Dutch authorities just hauled in 800 servers and arrested the two co-owners of a pair of hosting companies that quietly inherited Stark Industries Solutions, the same Russia-linked operation the EU sanctioned back in 2024. Different name, same infrastructure, same tenants. If that sounds depressingly familiar, congratulations: you’ve correctly identified one of the most exhausting cycles in modern cybersecurity, where takedowns make headlines and the attack infrastructure reappears under a new shell company before the press release ages.

The FBI spent the same week warning enterprises about Kali365, a phishing-as-a-service kit that hijacks Microsoft 365 sessions by abusing OAuth device-code flows. Two stories. One thread. Adversaries don’t build infrastructure anymore. They rent it.

The Same Bulletproof Host Keeps Getting Sanctioned

Here’s the funny part, if you have a dark sense of humor. Stark Industries Solutions was sanctioned by the EU in 2024 for serving as a staging ground for Russian intelligence operations. By 2025, two operators had quietly taken over the technical infrastructure under new corporate names. By 2026, those operators are in handcuffs and 800 servers are in a Dutch evidence locker. The infrastructure stayed online the whole time, just under fresh letterhead.

Takedowns matter. Disrupting hostile infrastructure has real, measurable value, especially when it gets servers offline during an active campaign. The deeper lesson is that the legitimate hosting economy makes reissuance trivial, and any defender betting their detection strategy on IP reputation lists is consuming a feed that’s already stale by the time the indicators get distributed. The attacker’s marginal cost to rebuild is a credit card and a registration form.

Phishing Comes With A Subscription Now

Kali365 is the same story at a different layer of the stack. The FBI says the kit abuses OAuth device-code authentication, a flow Microsoft built for devices without browsers, to coax users into entering an attacker-generated code on the real login.microsoftonline.com page. The user sees Microsoft’s domain. Conditional Access sees a clean sign-in. The phisher walks away with a session token that’s MFA-bypassed and policy-blessed.

Microsoft 365 logo representing the platform targeted by the Kali365 phishing-as-a-service kit
The FBI’s Kali365 advisory describes a service that turns Microsoft 365 takeover into a paid subscription.

This is the third device-code phishing kit to make headlines in the last year. None of them are clever. All of them work, because they ride a Microsoft-sanctioned authentication mechanism that most enterprises haven’t restricted. Combine commoditized bulletproof hosting with commoditized phishing-as-a-service and the cost of running a credible Microsoft 365 account takeover operation against your tenant is now lower than the cost of a midrange MDR subscription. The asymmetry matters.

Look at the rest of the week’s news through that lens and the pattern thickens. Ghost CMS exploited at 700 sites. TeamPCP rotating across three package ecosystems. Two more healthcare data breaches through third parties. Almost none of these incidents required the attacker to own anything. They rented compute, rented credentials, rented trust.

Where Cybersecurity Actually Helps Here

Stop treating hostile infrastructure as something you can outpace. Treat it as permanent ambient noise and harden the parts you control. A few concrete moves, vendor-neutral and applicable today:

  • Kill device-code flow where it doesn’t belong. In Entra ID, scope the OAuth 2.0 device authorization grant flow to specific user groups via Conditional Access. If your finance team doesn’t sign into Microsoft 365 from an Apple TV, they don’t need device-code auth enabled.
  • Shorten session and refresh token lifetimes. Default Microsoft 365 refresh tokens last 90 days. Reduce that aggressively for privileged accounts. Stolen tokens are the actual payload, not the password.
  • Build behavioral baselines for identity. Impossible travel, anomalous OAuth application consent, first-seen device fingerprints, sign-ins originating from hosting ASNs. These signals catch what reputation lists miss.
  • Treat hosting ASN egress as suspect by default. User workstations should rarely connect outbound to DigitalOcean, OVH, Hetzner, or whichever low-reputation hoster the latest bulletproof tenant has migrated to. Egress filtering and DNS logging at the firewall give you the visibility to spot it.
  • Inventory and constrain consented OAuth apps. The Kali365 pattern of stealing session tokens is bad. The pattern of getting a user to consent to a malicious OAuth application that lives in your tenant indefinitely is worse. Review consented apps quarterly. Block user consent for unverified publishers.
  • Watch the edge for brute-force and credential spray. Bulletproof hosts power most large-scale brute-force campaigns. Rate-limiting, geofencing, and threat detection on your authentication endpoints close one of the cheapest attacker tactics still in circulation.
  • Rehearse the playbook. When an executive’s M365 session token gets stolen, who revokes? How fast? Tabletop it before you live-fire it.

None of this requires a new product. Most of it requires defense in depth across identity, egress, and detection layers you already pay for. The threat-protection stack is rarely the missing piece here. The configuration is.

The Cycle Doesn’t End. Plan Like It

Eight hundred servers off the internet is a good day for Dutch investigators and a rough afternoon for whoever was renting them. By next quarter the infrastructure will have re-emerged under a new flag, probably in a jurisdiction with friendlier extradition treaties and a hosting reseller with a generous trial program. The cycle is the product. Treat takedowns as confirmation that the rental fleet keeps rotating and tune your security hardening to match.

If your defensive posture only works when law enforcement is winning, you’re running on hope. The teams that come through 2026 without a major incident will be the ones that quietly assumed hostile infrastructure exists in unlimited supply and built around that assumption: short sessions, tight Conditional Access, behavioral detection on identity, egress visibility, and an incident response runbook that doesn’t depend on the FBI publishing an alert first. The attackers rent everything now. Your cyber security program should be configured for permanent siege, not for the next news cycle.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.