl-vpn/> Limits: The listed hosting networks are not inherently malicious; Arctic Wolf recommends limiting any blocking to VPN authentication.
- **N07** Arctic Wolf, Fog and Akira Ransomware Operations Linked to SonicWall SSL VPN (2024-10-24). <https://arcticwolf.com/resources/blog/fog-and-akira-ransomware-operations-linked-to-sonicwall-ssl-vpn/> Limits: Historical exact-IP evidence; routing and ownership must be revalidated.
- **N08** Augur Security, Iran 2026 Threat Posture Assessment (2026). <https://www.augursecurity.com/post/threat-research-iran-2026-threat-posture-assessment> Limits: Campaign infrastructure does not imply provider complicity or actor nationality for every event.
- **N09** Arctic Wolf, Console Chaos: A Campaign Targeting Publicly Exposed Management Interfaces on Fortinet FortiGate Firewalls (2025-01-10). <https://arcticwolf.com/resources/blog/console-chaos-targets-fortinet-fortigate-firewalls/> Limits: Exact IPs are time-bounded; broad VPS and CDN networks require behavioral corroboration.
- **N10** eSentire, Tycoon 2FA Infrastructure Update (2026-04-01). <https://www.esentire.com/blog/tycoon-2fa-infrastructure-update-threat-actors-adapt-following-global-coalition-takedown> Limits: Infrastructure use does not establish provider complicity.
- **N11** Okta, Human-operated phishing kit targets cryptocurrency firms (2026). <https://www.okta.com/blog/threat-intelligence/human-operated-phishing-kit-targets-cryptocurrency-firms/> Limits: Shared hosting and proxy infrastructure can have legitimate customers.
- **N12** Huntress, Exploitation of SonicWall VPN (2025). <https://www.huntress.com/blog/exploitation-of-sonicwall-vpn> Limits: Use with vulnerability, authentication, and post-access telemetry.
- **N13** The DFIR Report, Navigating Through the Fog (2025-04-28). <https://thedfirreport.com/2025/04/28/navigating-through-the-fog/> Limits: Incident-specific infrastructure does not imply all provider space is malicious.
- **N14** Recorded Future, Exposing TAG-53 Credential-Harvesting Infrastructure for Russia-Aligned Espionage Operations (2024). <https://www.recordedfuture.com/research/exposing-tag-53-credential-harvesting-infrastructure-for-russia-aligned-espionage-operations> Limits: Attribution applies to campaign infrastructure, not provider ownership.
- **N15** Coralogix / Snowbit, Evil Token: AI-Enabled Device Code Phishing Campaign (2026). <https://coralogix.com/blog/evil-token-ai-enabled-device-code-phishing-campaign/> Limits: Exact IP and campaign context are time-bounded.
- **N16** Resecurity, SharePoint Zero-Day Exploit CVE-2025-53770 Network Infrastructure Mapping (2025). <https://www.resecurity.com/blog/article/sharepoint-zero-day-exploit-cve-2025-53770-network-infrastructure-mapping> Limits: IP allocation and current origin can change; no provider complicity is asserted.
- **N17** Google Threat Intelligence Group, UNC6671 Targets Financial Services and Enterprise Cloud Environments (2026-08-06). <https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments> Limits: Most source IPs were commercial VPN nodes and cycle quickly; residential ASNs should not be blocklisted.
- **N18** Push Security, We infiltrated a criminal phishing panel: here is what we found (2026-05-07). <https://pushsecurity.com/blog/inside-criminal-phishing-panel> Limits: Short-lived domains and operator-gated pages reduce static IOC durability.
- **N19** Censys, Hiding in Plain Sight: Tracking Bulletproof Hosting and Abused RDP Infrastructure (2026-02-03). <https://censys.com/blog/hiding-in-plain-sight-tracking-bulletproof-hosting-and-abused-rdp-infrastructure/> Limits: Censys distinguishes legitimate VPS abuse from BPH and warns attribution can be uncertain.
- **N20** Cisco Talos, ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 (2026-07-01). <https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/> Limits: Cloudflare-hosted indicators do not support adding or blocking the whole Cloudflare ASN.
- **N21** Team Cymru, Validating ShinyHunters Cyber Threat Actors Infrastructure (2026-08-05). <https://www.team-cymru.com/post/validating-shinyhunters-cyber-threat-actors-infrastructure> Limits: Campaign infrastructure is narrower than provider-wide attribution.
- **N22** Sophos, Malicious Use of Virtual Machine Infrastructure (2026-02-04). <https://www.sophos.com/en-us/blog/malicious-use-of-virtual-machine-infrastructure> Limits: Shared VM infrastructure can create provider-level false positives.
- **N23** Arctic Wolf, Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms (2026-09-03). <https://arcticwolf.com/resources/blog/security-bulletin-active-cloud-data-theft-and-extortion-campaign-targeting-microsoft-365-and-saas-platforms/> Limits: Detection thresholds require tenant baselining.
- **N24** Google Threat Intelligence Group, Disrupting the Largest Residential Proxy Network (2026-01-28). <https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network> Limits: Residential proxy use makes actor geography and ASN-wide treatment unreliable.
- **N25** Google Threat Intelligence Group, Google Continues Disruption of Residential Proxy Networks (2026-07-02). <https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks> Limits: Residential access ASNs must not be treated as malicious wholesale.
- **N26** Google Threat Intelligence Group, Expansion of ShinyHunters SaaS Data Theft (2026-01-30). <https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft> Limits: TTP correlation is more durable than infrastructure-only matching.
- **N27** Microsoft Security, Passkey-Themed Social Engineering Leads to Identity and Cloud Compromise (2026-09-09). <https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/> Limits: Domain indicators rotate; monitor authentication and enrollment behavior.
- **N28** FBI, AVrecon Malware-Infected Routers Exploited as Residential Proxies by SocksEscort (2026-03). <https://www.fbi.gov/file-repository/cyber-alerts/avrecon-malware-infected-routers-exploited-as-residential-proxies-by-socksescort.pdf> Limits: The subscriber ASN and country can be innocent infrastructure.
- **N29** PacketHub, PacketHub official service site (2026-09-15). <https://www.packethub.net/> Limits: Provider marketing does not independently establish threat activity.
- **N30** Netify, NordVPN network and infrastructure profile (2026-09-15). <https://www.netify.ai/resources/vpns/nordvpn> Limits: Association is not evidence of corporate ownership or malicious operation.
- **N31** Qurium, Weaponizing Proxy and VPN Providers (2026-09-15). <https://www.qurium.org/weaponizing-proxy-and-vpn-providers/vpn-providers/> Limits: Network relationships can change and do not imply all users are malicious.
- **N32** Microsoft Security, AI-Enabled Device Code Phishing Campaign (2026-04-06). <https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/> Limits: Focus on OAuth device-code and token behavior, not infrastructure alone.
- **N33** Ransomware.live, Ransomware.live IoCs (2026-09-29). <https://www.ransomware.live/ioc> Limits: The IP counter mixes bare IPv4, IPv4:port, and CIDR rows; public rows lack reliable observation dates and original source references. Revalidate exact indicators and do not promote an ASN from presence alone.
- **N34** Elastic Security Labs, Detecting Tycoon 2FA AiTM Attacks Across Entra ID and Google Workspace (2026-05-26). <https://www.elastic.co/security-labs/threat-command/tycoon-2fa-aitm-detection-engineering> Limits: Cloud IP geolocation is unreliable for infrastructure classification; ASN is context, not verdict.
- **N35** Cisco Talos, Large-Scale Brute-Force Activity Targeting VPNs and SSH Services (2024-04-16). <https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/> Limits: Source IPs change. Campaign-time RouteViews mapping must be kept separate from current IP-to-AS mapping.
- **N36** StrongVPN, StrongVPN official service site (2026-09-15). <https://strongvpn.org/> Limits: Official provider information does not establish malicious activity or complicity.
- **N37** Rapid7, Ongoing Malvertising Campaign Leads to Ransomware (2024-05-13). <https://www.rapid7.com/blog/post/2024/05/13/ongoing-malvertising-campaign-leads-to-ransomware/> Limits: Historical holder continuity to current KORGRID is unresolved.
- **N38** Silent Push, Silent Push Tracks a Mass Phishing Operation Through Fast Flux (2026-09-15). <https://www.silentpush.com/blog/fast-flux-phishing/> Limits: Publication explicitly warns not every ASN in the rotation is bulletproof. ASN set is an analytic seed, not a blanket deny list. DNSPod and Keitaro are legitimate shared services.
- **N39** GreyNoise, Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation (2026-09-21). <https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation> Limits: Main persistent exploitation IP remains redacted; do not infer or de-redact it. Red Heron relationship and Chinese-speaking attribution are assessed, not proven. Published addresses do not imply provider complicity.
- **N40** GreyNoise, Swarming Against Citrix 0-Day Exploitation (2026-09-28). <https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation> Limits: Attempt against the Swarm sensor did not establish a foothold. IOC set is incomplete. Exact IP evidence is strong; same origin ASN alone is not proof of related attack activity.
- **N41** Huntress, Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM (2026-09-17). <https://www.huntress.com/blog/new-settra-ransomware-variant> Limits: Initial access unknown. MeshAgent is legitimate dual-use RMM; detection must correlate its server and behavior. Neither provider is labeled a bulletproof host by Huntress.
- **N42** Spamhaus, Botnet Threat Update January to June 2026 (2026-07-10). <https://www.spamhaus.org/resource-hub/botnet-c-c/botnet-threat-update-january-to-june-2026/> Limits: Counts are not sign-in attack probabilities and are not normalized by provider size. Newly observed ranking does not measure response speed. Hyperscaler presence does not establish BPH status.
- **N43** U.S. Department of the Treasury, United States, Australia, and United Kingdom Sanction Russian Cybercrime Infrastructure Supporting Ransomware (2025-11-19). <https://home.treasury.gov/news/press-releases/sb0319> Limits: Designated legal entity is not automatically every rented upstream ASN. Requires legal/entity verification and current designation checking before sanctions enforcement.
- **N44** U.S. Department of the Treasury, Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against Americans (2026-07-13). <https://home.treasury.gov/news/press-releases/sb0559> Limits: 1VPNS rents infrastructure under false identities. Sanctioned VPN reseller does not make its unrelated underlying hosting companies sanctioned. No exact ASN is designated here.
- **N45** FBI, First VPN Service Used by Ransomware Actors to Compromise Systems (2026-05-21). <https://www.ic3.gov/CSA/2026/260521.pdf> Limits: FBI expressly warns that ephemeral cloud IPs may be reassigned and require current corroboration. Similar-named VPN services are excluded. May-era exit list is historical in September.
- **N46** Spamhaus, Bulletproof Hosting: Cutting off the facilitators (2026-06-11). <https://www.spamhaus.org/resource-hub/bulletproof-hosting/bulletproof-hosting-cutting-off-the-facilitators/> Limits: No named ASN in article. Use to improve methodology and collateral-risk controls, not as evidence to add a specific ASN.
- **N47** Cisco Talos, Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use (2026-09-17). <https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/> Limits: No exact public IP/ASN in extracted text. Russian-language attribution is suggestive. Wasabi and dual-use tools are not malicious providers; no ASN addition justified.
- **N48** eSentire, GhostCode: Dissecting a Novel Device Code Phishing Kit (2026-09-15). <https://www.esentire.com/blog/ghostcode-dissecting-a-novel-device-code-phishing-kit> Limits: Single observed incident. Residential addresses may be dynamic. Microsoft broker/resource IDs and scripting user agents are legitimate; correlate behavior. Source timestamp example has a weekday/date inconsistency, so use month-level observation scope.
- **N49** eSentire, GhostCode published IOC list (2026-09-15). <https://github.com/eSentire/iocs/blob/main/GhostCode/GhostCode-iocs-09-09-2026.txt> Limits: Lookalike domains are marked possible relations; compromised-site indicators should remain subdomain scoped.
- **N50** Microsoft, Unmasking EvilTokens: Getting to the root of device code phishing (2026-09-22). <https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/> Limits: No exact malicious IPs or new Clouvider/PacketHub attribution. Cloud platforms named are shared infrastructure, not malicious domains. A linked actor-profile label says Storm-2922 while narrative says Storm-2992; retain narrative attribution with discrepancy.
- **N51** Microsoft DCU, Disrupting EvilTokens: The AI Chatbot Built for Cybercrime (2026-09-22). <https://blogs.microsoft.com/on-the-issues/2026/09/22/disrupting-eviltokens-the-ai-chatbot-built-for-cybercrime/> Limits: Disruption does not prove all affiliates stopped; no literal IOC list in announcement.
- **N52** Microsoft, Storm-3168: Agentic-driven cloud attacks using compromised service principals (2026-09-25). <https://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/> Limits: Initial access unclear; exposed GitHub secret not confirmed used. No ransom note or successful exfiltration confirmed. Source gives no ASNs.
- **N53** Microsoft DART, Beyond source code: A path to the keys to the kingdom (2026-09-29). <https://www.microsoft.com/en-us/security/blog/2026/09/29/beyond-source-code-a-path-to-the-keys-to-the-kingdom/> Limits: No precise infrastructure IOC or ASN in blog. Do not infer vulnerability exploitation from valid-identity abuse.
- **N54** Kaspersky GERT, Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO (2026-09-21). <https://securelist.com/tr/payload-ransomware-via-group-policy/121335/> Limits: Credential theft method, lateral movement and IP roles not determined due logging gaps. No ASNs supplied; no live C2 confirmed. Windows impact occurred without encryption.
- **N55** Microsoft, Star Blizzard refines phishing and malware delivery with the RedFlick technique (2026-09-29). <https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/> Limits: Mostly historical delivery infrastructure, not cloud sign-in source evidence. No ASNs supplied.
- **N56** Microsoft, Beyond the ransomware: Tracking Storm-2570's consistent tradecraft across deployments (2026-09-24). <https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/> Limits: Initial access unconfirmed; no exact network indicators or provider ASN evidence extracted.
- **N57** Proofpoint, Spraying in the Andes: TeamFiltration Returns to Exploit Forgotten Service Accounts (2026-09-22). <https://www.proofpoint.com/us/blog/threat-insight/Spraying-in-the-Andes-TeamFiltration-Returns> Limits: AWS and DataCamp/CDN77 are shared infrastructure. Use the exact ranges, stale user agent, dormant-account pattern, failed-to-success sequence, and rapid ASN switch together; do not block the providers wholesale.
- **N58** Huntress, Railway PaaS abused in Microsoft 365 token replay campaign (2026-03-23). <https://www.huntress.com/blog/railway-paas-m365-token-replay-campaign> Limits: Railway is a legitimate PaaS. Use the ranges with device-code and token-replay behavior, not ASN-wide.
- **N59** Microsoft, AI-enabled device code phishing campaign (2026-04-06). <https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/> Limits: Ranges given as network addresses without length. Shared hosting; correlate with device-code flow.
- **N60** GreyNoise, Hidden pattern in credential-based attacks on Palo Alto and SonicWall (2025-12-04). <https://www.greynoise.io/blog/hidden-pattern-credential-based-attacks-palo-alto-sonicwall> Limits: GreyNoise notes these ASNs are not generally associated with malicious infrastructure.
- **N61** Check Point Research, Iran-nexus password spray campaign targeting cloud environments with a focus on the Middle East (2026-03-31). <https://blog.checkpoint.com/research/iran-nexus-password-spray-campaign-targeting-cloud-environments-with-a-focus-on-the-middle-east/> Limits: Commercial VPN exits are shared by many legitimate users.
- **N62** FBI and US Secret Service, FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts (JCSA-20261006-01) (2026-10-06). <https://www.ic3.gov/CSA/2026/261006.pdf> Limits: The agencies warn the addresses may be reassigned and should be treated as historical within the activity window. ASNs are RIPEstat mappings, not stated in the advisory.
- **N63** Huntress, Two INC ransom notes (2026-09-21). <https://www.huntress.com/blog/two-inc-ransom-notes> Limits: Initial access vector not determined. Endpoint C2, not sign-in source evidence.
- **N64** Netify, DataCamp hosting profile (2026-10-07). <https://www.netify.ai/resources/hosting/datacamp> Limits: Undated profile, retrieved 2026-10-07. Shows hosted services, not abuse.

## Refresh cadence

Machine-readable feeds at least weekly. Holder and route status monthly.
Campaign and provider research quarterly, or immediately when ownership
changes. The page states both the evidence snapshot date and the build
date, because a rebuild is not new evidence and conflating the two is how
a stale catalog looks current.
