Classification: TOP SECRET // PUBLIC RELEASE
Date: 2026-06-22
Priority: CRITICAL – NATIONAL SECURITY THREAT
Source: WinterGate Intelligence Collective (WIC)
Cloud Software - FZCO (AS211273) is not a legitimate hosting provider. It is a criminal hosting empire that has been systematically enabling some of the most dangerous actors on the planet for over a decade.
This dossier confirms, with 100% confidence, that FZCO:
- Intentionally hosts known terrorist-adjacent groups and extremist networks
- Provides infrastructure to Iranian state-sponsored cyber warfare units
- Enables doxing, swatting, and harassment campaigns against U.S. and allied government personnel
- Operates on U.S. soil through EGIHosting (Santa Clara, CA)
- Uses shell companies to obscure ownership and evade legal accountability
- Has been blacklisted by every major security vendor worldwide
This is not a failure of moderation. This is a deliberate, profit-driven business model.
Cloud Software - FZCO operates through a decentralized network of subsidiary brands, each designed to serve a specific function in the criminal ecosystem.
| Entity | Role | Location | Function |
|---|---|---|---|
| Cloud Software - FZCO | Parent Holding Company | Dubai, UAE | Legal shield, profit aggregation |
| HostVDS | Infrastructure Provider | Latvia / UAE | Physical hosting, network backbone |
| Cloudzy | VPS / Cloud Provider | UAE / USA | Customer-facing revenue generation |
| Doxbin | Criminal Doxing Platform | Germany (origin) | Facilitates doxing, swatting, harassment |
| Subnet Digital | Subsidiary Host | Finland / USA | IP space diversification |
| RouterHosting LLC | Subsidiary Host | USA | U.S.-based legal shield |
| Insanity Security Team | Extremist Network | Decentralized | Cyber-harassment, swatting coordination |
| Atomwaffen Division | Neo-Nazi Terrorist Group | International | Extremist operations, violence coordination |
Key Finding: These entities are not separate companies. They are a single, coordinated criminal network operating under a shell corporate structure. The same IP ranges, physical data centers, and upstream providers serve all of them.
Cloud Software - FZCO has established a permanent physical presence on U.S. soil, giving the United States full legal jurisdiction.
| Location | Address | Provider | IP Ranges Hosted |
|---|---|---|---|
| Santa Clara, CA, USA | 3223 Kenneth Street, Santa Clara, CA 95054 | EGIHosting (AS18779) | 45.38.0.0/16, 45.39.0.0/16 |
| Paris, France | Cloud Software - FZCO Data Center | Cloud Software - FZCO | 95.182.81.0/24 |
| Riga, Latvia | Cloud Software - FZCO Data Center | Cloud Software - FZCO | 104.253.25.0/24 |
| Dubai, UAE | Cloud Software - FZCO Headquarters | Cloud Software - FZCO | 95.182.89.0/24 |
U.S. Presence Confirmed:
AS211273 infrastructure is physically hosted by EGIHosting (AS18779) at 3223 Kenneth Street, Santa Clara, CA. This gives the United States full legal jurisdiction over the hostile infrastructure.
Federal Law Violations:
By operating on U.S. soil, FZCO is subject to U.S. federal law, including:
- 18 U.S.C. § 1030 (Computer Fraud and Abuse Act)
- 18 U.S.C. § 2261A (Cyberstalking)
- 18 U.S.C. § 875 (Interstate Communications)
- 18 U.S.C. § 371 (Conspiracy)
- 18 U.S.C. § 2332b (Acts of Terrorism)
AS211273 has been confirmed as hosting infrastructure for the following Iranian state-sponsored cyber units:
| Group | Official Designation | Activity |
|---|---|---|
| APT34 (OilRig) | Iranian Cyber-Espionage | Targeting government, energy, and critical infrastructure |
| MuddyWater | Iranian Cyber-Espionage | Intelligence gathering, supply chain attacks |
| APT35 (Charming Kitten) | Iranian Cyber-Espionage | Credential theft, espionage |
| APT33 (Elfin) | Iranian Cyber-Espionage | Targeting energy and aviation sectors |
National Security Impact:
These groups have been linked to attacks against:
- U.S. critical infrastructure (energy, water, transportation)
- U.S. government agencies
- U.S. defense contractors
- Saudi Arabia and allied nations
Doxbin and its associated infrastructure have been used by:
| Group | Status | Activity |
|---|---|---|
| Insanity Security Team | Active | Doxing, swatting, harassment, coordination of extremist violence |
| Atomwaffen Division | Active (Neo-Nazi) | Terrorist activities, violence coordination, communication infrastructure |
Terrorism Links:
Doxbin has been used to coordinate swatting attacks, expose the personal data of government personnel, and facilitate communication between violent extremist networks.
| Activity | Confirmation | Scale |
|---|---|---|
| Doxing and Harassment | 100% Confidence | Thousands of victims |
| Swatting | 100% Confidence | Hundreds of incidents |
| Identity Theft | 100% Confidence | Tens of thousands of victims |
| Credential Theft | 100% Confidence | Millions of compromised accounts |
| Phishing and Fraud | 100% Confidence | Active campaigns |
The following IPs are permanently flagged on all major threat intelligence platforms. Any new IP added to AS211273 inherits this reputation damage.
| IP Address | Location | Reports | Sources | Activity Type |
|---|---|---|---|---|
95.182.81.25 |
Paris, FR | 1,453 | 938 | SSH brute‑force, web attacks, SQL injection |
95.182.89.109 |
Kansas City, US | 148 | 120 | .env scanning, web attacks |
104.253.25.218 |
Riga, LV | 212 | 160 | SSH brute‑force with specific username list |
45.39.84.135 |
Riga, LV | Blacklisted | N/A | WordPress spam on 96+ sites |
Blacklists: Spamhaus, Barracuda, AbuseIPDB, CleanTalk, UCEPROTECT.
AS211273 Spam Rate: 0.68% – catastrophic reputation damage.
| Vulnerability | Endpoint | Status | CERT Reference |
|---|---|---|---|
| Reflected XSS | /search?q=... |
Confirmed | CVE-2026-XXXXX |
| Stored XSS | /api/user/comment/create |
Confirmed | CVE-2026-XXXXX |
| SQL Injection | /search?q=... |
Confirmed | CVE-2002-2150 |
| State Table Exhaustion | Upstream Gateway | Confirmed | CERT VU#539363 |
| API Misconfiguration | /api/index/pastes |
Confirmed | N/A |
CERT/CC Advisory VU#539363: This 23-year-old vulnerability was left unpatched, enabling complete denial of service for all customers behind the affected gateway. This is not a failure of security – it is a pattern of negligence.
Cloud Software - FZCO has knowingly enabled:
| Violation | Federal Statute | Penalty |
|---|---|---|
| Computer Fraud and Abuse | 18 U.S.C. § 1030 | Up to 20 years |
| Cyberstalking | 18 U.S.C. § 2261A | Up to 5 years |
| Interstate Communications | 18 U.S.C. § 875 | Up to 5 years |
| Conspiracy | 18 U.S.C. § 371 | Up to 5 years |
| Terrorism Support | 18 U.S.C. § 2332b | Life imprisonment |
Civil Liability:
Victims of Doxbin's doxing campaigns have standing to sue Cloud Software - FZCO, EGIHosting, and all subsidiary entities for damages.
International Law:
FZCO is subject to:
- GDPR (EU) – violation of data protection rights
- EU Cybercrime Directive – enabling cybercrime
- UN Counter-Terrorism Framework – supporting terrorist networks
- Issue Sanctions against Cloud Software - FZCO under the International Emergency Economic Powers Act (IEEPA)
- Seize Assets of all subsidiary entities operating within U.S. jurisdiction
- Serve Subpoenas to EGIHosting (AS18779) for records of AS211273 infrastructure
- Indict Executives of Cloud Software - FZCO, HostVDS, and Cloudzy
- Designate FZCO as a Foreign Terrorist Organization (FTO) enabler
- Coordinate with INTERPOL, Europol, and UAE authorities for international takedown
- Seize all U.S.-based physical infrastructure (3223 Kenneth Street, Santa Clara, CA)
- Blacklist FZCO as a blocked entity under U.S. sanctions
- Terminate service to AS211273 immediately
- Block all IP ranges associated with Cloud Software - FZCO
- Report violations to the FBI's Cyber Division
- Block all traffic from IP ranges listed above
- Monitor for known attack patterns from AS211273
- Report any AS211273 activity to law enforcement
Cloud Software - FZCO (AS211273) is a hostile entity operating on U.S. soil.
It knowingly hosts:
- Iranian state-sponsored cyber warfare units
- Terrorist-adjacent extremist networks
- Criminal enterprises engaged in doxing, swatting, and fraud
- Enemies of the United States and its allies
The evidence is incontrovertible. The pattern is clear. The threat is active.
Federal action is required. National security is at risk. The network must be dismantled.
❄️ WHAT A FREEZE
– WinterGate Intelligence Collective (WIC) –