Dutch financial crime investigators arrested two IT entrepreneurs and seized more than 800 servers, laptops, phones, and business records in raids targeting hosting infrastructure allegedly used for cyberattacks, interference operations, and disinformation campaigns linked to Russia. The suspects, identified in reporting as Andrey Nesterenko and Youssef Zinad, are accused of violating EU sanctions by providing economic resources to sanctioned entities. Authorities said the operation began on 18 May and included searches in Enschede and Almere and data centers in Dronten and Schiphol-Rijk.
The investigation focuses on Stark Industries, a hosting provider sanctioned by the EU in 2025, and on Dutch-linked firms including WorkTitans B.V., THE.Hosting, and MIRhosting, which investigators believe helped keep sanctioned infrastructure online after restrictions took effect. Multiple reports tied the network to infrastructure used by the pro-Russian group NoName057(16) and the Doppelgänger disinformation operation, while Dutch and European reporting also linked related services to attacks on Danish government bodies during municipal elections. MIRhosting denied knowingly supporting illegal activity and said it cooperated with authorities, but customers of related brands reported widespread outages and loss of access after the seizures.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
After the operation, customers of THE.Hosting, UFO.Hosting, and GEO.Hosting reported major outages, loss of control panel and billing access, data loss, weak support responses, and refund problems. These disruptions were linked in reporting to the seizure of infrastructure in the Dutch investigation.
Following the Dutch action, MIRhosting said it had suspended services to WorkTitans while asserting that its other operations were unaffected. The company also denied knowingly supporting illegal operations and said it was cooperating with authorities.
Reporting cited in the references says WorkTitans and MIRhosting were heavily used in pro-Russian attacks on Danish government bodies during the week of Denmark's municipal elections in November 2025. MIRhosting denied that its services were knowingly used to influence the elections.
Multiple references state that EU sanctions were imposed on PQHosting and Ivan and Iurie/Yuri Neculiti in May 2025. Reporting says this action later prompted Stark-related infrastructure to be shifted to a Dutch company.
On 2026-05-18, Dutch investigators arrested Andrey Nesterenko and Youssef Zinad, searched multiple business locations and data centers, and seized more than 800 servers along with laptops, phones, and records. Authorities said the suspects indirectly provided economic resources to EU-sanctioned entities and enabled infrastructure used in cyberattacks, interference operations, and disinformation campaigns.
FIOD's operation began on 2026-05-18, according to reporting citing the agency. The action targeted hosting infrastructure allegedly tied to cyberattacks, disinformation operations, and sanctions violations.
The Record reports that the European Union sanctioned Stark Industries on 2025-05-20. Authorities allege that after the sanctions, part of Stark's infrastructure was moved to a new Dutch firm to evade restrictions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcemalware.news
Open sourcesecurityaffairs.com
Open sourceteiss.co.uk
Open sourcetherecord.media
Open sourcekrebsonsecurity.com
Open sourcefiod.nl
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.