Between late 2022 and February 2024, Azarov’s eServer said it was managing two IP ranges that subsequently came under the control of Stark Industries Solutions.
Following the EU sanctions, Stark Industries Solutions rebranded as PQ Hosting and transferred its IP resources under the umbrella of Dutch WorkTitans.
In May this year, Dutch police arrested the owners of WorkTitans and MIRhosting on suspicion of aiding Stark Industries Solution in circumventing sanctions.
Archived routing data show that at the end of 2024, Azarov was an upstream provider for PQ Hosting, i.e. the rebranded Stark Industries Solutions.
BIRN identified at least eight IP ranges that WorkTitans listed as being located in or used from Serbia and Belgrade, with Serbian Open Exchange, an internet traffic exchange point, serving as the internet gateway for all the ranges. These include two previously advertised by eServer.
Azarov said his company “had no direct business relations with Stark Industries”.
“Subnets roam between some providers and if we get request from any of our clients to announce network we just do so – that’s our part of hosting business,” he said in a response to BIRN, written in English.
“And you say it later came under control of Stark – then maybe they acquired it somehow.”
BIRN also identified three other IP ranges that have, over the past several years, moved between eServer, Stark Industries Solutions and Aeza Group.
An analysis of the RIPE NCC database shows that numerous IP ranges previously controlled by Azarov have since passed to two providers previously linked to the Russian bulletproof ecosystem and infrastructure used in cyberattacks: Cypriot-registered IT-Hostline and Russia-based Fortis.
IT-Hostline was previously a partner of Stark Industries Solutions and now provides infrastructure to Aeza Group, according to France-based cybersecurity firm Intrinsec, while Fortis’s infrastructure was used by FIN7 hacking group, responsible for mass financial theft and corporate extortion, Insikt Group reported last year.
Former eServer ranges are also now advertised by Global Connectivity Solutions and Global Internet Solutions, both linked to Aeza Group, Insikt Group said, and identified a number of ransomware groups that it said had used their infrastructure.
According to RIPE NCC data, among the current users of IP ranges previously held by eServer are: Russian provider Rost, whose infrastructure was also reportedly used in the Doppelganger campaign; Russian Timeweb, where researchers this year found more than 300 active C2 servers – systems used to send instructions to malware-infected devices and steal data; and US-based Baxet Group, whose infrastructure has been linked to cyberattacks by Russia’s military intelligence service, GRU, as reported by Arctic Wolf Networks, an American cybersecurity company, in November 2025.
Today, Azarov advertises an IP range belonging to Neterra Ltd, a Bulgarian provider previously used by the hacking-for-hire and corporate espionage group DeathStalker and whose infrastructure was also partly used to distribute Pegasus spyware, according to Amnesty International.
Azarov, however, insisted his eServer “has a strict anti cybercrime policy on all of our locations”.
“By targeting on B2B and B2C markets we always monitor our networks and try to keep environment safe and trustworthy,” he wrote to BIRN.
“You can see that our networks are not in SBL and other lists and if some IPs get into it we act immediately. So as I told you we did not work directly with Stark Industries but even if their networks were announced by some of our clients, they were applied the same strict rules and filters so I don’t think there was any malicious activity.”
Typically in cybercrime, when one network is shut down or sanctioned, attackers simply transfer IP addresses and other internet resources to linked providers and continue their operations. This is how sanctioned companies Aeza and Stark Industries have continued to operate.
“Today, it is no longer a single server, but an entire dynamic infrastructure that is constantly changing,” Radunovic told BIRN. “That makes it difficult to track because it operates across multiple jurisdictions and legal procedures, so investigators, alongside technical traces, also follow money flows, cryptocurrencies and other connections.”
Provider ‘does not care’
