Russian Cyber Havoc: Proton66’s Global Cybercrime Surge Exposed!
Brace yourself for a cyber-comedy of errors! Proton66, the Russian bulletproof hosting service, is giving cybersecurity researchers a workout with mass scanning and brute-force attempts. Remember, if a shady IP asks you to dance, just say “nyet” and block those CIDR ranges to keep your data safe and sound.

Hot Take:
Oh, the irony. A bulletproof hosting service provider with more holes than a cheese grater. Proton66’s shady antics seem as predictable as a bad reality TV show plot twist. When your cybercrime operations are more active than your New Year’s gym membership, you know it’s time to reevaluate your life choices. But hey, at least the hackers are keeping their New Year’s resolution to try new things, like brute-forcing their way into the cybersecurity hall of shame.
Key Points:
- Proton66, a Russian bulletproof hosting service, is behind a surge in cyber attacks since January 8, 2025.
- The attacks involve mass scanning, credential brute-forcing, and exploitation attempts on global organizations.
- Several malware families, including GootLoader and SpyNote, have used Proton66’s infrastructure.
- Proton66-linked campaigns use compromised WordPress sites to redirect Android users to phishing pages.
- Organizations are advised to block CIDR ranges associated with Proton66 to mitigate threats.