TI-2026-028C | Published: June 2026 | Series: The Geography of Nowhere | Classification: PUBLIC | Investigation: TI-2026-028

The Marketplace Economy

IPXO, IP Leasing, and the Structural Death of Attribution

Part 1: The Business of Renting Addresses

In 2020, a Lithuanian company called Heficed rebranded. The new name: IPXO. The new business model: the world's first automated IP address marketplace. Their pitch was elegant โ€” IPv4 addresses are scarce (the pool exhausted in 2019), organizations hold unused blocks, why not let them earn revenue by leasing unused space?

By 2024, IPXO had facilitated the transfer of 1.7 million IP addresses. Their parent company, Digital Energy Technologies Ltd (UK Company #14095987), grew rapidly. IPXO's success attracted competitors: Interlir, IPTrading, IPv4Global, Prefixx. A billion-dollar secondary market emerged.

What happens to attribution โ€” the ability to trace malicious activity back to its source โ€” when IP addresses can be rented by the hour from anonymous marketplaces?

It dies. Not slowly, not partially. Structurally and completely. The IP address marketplace model creates a fundamental break in the chain of attribution that has underpinned Internet security since the 1990s.

Here's why: Traditional hosting means a server has an IP address assigned by its ISP. That ISP knows who rented the server. Law enforcement can subpoena the ISP. The IP points to the operator.

With IP leasing: the IP address and the server are decoupled. The IP comes from a marketplace (IPXO). The server comes from a hosting provider. The routing comes from a third party. The WHOIS shows whoever the marketplace assigned as abuse contact. None of these parties necessarily know the identity of the actual operator.

TRADITIONAL HOSTING: [Attacker] โ†’ [Server @ ISP] โ†’ IP address = ISP's allocation Attribution path: IP โ†’ ISP โ†’ billing records โ†’ attacker IP MARKETPLACE MODEL: [Attacker] โ†’ [Server @ Provider A] โ†“ announces [IP from Marketplace B] โ†“ registered to [Seller C in Country X] โ†“ WHOIS shows [Marketplace abuse desk] โ†“ actual routing via [Transit provider D in Country Y] Attribution path: IP โ†’ Marketplace โ†’ "we just rent addresses" โ†’ Provider A โ†’ "not our IPs" โ†’ Seller C โ†’ "sold/leased, not responsible" โ†’ DEAD END

Part 2: The Evidence in Our Database

Our honeypot has captured the marketplace model in action. Four IPs in our database are registered to "IPXO Incident Response Team" โ€” meaning their WHOIS abuse contact points to IPXO's generic desk rather than any actual operator:

IPThreat ScoreRDAP OrgAbuse CountryBGP CountryASN Operator
102.129.200.11793IPXO Incident Response TeamNL (Netherlands)ZA (South Africa)HBING LIMITED (GB)
102.129.200.10191IPXO Incident Response TeamNL (Netherlands)ZA (South Africa)HBING LIMITED (GB)
154.16.115.1791IPXO Incident Response TeamUS (United States)ZA (South Africa)WHG Hosting Services Ltd (GB)
154.16.115.16372IPXO Incident Response TeamUS (United States)ZA (South Africa)WHG Hosting Services Ltd (GB)

Notice the pattern:

  • RDAP says: IPXO (the marketplace)
  • Abuse contact says: Netherlands or United States
  • BGP routing says: South Africa
  • ASN operator says: United Kingdom

Four different answers to "who is responsible for this IP?" โ€” none of which identifies the actual attacker.

If you're a CERT investigating SSH brute-force attacks from 102.129.200.117, who do you contact?

The WHOIS says email IPXO's Dutch abuse desk. IPXO can tell you they leased the IP โ€” but to whom? To HBING LIMITED, a BVI-shell company registered in the UK. HBING's abuse contact points to a generic form. HBING routes through South Africa. HBING's registered office is a virtual address. HBING was incorporated in 2023. There is no natural person to find at the end of this chain.

Part 3: The IPXO โ†’ HBING โ†’ WHG Chain

The four IPXO IPs in our database reveal something specific: they all route through either HBING LIMITED (AS208949) or WHG Hosting Services Ltd (AS14670). And our entity-link analysis proves these are the same operator:

SHARED SSH KEY EVIDENCE (from honeypot sessions): โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” Key fingerprint: ac:a1:39:92:2e:d3:6a:33:a4:2d:9e:7f:59:a2:d0:f7 Used by: 179.61.232.244 (WHG, AS14670, routing AE) Used by: 65.60.5.244 (external) Used by: 89.38.96.216 (external) CONFIDENCE: 0.90 โ€” same SSH key = same operator Key fingerprint: 37:03:39:e7:d5:82:4e:08:81:55:eb:5b:5f:c8:52:ab Used by: 179.61.232.245 (WHG, AS14670, routing AE) Used by: 45.148.145.60 (HBING, AS208949, routing VG) CONFIDENCE: 0.90 โ€” WHG key used on HBING IP Key fingerprint: 42:2a:3a:18:b8:5b:10:71:68:d0:4a:6f:19:02:17:39 Used by: 102.129.200.117 (HBING/IPXO, AS208949, routing ZA) Used by: 104.194.8.142 (external) CONFIDENCE: 0.90 โ€” IPXO-registered IP shares keys with external

The second key is the smoking gun: SSH key 37:03:39:e7... is used by BOTH a WHG IP (179.61.232.245 on AS14670) AND an HBING IP (45.148.145.60 on AS208949). Same private key deployed across two supposedly independent companies. This is not "shared customer" โ€” this is same operator, different shell company.

Why would the same operator need two different ASNs and two different company names?

Resilience and reputation laundering. When one ASN gets flagged by abuse lists, traffic shifts to the other. When one company gets deplatformed from an upstream, the other continues. And when IPXO assigns abuse contacts, it points to the company that leased the IPs โ€” which may be HBING or WHG depending on which shell currently holds the marketplace contract. The actual infrastructure remains unchanged.

THE NESTING STRUCTURE: โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” [Actual Attacker] โ€” identity unknown โ†“ uses server at [WHG/HBING infrastructure] โ€” same operator (proved by shared SSH keys) โ†“ IP address sourced from [IPXO Marketplace] โ€” automated, minimal KYC โ†“ IP originally allocated to [Original holder] โ€” may not know current use โ†“ WHOIS shows [IPXO Incident Response Team] โ€” generic abuse desk GEOGRAPHIC ROUTING: WHG AS14670 โ†’ announces from UAE or South Africa HBING AS208949 โ†’ announces from South Africa or BVI Abuse contact โ†’ points to Netherlands or United States Company registration โ†’ United Kingdom FOUR LAYERS. FIVE JURISDICTIONS. ZERO ACCOUNTABILITY.

Part 4: The Full WHG Dataset

Beyond the IPXO-registered IPs, our database contains 24 IPs routing through WHG/HBING ASNs. The geographic patterns are extraordinary:

IPScoreRDAP OrgAbuse CountryBGP Routes ThroughASN
179.61.232.244100Private CustomerUSAE (UAE)14670 (WHG)
192.250.235.12698WHG Hosting ServicesSGGB204800 (WHG-SGP)
198.38.85.14994WHG Hosting ServicesINGB199404 (WHG-IN)
191.101.33.11092Private CustomerUSAE (UAE)14670 (WHG)
191.101.33.11591Private CustomerUSAE (UAE)14670 (WHG)
154.16.119.2289HostforWeb SupportUSZA14670 (WHG)
191.101.33.11486Private CustomerUSAE (UAE)14670 (WHG)
198.38.91.14185WHG Hosting ServicesSGGB204800 (WHG-SGP)
45.88.0.25285lir-vg-itweb-1-MNTNLVG (BVI)208949 (HBING)
192.250.227.2485WHG Hosting ServicesUSGB36454 (WHG-DAL)
45.148.146.5282lir-vg-itweb-1-MNTNLVG (BVI)208949 (HBING)
179.61.232.24581Private CustomerUSAE (UAE)14670 (WHG)
45.148.145.6081lir-vg-itweb-1-MNTNLVG (BVI)208949 (HBING)

The naming patterns reveal the structure:

  • "Private Customer" โ€” WHG doesn't even pretend to identify the user. RDAP shows the literal string "Private Customer"
  • "lir-vg-itweb-1-MNT" โ€” HBING's RIPE maintainer object. "VG" = Virgin Islands. "itweb" = the company behind it
  • "HostforWeb Support" โ€” one of WHG's retail brands
  • WHG Hosting Services Ltd โ€” the parent, but claiming Singapore, India, US abuse contacts despite routing through UK

A "Singapore" server that routes through the UK. A "US" server that routes through the UAE. A "Netherlands" server that routes through the British Virgin Islands. What country's law applies?

That's the point. Nobody's. The geographic fiction isn't a bug in the marketplace model โ€” it's the product. When your IP routes through UAE but claims US, which jurisdiction handles the abuse report? US CERTs say "not our BGP space." UAE CERTs say "not registered here." RIPE says "contact the maintainer." The maintainer is a BVI shell. The BVI has no cybercrime enforcement apparatus. The chain terminates in a jurisdiction with legal registration but no operational presence.

Part 5: The Structural Problem

IPXO isn't a criminal organization. WHG may not even know their infrastructure is being used for attacks. The problem is structural, not criminal. The marketplace model creates conditions where:

  1. IP addresses are commoditized โ€” anyone with a credit card can obtain them
  2. KYC is minimal โ€” marketplaces verify payment, not intent
  3. Abuse routing is circular โ€” IPXO says "contact the lessee," the lessee is a shell, the shell says "contact our upstream," the upstream says "not our IPs, contact IPXO"
  4. Geography is fictitious โ€” routing, registration, and abuse contacts can each claim different countries
  5. Deplatforming is meaningless โ€” lose one IP block, lease another. The server doesn't move. The operation doesn't stop.

The Attribution Death Spiral

CONFIDENCE: HIGH

Every technological advance in Internet security has assumed that IP โ†’ operator is eventually traceable. BGP monitoring, threat intelligence feeds, abuse desk workflows, WHOIS databases, even the legal frameworks for law enforcement access โ€” all assume a mapping from address to identity exists somewhere. The marketplace model eliminates this assumption. It doesn't evade attribution โ€” it makes attribution structurally impossible by design.

This is what academic researchers are beginning to document. A 2025 CAIDA study ("Examining Abuse of the IPv4 Leasing Market") found that leased IP space appears in blocklists at 3-5x the rate of directly-allocated space. A Halcyon 2023 report documented Cloudzy (later confirmed linked to Iranian state actors) using marketplace-sourced IPs for C2 infrastructure. Our data adds the granular evidence: specific IPs, specific SSH keys, specific cross-ASN operational links.

Part 6: What the Marketplace Model Enables

The WHG/HBING cluster in our database โ€” 24 IPs with average threat score of 80+ โ€” demonstrates what marketplace infrastructure enables operationally:

BEHAVIORAL EVIDENCE FROM HONEYPOT SESSIONS: โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” 179.61.232.244 (WHG, threat_score=100): HASSH: 14b2ddda386a4d1006108ccd231b42fc Client: SSH-2.0-libssh2_1.11.0 Shared SSH keys with: 3 other IPs (cross-provider) Classification: BOTNET 192.250.235.126 (WHG-SGP, threat_score=98): Same HASSH fingerprint cluster Classification: ABUSE 102.129.200.117 (HBING/IPXO, threat_score=93): Shared SSH keys with: 2 other IPs Classification: BOTNET COMMON TRAITS ACROSS ALL 24 IPs: โ€ข Same HASSH fingerprint family (libssh2_1.11.0) โ€ข Automated credential brute-forcing โ€ข Systematic scanning patterns (not random) โ€ข 24/7 operation (bot, not human) โ€ข Multi-country routing (never matches registration)

The same SSH library (libssh2_1.11.0) across WHG IPs in UAE, South Africa, UK, and BVI. The same SSH keys deployed across supposedly independent ASNs. This isn't multiple customers coincidentally choosing the same tools โ€” it's one botnet operator using the marketplace model to distribute across jurisdictions.

Can you prove it's one operator?

Shared SSH private keys are the strongest possible signal. A private key never leaves the machine that generated it unless the same person deploys it to multiple machines. When 179.61.232.245 (WHG, routing AE) shares SSH key 37:03:39:e7:... with 45.148.145.60 (HBING, routing VG), that key was generated once and deployed to both. The same person has root access to both machines. The companies are different. The ASNs are different. The routing countries are different. But the operator is one.

Part 7: The Future of Attribution

If IP addresses can be rented hourly, routed through arbitrary countries, and registered to anonymous shells โ€” what replaces IP-based attribution?

Our honeypot research suggests behavioral fingerprinting fills some of the gap:

  • HASSH fingerprints โ€” SSH client algorithm sets are stable across IP changes
  • SSH key reuse โ€” private keys travel with the operator, not the IP
  • Command patterns โ€” attack sequences (credential choices, post-exploitation commands) identify operators better than addresses
  • Temporal correlation โ€” activity timing across IPs reveals coordination

But this requires the defender to run honeypots, capture sessions, extract behavioral markers, and maintain correlation databases. Most organizations cannot do this. They rely on IP reputation feeds โ€” which are now being systematically undermined by the marketplace model.

The Asymmetry Inversion

CONFIDENCE: HIGH

Traditional cybersecurity assumed attacker disadvantage: defenders know their own infrastructure, attackers must discover it. The marketplace model inverts this for attribution: attackers can change their identity (IP) hourly at minimal cost, while defenders must maintain expensive behavioral analysis systems to track operators across identities. The marketplace subsidizes attacker anonymity while taxing defender attribution.

Conclusions

1. The Marketplace Model Is Not Fixable Within Current Frameworks

CONFIDENCE: HIGH

Adding KYC to IP marketplaces doesn't solve the structural problem. Even with perfect customer identification, the geographic routing fictions, multi-shell nesting, and cross-jurisdictional fragmentation make enforcement impossible. The model works because no single jurisdiction sees the full picture.

2. WHG and HBING Are the Same Operator Using Marketplace Infrastructure

CONFIDENCE: HIGH

SSH key sharing (confidence 0.90) proves same operator across AS14670 (WHG) and AS208949 (HBING). IPXO-registered IPs route through both. The marketplace provides the anonymity layer; the multi-ASN structure provides resilience. This is a model, not an anomaly.

3. Behavioral Attribution Is the Only Surviving Method

CONFIDENCE: MEDIUM

In the marketplace era, IP reputation is unreliable (IPs change hands hourly). WHOIS is unreliable (shows marketplace, not operator). Only behavioral fingerprinting โ€” SSH keys, HASSH, command patterns, temporal analysis โ€” survives the marketplace abstraction layer. This shifts the cost of security from "check a blocklist" to "operate a research platform."

4. The Scale Will Grow

CONFIDENCE: HIGH

IPXO moved 1.7M IPs. IPv4 scarcity ensures demand grows. Every new marketplace participant increases the pool of anonymously-rentable addresses. By 2027, a majority of IPv4 attacks may originate from marketplace-sourced IPs โ€” rendering traditional IP-based defense obsolete for most organizations.

Series Navigation

The Geography of Nowhere (TI-2026-028)

๐Ÿ“Ž Related investigations:
โ€ข TI-2026-025 โ€” The SSH Parasite (mdrfckr botnet operating on marketplace IPs)
โ€ข TI-2026-028B โ€” The LARUS Dossier (Cloud Innovation's AFRINIC allocation)
โ€ข Halcyon 2023 โ€” Cloudzy/Iranian APT marketplace abuse report
โ€ข CAIDA 2025 โ€” "Examining Abuse of the IPv4 Leasing Market"

Investigation TI-2026-028 | Data sources: LSN Honeypot entity-link database, IPXO public filings, CAIDA research, SSH key correlation analysis
All data from direct observation or publicly available sources.

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Geography of Nowhere โ€” 3 / 8 Next โ†’