Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

US Shuts Down Bulletproof Hosting Service LolekHosted, Charges Its Polish Operator

US authorities have announced charges against a Polish national who allegedly operated the LolekHosted.net bulletproof hosting service.

LolekHosted seized

US authorities have announced the seizure of LolekHosted.net, the domain used by the bulletproof hosting service LolekHosted, as well as charges against its alleged operator.

According to court documents, the domain had been used for roughly a decade to provide customers with secure web hosting services that facilitated cybercriminal activities, including the distribution of ransomware and information stealers, phishing, and distributed denial-of-service (DDoS) attacks.

An indictment unsealed on Friday claims that the domain LolekHosted.net was registered in 2014 by Artur Karol Grabowski, 36, a Polish national who allegedly operated the web hosting service company until the domain’s seizure.

Grabowski allegedly allowed LolekHosted clients to register accounts using false information, did not maintain IP address logs of client servers, changed those IP addresses, ignored abuse complaints from third parties and notified his clients of the legal inquiries he received.

He advertised LolekHosted as providing “100% privacy hosting,” allowing clients to perform all types of criminal activities, “except child porn”.

One of the illicit operations hosted on LolekHosted was the NetWalker ransomware, which made roughly 400 victims, including colleges, hospitals, law enforcement and emergency services, municipalities, school districts, and universities.

Advertisement. Scroll to continue reading.

The LolekHosted servers, documents presented in court claim, were used to launch approximately 50 NetWalker ransomware attacks against victims worldwide. The servers were used as intermediaries, to store hacking tools and victim data.

The NetWalker ransomware operators, authorities say, have received more than $146 million worth of bitcoin in ransom payments.

If found guilty, Grabowski faces up to 45 years in prison and the forfeiture of $21.5 million.

LolekHosted’s seizure was the result of a cooperation between law enforcement agencies in the US and Poland, with assistance from Europol.

Five alleged administrators of the bulletproof hosting service were arrested in Poland, but Grabowski remains a fugitive.

Related: Romanian Operator of Bulletproof Hosting Service Sentenced to Prison in US

Related: Los Angeles SIM Swapper Pleads Guilty to Cybercrime Charges

Related: US Charges Russians With Hacking Cryptocurrency Exchange

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

SolarWinds has appointed Justin Henkel as Chief Information Security Officer.

J. Paul Haynes has joined Cinchy as Chief Executive Officer.

Hatem Naguib has become Chief Executive Officer at Sysdig.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.