Introduction
In a significant escalation of Europe’s battle against hybrid warfare, Dutch financial crime authorities have dismantled a critical node of the Russian cyber-influence machine. On May 18, the Tax Intelligence and Investigation Service (FIOD) arrested two individuals in the Netherlands—a 57-year-old Amsterdam resident and a 39-year-old from The Hague—on charges of violating international sanctions.
The arrests center on the operation of two interconnected internet hosting companies, MIRhosting and WorkTitans BV, which investigators allege provided the digital backbone for Russian intelligence agencies. These firms served as the primary infrastructure for distributed denial-of-service (DDoS) attacks, disinformation campaigns, and political interference operations aimed at the heart of the European Union. The operation resulted in the seizure of three business premises, two data centers, and over 800 servers, marking a major blow to the "bulletproof" hosting networks that have facilitated Russian state-sponsored mischief since the invasion of Ukraine.
The Anatomy of the Network: A Chronology of Evasion
The collapse of this operation is the culmination of a multi-year investigation that traces back to the digital aftermath of the 2022 invasion of Ukraine.
The Rise of Stark Industries Solutions
Two weeks prior to the Russian invasion of Ukraine, a mysterious hosting provider known as "Stark Industries Solutions" materialized in the digital landscape. It quickly gained notoriety as a "bulletproof" host—a service provider that intentionally ignores abuse reports and legal takedowns, effectively acting as a sanctuary for cybercriminals. By 2024, deep-dive investigations, including those by KrebsOnSecurity, identified Stark as a primary staging ground for Russian-backed hacking groups to launch massive DDoS attacks against European infrastructure.
The Neculiti Connection and EU Sanctions
The network’s reach was extended by two Moldovan brothers, Ivan and Yuri Neculiti, and their company, PQHosting. Acting as a gateway for Stark, PQHosting became a vital conduit for Russian intelligence. In May 2025, the European Union formally sanctioned the Neculiti brothers and PQHosting for their role in facilitating Russia’s hybrid warfare efforts.
The "the[.]hosting" Shell Game
As the threat of sanctions loomed in early 2025, the network executed a strategic pivot. Reports indicate that, nearly two weeks before the official announcement of EU sanctions, the assets of Stark Industries were quietly migrated to a new entity branded as "the[.]hosting." This entity operated under the umbrella of a Dutch firm, WorkTitans BV, which was controlled by two men: Andrey Nesterenko, the Russian-born founder of MIRhosting, and his associate, Youssef Zinad. This move allowed the network to maintain its internet connectivity through MIRhosting, effectively bypassing the initial round of sanctions.
The Key Players: From Piano Prodigy to Shadow Operator
The profiles of the two men arrested reveal the complexities of modern, high-tech subversion.

Andrey Nesterenko: The Architect
Andrey Nesterenko, 39, has a history that stretches back to the early days of cyber-conflict. Born in Nizhny Novgorod, Russia, he was a child piano prodigy before transitioning into the world of IT infrastructure. In 2004, he founded Innovation IT Solutions Corp. Notably, this company was responsible for hosting stopgeorgia[.]ru, a hacktivist site that coordinated cyberattacks against Georgia during the 2008 Russo-Georgian War—a conflict widely cited by cybersecurity historians as the first instance of simultaneous kinetic and cyber warfare.
Despite his track record, Nesterenko has consistently denied wrongdoing, claiming his services were misused without his knowledge. He characterizes the Dutch authorities’ actions as an overreach that harms "legitimate" business operations.
Youssef Zinad: The Shadowy Associate
The 57-year-old Zinad, based in Amsterdam, maintained a far more enigmatic profile. Following initial media exposure in 2025, Zinad retreated from public view, deleting his digital footprint and severing contact with professional acquaintances. Investigations by de Volkskrant revealed a man in hiding; visits to his registered address in Almere found a shuttered home with abandoned belongings, suggesting a desperate attempt to evade scrutiny before his eventual capture in Amsterdam.
Supporting Data: Evidence of Influence Operations
The impact of this infrastructure was not merely theoretical; it was actively weaponized against the democratic processes of European nations.
Data reviewed by de Volkskrant indicates that WorkTitans and MIRhosting were the most heavily utilized networks during a surge of pro-Russian cyberattacks targeting Danish government bodies in November 2025. This period coincided with Denmark’s municipal elections, underscoring the role of these hosting companies in disrupting democratic stability.
The seizure of 800 servers provides investigators with a treasure trove of metadata, traffic logs, and client communication. The immediate aftermath of the raid saw a massive outage for "the[.]hosting" customers, accompanied by an automated message notifying them that their data was lost and unrecoverable—a stark indicator of the suddenness and finality of the Dutch intervention.
Official Responses and Denials
The tension between the Dutch authorities and the operators of MIRhosting has created a public relations battle alongside the legal one.

The MIRhosting Defense
In a statement issued following the raid, MIRhosting maintained that they had conducted an internal audit and found no evidence of their infrastructure being used to influence the Danish elections. They argued that:
- There were no observed traffic spikes during the election period.
- The company received no prior abuse reports or official requests regarding suspicious activity.
- The transition of assets to WorkTitans was a legitimate business transaction, not a sanctions-evasion tactic.
Nesterenko further argued that the hardware transfer was completed before the sanctions were finalized, framing his arrest as a catastrophic error by the Dutch justice system that targets a legitimate service provider.
The Reality of the Evidence
However, the claims made by Nesterenko are contradicted by his own business records. While he claimed Zinad was merely an external contractor, evidence emerged of Zinad using a @mirhosting.com email address, and official records listed him as a point of contact for the company’s offices in Almere. These discrepancies suggest a deliberate effort to obfuscate the ownership and control of the infrastructure to create "plausible deniability."
Implications: The Future of Cyber-Sovereignty
The arrest of Nesterenko and Zinad signals a shift in how the European Union addresses "bulletproof" hosting. Historically, such providers have operated in a gray area, shielded by the anonymity of the internet and the jurisdictional complexity of international law. By utilizing financial crime statutes to seize the physical infrastructure—the servers and the data they contain—the Netherlands has provided a blueprint for other EU member states to follow.
Disruption vs. Eradication
While this raid effectively decapitated one of the most active networks supporting Russian hybrid warfare, experts warn that the battle is far from over. The ease with which the network transitioned from PQHosting to WorkTitans illustrates the agility of these operators. As long as there is a demand for anonymity in the digital underground, infrastructure will continue to migrate.
The Burden of Responsibility
The case also sets a high-stakes precedent for hosting providers. It suggests that "willful blindness"—the practice of turning a blind eye to the malicious activities of one’s clients—is no longer a viable defense. If a hosting provider’s business model relies on the obfuscation of state-sponsored threat actors, they risk being classified as accomplices to the very activities they host.
As the Dutch investigation continues, the international cybersecurity community will be watching closely to see if the data seized from those 800 servers reveals the true scale of the Russian influence campaign, and whether these arrests will lead to further prosecutions of the shadowy facilitators who help turn the internet into a theater of war.

