Summary

  • Security experts have discovered that Russian web hosting provider Prospero is routing its operations through networks operated by Russian antivirus and security firm Kaspersky Lab.
  • Prospero has courted one of the nastiest cybercrime groups in Russia, hosting control servers for multiple ransomware gangs and spreading malware via fake browser updates.
  • Hosting networks were ranked last year by their hosting of spam bots, and Prospero was found to have a higher spam score than any other provider by far.
  • The US banned the use of Kaspersky Lab software in federal agencies in 2017, and last year the US Commerce Department banned the sale of Kaspersky Lab software in the US, effective from 2024, citing espionage concerns.
  • cybersecurity researchers suspect that Kaspersky is providing transit to Prospero for financial reasons, perhaps because Prospero is purchasing DDoS protection from Kaspersky, but this does not mitigate the security concerns surrounding the Russian antivirus firm.

By BrianKrebs

Original Article