Proton66 is a Russian bulletproof hosting provider and autonomous system associated with infrastructure used to enable a broad range of cybercriminal operations. It has been linked to malicious activity including mass scanning, credential brute forcing, exploitation of newly disclosed vulnerabilities, phishing, malware delivery, and command-and-control hosting. Proton66 has also been connected to other bulletproof network entities including PROSPERO, and reporting has described relationships among Proton66, PROSPERO, Securehost, and BEARHOST. Activity associated with Proton66 increased markedly from early 2025, with infrastructure observed supporting opportunistic and targeted intrusion activity against internet-facing systems. Reported operations included exploitation attempts against products from Palo Alto Networks, Mitel, D-Link, and Fortinet, including campaigns associated with the initial access broker Mora_001 and subsequent SuperBlack ransomware infections. Proton66-hosted infrastructure has also been used to distribute or support malware families including XWorm, Strela Stealer, GootLoader, SpyNote, and WeaXor, a Mallox variant. Beyond exploitation and malware hosting, Proton66 infrastructure has supported phishing and social-engineering campaigns. Observed operations included Android-focused phishing using compromised WordPress sites and fake application-delivery lures, multilingual targeting in European languages, Korean-language lures tied to XWorm delivery, and campaigns against email users in Central Europe involving Strela Stealer. The provider’s infrastructure has been used for redirectors, obfuscated scripts, payload staging, and command-and-control services, illustrating its role as an enabling platform for multiple criminal actors rather than a single intrusion set. The dominant pattern is provision of resilient hosting for malicious operations spanning reconnaissance, credential attacks, initial access, payload delivery, and post-compromise control. Proton66 is best characterized as cybercriminal enabling infrastructure with strong links to financially motivated intrusion and ransomware ecosystems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Proton66 is an anonymous Russian autonomous system (ASN198953) providing bulletproof hosting services to cybercriminals. It supports a range of malicious activities including ransomware distribution, credential brute forcing, exploitation of vulnerabilities, phishing, and information stealing campaigns.
Proton66 is a Russian bulletproof hosting provider whose infrastructure is used for mass scanning, credential brute-forcing, exploitation of recent vulnerabilities, and hosting C2 servers and phishing pages for various malware campaigns. The infrastructure is linked to the distribution of malware such as GootLoader, SpyNote, XWorm, StrelaStealer, and the WeaXor ransomware, as well as facilitating phishing and social engineering attacks targeting multiple geographies and languages.
Named as a primary subject in the title, indicating discussion of links between bulletproof networks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.