Dismantling the Infrastructure of Hybrid Warfare: The Dutch Raid on MIRhosting
The battle against state-sponsored cyber warfare is rarely fought in the headlines; it is fought in the mundane details of BGP routing, IP allocations, and data center leases. A recent operation by the Dutch financial crimes agency (FIOD) has brought one such battle to light, resulting in the seizure of over 800 servers and the arrest of two men accused of facilitating Russian cyberattacks and disinformation campaigns within the European Union.
This operation represents a critical strike against the "bulletproof hosting" ecosystem—a network of providers that intentionally ignore abuse reports and sanctions to provide a safe harbor for malicious actors.
The Architecture of Evasion: From Stark Industries to MIRhosting
At the center of this case is Stark Industries Solutions, a hosting provider that appeared just two weeks before Russia's invasion of Ukraine. Stark quickly became a notorious staging ground for massive Distributed Denial-of-Service (DDoS) attacks and a primary supplier of anonymity services for Russian-backed hacking groups.
When the EU began sanctioning the conduits that allowed Stark Industries to reach the global internet, the network demonstrated a sophisticated ability to pivot. Initially, the Moldovan-based PQHosting provided the necessary connectivity. However, as sanctions against PQHosting loomed, the infrastructure was rapidly migrated to a new entity called the[.]hosting, controlled by a Dutch company, WorkTitans BV.
This migration was not a random shift but a calculated move to maintain operational continuity. WorkTitans, in turn, relied on MIRhosting, a Dutch-based ISP operated by Andrey Nesterenko, a Russian native. By shifting the infrastructure to a Dutch entity, the operators attempted to bypass EU sanctions and hide behind the legal protections of a member state.
The Takedown and the Human Element
On May 18, 2026, FIOD investigators executed raids across three businesses and two data centers in Enschede, Almere, Dronten, and Schiphol-Rijk. The operation resulted in the seizure of laptops, phones, and 800 servers. The two primary targets were:
- Andrey Nesterenko (39): Founder of MIRhosting and Innovation IT Solutions Corp. Nesterenko has a history of providing infrastructure for Russian interests, including hosting a hacktivist site used during the 2008 invasion of Georgia.
- Youssef Zinad (57): An Amsterdam-based associate who reportedly helped manage the business tasks for WorkTitans and MIRhosting, though Nesterenko has denied Zinad was an official employee.
The impact of the seizure was immediate. Customers of "the-hosting" were notified that their data had been lost and was unrecoverable, effectively wiping out a significant portion of the infrastructure used for pro-Russian influence operations.
Evidence of Influence: The Danish Elections
While the suspects denied knowledge of the misuse of their servers, investigative reports from de Volkskrant suggest a more direct connection. Data indicates that WorkTitans and MIRhosting were the most heavily used networks in pro-Russian attacks targeting Danish government bodies during the week of Denmark's municipal elections in November 2025.
Despite these findings, MIRhosting issued a public statement claiming that no anomalies or spikes in traffic were observed during that period and that they had received no official abuse reports prior to the media publication.
Technical Insights and Industry Perspectives
The community reaction to this seizure highlights several recurring themes in the world of cyber-infrastructure:
The "Bulletproof" Paradox
Industry observers note that these entities are rarely "hosting companies" in the traditional sense. As one security professional pointed out, these are often front companies for intelligence agencies that do not provide services to the general public, but rather exist solely to shield state actors.
The Skill Gap
There is a recurring frustration among security defenders regarding the talent involved in these operations. The engineering required to maintain global, resilient, and sanction-evading infrastructure is significant. As one defender noted:
"The people involved definitely have the skills to be profitable at legitimate work; it just puzzles me that they choose to support criminals."
The Limits of Sanctions
This case underscores the "whack-a-mole" nature of sanctions. When one provider (PQHosting) is sanctioned, the assets simply migrate to another (MIRhosting/WorkTitans). This suggests that as long as there are jurisdictions or providers willing to overlook the source of traffic, state-sponsored actors will find a way to stay online.
Conclusion
The seizure of 800 servers in the Netherlands is a significant tactical victory, but it highlights a systemic vulnerability. The ability of Russian intelligence to rapidly shift infrastructure across borders and through shell companies demonstrates the agility of modern hybrid warfare. For the security community, the lesson is clear: monitoring the infrastructure—the ISPs and data centers—is just as critical as monitoring the malware.