Skip to content

Kaspersky Lab Routing Traffic for Notorious Cybercriminal Host Prospero

Kaspersky Lab's networks found supporting a major cybercrime host. U.S. government's actions highlight ongoing scrutiny of the security company's ties to Russia.

In the image there is a spider crawling on the web.
In the image there is a spider crawling on the web.

Kaspersky Lab Routing Traffic for Notorious Cybercriminal Host Prospero

Spamhaus has discovered that the notorious cybercriminal hosting provider Prospero OOO has been routing its internet traffic through networks operated by Kaspersky Lab in Moscow. Kaspersky has denied providing services to Prospero and is investigating the matter. This revelation comes amidst ongoing concerns about Kaspersky's potential ties to the Russian government.

Prospero, known for its bulletproof hosting services advertised on Russian cybercrime forums since 2019, has been a persistent source of malware, botnet controllers, and phishing websites. It has a higher spam score than any other hosting provider, according to Interisle Consulting Group. Recently, it has been hosting control servers for ransomware gangs like SocGholish and GootLoader under its BEARHOST name.

In December 2024, a company providing DDoS protection started routing traffic via its networks, although the specific company remains unnamed. The U.S. Department of Homeland Security previously barred federal agencies from using Kaspersky software in 2017 due to national security concerns. More recently, the U.S. Commerce Department banned the sale of Kaspersky software in the U.S., citing potential intelligence gathering on behalf of the Russian government.

The unexpected connection between Prospero and Kaspersky Lab raises serious concerns. While Kaspersky investigates, the U.S. government's actions highlight the ongoing scrutiny of the company's ties to the Russian government. As Prospero continues to facilitate cybercrime, the routing of its traffic through Kaspersky's networks could have significant implications for global cybersecurity.

Read also:

Latest