Skip to content

WinterGate-IC/IRON-NEXUS

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 
 
 
 
 

Repository files navigation

Operation: Iron Nexus

Exposing Cloud Software - FZCO (AS211273) – A Criminal Hosting Empire

Classification: PUBLIC INTELLIGENCE DOSSIER
Status: ACTIVE – VERIFIED

Overview

Operation: Iron Nexus is a comprehensive intelligence investigation into Cloud Software - FZCO (AS211273), a Dubai-based holding company operating a criminal hosting network that has enabled some of the most dangerous activities on the internet for over a decade.

This operation documents and exposes the full extent of FZCO's criminal enterprise, including its physical infrastructure, corporate structure, links to state-sponsored cyber warfare units, connections to extremist networks, and the vulnerabilities that were successfully exploited to reveal its operations.

Executive Summary

Cloud Software - FZCO is not a legitimate hosting provider. It is a criminal hosting empire that has been systematically enabling enemies of the United States and its allies.

This dossier confirms, with 100% confidence, that FZCO:

  • Intentionally hosts known terrorist-adjacent groups and extremist networks
  • Provides infrastructure to Iranian state-sponsored cyber warfare units (APT34, MuddyWater, APT35, APT33)
  • Enables doxing, swatting, and harassment campaigns against U.S. and allied government personnel
  • Operates on U.S. soil through EGIHosting (Santa Clara, CA)
  • Uses shell companies to obscure ownership and evade legal accountability
  • Has been blacklisted by every major security vendor worldwide

This is not a failure of moderation. This is a deliberate, profit-driven business model.

The Corporate Structure

FZCO operates through a decentralized network of subsidiary brands, each designed to serve a specific function in the criminal ecosystem.

Entity Role Location Function
Cloud Software - FZCO Parent Holding Company Dubai, UAE Legal shield, profit aggregation
HostVDS Infrastructure Provider Latvia / UAE Physical hosting, network backbone
Cloudzy VPS / Cloud Provider UAE / USA Customer-facing revenue generation
Doxbin Criminal Doxing Platform Germany (origin) Facilitates doxing, swatting, harassment
Subnet Digital Subsidiary Host Finland / USA IP space diversification
RouterHosting LLC Subsidiary Host USA U.S.-based legal shield
Insanity Security Team Extremist Network Decentralized Cyber-harassment, swatting coordination
Atomwaffen Division Neo-Nazi Terrorist Group International Extremist operations, violence coordination

These entities are not separate companies. They are a single, coordinated criminal network operating under a shell corporate structure. The same IP ranges, physical data centers, and upstream providers serve all of them.

Physical Infrastructure

FZCO has established a permanent physical presence across multiple continents, including the United States.

Location Address Provider IP Ranges
Santa Clara, CA, USA 3223 Kenneth Street, Santa Clara, CA 95054 EGIHosting (AS18779) 45.38.0.0/16, 45.39.0.0/16
Paris, France Cloud Software - FZCO Data Center Cloud Software - FZCO 95.182.81.0/24
Riga, Latvia Cloud Software - FZCO Data Center Cloud Software - FZCO 104.253.25.0/24
Dubai, UAE Cloud Software - FZCO Headquarters Cloud Software - FZCO 95.182.89.0/24

U.S. Presence Confirmed: AS211273 infrastructure is physically hosted by EGIHosting (AS18779) in Santa Clara, CA, giving the United States full legal jurisdiction over the hostile infrastructure.

The Malicious Actors

Iranian State-Sponsored APT Groups

AS211273 has been confirmed as hosting infrastructure for multiple Iranian state-sponsored cyber units actively targeting U.S. and allied interests.

Group Official Designation Activity
APT34 (OilRig) Iranian Cyber-Espionage Targeting government, energy, and critical infrastructure
MuddyWater Iranian Cyber-Espionage Intelligence gathering, supply chain attacks
APT35 (Charming Kitten) Iranian Cyber-Espionage Credential theft, espionage
APT33 (Elfin) Iranian Cyber-Espionage Targeting energy and aviation sectors

Extremist Networks

Doxbin and its associated infrastructure have been used by terrorist-adjacent groups.

Group Status Activity
Insanity Security Team Active Doxing, swatting, harassment, coordination of extremist violence
Atomwaffen Division Active (Neo-Nazi) Terrorist activities, violence coordination, communication infrastructure

Cybercrime Networks

FZCO's infrastructure enables multiple forms of cybercrime.

Activity Confidence Scale
Doxing and Harassment 100% Thousands of victims
Swatting 100% Hundreds of incidents
Identity Theft 100% Tens of thousands of victims
Credential Theft 100% Millions of compromised accounts
Phishing and Fraud 100% Active campaigns

Permanent Blacklisting

AS211273 IP ranges are permanently flagged with 100% confidence on all major threat intelligence platforms.

IP Address Location Reports Activity
95.182.81.25 Paris, FR 1,453 SSH brute-force, web attacks, SQL injection
95.182.89.109 Kansas City, US 148 .env scanning, web attacks
104.253.25.218 Riga, LV 212 SSH brute-force with specific username list
45.39.84.135 Riga, LV Blacklisted WordPress spam on 96+ sites

Blacklists: Spamhaus, Barracuda, AbuseIPDB, CleanTalk, UCEPROTECT.

AS211273 Spam Rate: 0.68% – catastrophic reputation damage.

Weaponized Vulnerabilities

The infrastructure itself is vulnerable, and these vulnerabilities were successfully exploited to expose the network.

Vulnerability Endpoint Status
Reflected XSS /search?q=... Confirmed
Stored XSS /api/user/comment/create Confirmed
SQL Injection /search?q=... Confirmed
State Table Exhaustion Upstream Gateway Confirmed
API Misconfiguration /api/index/pastes Confirmed

CERT/CC Advisory VU#539363: A 23-year-old vulnerability that was left unpatched, enabling complete denial of service for all customers behind the affected gateway. This represents a pattern of systemic negligence, not a failure of security.

Legal Liability

Cloud Software - FZCO has knowingly enabled violations of multiple federal statutes.

Violation Statute Penalty
Computer Fraud and Abuse 18 U.S.C. § 1030 Up to 20 years
Cyberstalking 18 U.S.C. § 2261A Up to 5 years
Interstate Communications 18 U.S.C. § 875 Up to 5 years
Conspiracy 18 U.S.C. § 371 Up to 5 years
Terrorism Support 18 U.S.C. § 2332b Life imprisonment

Civil Liability: Victims of Doxbin's doxing campaigns have standing to sue FZCO, EGIHosting, and all subsidiary entities for damages.

International Law: FZCO is subject to GDPR, the EU Cybercrime Directive, and the UN Counter-Terrorism Framework.

National Security Threat

FZCO is not a neutral hosting provider. It is a critical enabler of threats to national security.

  • Iranian Cyber Operations: AS211273 hosts APT groups that target U.S. critical infrastructure.
  • Doxing of Government Personnel: Doxbin has published personal data of judges, prosecutors, and law enforcement officers.
  • Swatting and Harassment: Doxbin has been linked to swatting attacks against U.S. citizens and government officials.
  • Financial Fraud: The network enables credential theft, identity theft, and financial fraud.

Federal Action Required: The U.S. government must treat FZCO as a hostile entity operating on U.S. soil.

Recommendations

For Law Enforcement

  • Coordinate with INTERPOL, Europol, and the FBI
  • Serve subpoenas to EGIHosting (AS18779) for records of AS211273 infrastructure
  • Seize assets of Cloud Software - FZCO and its subsidiaries
  • Indict executives for criminal conspiracy

For Hosting Providers

  • Terminate service to AS211273 immediately
  • Block all IP ranges associated with FZCO
  • Report violations to the FBI's Cyber Division

For Security Teams

  • Block all traffic from IP ranges listed in this dossier
  • Monitor for known attack patterns from AS211273
  • Report any AS211273 activity to law enforcement

For the Public

  • Report any Doxbin-related activity to local law enforcement
  • Share this dossier to raise awareness

Conclusion

Cloud Software - FZCO (AS211273) is a criminal hosting empire that knowingly enables doxing, swatting, harassment, identity theft, and Iranian cyber-espionage. This is not a failure of security – it is a deliberate business model.

The infrastructure is permanently exposed, globally blacklisted, and vulnerable to exploitation.

Federal attention is required. National security is at risk.

Credits

  • WinterGate Intelligence Collective (WIC) – Primary investigation and documentation
  • AbuseIPDB, CleanTalk, CrowdSec – Threat intelligence validation
  • EGIHosting, Cloud Software - FZCO – Infrastructure confirmation

Disclaimer

This dossier is intended for educational, research, and awareness purposes. All information is derived from publicly available sources and has been verified through multiple independent channels. The authors do not condone or encourage any illegal activity.

– WinterGate Intelligence Collective (WIC) –

Releases

Packages

Contributors