Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Short answer: On May 7, 2021, the U.S. Department of Justice announced that four Eastern European nationals pleaded guilty to one count of RICO conspiracy for operating bulletproof-hosting services from 2008 through 2015. Their infrastructure supported malware distribution, botnets and theft of banking credentials; each faced a statutory maximum of 20 years in prison.
What happened on May 7, 2021?
The defendants admitted participating in a bulletproof-hosting organization that rented internet infrastructure to cybercriminal customers. The guilty pleas were entered before Chief U.S. District Judge Denise Page Hood in the Eastern District of Michigan.
The “go-to” description is journalistic. The Justice Department described the men as founders or members of a bulletproof-hosting organization, rather than as operators of the malware campaigns themselves.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Who were the four defendants?
| Defendant | Nationality | Role described by DOJ |
|---|---|---|
| Aleksandr Grichishkin | Russian | Day-to-day leader of the operation |
| Andrei Skvortsov | Russian | Handled marketing and important or disgruntled clients |
| Aleksandr Skorodumov | Lithuanian | Administered domains and IP addresses and answered abuse notices |
| Pavel Stassi | Estonian | Handled administrative and marketing work and used false or stolen personal information for registrations |
What is bulletproof hosting?
Bulletproof hosting is a hosting service designed to keep customers’ online operations running despite abuse complaints, blocklists or law-enforcement attention. In this case, the providers rented IP addresses, servers and domain names to criminal clients and managed the infrastructure around them.
#1 Best Overall
The service did not make malware harmless or invisible. It gave criminals a resilient place to distribute malicious software, operate botnets and collect stolen data while the hosts handled the practical work of keeping the infrastructure available.
What malware and criminal activity did the service support?
| Named tool or activity | How it was connected to the hosting operation |
|---|---|
| Zeus | Hosted malware used in campaigns targeting victims and banking credentials |
| SpyEye | Hosted malware associated with theft of banking information |
| Citadel | Hosted malware used by cybercriminal customers |
| Blackhole Exploit Kit | Hosted exploit-kit infrastructure for distributing malicious code |
| Botnets and credential theft | Criminal activities enabled by the rented servers, IP addresses and domains |
The DOJ said attacks launched between 2009 and 2015 caused or attempted to cause millions of dollars in losses to U.S. victims. That is the agency’s wording; its announcement did not provide one more precise total.
How did the hosts help customers evade detection?
The organization treated infrastructure management as an evasion service. Its reported methods included:
- Monitoring blocklists for IP addresses, domains or content that had been flagged.
- Moving flagged material to new servers or addresses so campaigns could continue.
- Registering domains and infrastructure with false or stolen identities.
- Responding to abuse notices and managing client relationships, including difficult or high-value customers.
These measures shifted the burden of disruption from the criminal customer to the hosters, allowing campaigns to recover when a provider, researcher or investigator identified their infrastructure.
Rank #3
- non-fiction african american book set
- non-fiction black book set
- non-fiction african american children's book set
- non-fiction black children's book set
What was the timeline?
| Period or date | Event |
|---|---|
| 2008–2015 | The bulletproof-hosting services described in the case operated. |
| 2009–2015 | The DOJ’s stated period for the related malware attacks that caused or attempted losses to U.S. victims. |
| May 7, 2021 | The DOJ announced the four guilty pleas to one-count RICO conspiracy. |
| June, July and September 2021 | The DOJ listed sentencing dates for the defendants; the announcement did not state the eventual sentences. |
What charges and prison penalties did they face?
Each man pleaded guilty to one count of conspiracy under the Racketeer Influenced and Corrupt Organizations Act. The statutory maximum was 20 years in prison for each defendant.
A maximum penalty is not an imposed sentence. The DOJ said the court would consider the federal Sentencing Guidelines and other statutory factors when determining punishment. The announcement supplied sentencing dates but no final sentencing results.
Rank #4
How was the case investigated?
The FBI investigated with assistance from authorities in Germany, Estonia and the United Kingdom. The cross-border cooperation reflected the way the hosting business, its infrastructure and its customers operated across jurisdictions.
“The criminal organizations that purposefully aid these actors — the so-called bulletproof hosters, money launderers, purveyors of stolen identity information, and the like — are no less responsible for the harms these malware campaigns cause, and we are committed to holding them accountable.”
— Nicholas L. McQuaid, Acting Assistant Attorney General
The case’s central point was that providing servers, domains, identity records and rapid replacement infrastructure can be part of a cybercrime enterprise, even when the provider did not write the malware or directly steal from victims.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

