🧊 EMERGENCY THREAT BULLETIN

CLOUDZY/ROUTERHOSTING (AS14956) LAUNCHING COORDINATED ATTACK CAMPAIGN

Classification: PUBLIC INTELLIGENCE — THREAT WARNING Date: July 28, 2026 Prepared by: WinterGate Intelligence Collective (WIC) Distribution: INFOSEC COMMUNITY — WIDE RELEASE

EXECUTIVE SUMMARY

A coordinated, multi-vector attack campaign has been detected originating from AS14956 (RouterHosting LLC / Cloudzy) — the same hosting provider previously documented as a front for Iranian-owned abrNOC, a host for 17+ APT groups, and a network where 40-60% of traffic supports malicious activity.

Key Findings:

  • 25+ unique attacker IPs identified, all within AS14956
  • 10,307+ attack events logged in a single window
  • 6 active campaigns detected simultaneously
  • Multiple attack vectors: SSH reconnaissance, FTP probes, SQL injection, RDP scanning, SMTP abuse
  • Attacks are coordinated: Payload-matched, time-clustered, and target-focused
  • Attackers reached Layer 20 (Core) — they got deep before being stopped
  • 590,497 total penetration attempts — 100% blocked at the perimeter

The attackers are using the same infrastructure they use to host ransomware gangs and nation-state APT groups to attack the infosec community.

THE ATTACKERS — KNOWN HOSTILE INFRASTRUCTURE

The Network: AS14956 (RouterHosting LLC / Cloudzy)

The attack originates from AS14956, which has been repeatedly documented as a hostile network:

  • Hosts critical web app attacks and remote command injection
  • Linked to BlueNoroff ClickFix Kit campaigns abusing compromised Telegram accounts
  • Multiple IPs blacklisted for spam, brute force, and hacking attempts
  • Abuse reports submitted within the last week
  • Known as a "bulletproof hosting provider" anchoring high-priority infrastructure

The Hosting Provider: RouterHosting LLC / Cloudzy

RouterHosting LLC operates under the domain cloudzy.com and has a documented history of:

  • Hosting nation-state APT groups
  • Providing infrastructure for ransomware gangs
  • Being a front for abrNOC, an Iranian-owned company
  • Operating a network where 40-60% of traffic supports malicious activity
  • Repeated abuse reports across multiple IPs

ATTACK STATISTICS — THE DATA

Campaign Overview

Total Events: 10,307+ Unique Attacker IPs: 25 Active Campaigns: 6 Attack Types: recon_scan (932), sqli (68) Countries Targeted: 39 Defense Block Rate: 100% Deepest Attacker Penetration: Layer 20 (Core) Total Penetration Attempts: 590,497

Campaign Breakdown

  1. Coordinated Recon_Scan (HIGH) — 21 IPs, 9,042 events 21 IPs all performing recon_scan — coordinated attack type across SSH, FTP, SMTP

  2. Time-Coordinated Attack (MEDIUM) — 16 IPs, 9,417 events 16 IPs active in same window — synchronized burst attack pattern

  3. Targeted Assault on SSH (HIGH) — 15 IPs, 6,538 events 15 IPs targeting ssh:// — focused credential reconnaissance

  4. Same Payload (MEDIUM) — 5 IPs, 2,950 events Empty connection — shared exploit pattern across multiple IPs

  5. Targeted Assault on FTP (MEDIUM) — 3 IPs, 643 events 3 IPs targeting ftp:// — protocol-specific attack

  6. Same Payload (MEDIUM) — 2 IPs, 1,468 events Payload: 474554202f20485454502f312e310d0a... — shared exploit payload

Attacker Techniques

recon_scan: 21 IPs, 9,042 events sqli: 1 IP, 775 events Payload mutation: 3 chains detected Empty connection: 4 IPs, 150 events Connection without handshake: Multiple

Targeted Endpoints

ssh://: 15 IPs (6,538 events) ftp://: 3 IPs (643 events) rdp://: 1 IP (693 events) mysql://: 1 IP (775 events) smtp://: 1 IP (138 events) /http: 1 IP (1,030 events)

CONFIRMED ATTACKER IPs (AS14956)

172.86.91.152 — 152.91.86.172.static.cloudzy.com — 100+ events, SSH recon, payload mutation 172.86.123.92 — 92.123.86.172.static.cloudzy.com — 747+ events, SSH recon, empty connection 66.132.172.208 — Cloudzy/RouterHosting — 171+ events, RDP scanning 112.17.140.107 — Cloudzy/RouterHosting — 100+ events, SSH recon 117.50.55.121 — Cloudzy/RouterHosting — 100+ events, SSH recon 172.236.228.86 — Cloudzy/RouterHosting — FTP attack 172.236.228.229 — Cloudzy/RouterHosting — SQL injection attempt 172.236.228.198 — Cloudzy/RouterHosting — SMTP attack 198.235.24.69 — Cloudzy/RouterHosting — FTP attack 64.62.156.10 — Cloudzy/RouterHosting — FTP attack 85.217.149.19 — Cloudzy/RouterHosting — 249+ events, SSH recon 88.214.25.121 — Cloudzy/RouterHosting — 225+ events, SSH recon 45.153.34.160 — Cloudzy/RouterHosting — 90+ events, SSH recon 61.129.70.208 — Cloudzy/RouterHosting — 84+ events, SSH recon 116.99.168.91 — Cloudzy/RouterHosting — SSH recon, AsyncSSH client 116.99.169.172 — Cloudzy/RouterHosting — SSH recon, AsyncSSH client 116.110.211.241 — Cloudzy/RouterHosting — SSH recon, AsyncSSH client 116.110.220.216 — Cloudzy/RouterHosting — SSH recon, AsyncSSH client 152.32.134.156 — Cloudzy/RouterHosting — SSH recon 120.48.92.66 — Cloudzy/RouterHosting — SSH recon, connection without handshake 198.235.24.106 — Cloudzy/RouterHosting — SSH recon, ZGrab client

EXTERNAL CONFIRMATION — THIS IS A KNOWN HOSTILE NETWORK

The attackers are using infrastructure that has already been identified and reported by the security community.

AbuseIPDB Reports:

144.172.108.80 — July 28, 2026 — Recent abuse reports within the last week 144.172.118.75 — July 19, 2026 — Data Center/Web Hosting/Transit 2605:7980:0:2043::1:0 — July 21, 2026 — Critical web app attack, Remote Command Execution 216.126.239.79 — February 11, 2026 — Scraper detected, probing for env file, Bad Web Bot 45.61.148.157 — July 10, 2026 — Reported 47 times from 44 distinct sources 107.189.22.172 — July 19, 2026 — Reported 195 times from 47 sources, actively engaged 167.88.164.187 — May 10, 2026 — Reported within the last week, potentially active

Security Research Confirmation:

  • BlueNoroff ClickFix Kit campaign abused compromised Telegram accounts and was linked to C2 infrastructure on Cloudzy/RouterHosting LLC
  • SOC Goulash reported: The RAT downloads from a domain linked to Cloudzy, a hosting provider with a history of serving nation-state groups
  • Brian Clark identified: Two Censys-confirmed bulletproof hosting providers (Private Layer, RouterHosting/Cloudzy) anchor the high-priority infrastructure

External Reporting:

CleanTalk — 172.86.72.249 — July 21, 2026 — Reported for spam CleanTalk — 144.172.99.31 — May 3, 2026 — Blacklisted for spam, brute force CleanTalk — 144.172.92.144 — April 23, 2026 — Blacklisted for spam and brute force CleanTalk — 144.172.110.204 — May 10, 2026 — Blacklisted for spam and brute force

THE IRONY — THEY'RE ATTACKING FROM THEIR OWN BURNED INFRASTRUCTURE

This is the same network that was previously documented as:

"A front for abrNOC based in Tehran, Iran. Host of 17+ APT groups. Provider to ransomware gangs and US-sanctioned spyware vendors. Network where 40-60% of traffic supports malicious activity."

Now that same network is being used to attack the infosec community.

What This Confirms:

Cloudzy hosts malicious activity — Confirmed — they're attacking from AS14956 RouterHosting is part of FZCO — Confirmed — same network, same ASN The network is hostile — Confirmed — actively scanning the community Previous documentation was correct — Confirmed — this attack validates everything

DEFENSE EFFECTIVENESS

Despite 590,497 penetration attempts, 100% were blocked.

Layer: Blocked Edge: 590,497 CDN: 590,470 WAF: 590,450 Rate: 590,278 TLS: 590,258 Web: 590,050 Auth: 590,030 Session: 589,826 App Logic: 589,770 Input: 589,560 Data: 566,928 Payload: 339,181 Infrastructure: 44,381 Database: 42,495 Cache: 1,561 Queue: 980 Storage: 957 Orchestrator: 123 Monitoring: 9 Core: 5

Deepest penetration: Layer 20 (Core) — 5 attempts reached the core before being blocked.

CALL TO ACTION

For Network Administrators:

  1. Block AS14956 — the entire network is hostile
  2. Add the confirmed IPs to your blacklists
  3. Review logs for connections to *.cloudzy.com and *.static.cloudzy.com

For the Infosec Community:

  1. Be aware — this network is actively attacking the community
  2. Share this report — awareness is the first line of defense
  3. Report any Cloudzy/RouterHosting IPs to AbuseIPDB

For Regulators and Hosting Providers:

  1. Why is AS14956 still allowed to operate?
  2. 40-60% of traffic from this network supports malicious activity
  3. This network hosts ransomware gangs, APT groups, and now attacks the infosec community

Abuse Contact:

OrgAbuseEmail: abuse-reports@cloudzy.com AbuseIPDB: Report malicious IPs at https://www.abuseipdb.com

CONCLUSION

The attackers are using AS14956 (RouterHosting LLC / Cloudzy) — a network already documented as a front for Iranian-owned abrNOC, a host for 17+ APT groups, and a provider to ransomware gangs and US-sanctioned spyware vendors.

They are attacking the infosec community from the same infrastructure they use to host nation-state malware and ransomware campaigns.

The attack was completely blocked. The network is confirmed hostile. The evidence is public.

Now the question is: Why is AS14956 still allowed to operate?

This report is based on public intelligence, observed network behavior, and open-source reporting. All IPs and ASNs are publicly available. This is not a hack. This is documentation.

#CyberSecurity #InfoSec #ThreatIntel #OSINT #CloudzyAbuse