# Netherlands Dismantles Russian-Linked Hosting Infrastructure, Arrests Two Operators


Dutch authorities seize 800 servers and arrest operators of companies accused of enabling cyberattacks and election interference on behalf of Russia


Dutch financial crime investigators have arrested two men accused of operating Internet hosting infrastructure used by Russia to launch cyberattacks, spread disinformation, and interfere in European elections. The May 18 raids by the Dutch financial crimes agency (FIOD) resulted in the seizure of over 800 servers and the takedown of critical nodes in a sprawling infrastructure network that repeatedly appeared in attacks on European government bodies and critical infrastructure.


The arrests of Andrey Nesterenko, 39, a Russian national operating from the Netherlands, and Youssef Zinad, 57, from Amsterdam, represent a significant law enforcement victory against the infrastructure ecosystem supporting Russian hybrid warfare operations. However, the case also illustrates a troubling pattern: Russia's ability to rapidly rebuild compromised hosting networks and evade sanctions through shell companies and international relocation.


## The Infrastructure Network


The seized servers belonged to the-hosting, a domain operated by the Dutch entity WorkTitans BV. According to Dutch investigators, WorkTitans served as the primary infrastructure provider for Stark Industries Solutions, a sprawling hosting company that has become synonymous with Russian cyberattacks in Europe.


Stark Industries itself is a remarkable case study in the anatomy of a sanctions-evasion network. The company materialized just two weeks before Russia's invasion of Ukraine in February 2022, and within months became a top supplier of:


  • Distributed denial-of-service (DDoS) attack infrastructure
  • Proxy and anonymity services for masking malicious traffic
  • Hosting for phishing and malware campaigns
  • Disinformation and influence operation platforms

  • Authorities first sanctioned Stark Industries in 2024, but the company's operators simply restructured their operations rather than cease them.


    ## The Sanctions-Evasion Playbook


    The pattern uncovered by Dutch investigators reveals the sophisticated nature of how Russian threat actors adapt to law enforcement pressure. In May 2024, KrebsOnSecurity published a detailed investigation identifying that Stark Industries was primarily operated through two main Internet conduits:


    1. PQHosting, controlled by Moldovan brothers Ivan and Yuri Neculiti

    2. MIRhosting, operated by Nesterenko from the Netherlands


    When EU sanctions against PQHosting and the Neculiti brothers were announced in May 2025, media outlets leaked the news nearly two weeks before the sanctions officially took effect. During that window, the operators had advance warning—and used it strategically.


    The Stark network assets were transferred to a new entity: the-hosting, operating under the Dutch company WorkTitans BV. The company was controlled by Nesterenko (who also ran MIRhosting) and Zinad, who had previously worked at MIRhosting. WorkTitans maintained connectivity to the broader Internet exclusively through MIRhosting—effectively consolidating control while maintaining the appearance of independence.


    This maneuver allowed Stark Industries to remain operational despite sanctions, simply by changing the legal entities and personnel names on contracts while maintaining the same underlying infrastructure and purpose.


    ## Election Interference and Recent Attacks


    The timing of the raids carries particular significance given recent developments in European politics. De Volkskrant, a Dutch news outlet, reported that investigators found evidence that WorkTitans and MIRhosting networks were the most-used infrastructure for pro-Russian cyberattacks on Danish government bodies during the week of November 13-19, 2025—coinciding with Denmark's municipal elections.


    This finding underscores a critical dimension of Russian hybrid warfare: infrastructure targeting is not random. Threat actors appear to strategically position attack nodes in jurisdictions where they believe they can achieve maximum political impact, timing operations to coincide with electoral activity.


    The Danish election-period attacks represent just one documented instance. According to law enforcement filings, the seized infrastructure had been leveraged in:


  • Disinformation campaigns across EU member states
  • Cyberattacks on government agencies and critical infrastructure
  • Election interference operations designed to manipulate democratic processes

  • ## Seizure Details and Impact


    The FIOD raids on May 18 targeted three businesses across Enschede, Almere, and two data centers in Dronten and Schiphol-Rijk. Officers seized:


  • Over 800 servers from the-hosting
  • Laptops and telephones
  • Network and infrastructure documentation

  • Following the seizures, the-hosting issued a statement to customers confirming that data stored on the seized servers had been lost and could not be recovered—effectively terminating service for an unknown number of downstream users who had rented infrastructure from the company.


    ## The Suspects


    Andrey Nesterenko (39), a Russian national, appeared to operate MIRhosting and WorkTitans with minimal transparency about the source of capital or business model. Prior to his arrest, Nesterenko denied knowledge that his servers were being misused for cyberattacks, claiming he had terminated services with the Neculiti brothers when EU sanctions took effect in May 2025. He threatened legal action against media outlets reporting on his operations.


    Youssef Zinad (57) maintained a lower public profile, though investigators found clear evidence of his involvement in WorkTitans ownership and operation. Zinad's background in MIRhosting—where he had previously worked—provided direct continuity with the earlier infrastructure ecosystem.


    Both men were charged under Dutch sanctions law with violating EU restrictions by making economic resources available to sanctioned entities, a serious federal crime carrying potential prison sentences.


    ## Legal and Regulatory Response


    The arrests represent the first direct criminal prosecutions of infrastructure operators under EU sanctions law. Previous actions had focused on sanctioning the companies themselves, but sanctioning an entity has proven insufficient if the underlying operators can quickly reconstitute infrastructure under new legal structures.


    The Dutch approach—prosecuting individual operators under criminal law rather than relying solely on administrative sanctions—may establish a new enforcement precedent. However, the pattern also demonstrates the core challenge: threat actors operating in jurisdictions with weak rule of law (or maintaining operational distance from them) can continue operations indefinitely.


    ---


    ## HackWire Analysis


    The Revolving Door of Sanctions Evasion — Why Designating Companies Fails Against Sophisticated Operators


    This case reveals a critical weakness in how Western nations approach sanctions against Russian cyber infrastructure: designating companies is functionally useless without prosecuting the operators behind them.


    The Stark Industries ecosystem had been sanctioned for months, yet continued operating with minimal interruption because the operators simply created shell companies with different names, moved assets between jurisdictions, and hired new front-people. MIRhosting claimed to have severed ties with PQHosting, yet Nesterenko and Zinad—the operators of MIRhosting—immediately created WorkTitans to fill the exact same role.


    What changed was not sanctions. What changed was criminal investigation and prosecution of the individual operators. The moment law enforcement arrested the two men running the network, the infrastructure collapsed within hours. Customers received notifications that their data had been destroyed; the network fell offline; the operational capability was genuinely disrupted.


    The broader pattern is sobering: Russian threat actors have demonstrated they can rebuild sanctioned infrastructure networks in weeks, not months. The advance warning of PQHosting sanctions gave operators just enough time to migrate to new legal entities. If law enforcement had not moved with equal speed to investigate Nesterenko and Zinad, the network would likely remain operational today under the-hosting and WorkTitans names.


    The election-period timing of the Danish attacks is additionally troubling. This suggests Russian threat actors view their infrastructure positioning as a tactical asset to be deployed opportunistically, not a static resource. They position attack capability not randomly, but where they believe they can achieve political impact—and they do so with calendar awareness of electoral events.


    For defenders and policy makers, the lesson is clear: sanctions on entities require simultaneous criminal prosecution of operators to be effective. Without arresting the people making operational decisions, threat actors will simply restructure and continue. European law enforcement moved correctly here, but this model needs to become standard practice across jurisdictions if sanctions are to have genuine deterrent effect.


    HackWire Editorial


    ---


    ## Implications for Organizations


    Government agencies in EU member states should conduct immediate audits of any infrastructure or services that may have depended on WorkTitans, the-hosting, MIRhosting, or Stark Industries connectivity. Assume any data transmitted through these networks during operational periods may have been monitored or intercepted.


    Critical infrastructure operators in Denmark, the Netherlands, and other EU countries should review logs for any traffic or access patterns consistent with reconnaissance activity from the IP ranges operated by these providers. The week of November 13-19, 2025, should be treated as a specific period requiring forensic review.


    European hosting providers should review their upstream connectivity providers to ensure they are not inadvertently purchasing transit from operations with links to sanctioned entities or known threat actors.


    ## Looking Forward


    The arrests and server seizures represent a significant tactical victory, but the underlying challenge remains: Russia has demonstrated it can reconstitute cyber infrastructure quickly and repeatedly. The next frontier for law enforcement will be identifying whether other operators are already rebuilding this capacity elsewhere.


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)