A prominent purveyor of abuse-tolerant hosting infrastructure for criminal enterprises has begun funneling traffic through systems managed by Kaspersky Lab, the Moscow-based antivirus vendor, according to security researchers. The shift marks a notable development in how Prospero OOO, a Russia-based firm long associated with malware distribution, botnet command-and-control operations, and phishing campaigns, conducts its business.

Prospero has maintained a reputation as a reliable partner for cybercriminals seeking what the industry calls bulletproof hosting—services designed to withstand legal takedown requests and abuse complaints. The French security firm Intrinsec documented last year that Prospero operates under aliases including Securehost and BEARHOST, brands advertised across Russian hacking forums since at least 2019.

Marketing materials attributed to BEARHOST explicitly promise indifference to legal action. One forum post states:

Intrinsec's investigation revealed that Prospero has provided infrastructure to several major ransomware operations and regularly hosts malware families such as SocGholish and GootLoader. These threats typically propagate through counterfeit software update prompts on compromised websites and frequently serve as entry points for more devastating attacks.

The organization Spamhaus, which maintains blacklists relied upon by internet service providers globally to identify malware and spam sources, detected the routing change involving Prospero and Kaspersky Lab's Moscow-based networks earlier this week.

Kaspersky responded to the findings with a written statement denying any business relationship with the hosting provider. The company contended that network routing through its infrastructure does not necessarily indicate service provision, noting that its autonomous system numbers may appear as technical intermediaries in telecom provider networks where Kaspersky operates its DDoS mitigation services.

A fake browser update page pushing mobile malware. Image: Intrinsec.

Kaspersky denies these claims as the company does not work and has never worked with the service provider in question. The routing through networks operated by Kaspersky doesn't by default mean provision of the company's services, as Kaspersky's automatic system (AS) path might appear as a technical prefix in the network of telecom providers the company works with and provides its DDoS services.

Kaspersky Lab statement

Kaspersky pays great attention to conducting business ethically and ensuring that its solutions are used for their original purpose of providing cybersecurity protection. The company is currently investigating the situation to inform the company whose network could have served as a transit for a "bulletproof" web hosting provider so that the former takes the necessary measures.

Kaspersky Lab statement

Kaspersky's Troubled History in the West

Kaspersky's research division has long earned respect within the security community for significant threat discoveries. The company began selling antivirus and security products in the United States in 2005. However, this reputation faced a major setback in September 2017 when the Department of Homeland Security prohibited all federal agencies from deploying Kaspersky software and mandated removal within 90 days.

The DHS announcement provided no explicit reasoning for the ban. Cybersecurity journalist Kim Zetter reported that unnamed government sources cited two separate incidents. According to these accounts, an NSA contractor had Kaspersky antivirus running on a personal computer where he was developing offensive hacking tools. The software detected the source code as malicious and extracted it—behavior consistent with standard antivirus operation.

A second reported incident involved Israeli intelligence discovering Russian government hackers using Kaspersky software to search customer systems for files containing U.S. classified information.

Kaspersky disputed both allegations. Regarding the NSA contractor's computer, the company explained that its software functioned as designed, quarantining suspicious files for analysis. Once Kaspersky determined the detected code was development source code rather than malware, CEO Eugene Kaspersky stated he ordered its deletion. The company also denied that anyone had leveraged its software to search customer machines for classified material.

Last year, the U.S. Commerce Department extended the restrictions by banning Kaspersky software sales within the United States, with the prohibition taking effect July 20, 2024. U.S. officials justified the action by pointing to Russian law, which requires domestic companies to cooperate with government investigations, potentially allowing the Russian state to compel Kaspersky to conduct covert intelligence operations.

Prospero's Spam Dominance and the Kaspersky Connection

AS209030, owned by Kaspersky Lab, is providing connectivity to the bulletproof host Prospero (AS200593). Image: cidr-report.org.

Research conducted by Interisle Consulting Group last year examined hosting networks based on their scale and concentration of spambot infrastructure. Prospero ranked significantly higher in spam activity than any competing provider.

The connection between Prospero and Kaspersky's networks emerged recently. Doug Madory, director of Internet analysis at Kentik, identified routing records showing the relationship commenced in early December 2024.

Madory noted that Kaspersky's network infrastructure hosts several major financial institutions, including Alfa-Bank, Russia's largest bank. Kaspersky offers DDoS protection services to customers, and Madory suggested Prospero might simply be purchasing this defensive capability.

However, security researchers contend this explanation does not resolve the underlying concern. Zach Edwards, a senior threat researcher at Silent Push, argued that offering DDoS mitigation to a recognized bulletproof hosting operation may be more problematic than merely permitting its traffic to traverse Kaspersky's network.

In some ways, providing DDoS protection to a well-known bulletproof hosting provider may be even worse than just allowing them to connect to the rest of the Internet over your infrastructure.

Zach Edwards, Silent Push

Source: Krebs on Security