PQ.Hosting (STARK INDUSTRIES SOLUTIONS LTD, formerly MoreneHost) sanctioned by EU

edited May 20 in General

Looks like the EU has sanctioned STARK INDUSTRIES SOLUTIONS LTD, that is PQ.hosting and Ivan Neculiti, its founder.
STARK was primarily used as a shell company for their ASN, to not attract attention to their main brand, PQ. They started started selling servers under STARK brand too.

Among those listed are also Stark Industries, a web hosting service, its CEO Iurie Neculiti and owner Ivan Neculiti. They have been acting as enablers of various Russian state-sponsored and affiliated actors to conduct destabilising activities including, information manipulation interference and cyber-attacks against the Union and third countries.

Those designated today will be subject to an asset freeze and EU citizens and companies will be forbidden from making funds available to them. In addition, natural persons will also be subject to a travel ban, which will prevent them from entering or transiting through EU territories.

https://www.consilium.europa.eu/en/press/press-releases/2025/05/20/russian-hybrid-threats-eu-lists-further-21-individuals-and-6-entities-and-introduces-sectoral-measures-in-response-to-destabilising-activities-against-the-eu-its-member-states-and-international-partners/ (archive)

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202500966 (archive)

They knew about it ahead of time, and have moved their ASN from STARK to their Moldovan company

Status of the network as of now

Thanked by (2)Nyr someTom

Comments

  • ZizzyDizzyMCZizzyDizzyMC Hosting Provider

    Seen this ASN pop up doing some nasty things in the Fortigate / Sonicwall CVE space recently, not surprised at all.

  • edited May 21

    @ZizzyDizzyMC said:
    Seen this ASN pop up doing some nasty things in the Fortigate / Sonicwall CVE space recently, not surprised at all.

    Its a gamble whether they will suspend you for malicious activity.
    I have been suspended over a fake "botnet c2" report from some Chinese "researcher" before.

    They also have(or used to) an interesting policy, where only the server gets terminated for abuse, but not the entire account. So you could just keep buying VPS over and over when suspended.

    But there are also IP's that don't get suspended ever, makes you wonder who are their customers and why do they ignore reports for one group, but not another.
    Connections to Russia get journo scum excited, but in this case I do think FSB is involved. There are many things I've heard over the years, that line up.

  • ZizzyDizzyMCZizzyDizzyMC Hosting Provider

    @treesmokah said:

    @ZizzyDizzyMC said:
    Seen this ASN pop up doing some nasty things in the Fortigate / Sonicwall CVE space recently, not surprised at all.

    Its a gamble whether they will suspend you for malicious activity.
    I have been suspended over a fake "botnet c2" report from some Chinese "researcher" before.

    They also have(or used to) an interesting policy, where only the server gets terminated for abuse, but not the entire account. So you could just keep buying VPS over and over when suspended.

    But there are also IP's that don't get suspended ever, makes you wonder who are their customers and why do they ignore reports for one group, but not another.
    Connections to Russia get journo scum excited, but in this case I do think FSB is involved. There are many things I've heard over the years, that line up.

    Without any sensitive info being given out - it is well known among cybersec that this group as well as a few others I won't name are state sponsored actors, acting as if they were not. They sell legitimate goods on the side to make it seem legit, but they mess up in strange ways, like only certain blocks are used for X activities.

    You can tell the difference from say, Frantech / BuyVM - where you see one of these IPs in a log and it can be pretty bad - but then you check and it's like "oh, tor block, ez ban" Where these state sponsored / used hosts just don't have that obviousness to them. It's like they're trying to keep it low key while door knocking ~200,000 firewalls trying to exploit a CVE where a proof of concept was not yet released. They'll change ip block hands between each other etc. It's like they think we're stupid or something. Not like ARIN RIPE etc don't keep logs of that shit dawg. FR FR ong, no cap.

    Thanked by (1)someTom
  • edited May 24

    PQ sent this to their customers

    Dear Client,
    We would like to inform you that on May 20, 2025, Stark Industries Solutions and its management were added to the European Union’s sanction lists.
    At present, we are carefully reviewing the situation together with our legal team and making every effort to resolve it. We are confident that a constructive solution will be found soon.
    PQ.Hosting’s top priority has always been the security of our clients’ data and the stability of the services we provide. However, due to the current circumstances and potential regulatory restrictions, we cannot guarantee uninterrupted service operation in some European countries with 100% certainty.
    As a preventive measure, we offer our clients whose servers are hosted in Europe an additional server free of charge to facilitate potential data transfer and minimize risks.
    We also strongly recommend that you promptly create backups of your data to ensure its safety in any scenario.
    We will continue to keep you informed about the developments. An official statement with more detailed information will be prepared shortly.
    Thank you for your understanding and trust. We are doing everything possible to maintain the stability and reliability of our services under any circumstances.
    Sincerely,The PQ.Hosting Team

    Network status as of now, looks like its crumbling. 33 /24's down since the initial post was made.

    Country list (archive)

    Thanked by (1)10thHouse
  • @ZizzyDizzyMC said:

    @treesmokah said:

    @ZizzyDizzyMC said:
    Seen this ASN pop up doing some nasty things in the Fortigate / Sonicwall CVE space recently, not surprised at all.

    Its a gamble whether they will suspend you for malicious activity.
    I have been suspended over a fake "botnet c2" report from some Chinese "researcher" before.

    They also have(or used to) an interesting policy, where only the server gets terminated for abuse, but not the entire account. So you could just keep buying VPS over and over when suspended.

    But there are also IP's that don't get suspended ever, makes you wonder who are their customers and why do they ignore reports for one group, but not another.
    Connections to Russia get journo scum excited, but in this case I do think FSB is involved. There are many things I've heard over the years, that line up.

    Without any sensitive info being given out - it is well known among cybersec that this group as well as a few others I won't name are state sponsored actors, acting as if they were not. They sell legitimate goods on the side to make it seem legit, but they mess up in strange ways, like only certain blocks are used for X activities.

    You can tell the difference from say, Frantech / BuyVM - where you see one of these IPs in a log and it can be pretty bad - but then you check and it's like "oh, tor block, ez ban" Where these state sponsored / used hosts just don't have that obviousness to them. It's like they're trying to keep it low key while door knocking ~200,000 firewalls trying to exploit a CVE where a proof of concept was not yet released. They'll change ip block hands between each other etc. It's like they think we're stupid or something. Not like ARIN RIPE etc don't keep logs of that shit dawg. FR FR ong, no cap.

    Unsurprisingly, many are Russian.

  • edited May 29

    As a part of damage control, PQ.hosting has renamed to THE.hosting. I do not believe its "new ownership and management", just a new shell.

    PQ.Hosting: THE.Hosting: Important News About the Company’s Transformation
    On May 29, 2025, the PQ.Hosting brand will officially cease to exist.

    This decision marks the completion of a full-scale transformation, through which all assets, infrastructure, and customer services are transferred under the management of a new company — THE.Hosting.

    The PQ.Hosting project no longer exists — neither as a legal entity nor as an operational structure. From the moment of transition, full control over all operational and technical activities has passed to new owners with no connection to the previous management or beneficiaries.

    Services will continue to operate without interruption. All current VPS, other services, locations, pricing plans, and billing cycles will be automatically extended — no action is required from clients. Access to services will be automatically redirected to the new website and billing platform of THE.Hosting. The entire infrastructure — including the network, control panels, and automation — will continue functioning, but now under new management.

    THE.Hosting remains committed to its core mission: delivering reliable, high-quality hosting worldwide.

    We are confident that our future will only grow stronger and more resilient. With each passing day, we become better equipped to serve, and our commitment to delivering the best possible service remains the foundation of our approach. Our team is available 24/7 and ready to answer any questions.

    THE.Hosting is the evolution of trusted hosting with a renewed approach.

    Everything you valued remains. Everything that can be improved — will be.

    We are proud to enter this new chapter and to serve you with even greater strength and confidence.

    https://the.hosting/en/news/pqhosting-thehosting-important-news-about-the-companys-transformation (archive)

    Their ASN is still called "PQ HOSTING PLUS S.R.L.", however most subnets have been renamed to "WorkTitans B.V.".
    What does a recruitment company have to do with hosting? Probably nothing, PQ either bought them to use as a shell, or they knew eachother prior to that.

    Thanked by (3)skhron 10thHouse Alyx
  • ZizzyDizzyMCZizzyDizzyMC Hosting Provider

    @treesmokah said:
    As a part of damage control, PQ.hosting has renamed to THE.hosting. I do not believe its "new ownership and management", just a new shell.

    PQ.Hosting: THE.Hosting: Important News About the Company’s Transformation
    On May 29, 2025, the PQ.Hosting brand will officially cease to exist.

    This decision marks the completion of a full-scale transformation, through which all assets, infrastructure, and customer services are transferred under the management of a new company — THE.Hosting.

    The PQ.Hosting project no longer exists — neither as a legal entity nor as an operational structure. From the moment of transition, full control over all operational and technical activities has passed to new owners with no connection to the previous management or beneficiaries.

    Services will continue to operate without interruption. All current VPS, other services, locations, pricing plans, and billing cycles will be automatically extended — no action is required from clients. Access to services will be automatically redirected to the new website and billing platform of THE.Hosting. The entire infrastructure — including the network, control panels, and automation — will continue functioning, but now under new management.

    THE.Hosting remains committed to its core mission: delivering reliable, high-quality hosting worldwide.

    We are confident that our future will only grow stronger and more resilient. With each passing day, we become better equipped to serve, and our commitment to delivering the best possible service remains the foundation of our approach. Our team is available 24/7 and ready to answer any questions.

    THE.Hosting is the evolution of trusted hosting with a renewed approach.

    Everything you valued remains. Everything that can be improved — will be.

    We are proud to enter this new chapter and to serve you with even greater strength and confidence.

    https://the.hosting/en/news/pqhosting-thehosting-important-news-about-the-companys-transformation (archive)

    Their ASN is still called "PQ HOSTING PLUS S.R.L.", however most subnets have been renamed to "WorkTitans B.V.".
    What does a recruitment company have to do with hosting? Probably nothing, PQ either bought them to use as a shell, or they knew eachother prior to that.

    Yep, just another ASN to add to the filter. This happens every 2-3 weeks btw, it just so happens that you are paying attention to this one.

  • edited May 30

    Upon taking a closer look at "the.hosting" ORG on RIPE, I have found a someones personal email attached as a contact on MNT.
    https://apps.db.ripe.net/db-web-ui/lookup?source=ripe&key=THE-HOSTING-MNT&type=mntner (archive)

    Its also shown on "ufo.hosting"(which is where PQ hosting RU customers were redirected before) MNT
    https://apps.db.ripe.net/db-web-ui/lookup?source=ripe&key=UFO42-MNT&type=mntner (archive)

    "[email protected]" appears to be Dmitrii Aleksandrovich Miasnikov(Мясников Дмитрий Александрович) aka "jimboframe", according to information gathered from leaked databases.

    And sure enough, 91.207.183.0/24 coming from his personal ripe org, ru.ripe7 is announced on UFO Hosting ASN.

    I still stand by that WorkTitans B.V. is just a front, PQ/THE appears to be still operated by Russians.

    Thanked by (2)skhron 10thHouse
Sign In or Register to comment.