The Cyber Landlords of Illicit Finance

Everyone watches the wallets and the exchanges. The infrastructure they all sit on top of has been hiding in plain sight.
Over ten months in 2025, the U.S. Treasury sanctioned three bulletproof hosting providers in a row. Zservers came first, in February, in a joint action with the UK and Australia. Aeza Group followed on July 1. Media Land came in November, along with an expanded net around the Aeza network. In each case the target was not a ransomware crew, a scam ring, or a darknet market. It was their cyber landlord.
Aeza is the clearest illustration of the pattern. OFAC designated the company along with a UK front company used to lease IP addresses to criminals, two subsidiaries, and four of its leaders. The stated reason was that Aeza rented the digital ground that ransomware operators, infostealer crews, and a darknet drug marketplace all stood on. Treasury even named a cryptocurrency wallet tied to the operation that had processed more than $350,000. The target, in other words, was not any single crime. It was the infrastructure supporting the entire portfolio.
That shift in aim targets a part of the illicit economy that rarely makes the conversation. In the echo chamber of compliance folks and illicit finance watchers, we talk about wallets, tokens, and exchanges, the visible top of the stack where value moves. Underneath all of it sits infrastructure: servers, IP space, domains, and hosting. A specialized corner of that infrastructure market exists specifically to keep illegal operations online, and that is the corner enforcement is now reaching for.
What Bulletproof Hosting Actually Is
Bulletproof hosting is, in plain terms, hosting that promises not to cooperate. A mainstream provider will suspend a customer running a phishing page or a malware server once abuse complaints arrive. A bulletproof host advertises the opposite, marketing itself as ignoring abuse reports, copyright notices, and takedown requests, and it usually wraps that promise in offshore infrastructure, anonymous sign-up, and cryptocurrency-only payment. The striking thing is how open the sales pitch is, with terms like “DMCA ignored” and “bulletproof” serving as the actual product description rather than any kind of euphemism.
This does not mean every customer of such a service is a criminal, and it is worth saying so plainly, because there are legitimate reasons to want privacy and censorship resistance. But look at the marketing profile: no questions asked, no identity required, paid in crypto, hosted beyond easy legal reach, and engineered to stay online through complaints. That is precisely what phishing kits, malware command-and-control, online fraud, child sexual abuse material, and illicit marketplaces need in order to survive. When a provider optimizes for exactly the things that frustrate investigators, its customer base tends to follow the optimization.
An Ecosystem That Advertises Itself
What makes this corner of the market genuinely modern is how frictionless and openly commercial it has become. The pattern that recurs across these operations looks less like a shadowy back alley and more like a startup’s onboarding flow. Services run through automated chat bots on messaging platforms, where a user picks a plan, selects a cryptocurrency, and receives a freshly generated wallet address. Once the blockchain confirms the payment, the server or domain is provisioned automatically, with no human review and no identity check anywhere in the process.
These services also refer business to one another, and that is the part worth understanding, because it is where the ecosystem becomes visible. A no-questions crypto swap service will handle payments for an online gambling platform. That gambling platform, in turn, routes deposits and withdrawals in ways that minimize identity checks. The same operators promote the bulletproof host that keeps the whole arrangement online, and the host advertises directly in the same channels where those customers already gather. Each piece is unremarkable in isolation, but assembled, they form a stack where money can enter, move, and leave with very little friction and even less visibility. The telling detail is that the participants advertise their relationships to one another out in the open, because in this shady, no-KYC market a referral is a selling point rather than a liability.
Why the Infrastructure Layer Matters
The reason this layer deserves more attention than it gets is durability. A wallet or an exchange account can be discarded in minutes, and a designated marketplace can rebrand and reappear within weeks, but the operation still has to run on something underneath. The hosting layer is stickier than the storefronts sitting on top of it, because it requires real infrastructure, real IP allocations, real commercial relationships, and real money moving to real providers. All of that is harder to spin up and tear down on a whim, which is exactly what makes it a high-value target. Reach the host, and you are not swatting one head of the hydra, you are cauterizing the neck all the heads grow from.
This is why the recent designations matter more than just OFAC targeting cyber actors. Naming a hosting provider, its front company, its subsidiaries, its leaders, and a payment wallet in a single action is a template and repeating that template three times in under a year reveals a larger strategy. It signals that the U.S. government is willing to treat digital infrastructure as a sanctionable target in the same way it treats a bank or an exchange, and to follow the ownership and the money down to the layer where disruption actually sticks. The bulletproof-hosting business has operated for years on the assumption that offshore servers and anonymous crypto payments placed it beyond the reach of regulators. That assumption is now being tested in the open.
How This Layer Gets Mapped
Infrastructure of this kind rarely reveals itself from a single vantage point. Understanding it requires combining the open-source signals of how these services market and connect to one another, the fingerprints of the networks and IP space they operate on, and the on-chain trail left by the cryptocurrency payments that fund them. No single strand is conclusive on its own. Together, they turn a scattering of anonymous listings, disposable wallets, and offshore entities into a picture of an actual operation with real infrastructure and real counterparties behind it. Jurisdiction is woven through all of it. These operations deliberately scatter themselves across borders, with servers in one country, corporate registration in another, and a front company in a third selected precisely because it is permissive or slow to cooperate. That fragmentation is a defensive design intended to ensure that no single authority can see or reach the entire network.
The recent Treasury actions highlight an important reality: infrastructure of this kind is difficult for any one organization to map alone. The more governments and the private sector combine what each can see, open-source signals, network fingerprints, and blockchain flows, the faster these ecosystems come into focus.
The visible economy of wallets and exchanges will continue to attract the headlines. But the hosting, IP space, and commercial infrastructure that keep illicit operations online are where a growing share of the real leverage sits. It has been hiding in plain sight for years. It is encouraging to see enforcement finally reaching for the floor instead of only the furniture.
Meridian3 is an investigations and intelligence firm working at the intersection of open-source intelligence, financial intelligence, sanctions, and digital assets. We focus on the networks and infrastructure that move money, enable illicit activity, and connect actors across borders.





Comments