A new joint guide outlining how internet service providers and network defenders can curb cyber-crime enabled by so-called bulletproof hosting (BPH) infrastructure has been released by the US Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency and a coalition of US and international partners.
The publication sets out how BPH infrastructure is used to support ransomware, phishing, malware delivery and other forms of cyber-attack targeting critical sectors. According to the agencies, these hosting services are deliberately designed to ignore legal takedown requests and complaints, providing cyber-criminals with resilient platforms from which to operate with minimal risk of disruption.
Bulletproof hosting providers typically lease or resell their own – or in some cases stolen – infrastructure to malicious actors. Marketed as “bulletproof” due to their refusal to cooperate with law enforcement or respond to abuse reports, these services enable threat actors to obfuscate their operations, rapidly rotate IP addresses and host illicit content while evading traditional detection and enforcement mechanisms.
Techniques such as fast flux, command-and-control activity and data extortion schemes are frequently routed through these networks.
The guidance, titled Bulletproof Defense: Mitigating Risks From Bulletproof Hosting Providers, outlines a series of defensive measures aimed at reducing the operational value of BPH infrastructure.
These measures focus on improving the identification of malicious internet resources, enhancing traffic visibility and deploying targeted filtering approaches that minimise the risk of unintended disruption to legitimate systems.
“Bulletproof hosting is one of the core enablers of modern cyber-crime,” said acting CISA director Madhu Gottumukkala.
“By shining a light on these illicit infrastructures and giving defenders concrete actions, we are making it harder for criminals to hide and easier for our partners to protect the systems Americans rely on every day.”
Among the key recommendations is the creation and maintenance of a “high confidence” list of malicious internet resources, drawn from commercial and open-source threat intelligence and trusted information-sharing channels.
Network defenders are also advised to conduct continuous traffic analysis to identify suspicious patterns and anomalies, alongside implementing automated reviews of blocklists and establishing feedback mechanisms to reduce the likelihood of accidental blocking.
The agencies further encourage the sharing of threat intelligence across public and private channels and the deployment of filters at the network edge to disrupt malicious traffic as close to its source as possible. These measures, they suggest, would increase the operational cost and complexity for cyber-criminals relying on BPH services.
Recommended reading
- Developers Expect AI to Redefine Their Roles in 2026
- Report: Software Bloat Is Costing Firms $1 Trillion a Year
- What are the Top Strategic Trends for Software Engineers?
“Cyber-criminals persist in their efforts to disrupt networks and systems while remaining undetectable and difficult to trace,” commented Nick Andersen, executive assistant director for CISA’s Cybersecurity Division.
“BPH providers are increasingly becoming common accomplices, posing an imminent and significant risk.”
Internet service providers are also urged to take a more proactive role in protecting customers, including notifying them of potential threats, offering optional filtering tools and working collaboratively to establish sector-wide standards and codes of conduct aimed at preventing BPH abuse.
The guide notes that, over time, consistent implementation of these measures could force cyber-criminals away from bulletproof hosts and towards legitimate infrastructure providers that respond to law enforcement requests and abuse reports, ultimately reducing the resilience and effectiveness of malicious campaigns embedded within the global internet ecosystem.





