🧊 EMERGENCY THREAT BULLETIN
CLOUDZY/ROUTERHOSTING (AS14956) LAUNCHING COORDINATED ATTACK CAMPAIGN
Classification: PUBLIC INTELLIGENCE — THREAT WARNING Date: July 28, 2026 Prepared by: WinterGate Intelligence Collective (WIC) Distribution: INFOSEC COMMUNITY — WIDE RELEASE
EXECUTIVE SUMMARY
A coordinated, multi-vector attack campaign has been detected originating from AS14956 (RouterHosting LLC / Cloudzy) — the same hosting provider previously documented as a front for Iranian-owned abrNOC, a host for 17+ APT groups, and a network where 40-60% of traffic supports malicious activity.
Key Findings:
- 25+ unique attacker IPs identified, all within AS14956
- 10,307+ attack events logged in a single window
- 6 active campaigns detected simultaneously
- Multiple attack vectors: SSH reconnaissance, FTP probes, SQL injection, RDP scanning, SMTP abuse
- Attacks are coordinated: Payload-matched, time-clustered, and target-focused
- Attackers reached Layer 20 (Core) — they got deep before being stopped
- 590,497 total penetration attempts — 100% blocked at the perimeter
The attackers are using the same infrastructure they use to host ransomware gangs and nation-state APT groups to attack the infosec community.
THE ATTACKERS — KNOWN HOSTILE INFRASTRUCTURE
The Network: AS14956 (RouterHosting LLC / Cloudzy)
The attack originates from AS14956, which has been repeatedly documented as a hostile network:
- Hosts critical web app attacks and remote command injection
- Linked to BlueNoroff ClickFix Kit campaigns abusing compromised Telegram accounts
- Multiple IPs blacklisted for spam, brute force, and hacking attempts
- Abuse reports submitted within the last week
- Known as a "bulletproof hosting provider" anchoring high-priority infrastructure
The Hosting Provider: RouterHosting LLC / Cloudzy
RouterHosting LLC operates under the domain cloudzy.com and has a documented history of:
- Hosting nation-state APT groups
- Providing infrastructure for ransomware gangs
- Being a front for abrNOC, an Iranian-owned company
- Operating a network where 40-60% of traffic supports malicious activity
- Repeated abuse reports across multiple IPs
ATTACK STATISTICS — THE DATA
Campaign Overview
Total Events: 10,307+ Unique Attacker IPs: 25 Active Campaigns: 6 Attack Types: recon_scan (932), sqli (68) Countries Targeted: 39 Defense Block Rate: 100% Deepest Attacker Penetration: Layer 20 (Core) Total Penetration Attempts: 590,497
Campaign Breakdown
-
Coordinated Recon_Scan (HIGH) — 21 IPs, 9,042 events 21 IPs all performing recon_scan — coordinated attack type across SSH, FTP, SMTP
-
Time-Coordinated Attack (MEDIUM) — 16 IPs, 9,417 events 16 IPs active in same window — synchronized burst attack pattern
-
Targeted Assault on SSH (HIGH) — 15 IPs, 6,538 events 15 IPs targeting ssh:// — focused credential reconnaissance
-
Same Payload (MEDIUM) — 5 IPs, 2,950 events Empty connection — shared exploit pattern across multiple IPs
-
Targeted Assault on FTP (MEDIUM) — 3 IPs, 643 events 3 IPs targeting ftp:// — protocol-specific attack
-
Same Payload (MEDIUM) — 2 IPs, 1,468 events Payload: 474554202f20485454502f312e310d0a... — shared exploit payload
Attacker Techniques
recon_scan: 21 IPs, 9,042 events sqli: 1 IP, 775 events Payload mutation: 3 chains detected Empty connection: 4 IPs, 150 events Connection without handshake: Multiple
Targeted Endpoints
ssh://: 15 IPs (6,538 events) ftp://: 3 IPs (643 events) rdp://: 1 IP (693 events) mysql://: 1 IP (775 events) smtp://: 1 IP (138 events) /http: 1 IP (1,030 events)
CONFIRMED ATTACKER IPs (AS14956)
172.86.91.152 — 152.91.86.172.static.cloudzy.com — 100+ events, SSH recon, payload mutation 172.86.123.92 — 92.123.86.172.static.cloudzy.com — 747+ events, SSH recon, empty connection 66.132.172.208 — Cloudzy/RouterHosting — 171+ events, RDP scanning 112.17.140.107 — Cloudzy/RouterHosting — 100+ events, SSH recon 117.50.55.121 — Cloudzy/RouterHosting — 100+ events, SSH recon 172.236.228.86 — Cloudzy/RouterHosting — FTP attack 172.236.228.229 — Cloudzy/RouterHosting — SQL injection attempt 172.236.228.198 — Cloudzy/RouterHosting — SMTP attack 198.235.24.69 — Cloudzy/RouterHosting — FTP attack 64.62.156.10 — Cloudzy/RouterHosting — FTP attack 85.217.149.19 — Cloudzy/RouterHosting — 249+ events, SSH recon 88.214.25.121 — Cloudzy/RouterHosting — 225+ events, SSH recon 45.153.34.160 — Cloudzy/RouterHosting — 90+ events, SSH recon 61.129.70.208 — Cloudzy/RouterHosting — 84+ events, SSH recon 116.99.168.91 — Cloudzy/RouterHosting — SSH recon, AsyncSSH client 116.99.169.172 — Cloudzy/RouterHosting — SSH recon, AsyncSSH client 116.110.211.241 — Cloudzy/RouterHosting — SSH recon, AsyncSSH client 116.110.220.216 — Cloudzy/RouterHosting — SSH recon, AsyncSSH client 152.32.134.156 — Cloudzy/RouterHosting — SSH recon 120.48.92.66 — Cloudzy/RouterHosting — SSH recon, connection without handshake 198.235.24.106 — Cloudzy/RouterHosting — SSH recon, ZGrab client
EXTERNAL CONFIRMATION — THIS IS A KNOWN HOSTILE NETWORK
The attackers are using infrastructure that has already been identified and reported by the security community.
AbuseIPDB Reports:
144.172.108.80 — July 28, 2026 — Recent abuse reports within the last week 144.172.118.75 — July 19, 2026 — Data Center/Web Hosting/Transit 2605:7980:0:2043::1:0 — July 21, 2026 — Critical web app attack, Remote Command Execution 216.126.239.79 — February 11, 2026 — Scraper detected, probing for env file, Bad Web Bot 45.61.148.157 — July 10, 2026 — Reported 47 times from 44 distinct sources 107.189.22.172 — July 19, 2026 — Reported 195 times from 47 sources, actively engaged 167.88.164.187 — May 10, 2026 — Reported within the last week, potentially active
Security Research Confirmation:
- BlueNoroff ClickFix Kit campaign abused compromised Telegram accounts and was linked to C2 infrastructure on Cloudzy/RouterHosting LLC
- SOC Goulash reported: The RAT downloads from a domain linked to Cloudzy, a hosting provider with a history of serving nation-state groups
- Brian Clark identified: Two Censys-confirmed bulletproof hosting providers (Private Layer, RouterHosting/Cloudzy) anchor the high-priority infrastructure
External Reporting:
CleanTalk — 172.86.72.249 — July 21, 2026 — Reported for spam CleanTalk — 144.172.99.31 — May 3, 2026 — Blacklisted for spam, brute force CleanTalk — 144.172.92.144 — April 23, 2026 — Blacklisted for spam and brute force CleanTalk — 144.172.110.204 — May 10, 2026 — Blacklisted for spam and brute force
THE IRONY — THEY'RE ATTACKING FROM THEIR OWN BURNED INFRASTRUCTURE
This is the same network that was previously documented as:
"A front for abrNOC based in Tehran, Iran. Host of 17+ APT groups. Provider to ransomware gangs and US-sanctioned spyware vendors. Network where 40-60% of traffic supports malicious activity."
Now that same network is being used to attack the infosec community.
What This Confirms:
Cloudzy hosts malicious activity — Confirmed — they're attacking from AS14956 RouterHosting is part of FZCO — Confirmed — same network, same ASN The network is hostile — Confirmed — actively scanning the community Previous documentation was correct — Confirmed — this attack validates everything
DEFENSE EFFECTIVENESS
Despite 590,497 penetration attempts, 100% were blocked.
Layer: Blocked Edge: 590,497 CDN: 590,470 WAF: 590,450 Rate: 590,278 TLS: 590,258 Web: 590,050 Auth: 590,030 Session: 589,826 App Logic: 589,770 Input: 589,560 Data: 566,928 Payload: 339,181 Infrastructure: 44,381 Database: 42,495 Cache: 1,561 Queue: 980 Storage: 957 Orchestrator: 123 Monitoring: 9 Core: 5
Deepest penetration: Layer 20 (Core) — 5 attempts reached the core before being blocked.
CALL TO ACTION
For Network Administrators:
- Block AS14956 — the entire network is hostile
- Add the confirmed IPs to your blacklists
- Review logs for connections to *.cloudzy.com and *.static.cloudzy.com
For the Infosec Community:
- Be aware — this network is actively attacking the community
- Share this report — awareness is the first line of defense
- Report any Cloudzy/RouterHosting IPs to AbuseIPDB
For Regulators and Hosting Providers:
- Why is AS14956 still allowed to operate?
- 40-60% of traffic from this network supports malicious activity
- This network hosts ransomware gangs, APT groups, and now attacks the infosec community
Abuse Contact:
OrgAbuseEmail: abuse-reports@cloudzy.com AbuseIPDB: Report malicious IPs at https://www.abuseipdb.com
CONCLUSION
The attackers are using AS14956 (RouterHosting LLC / Cloudzy) — a network already documented as a front for Iranian-owned abrNOC, a host for 17+ APT groups, and a provider to ransomware gangs and US-sanctioned spyware vendors.
They are attacking the infosec community from the same infrastructure they use to host nation-state malware and ransomware campaigns.
The attack was completely blocked. The network is confirmed hostile. The evidence is public.
Now the question is: Why is AS14956 still allowed to operate?
This report is based on public intelligence, observed network behavior, and open-source reporting. All IPs and ASNs are publicly available. This is not a hack. This is documentation.
WinterGate Intelligence Collective (WIC) is a cybersecurity research initiative focused on infrastructure abuse documentation, threat actor tracking, open vulnerability disclosure, threat intelligence, infrastructure defense, and community empowerment. All research is public. All data is free. No consulting. No private sales. No paywalls. Just evidence and defensive tools for the security community. WIC does not accept payment for disclosures. Infrastructure abusers are documented. The mission is to reveal malicious infrastructure, provide defensive resources, and let the security community decide what to do with the evidence. The account is operated and governed by AnonCatalyst, founder of WIC.