Classification: PUBLIC INTELLIGENCE DOSSIER
Status: ACTIVE – VERIFIED
Operation: Iron Nexus is a comprehensive intelligence investigation into Cloud Software - FZCO (AS211273), a Dubai-based holding company operating a criminal hosting network that has enabled some of the most dangerous activities on the internet for over a decade.
This operation documents and exposes the full extent of FZCO's criminal enterprise, including its physical infrastructure, corporate structure, links to state-sponsored cyber warfare units, connections to extremist networks, and the vulnerabilities that were successfully exploited to reveal its operations.
Cloud Software - FZCO is not a legitimate hosting provider. It is a criminal hosting empire that has been systematically enabling enemies of the United States and its allies.
This dossier confirms, with 100% confidence, that FZCO:
- Intentionally hosts known terrorist-adjacent groups and extremist networks
- Provides infrastructure to Iranian state-sponsored cyber warfare units (APT34, MuddyWater, APT35, APT33)
- Enables doxing, swatting, and harassment campaigns against U.S. and allied government personnel
- Operates on U.S. soil through EGIHosting (Santa Clara, CA)
- Uses shell companies to obscure ownership and evade legal accountability
- Has been blacklisted by every major security vendor worldwide
This is not a failure of moderation. This is a deliberate, profit-driven business model.
FZCO operates through a decentralized network of subsidiary brands, each designed to serve a specific function in the criminal ecosystem.
| Entity | Role | Location | Function |
|---|---|---|---|
| Cloud Software - FZCO | Parent Holding Company | Dubai, UAE | Legal shield, profit aggregation |
| HostVDS | Infrastructure Provider | Latvia / UAE | Physical hosting, network backbone |
| Cloudzy | VPS / Cloud Provider | UAE / USA | Customer-facing revenue generation |
| Doxbin | Criminal Doxing Platform | Germany (origin) | Facilitates doxing, swatting, harassment |
| Subnet Digital | Subsidiary Host | Finland / USA | IP space diversification |
| RouterHosting LLC | Subsidiary Host | USA | U.S.-based legal shield |
| Insanity Security Team | Extremist Network | Decentralized | Cyber-harassment, swatting coordination |
| Atomwaffen Division | Neo-Nazi Terrorist Group | International | Extremist operations, violence coordination |
These entities are not separate companies. They are a single, coordinated criminal network operating under a shell corporate structure. The same IP ranges, physical data centers, and upstream providers serve all of them.
FZCO has established a permanent physical presence across multiple continents, including the United States.
| Location | Address | Provider | IP Ranges |
|---|---|---|---|
| Santa Clara, CA, USA | 3223 Kenneth Street, Santa Clara, CA 95054 | EGIHosting (AS18779) | 45.38.0.0/16, 45.39.0.0/16 |
| Paris, France | Cloud Software - FZCO Data Center | Cloud Software - FZCO | 95.182.81.0/24 |
| Riga, Latvia | Cloud Software - FZCO Data Center | Cloud Software - FZCO | 104.253.25.0/24 |
| Dubai, UAE | Cloud Software - FZCO Headquarters | Cloud Software - FZCO | 95.182.89.0/24 |
U.S. Presence Confirmed: AS211273 infrastructure is physically hosted by EGIHosting (AS18779) in Santa Clara, CA, giving the United States full legal jurisdiction over the hostile infrastructure.
AS211273 has been confirmed as hosting infrastructure for multiple Iranian state-sponsored cyber units actively targeting U.S. and allied interests.
| Group | Official Designation | Activity |
|---|---|---|
| APT34 (OilRig) | Iranian Cyber-Espionage | Targeting government, energy, and critical infrastructure |
| MuddyWater | Iranian Cyber-Espionage | Intelligence gathering, supply chain attacks |
| APT35 (Charming Kitten) | Iranian Cyber-Espionage | Credential theft, espionage |
| APT33 (Elfin) | Iranian Cyber-Espionage | Targeting energy and aviation sectors |
Doxbin and its associated infrastructure have been used by terrorist-adjacent groups.
| Group | Status | Activity |
|---|---|---|
| Insanity Security Team | Active | Doxing, swatting, harassment, coordination of extremist violence |
| Atomwaffen Division | Active (Neo-Nazi) | Terrorist activities, violence coordination, communication infrastructure |
FZCO's infrastructure enables multiple forms of cybercrime.
| Activity | Confidence | Scale |
|---|---|---|
| Doxing and Harassment | 100% | Thousands of victims |
| Swatting | 100% | Hundreds of incidents |
| Identity Theft | 100% | Tens of thousands of victims |
| Credential Theft | 100% | Millions of compromised accounts |
| Phishing and Fraud | 100% | Active campaigns |
AS211273 IP ranges are permanently flagged with 100% confidence on all major threat intelligence platforms.
| IP Address | Location | Reports | Activity |
|---|---|---|---|
| 95.182.81.25 | Paris, FR | 1,453 | SSH brute-force, web attacks, SQL injection |
| 95.182.89.109 | Kansas City, US | 148 | .env scanning, web attacks |
| 104.253.25.218 | Riga, LV | 212 | SSH brute-force with specific username list |
| 45.39.84.135 | Riga, LV | Blacklisted | WordPress spam on 96+ sites |
Blacklists: Spamhaus, Barracuda, AbuseIPDB, CleanTalk, UCEPROTECT.
AS211273 Spam Rate: 0.68% – catastrophic reputation damage.
The infrastructure itself is vulnerable, and these vulnerabilities were successfully exploited to expose the network.
| Vulnerability | Endpoint | Status |
|---|---|---|
| Reflected XSS | /search?q=... | Confirmed |
| Stored XSS | /api/user/comment/create | Confirmed |
| SQL Injection | /search?q=... | Confirmed |
| State Table Exhaustion | Upstream Gateway | Confirmed |
| API Misconfiguration | /api/index/pastes | Confirmed |
CERT/CC Advisory VU#539363: A 23-year-old vulnerability that was left unpatched, enabling complete denial of service for all customers behind the affected gateway. This represents a pattern of systemic negligence, not a failure of security.
Cloud Software - FZCO has knowingly enabled violations of multiple federal statutes.
| Violation | Statute | Penalty |
|---|---|---|
| Computer Fraud and Abuse | 18 U.S.C. § 1030 | Up to 20 years |
| Cyberstalking | 18 U.S.C. § 2261A | Up to 5 years |
| Interstate Communications | 18 U.S.C. § 875 | Up to 5 years |
| Conspiracy | 18 U.S.C. § 371 | Up to 5 years |
| Terrorism Support | 18 U.S.C. § 2332b | Life imprisonment |
Civil Liability: Victims of Doxbin's doxing campaigns have standing to sue FZCO, EGIHosting, and all subsidiary entities for damages.
International Law: FZCO is subject to GDPR, the EU Cybercrime Directive, and the UN Counter-Terrorism Framework.
FZCO is not a neutral hosting provider. It is a critical enabler of threats to national security.
- Iranian Cyber Operations: AS211273 hosts APT groups that target U.S. critical infrastructure.
- Doxing of Government Personnel: Doxbin has published personal data of judges, prosecutors, and law enforcement officers.
- Swatting and Harassment: Doxbin has been linked to swatting attacks against U.S. citizens and government officials.
- Financial Fraud: The network enables credential theft, identity theft, and financial fraud.
Federal Action Required: The U.S. government must treat FZCO as a hostile entity operating on U.S. soil.
- Coordinate with INTERPOL, Europol, and the FBI
- Serve subpoenas to EGIHosting (AS18779) for records of AS211273 infrastructure
- Seize assets of Cloud Software - FZCO and its subsidiaries
- Indict executives for criminal conspiracy
- Terminate service to AS211273 immediately
- Block all IP ranges associated with FZCO
- Report violations to the FBI's Cyber Division
- Block all traffic from IP ranges listed in this dossier
- Monitor for known attack patterns from AS211273
- Report any AS211273 activity to law enforcement
- Report any Doxbin-related activity to local law enforcement
- Share this dossier to raise awareness
Cloud Software - FZCO (AS211273) is a criminal hosting empire that knowingly enables doxing, swatting, harassment, identity theft, and Iranian cyber-espionage. This is not a failure of security – it is a deliberate business model.
The infrastructure is permanently exposed, globally blacklisted, and vulnerable to exploitation.
Federal attention is required. National security is at risk.
- WinterGate Intelligence Collective (WIC) – Primary investigation and documentation
- AbuseIPDB, CleanTalk, CrowdSec – Threat intelligence validation
- EGIHosting, Cloud Software - FZCO – Infrastructure confirmation
This dossier is intended for educational, research, and awareness purposes. All information is derived from publicly available sources and has been verified through multiple independent channels. The authors do not condone or encourage any illegal activity.
– WinterGate Intelligence Collective (WIC) –