Full Report
The U.S. Department of the Treasury has sanctioned Russian hosting company Aeza Group and four operators for allegedly acting as a bulletproof hosting company for ransomware gangs, infostealer operations, darknet drug markets, and Russian disinformation campaigns. [...]
Analysis Summary
# Threat Actor: Hosting Providers (Aeza Group)
## Attribution & Identity
The entity identified is **Aeza Group**. Sanctioned individuals associated with Aeza Group include:
* **Vagif Vugarovich Penzev** (General Director and 33% owner)
* **Vladimir Vyacheslavovich Gast** (Technical Director)
* **Igor Anatolyevich Knyazev** (33% owner)
Associated companies include Aeza International Ltd., Aeza Logistic LLC, and Cloud Solutions LLC. The group is presented in the context of facilitating cybercrime operations through its hosting services.
## Activity Summary
Aeza Group has been sanctioned by the U.S. Treasury Department for **hosting servers used for ransomware and infostealer operations**. This action builds upon previous sanctions against other bulletproof hosting providers like ZServers and Xhost, which were used by the LockBit ransomware gang. The article also notes that some Aeza staff, including Penzev and Bozoyan (likely an unlisted individual or alias related to Penzev's ownership), were previously arrested in Russia for "illegal banking activities as part of an organized criminal group" and hosting the **BlackSprut** drugs marketplace.
## Tactics, Techniques & Procedures
The primary TTP associated with the Aeza Group, in its capacity as a service provider, is:
* **Command and Control (C2) Hosting:** Providing bulletproof hosting infrastructure used by cybercriminals to host malware (ransomware, infostealers) and C2 infrastructure.
* *Note: No specific technical TTPs (like specific hacking techniques or MITRE matrices) are detailed for the attackers using their infrastructure, only the facilitation role.*
## Targeting
* **Sectors:** Not explicitly detailed for targets, but the infrastructure supported **ransomware groups** and operators of the **BlackSprut drugs marketplace**.
* **Geography:** Targeting of Aeza Group is by the US Treasury, implying international reach for the services they provide.
* **Victims:** The specific victims benefiting from the hosting are various cybercriminal enterprises, including ransomware operators.
## Tools & Infrastructure
* **Malware families used:** Ransomware and Infostealers (general mention).
* **Infrastructure (C2, domains, IPs):** The services offered by Aeza International Ltd., Aeza Logistic LLC, and Cloud Solutions LLC. (No specific domains or IPs were provided and defanged in the provided text snippet).
## Implications
Aeza Group's sanction demonstrates continued focus by international bodies on **disrupting the underlying infrastructure** that enables major cybercrime operations, particularly ransomware. Bypassing or targeting law enforcement action in one jurisdiction (as evidenced potentially by the Russian arrests) by relying on hosting services is a common playbook that enforcement agencies are actively targeting.
## Mitigations
The specific mitigation mentioned is **sanctions**:
* U.S. entities are prohibited from doing business with Aeza Group and associated individuals/companies.
* Assets of the sanctioned individuals and companies are subject to freezing in the U.S.