Sophos reported that some hosting environments are unintentionally (and in some cases deliberately) helping criminals conceal ransomware and malware infrastructure by repeatedly deploying preconfigured Windows VM images without changing default system identifiers such as hostnames. This results in large numbers of unrelated servers sharing the same computer name, which can make distinct threat operations appear connected and can cause older infrastructure to “disappear” and reappear under the same hostname but different IPs—complicating tracking, attribution, and takedown efforts. Sophos observed more than 7,000 servers associated with ransomware activity sharing a single hostname, and noted that this pattern can provide cover for short-lived ransomware operations among legitimate systems.
In investigations tied to recent WantToCry ransomware activity, Sophos found attackers abusing VMs provisioned via ISPsystem’s VMmanager (a legitimate virtualization management platform used by hosting providers) to host and deliver payloads at scale, with identical hostnames indicating reuse of default Windows templates. The same hostname patterns were also observed across infrastructure linked to multiple operations, including LockBit, Qilin, Conti, ALPHV/BlackCat, and malware campaigns involving Ursnif, RedLine, and Lummar. Sophos assessed that bulletproof hosting providers can exploit this design/operational weakness to blend malicious C2 and payload-delivery systems into large pools of innocuous VMs; cited providers associated with this activity included Stark Industries Solutions Ltd., Zomro B.V., First Server Limited, Partner Hosting LTD, and JSC IOT.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
After reporting on Sophos' findings, BleepingComputer contacted ISPsystem for comment regarding the abuse of its VMmanager platform and possible mitigations. No statement was available at the time of publication.
Sophos assessed that a small cluster of disreputable or sanctioned hosting providers were predominant hosts for the malicious VMs, naming providers such as MasterRDP, Stark Industries Solutions Ltd., and Zomro B.V. The report said these providers used VMmanager-based infrastructure to support ransomware and malware operations while resisting legal or takedown requests.
Sophos disclosed that bulletproof hosting providers were repeatedly deploying preconfigured Windows VM images without changing default settings, causing thousands of servers to share the same hostnames. The company said this made unrelated criminal operations appear linked, complicated attribution, and slowed takedown efforts.
During investigations into recent WantToCry and other ransomware incidents, Sophos identified many attacker-controlled Windows VMs sharing identical hostnames and system identifiers consistent with VMmanager default Windows templates. The pattern allowed researchers to map thousands of active devices and connect infrastructure used by ransomware and infostealer operations.
In late 2025, multiple ransomware incidents revealed attackers renting virtual machines provisioned through ISPsystem's VMmanager platform to host command-and-control and payload-delivery infrastructure. The use of legitimate data-center VMs gave threat actors high-bandwidth, trusted-looking systems that helped them evade blocks and suspicion.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.