CRITICAL โ€” SANCTIONS EVASION ANALYSIS

โš–๏ธ TI-2026-026F โ€” The Sanctions Question: Iranian Transit Through German Infrastructure

Series: The Phantom ASN (Part 6 of 6) ยท Published: July 2025 ยท Classification: Legal Analysis + OSINT + BGP Forensics + Regulatory Framework

Executive Summary: In June 2026, four Iranian LIRs began routing internet traffic through AS198584 โ€” a German ASN operated by PIO-Hosting GmbH (which is, as we've demonstrated, XSServer GmbH in disguise). EU Council Regulation 267/2012 prohibits making "economic resources" available to designated Iranian entities. Internet transit is an economic resource. This final installment examines the legal framework, the plausible deniability structure, and asks the hardest question: is this sanctions evasion hiding in plain sight, or is the entire German "gray transit" sector a legal gray zone that no regulator has chosen to clarify?

4+Iranian LIRs
June 2026Onboarding Date
267/2012EU Regulation
10 yearsMax Penalty (ยง18 AWG)
0Known Enforcement Actions
5Intermediary Layers
EU SanctionsIranRegulation 267/2012 ยง18 AWGBAFATransit Provider InterLIRPlausible DeniabilityGray Zone

Chapter 1: The Observable Facts

BGP routing data shows the following Iranian-registered prefixes transiting via AS198584 (PIO-Hosting GmbH, Germany):

LIR MaintainerPrefixFirst SeenContact Pattern
lir-ir-salehi-1-MNT91.206.28.0/24June 2026Iranian naming convention
lir-ir-seyeddavood-1-MNT185.43.33.0/24June 2026Iranian naming convention
lir-ir-mazdab-1-MNT91.207.x.0/24June 2026Iranian naming convention
lir-ir-nahor-1-MNTVariousJune 2026Iranian naming convention
InterLIR (Iranian contact)212.102.x.0/24June 2026Marketplace-brokered

The lir-ir- naming convention in RIPE identifies Iranian Local Internet Registries. These are organizations in Iran that have RIPE NCC membership and manage IP address allocations. They are by definition Iranian entities.

All four appeared within the same month โ€” June 2026 โ€” suggesting a bulk onboarding arrangement rather than individual customer acquisitions over time.

The fifth entry (InterLIR) indicates the involvement of an IP address marketplace as a broker โ€” potentially IPXO/InterLIR facilitating the connection between Iranian LIRs and German transit.

๐Ÿ“Ž Source: RIPE BGP data ยท Route announcements via AS198584 ยท RIPE LIR naming conventions ยท RIPEstat routing history

Chapter 2: EU Sanctions Law โ€” What It Actually Says

EU Council Regulation (EC) No 267/2012 (consolidated with amendments through 2026) imposes comprehensive restrictive measures against Iran. The relevant provisions:

Article 23(2):

"No funds or economic resources shall be made available, directly or indirectly, to or for the benefit of [...] natural or legal persons, entities or bodies listed in Annex IX."

Article 1(i) โ€” Definition of "economic resources":

"assets of every kind, whether tangible or intangible, movable or immovable, which are not funds but may be used to obtain funds, goods or services"

Internet transit โ€” bandwidth, routing, connectivity โ€” is an intangible asset that can be used to obtain services. It falls within this definition.

German implementation โ€” AuรŸenwirtschaftsgesetz (AWG) ยง18:

"Whoever willfully violates a directly applicable prohibition [...] shall be punished with imprisonment of not less than one year and not more than ten years."

The critical question: are the Iranian LIRs routing through PIO-Hosting designated entities (listed in Annex IX), or are they private companies not covered by the sanctions regime?

๐Ÿ“Ž Source: EUR-Lex Regulation 267/2012 ยท AWG ยง18 ยท BAFA sanctions guidance

โ“ Are all Iranian companies sanctioned, or only specific ones?

Only entities listed in Annexes VIII and IX of Regulation 267/2012. Not every Iranian company is sanctioned. The sanctions target specific entities connected to nuclear proliferation, IRGC, and designated banks. However, Article 23(3) extends to entities "owned or controlled by" designated persons โ€” and in Iran, the IRGC has economic interests in all major sectors including telecommunications. The question for PIO-Hosting is: did they verify that their Iranian LIR customers are NOT controlled by designated entities? Under EU sanctions compliance, the burden of proof is on the provider.

Chapter 3: Due Diligence โ€” What PIO-Hosting Should Have Done

Under EU sanctions regulations, any entity providing services to potentially sanctioned persons must conduct Know Your Customer (KYC) due diligence. For PIO-Hosting, this would require:

  1. Identify the customer: Determine who controls the Iranian LIR
  2. Screen against sanctions lists: Check EU Consolidated List, OFAC SDN, UN sanctions
  3. Determine beneficial ownership: Identify the natural persons who own/control the entity
  4. Assess the risk: Iranian telecommunications entities have elevated risk due to IRGC involvement
  5. Document the decision: Maintain records of compliance checks

The observable evidence suggests none of this occurred:

  • Bulk onboarding: Four LIRs in one month suggests a marketplace deal, not individual KYC processes
  • No public compliance program: PIO-Hosting's website mentions no sanctions compliance
  • Known bulletproof operation: A company already hosting C2 panels and reputation launderers is unlikely to have a compliance department
  • InterLIR marketplace involvement: Suggests the broker handled the connection, removing PIO from direct customer contact

The German regulator responsible for sanctions enforcement is BAFA (Bundesamt fรผr Wirtschaft und Ausfuhrkontrolle โ€” Federal Office for Economic Affairs and Export Control). They issue specific guidance on due diligence requirements. PIO-Hosting, as a German GmbH, is subject to BAFA oversight.

๐Ÿ“Ž Source: BAFA sanctions compliance guidance ยท EU Best Practices for sanctions implementation ยท AWG compliance requirements

๐Ÿ“– Read Between the Lines

  • The "marketplace" intermediary (InterLIR/IPXO) serves as a compliance buffer. PIO-Hosting can claim: "Our customer is InterLIR (Lithuanian company), not Iranian entities." But Article 23(2) says "directly or indirectly" โ€” the word "indirectly" was included precisely to prevent this kind of layering.
  • The timing (June 2026) coincides with EU-Iran tensions over the nuclear deal. Sanctions enforcement typically tightens during political tensions. Onboarding Iranian customers at this moment is either reckless or deliberate.
  • BAFA's enforcement record for internet services is essentially zero. They focus on physical goods (dual-use technology, weapons components). Digital services โ€” hosting, transit, cloud โ€” exist in an enforcement gap. This isn't because the law doesn't cover them; it's because the regulator hasn't built capacity for this sector.

Chapter 4: Plausible Deniability โ€” Five Layers Between Iran and Germany

The routing path from an Iranian LIR to the public internet passes through:

Iranian LIR (e.g., lir-ir-salehi)
  โ†“ IP blocks registered to Iranian entity
InterLIR Marketplace (Lithuania?)
  โ†“ Broker arranges transit
PIO-Hosting GmbH (Germany, AS198584)
  โ†“ BGP announcement
SkyLink Data Center BV (Netherlands, AS44592)
  โ†“ Upstream transit
Tier-1 carriers โ†’ Internet
    

Each layer provides deniability:

EntityDefense
Iranian LIR"We bought legitimate internet services"
InterLIR marketplace"We're a platform; we don't screen end-users of transit"
PIO-Hosting"Our customer is [marketplace], not Iran"
SkyLink"We provide upstream to PIO; we don't know their customers"
Tier-1 carriers"We peer with SkyLink; due diligence stops at our customer"

Every entity claims the person next to them is responsible. Nobody claims responsibility for the end-to-end chain. This is the distributed irresponsibility that makes internet sanctions enforcement nearly impossible.

๐Ÿ“Ž Source: BGP AS path analysis ยท Transit relationship mapping ยท Sanctions compliance doctrine

โ“ Has any internet company ever been prosecuted under EU Iran sanctions for providing transit?

To our knowledge: no. EU sanctions prosecutions focus on banks (Standard Chartered: $1.1B fine), oil traders, and weapons manufacturers. The digital services sector has avoided prosecution entirely โ€” not because it's compliant, but because regulators lack the technical capacity to trace BGP routing paths and understand the relationship between ASNs, LIRs, and prefix announcements. The infrastructure is opaque by design, and regulators haven't invested in making it transparent.

Chapter 5: The Iranian LIRs โ€” Who Are They?

The lir-ir- naming convention tells us these are RIPE NCC members operating from Iran. But identifying the actual organizations behind the maintainer names requires deeper investigation:

MaintainerName FragmentPossible Entity Type
lir-ir-salehiSalehi (common surname)Individual or small ISP
lir-ir-seyeddavoodSeyed Davood (given name)Individual or family business
lir-ir-mazdabMazdab (company name?)Corporate entity
lir-ir-nahorNahor (name/brand)Unknown

Iranian ISPs and telecoms have complex ownership structures. Major carriers (Iran Telecom, MCI, Irancell) are partially state-owned and have IRGC board members. Smaller ISPs often have opaque ownership that may include IRGC-linked investment funds.

Without comprehensive KYC (which PIO-Hosting evidently didn't perform), it's impossible to determine whether these LIRs are:

  • Scenario A: Legitimate private Iranian businesses needing European connectivity (legal, requires no license)
  • Scenario B: Entities partially owned by IRGC-linked investment vehicles (illegal without specific license from BAFA)
  • Scenario C: Front companies for sanctioned telecommunications infrastructure (criminal offense under ยง18 AWG)

The problem: scenarios B and C look identical to scenario A from the outside. Only comprehensive due diligence can distinguish them. PIO-Hosting's business model makes due diligence unprofitable.

๐Ÿ“Ž Source: RIPE WHOIS ยท Iranian telecommunications sector analysis ยท IRGC economic portfolio research

Chapter 6: The Enforcement Gap โ€” Why Nothing Happens

Germany has robust sanctions enforcement for traditional sectors. BAFA processed 12,000+ export license applications in 2023. The Zoll (customs) intercepts prohibited goods. Banks employ thousands of compliance officers.

But for internet services:

Traditional SectorInternet Sector
Physical goods โ†’ customs inspectionData packets โ†’ no border control
Bank transfer โ†’ SWIFT message (traceable)BGP announcement โ†’ technical (opaque)
Export license โ†’ BAFA applicationTransit agreement โ†’ no licensing required
Shipping records โ†’ paper trailRouting tables โ†’ ephemeral, deletable
Compliance officers โ†’ legally mandatedAbuse contacts โ†’ no legal standard

The regulatory apparatus was built for the physical economy. The digital economy operates in the gap between laws (which cover it) and enforcement (which doesn't reach it).

BAFA has no BGP monitoring capability. They cannot independently verify that a German ASN is routing Iranian traffic. They would need to be told โ€” by a complaint, by intelligence services, or by investigative journalism.

This dossier constitutes such notification.

๐Ÿ“Ž Source: BAFA annual report 2023 ยท German sanctions enforcement statistics ยท AWG implementation analysis

โ“ Could this investigation trigger actual enforcement?

Potentially. Under German law, ยง138 StGB (failure to report planned serious offenses) doesn't apply to sanctions violations specifically. But BAFA accepts anonymous tips and investigates on its own authority. The evidence here โ€” four Iranian LIRs, verifiable BGP data, a known bulletproof operator โ€” meets the threshold for a BAFA inquiry. Whether it leads to prosecution depends on (a) identifying the specific Iranian entities and (b) proving PIO-Hosting knew or should have known about the sanctions risk. Given their broader bulletproof operation, the "should have known" standard is easily met.

Chapter 7: Iran's Internet โ€” The Broader Context

Iran's internet infrastructure is deliberately isolated. The state controls international gateways through the Telecommunication Infrastructure Company (TIC). During protests (2019, 2022), authorities demonstrated they can cut internet access entirely.

Why would Iranian entities need German transit? Several scenarios:

  • Censorship circumvention: VPN/proxy services for Iranian citizens (arguably humanitarian)
  • Sanctions evasion: Iranian companies accessing services that geo-block Iranian IPs
  • Intelligence operations: State-linked actors need infrastructure outside Iranian address space
  • Commercial hosting: Iranian businesses wanting European server locations for latency
  • Cybercrime: Iran-based threat actors (APT33, APT34) using European infrastructure for operations

The moral complexity: the same infrastructure that enables sanctions evasion by IRGC-linked entities might also enable ordinary Iranians to access the uncensored internet. The technology is neutral. The intent determines legality. But PIO-Hosting's customer mix (C2 panels, reputation launderers, bulletproof hosting) suggests they're not in the business of supporting human rights.

๐Ÿ“Ž Source: Freedom House "Freedom on the Net" Iran report ยท CERT-EU threat advisories ยท APT group attribution reports

๐Ÿ“– Read Between the Lines

  • Iran's APT groups (Charming Kitten, OilRig, MuddyWater) consistently need European hosting for their operations. They target European and American organizations from European infrastructure to avoid triggering geographic IP alerts. PIO-Hosting's "no questions asked" model is exactly what an APT needs.
  • The timing (June 2026) follows a pattern: Iranian LIR acquisition spikes during periods of political tension when existing providers quietly terminate Iranian customers. The demand doesn't disappear โ€” it moves to providers who don't ask questions.
  • RIPE NCC's own policies allow Iranian organizations to be members. The question isn't whether Iranians can have RIPE resources (they can), but whether German companies can provide transit to those resources under EU sanctions law.

Chapter 8: What Enforcement Would Look Like

If German authorities chose to enforce:

  1. BAFA inquiry: Request PIO-Hosting's customer records for Iranian-registered prefixes
  2. KYC verification: Demand evidence of sanctions screening for Iranian customers
  3. Company structure investigation: Note that PIO = XSServer = SkyLink (same team, see 026C)
  4. Preliminary assessment: Determine if any Iranian LIR connects to Annex IX entities
  5. If positive: Criminal referral to Staatsanwaltschaft (state prosecution) under ยง18 AWG
  6. Penalties: Up to 10 years imprisonment (individuals), asset seizure, RIPE NCC membership revocation

The practical obstacles:

  • BAFA has never prosecuted an internet transit case
  • Prosecutors would need to understand BGP, RIPE, LIRs โ€” technical knowledge courts lack
  • PIO's shell structure (see 026C) adds jurisdictional complexity
  • The marketplace intermediary provides legal distance

Most likely outcome: BAFA sends a letter. PIO drops the Iranian routes. The LIRs move to another bulletproof provider. The cycle continues.

๐Ÿ“Ž Source: BAFA enforcement procedures ยท AWG prosecution statistics ยท Staatsanwaltschaft jurisdiction

Chapter 9: Series Conclusion โ€” The Structure That Protects Itself

Over six installments, we've traced a path from our honeypot โ€” a single SSH brute-force attempt โ€” to:

  • Two bulletproof ASNs allocated one month apart (026A)
  • A UK shell company with a Turkish director and missing PSC filing (026B)
  • Three German companies sharing a phone number and running gray transit (026C)
  • A $55 million IP marketplace whose co-founder sits on the abuse policy committee (026D)
  • A Panama Papers nominee director controlling IPs from the Seychelles (026E)
  • Four Iranian LIRs routing through German infrastructure with zero sanctions compliance (this dossier)

The structure is not accidental. Every layer exists because the layer below it needs protection and the layer above it needs plausible deniability. Remove any single layer and the system adapts โ€” routes change, nominees rotate, companies re-incorporate.

This is the modern architecture of impunity: not one powerful entity above the law, but dozens of entities, each below the threshold of enforcement attention, collectively enabling operations that no single one of them would be permitted to conduct alone.

The solution requires what the structure prevents: simultaneous, coordinated, multi-jurisdictional action. Until internet governance bodies (RIPE NCC), sanctions regulators (BAFA), corporate transparency enforcers (UK Companies House), and law enforcement (BKA, NCA, Europol) act together โ€” in the same week, against the same network โ€” the phantom ASNs will continue to haunt the internet.

Our honeypot will keep recording. The data will keep accumulating. And when the coordination finally happens, the evidence will be here.

๐Ÿ”ฌ Series Methodology: This six-part investigation combined honeypot forensics (SSH HASSH clustering, SSH key sharing, temporal analysis), deep OSINT enrichment (12 sources including Shodan, AbuseIPDB, GreyNoise, OTX, VirusTotal), corporate registry analysis (UK, Germany, Lithuania, BVI), ICIJ Offshore Leaks Database queries, academic literature review (CAIDA/UCSD 2024), EU sanctions law analysis, BGP routing forensics, passive DNS enrichment, and active reconnaissance (Tor-routed nmap/httpx/nuclei). All findings are sourced and verifiable through public records.
โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Phantom ASN โ€” 6 / 17 Next โ†’