The Phantom ASN Ecosystem โ Part 14 of 16
๐ฑ๐น The Lithuanian Connection
How a Small Baltic Nation Became the IP Address Laundering Capital of Europe
TI-2026-026N | Published June 2026 | ~95 min read
Chapter 1: From Kaunas to Everywhere
Lithuania is a country of 2.8 million people on the Baltic coast, sandwiched between Latvia, Belarus, Poland, and the Russian exclave of Kaliningrad. It's known for basketball, amber, medieval architecture, and โ in a development that would have been unthinkable during the Soviet occupation โ for becoming one of Europe's most aggressive fintech and technology jurisdictions.
Vilnius hosts Revolut's European banking license. Lithuania issued more fintech licenses in 2023 than the rest of the EU combined. The country's pitch is simple: low taxes, fast regulation, English-speaking workforce, EU membership. For legitimate fintech companies, Lithuania is what Ireland was to tech multinationals in the 2000s โ a regulatory gateway to the European market.
But the same attributes that attract legitimate fintech โ light regulation, fast incorporation, EU single market access โ also attract something else. And in Kaunas, Lithuania's second city (population 315,000), a company called IPXO UAB has built what it describes as "the world's first full-stack IP address management marketplace."
IPXO doesn't sell servers. It doesn't host websites. It doesn't carry data traffic. It does something more fundamental: it leases the addresses that make the internet work. And in doing so, it has become a critical node in the infrastructure that enables everything from legitimate cloud computing to bulletproof hosting, from CDN operations to botnet command and control.
๐ IPXO by the Numbers
| Metric | Value | Context |
|---|---|---|
| IPv4 addresses managed | 14 million | ~0.4% of all IPv4 addresses (3.7 billion total) |
| Leases facilitated | 63,000+ | Each lease can cover /24 to /16 blocks (256 to 65,536 IPs) |
| Payouts to IP owners | $55 million | At ~$0.40-0.60/IP/month, consistent with market rates |
| Founded | 2021 (rebrand from Heficed) | Predecessor entities date to ~2015 |
| CEO | Vincentas Grinius | Previously CEO of Heficed/Digital Energy Technologies |
| Headquarters | Kaunas, Lithuania | With entities in Austin TX and London UK |
๐ฎ The Conspirationist Asks
Every good hiding place has two qualities: it must be overlooked by those who seek, and it must be ordinary to those who pass by. Lithuania is both. To the EU, it's a model member state โ fast-growing, digitally ambitious, militarily committed to NATO. To the global internet governance community, it's barely visible โ a small country with a few LIRs and no major internet exchange. To an IP address marketplace operator, it's perfect: EU legitimacy, minimal regulatory friction, and an address โ both physical and digital โ that no one thinks twice about. The Lithuanian connection isn't about Lithuania being corrupt. It's about Lithuania being convenient.
Chapter 2: The Corporate Matryoshka
To understand IPXO, you must first understand what it is not. It is not a single company. It is a corporate matryoshka โ nested entities across multiple jurisdictions, each layer serving a specific purpose in the overall architecture of legal insulation.
Layer 1: IPXO UAB โ The Lithuanian Front
IPXO UAB is the operational entity. UAB (Uลพdaroji Akcinฤ Bendrovฤ) is Lithuania's equivalent of a limited liability company. It's registered in Kaunas, employs the staff, runs the marketplace platform, and handles day-to-day operations. This is the entity that signs contracts with IP address owners and lessees. This is the entity that handles abuse complaints. This is the entity whose ISO 27001 certification gets prominently displayed on the website.
Lithuania was chosen not by accident but by design. Lithuanian corporate law requires minimal capitalization (โฌ2,500 for a UAB), allows single-person boards, imposes no residency requirements on directors, and โ critically โ does not require public disclosure of beneficial ownership beyond what the EU's Anti-Money Laundering Directives mandate. For a company managing 14 million IP addresses, the regulatory burden is lighter than what a food truck operator faces in most EU capitals.
Layer 2: IPXO LLC โ The American Address
IPXO LLC is registered in Austin, Texas. The RDAP records for IPXO-managed IP space list a Dallas address: 3132 State Street, Dallas, TX 75204-3500. Texas LLCs are among the easiest corporate structures in the world to establish โ no operating agreement required, no annual report filing, no requirement to disclose members or managers publicly. An IPXO LLC exists primarily for one purpose: to hold ARIN-delegated IP address resources. ARIN (American Registry for Internet Numbers) requires US or Canadian entities for resource membership. The Texas LLC is the ARIN membership vehicle.
Layer 3: Internet Utilities Europe and Asia Ltd โ The London Mystery
Then there's Internet Utilities Europe and Asia Ltd, registered at Companies House in London (Company No. 12540160). This entity was incorporated on March 18, 2020 โ during the COVID-19 lockdowns. Its registered address is a virtual office in London. Its directors and persons with significant control connect back to the Heficed/IPXO corporate constellation.
Why London? Because RIPE NCC (Rรฉseaux IP Europรฉens Network Coordination Centre) โ the Regional Internet Registry for Europe, the Middle East, and parts of Central Asia โ is headquartered in Amsterdam but operates under Dutch law with English as its working language. A UK entity, despite Brexit, maintains credibility in the European internet governance community. London is where the internet's old money lives โ LINX (London Internet Exchange), the legacy ISPs, the standards bodies. Having a London entity signals establishment credibility that a Kaunas address cannot.
Layer 4: The Heficed Predecessor
Before IPXO, there was Heficed. Before Heficed, there was Digital Energy Technologies Ltd. The corporate lineage is:
Corporate Evolution Timeline
| Year | Entity | Jurisdiction | Activity |
|---|---|---|---|
| ~2015 | Digital Energy Technologies Ltd | UK | VPS/dedicated hosting, IP address management |
| ~2018 | Heficed (rebrand) | Lithuania/UK | Hosting + IP leasing platform launch |
| 2020 | Internet Utilities Europe and Asia Ltd | UK | Incorporated (Companies House 12540160) |
| 2021 | IPXO UAB (rebrand from Heficed) | Lithuania | Full pivot to IP address marketplace |
| 2021+ | IPXO LLC | Texas, USA | ARIN membership vehicle |
Each rebrand coincided with a shift in business model โ and a distancing from the abuse reports associated with the previous brand name. Digital Energy Technologies accumulated hosting abuse reports. Heficed accumulated IP leasing abuse reports. IPXO launched as the "clean" marketplace brand, leaving the accumulated negative reputation of Heficed behind while maintaining the same infrastructure, the same people, and the same IP address blocks.
๐ด Finding: Multi-Jurisdictional Insulation Architecture
The IPXO corporate structure spans at minimum four jurisdictions (Lithuania, USA, UK, and through lessee relationships, dozens more). This is not unusual for a technology company, but the specific pattern โ Lithuanian operations, US registry vehicle, UK governance credibility, serial rebranding โ creates a structure where no single regulator has complete oversight. Lithuania's Communications Regulatory Authority (RRT) sees the operations. ARIN sees the American entity. Companies House sees the UK shell. None of them sees the complete picture. This is a feature, not a bug.
Confidence: HIGH โ Based on corporate registry records, RDAP data, and documented rebrand timeline.
๐ฎ The Conspirationist Asks
There is a pattern in the internet infrastructure industry that goes like this: a company accumulates abuse reports under Brand A. It creates Brand B as a "marketplace" or "platform" entity. It transfers the operations, the staff, and the IP address blocks to Brand B. Brand B has no abuse history. Brand A is quietly dissolved or left dormant. The abuse reports associated with Brand A become historical curiosities, findable only by researchers who know to look. The customers of Brand B, when they Google the company, find a clean record. This is not fraud. It's not even deception, strictly speaking โ the company genuinely is new. What it is, precisely, is reputation laundering. The product hasn't changed. The management hasn't changed. The IP blocks haven't changed. Only the name has changed. And that's enough, because search engines don't track corporate genealogy.
Chapter 3: The Man From Heficed
Vincentas Grinius is the CEO and co-founder of IPXO. His LinkedIn describes him as a serial entrepreneur in the internet infrastructure space. He previously led Heficed and Digital Energy Technologies. He sits on RIPE NCC committees. He speaks at industry events. He has been quoted in press releases announcing IPXO's funding rounds and milestones.
Let's examine what is publicly known about the man behind 14 million IP addresses.
The Public Profile
Grinius presents himself as a technologist turned entrepreneur. His career arc follows a pattern common in Eastern European tech: technical education, early work in hosting/infrastructure, followed by a pivot to IP address management as the IPv4 exhaustion crisis made existing address blocks valuable assets. His LinkedIn shows connections across the Baltic tech ecosystem โ Kaunas-based companies, Lithuanian tech accelerators, and the broader European hosting community.
He has been active in RIPE NCC governance. RIPE NCC is a member-based organization; any entity holding IP address resources in the RIPE region can participate in its governance. This means that the person whose companies lease IP addresses to customers โ including customers who attack honeypots โ also participates in setting the policies that govern how those IP addresses are allocated and managed.
The Governance Problem
This is not corruption. It is structural conflict of interest. The same dynamic exists across internet governance: the people who build the infrastructure also set its rules. The Internet Engineering Task Force (IETF) is dominated by engineers from the companies whose products implement the standards. RIPE NCC's governance is dominated by the LIRs (Local Internet Registries) who hold the resources. ARIN's governance is dominated by US ISPs and hosting companies.
But there's a difference between a large ISP like Deutsche Telekom sitting on RIPE governance (inevitable, given their resource holdings) and an IP address marketplace operator whose business model depends on fluidity of resource transfers sitting on governance. Deutsche Telekom wants stable, long-term allocations. An IP marketplace wants flexibility, easy transfers, and minimal oversight of how leased addresses are used. Their governance incentives point in opposite directions.
๐ RIPE NCC Governance & IP Leasing Conflict
RIPE NCC's Transfer Policy (RIPE-786) governs how IP address resources can be transferred between organizations. The policy was designed for permanent transfers โ ISP A sells its address block to ISP B. IP leasing platforms like IPXO operate in a grey area: they don't permanently transfer addresses, they temporarily delegate them. This delegation uses RIPE database objects (route objects, inetnum objects) to authorize BGP announcements, but the underlying allocation remains with the original holder.
The governance question is: should RIPE NCC require the same due diligence for temporary delegations as for permanent transfers? The IP leasing industry's answer is no โ that would add friction and reduce marketplace velocity. The security community's answer is yes โ because a temporarily delegated IP address used for botnet C&C is just as dangerous as a permanently transferred one.
Vincentas Grinius participates in the governance structure that determines which answer prevails. He has a direct financial interest in the outcome. This is documented, public, and legal. It is also a textbook case of regulatory capture.
๐ฎ The Conspirationist Asks
The history of internet governance is the history of managed conflicts of interest. The same people who build the protocols sit on the standards bodies that standardize them. The same companies that profit from address scarcity sit on the registries that manage address allocation. This is not a scandal โ it's the architecture. The question is never "does conflict of interest exist?" (it always does) but rather "is the conflict managed transparently?" In the case of IP leasing and RIPE governance, the answer is: barely. There are no public recusal policies for RIPE NCC governance participants who have commercial interests in the topics being discussed. There is no register of interests. There is no requirement to declare potential conflicts before voting or contributing to consensus. The system relies on trust and good faith. In a community of 20,000 members managing $150+ billion in IP address assets, this is perhaps... optimistic.
Chapter 4: Heficed โ IPXO โ The Rebrand That Changed Nothing
In 2021, Heficed became IPXO. The press releases spoke of "a new chapter," "marketplace innovation," and "IP address lifecycle management." The reality was simpler: the Heficed brand had accumulated too much baggage.
The Heficed Era
Heficed operated as both a hosting provider and an IP address leasing platform. This combination was problematic. As a hosting provider, Heficed operated servers, managed infrastructure, and dealt with abuse complaints about content hosted on those servers. As an IP address lessor, Heficed leased address blocks to other hosting providers, who then hosted their own content โ and generated their own abuse.
The dual role created a convenient ambiguity. When abuse was reported on a Heficed IP, the response could be: "We don't host that content โ we leased the address to another provider. Contact them." When the other provider was contacted, their response could be: "The address isn't ours โ it's leased from Heficed. Contact them." The abuse report circulated between two entities, neither claiming responsibility, until the reporter gave up.
This pattern โ known in the industry as "abuse report ping-pong" โ is not unique to Heficed. It's endemic in the IP leasing market. But Heficed's scale made it more visible than most. By 2020, Heficed appeared regularly on abuse tracking databases. The brand was, in industry terms, "burned."
The Clean Slate Maneuver
The IPXO rebrand solved this problem entirely. A new company name. A new website. New marketing materials. New press coverage. The Google search results for "IPXO abuse" in 2021 returned zero relevant results. The Google search results for "Heficed abuse" returned thousands. Same company. Same people. Same IP blocks. Different searchability.
๐ด Finding: Brand Discontinuity as Abuse History Erasure
The Heficed โ IPXO rebrand demonstrates a structural weakness in internet governance: abuse reputation is tied to brand names, not to underlying infrastructure or personnel. When Heficed became IPXO, every abuse database, every blocklist maintainer, every security researcher who had flagged Heficed had to start from scratch with IPXO. The IP address blocks remained the same. The BGP announcements remained the same. The RIPE database objects remained the same. But the human-readable identifier โ the name that researchers search for, that appears in abuse reports, that gets discussed on mailing lists โ reset to zero.
This is not an IPXO-specific problem. It is a systemic vulnerability in how the internet governance community tracks and responds to abuse. Any organization can rebrand. No mechanism exists to transfer abuse reputation across corporate rebrands.
Confidence: HIGH โ Based on documented rebrand timeline, public archive searches, and confirmed continuity of IP address resources.
What Changed โ and What Didn't
| Aspect | Changed? | Details |
|---|---|---|
| Company name | โ Yes | Heficed โ IPXO |
| CEO | โ No | Vincentas Grinius remained |
| Core team | โ No | Key staff transferred |
| IP address blocks | โ No | Same RIPE allocations |
| RIPE LIR membership | โ No | Same ORG-IL687-RIPE |
| Business model | โ ๏ธ Partial | Hosting deprecated, marketplace emphasized |
| Customer base | โ No | Existing lessees continued |
| Abuse response SLA | โ No | Same 24-hour target |
| Brand reputation | โ Reset | Clean search results |
| Abuse history | โ Erased | Historical reports not transferred |
๐ฎ The Conspirationist Asks
Chapter 5: The IP Leasing Machine
To understand why IPXO matters for threat intelligence, you need to understand the mechanics of IP address leasing โ and why it's the perfect vehicle for enabling abuse while maintaining plausible deniability.
How IP Leasing Works
An IP address lease, in simplified terms, works like this:
IP Address Leasing Flow
- The Owner holds a block of IP addresses (e.g., a /16 = 65,536 addresses) allocated by a Regional Internet Registry (RIR). These addresses were historically free; today they trade at $40-55/address on the transfer market.
- The Marketplace (IPXO) connects owners with lessees. The owner lists their unused blocks on the platform. IPXO handles the technical mechanics of delegation.
- The Lessee requests a block of addresses for a specified period. They might be an ISP, a hosting company, a CDN, or โ and here's the problem โ a bulletproof hosting operation, a spammer, or a botnet operator.
- The Delegation happens via RIPE database objects. The owner (or IPXO on their behalf) creates route objects and inetnum objects that authorize the lessee's ASN to announce the addresses. This is a database change, not a physical transfer โ the addresses don't move anywhere. What moves is the authorization to announce them.
- The Revenue flows: lessee pays IPXO, IPXO takes a commission (industry standard: 10-20%), IPXO pays the owner.
The Due Diligence Problem
IPXO claims to perform due diligence on lessees. Its website mentions "IP abuse prevention" and "reputation monitoring." But the fundamental tension is this: thoroughness slows velocity, and velocity is revenue.
If IPXO processes 63,000 leases, each requiring genuine due diligence โ background checks on the lessee, verification of use case, monitoring of announced routes, analysis of traffic patterns โ the operational cost would be enormous. A single compliance analyst can handle perhaps 10-20 thorough reviews per day. At 63,000 leases, that's 3,150-6,300 analyst-days, or 12-25 full-time compliance staff working every business day of the year, assuming each lease needs only one review.
But leases aren't static. They need ongoing monitoring. A lessee who passes initial due diligence can start using the addresses for abuse the day after the check. Continuous monitoring of 14 million addresses for abuse indicators would require a security operations center rivaling those of major ISPs โ an investment that would wipe out the margins of a marketplace business model.
The HBING Connection
Here's where IPXO's due diligence claims meet our honeypot data. Consider AS208949 โ HBING LIMITED, registered in the UK:
๐ด Finding: IPXO as Abuse Contact for Bulletproof ASN
Our honeypot recorded 5 IPs from AS208949 (HBING LIMITED), all with threat scores of 78-93 and abuse scores of 100%. All 5 IPs geolocate to the Netherlands. The RDAP abuse contact for two of these IPs is support@ipxo.com โ IPXO's own support email, listed as the "IPXO Incident Response Team." The other three IPs list abuse.webltd@gmail.com โ a Gmail address associated with "IT WEB LTD" registered in the British Virgin Islands.
AS208949 is flagged as bulletproof in our intelligence database with a risk score of 95.26 out of 100. Every single IP we've observed from this ASN has a 100% abuse score on AbuseIPDB. This ASN's 10 announced prefixes include ranges from Africa (102.129.x.x), Europe (45.x.x.x, 93.x.x.x, 185.x.x.x, 193.x.x.x, 195.x.x.x), and various other ranges โ a geographic dispersion that suggests acquired rather than allocated address space.
Confidence: HIGH โ Direct evidence from honeypot, RDAP, BGP, and AbuseIPDB data.
Let's break down what the data shows:
| IP Address | Threat | Abuse | Hits | RDAP Org | Abuse Contact | AbuseIPDB ISP |
|---|---|---|---|---|---|---|
102.129.200.117 | 93 | 100% | 42 | IPXO Incident Response Team | support@ipxo.com | Digital Energy Technologies Ltd |
102.129.200.101 | 88 | 100% | 24 | IPXO Incident Response Team | support@ipxo.com | Digital Energy Technologies Ltd |
45.88.0.252 | 83 | 100% | 30 | lir-vg-itweb-1-MNT | abuse.webltd@gmail.com | IT WEB LTD |
45.148.146.52 | 79 | 100% | 36 | lir-vg-itweb-1-MNT | abuse.webltd@gmail.com | IT WEB LTD |
45.148.145.60 | 78 | 100% | 36 | lir-vg-itweb-1-MNT | abuse.webltd@gmail.com | IT WEB LTD |
The Geography Discrepancy
Notice something critical: all 5 IPs geolocate to the Netherlands. But the registrant data tells a different story:
- RDAP country for
102.129.200.x: US (registered via IPXO's Dallas address) - RDAP country for
45.88.0.252: Poland - RDAP country for
45.148.146.52: Poland - RDAP country for
45.148.145.60: Belgium - ASN registration country: United Kingdom
- Actual geolocation: Netherlands
Five countries involved โ US, Poland, Belgium, UK, Netherlands โ and the corporate entities span Lithuania, Texas, British Virgin Islands, and London. This is not a network. This is a jurisdictional labyrinth.
๐ The Digital Energy Technologies Persistence
AbuseIPDB identifies the ISP for the 102.129.200.x range as "Digital Energy Technologies Limited" โ the pre-Heficed corporate entity. This means that even after two rebrands (Digital Energy โ Heficed โ IPXO), the underlying infrastructure still carries fingerprints of the original entity in third-party databases. The IPXO rebrand cleaned the company website and press coverage, but it couldn't clean AbuseIPDB, Shodan, or other databases that crawl and index network infrastructure independently of corporate marketing.
The IT WEB LTD / BVI Connection
Three of the five HBING IPs list their RDAP organization as lir-vg-itweb-1-MNT, with the abuse email abuse.webltd@gmail.com and a phone number +14708099233 (a US number, area code 470 = Atlanta, Georgia). The entity "IT WEB LTD" is registered in the British Virgin Islands.
The BVI is the world's most popular offshore incorporation jurisdiction, with more registered companies than residents. BVI corporate registrations do not require disclosure of beneficial ownership, directors, or financial statements. A BVI company operating IP address resources through a UK-registered ASN, managed via IPXO's Lithuanian platform, with addresses geolocating to the Netherlands โ this is jurisdictional complexity that serves no legitimate technical purpose.
๐ The IT WEB LTD Footprint
Searching our threat intelligence database for abuse.webltd@gmail.com reveals 7 IPs across 3 ASNs, all geolocating to the Netherlands:
| ASN | Name | Country | Risk Score | Bulletproof? | IPs |
|---|---|---|---|---|---|
| 208949 | HBING LIMITED | GB | 95.26 | โ Yes | 3 |
| 215224 | NovoServe B.V. | NL | 88.79 | โ Yes | 3 |
| 200313 | IT WEB LTD | VG | 1.2 | โ No | 1 |
A single Gmail address connects a BVI shell company to two bulletproof ASNs (combined risk scores: 95 and 89) and its own low-risk ASN. The Gmail address โ not a corporate domain โ as the abuse contact for IP addresses serving 7 attackers suggests that abuse handling is not a priority. This is infrastructure designed to appear managed while being effectively unaccountable.
๐ฎ The Conspirationist Asks
abuse.webltd@gmail.com becomes too well-known to blocklist operators, a new Gmail address can be created in 30 seconds.The IP leasing market has created what economists call a "moral hazard" โ a situation where one party can take risks because another party bears the consequences. The IP address owner collects lease payments while IPXO handles compliance. IPXO collects commissions while the lessees handle operations. The lessees operate bulletproof networks while law enforcement struggles to identify who is responsible. At each layer, the entity closest to the abuse has the least liability, and the entity with the most liability has the least knowledge of the abuse. This isn't a design flaw. This is the design. The IP leasing market works precisely because it distributes responsibility until no single entity bears enough of it to trigger enforcement action. IPXO didn't invent this structure. But IPXO, managing 14 million addresses and 63,000 leases, has scaled it to a degree that makes it a systemic risk to internet security governance.
Chapter 6: The RIPE Committee Problem
RIPE NCC is not a regulator. This fact โ stated repeatedly by RIPE NCC itself โ is the foundation of both its strength and its vulnerability. RIPE NCC is a registry: it records who holds what IP addresses, maintains the technical databases that make internet routing work, and facilitates community governance of numbering resources. It does not police how those resources are used.
This distinction matters enormously for the IP leasing market. If RIPE NCC were a regulator, it could revoke allocations from entities that facilitated abuse. It could impose due diligence requirements on resource transfers. It could audit marketplace operators like IPXO. But as a registry, it does none of these things โ because its community has not reached consensus that it should.
The Governance Structure
RIPE NCC governance operates through several mechanisms:
RIPE NCC Governance Layers
| Body | Function | Composition |
|---|---|---|
| General Meeting | Sets overall direction, elects board | All 20,000+ members can participate |
| Executive Board | Strategic oversight | Elected members (typically 7-9) |
| Working Groups | Policy development | Self-selecting, open to all participants |
| RIPE NCC Staff | Operations | ~350 employees (Amsterdam HQ) |
The critical layer is the Working Groups. This is where IP address allocation policy, transfer policy, and abuse handling guidelines are developed. Working groups are open โ anyone can participate. They operate on "rough consensus" โ no formal voting, but rather the chairs' assessment of the room's opinion.
This openness is both RIPE's greatest democratic achievement and its greatest vulnerability to capture. When an IP leasing marketplace operator participates consistently in working groups that discuss transfer policy, their voice carries weight not because of a formal vote but because of persistent presence. Most RIPE members โ small ISPs, university networks, research institutes โ don't have the resources or interest to participate in policy discussions about IP address markets. The marketplace operators do. Their livelihoods depend on the outcomes.
The Specific Policy Gap
RIPE's Transfer Policy (RIPE-786) governs permanent transfers of IP address resources. It requires documentation, verification of the receiving entity's need, and a cooling-off period. These requirements exist because permanent transfers were identified as a vector for address space fraud.
But IP leasing โ temporary delegation of address usage rights โ operates largely outside this policy framework. A temporary delegation doesn't trigger transfer policy requirements because technically, no transfer occurs. The addresses remain allocated to the original holder. What changes is the routing authorization โ the RIPE database objects that tell the global routing system "this ASN is authorized to announce this prefix."
This policy gap means that IPXO can facilitate thousands of temporary delegations per month with zero RIPE NCC oversight of the individual transactions. The only point of governance contact is the RIPE member agreement itself, which requires members to maintain accurate database records. Whether a member is leasing its addresses to bulletproof operators or legitimate cloud providers is, from RIPE NCC's perspective, outside its mandate.
๐ด Finding: Regulatory Gap in Temporary IP Address Delegations
RIPE NCC's policy framework creates a two-tier system: permanent transfers are subject to due diligence and verification; temporary delegations (leases) are not. IPXO's business model โ leasing 14 million addresses via 63,000 temporary delegations โ operates entirely in the unregulated tier. The IP leasing industry benefits from this gap. Members of the IP leasing industry participate in the governance process that would need to close it. The gap has existed since IP leasing became a significant market (~2017-2018). No policy proposal to subject temporary delegations to transfer-equivalent oversight has reached consensus.
Confidence: HIGH โ Based on RIPE policy documentation, governance structure analysis, and observable policy gap.
๐ฎ The Conspirationist Asks
Chapter 7: The ISO 27001 Shield
IPXO holds ISO 27001 certification. This is prominently displayed on its website, referenced in press releases, and cited in response to questions about security and due diligence. ISO 27001 has become the cybersecurity equivalent of a doctor's diploma on the wall โ it signals competence to non-experts and provides comfort to business partners who lack the ability to independently assess security practices.
But ISO 27001 does not certify what most people think it certifies.
What ISO 27001 Actually Certifies
ISO 27001 certifies that an organization has an Information Security Management System (ISMS). Specifically, it certifies that:
- The organization has identified its information security risks
- The organization has documented policies and procedures to manage those risks
- The organization has implemented controls from Annex A (a menu of 114 possible controls)
- The organization conducts internal audits and management reviews
- The organization pursues continuous improvement
What ISO 27001 does not certify:
- That the organization's products or services are secure
- That the organization's customers are legitimate
- That the organization's IP addresses are not being used for abuse
- That the organization's due diligence on lessees is effective
- That the organization's abuse response is timely or adequate
- That the organization is not facilitating cybercrime through its marketplace
The critical distinction: ISO 27001 certifies process, not outcomes. You can have a perfectly certified ISMS that documents, reviews, and continuously improves a due diligence process that is fundamentally inadequate. As long as the process exists, is documented, is reviewed, and is improved (even marginally), the certification holds.
The Certification Scope Question
Every ISO 27001 certification has a defined scope โ the specific processes, systems, and services covered by the certification. The scope statement determines what the auditor examines. What falls outside the scope is not assessed.
For an IP address marketplace, the relevant question is: does the certification scope include lessee due diligence? If the scope is "management of the IPXO marketplace platform" โ the servers, the databases, the internal processes โ then the certification means IPXO keeps its own systems secure. It says nothing about whether the IP addresses flowing through the marketplace are used securely by the lessees.
This is like certifying that a gun shop has excellent inventory management while saying nothing about whether it performs background checks on buyers.
๐ The Certification Gap Analysis
| What ISO 27001 Covers | What It Doesn't Cover |
|---|---|
| IPXO's internal network security | How leased IPs are used by customers |
| Employee access controls | Customer vetting effectiveness |
| Data backup and recovery | Whether abuse reports are actually resolved |
| Incident management procedures | Whether bulletproof operators are screened out |
| Physical security of offices | Geographic accuracy of RIPE database objects |
| Change management processes | Whether leased addresses facilitate cybercrime |
๐ฎ The Conspirationist Asks
Certifications are a language. They communicate trustworthiness in a world too complex for individual verification. When you see a pilot's license, you trust that the pilot can fly. When you see an ISO 27001 badge, you trust that the organization manages security responsibly. But the analogy breaks down in a critical way: a pilot's license certifies the ability to do a specific, dangerous thing safely. ISO 27001 certifies the existence of a management system โ not the effectiveness of that system in preventing specific harms. A company can be ISO 27001 certified and simultaneously facilitate massive cybercrime through its IP leasing marketplace, provided its internal processes for doing so are properly documented, reviewed, and continuously improved. The certification doesn't prevent harm. It certifies the documentation of the process that causes harm. This is not a flaw in ISO 27001. It's a flaw in how ISO 27001 is interpreted โ and the interpretation gap is actively exploited by entities whose business models benefit from the appearance of compliance without its substance.
Chapter 8: The PIO-HBING Pipeline โ When Leased IPs Attack
The theory is one thing. The evidence is another. Let's look at what our honeypot actually recorded from IP addresses connected to the IPXO ecosystem.
The HBING Network in Detail
AS208949 (HBING LIMITED) is a UK-registered company (Companies House 13836998) with its registered address at 124 City Road, London, EC1V 2NX โ a generic company formation agency address used by thousands of shell and nominee companies. Its RIPE record was created on April 2, 2023, making it barely three years old. Its abuse contact is hbinglimited@mail.com โ a free email address from mail.com, which is itself a significant indicator.
HBING LIMITED announces 10 IPv4 prefixes via BGP โ a modest network, but the prefixes reveal something interesting:
๐ HBING LIMITED BGP Announcements
| Prefix | Region Origin | Notes |
|---|---|---|
102.129.200.0/24 | Africa (AFRINIC) | IPXO as abuse contact |
102.165.51.0/24 | Africa (AFRINIC) | African IP space via UK company |
45.88.0.0/24 | RIPE (Netherlands) | IT WEB LTD (BVI) as registrant |
45.148.145.0/24 | RIPE (Belgium/NL) | IT WEB LTD (BVI) as registrant |
45.148.146.0/24 | RIPE (Poland/NL) | IT WEB LTD (BVI) as registrant |
93.113.203.0/24 | RIPE | European allocation |
185.114.146.0/23 | RIPE | European allocation (/23 = 512 IPs) |
192.101.68.0/24 | ARIN (legacy) | American legacy space |
193.151.109.0/24 | RIPE | European allocation |
195.211.191.0/24 | RIPE | European allocation |
A UK company, three years old, announcing IP space from Africa, Europe, and North America โ regions governed by three different RIRs (AFRINIC, RIPE, ARIN). This is not how a legitimate ISP operates. Legitimate ISPs typically have IP allocations from their home region's RIR. Acquiring address space from three different RIRs suggests systematic purchase or lease of address blocks on the secondary market โ exactly the kind of activity that IP leasing marketplaces like IPXO facilitate.
The Hitrow Discovery
Our active reconnaissance scans of HBING infrastructure revealed something unexpected. The IP 102.129.200.117 โ our highest-threat HBING node (threat score 93) โ runs a web server on ports 80 and 8080 serving software called Hitrow 1.1.43, with the page title "Welcome to Hitrow."
Hitrow is not a household name. It appears to be a control panel or management interface for IP-based services. Its presence on an IP that attacked our honeypot 42 times suggests that this is not a compromised residential router or a misconfigured cloud instance โ this is purpose-built infrastructure for IP-based operations.
๐ Active Recon: HBING Infrastructure
| IP | Port | Service | Product |
|---|---|---|---|
102.129.200.117 | 22 | SSH | (standard) |
102.129.200.117 | 80 | HTTP | Hitrow 1.1.43 |
102.129.200.117 | 8080 | HTTP | Hitrow 1.1.43 |
The Passive DNS Trail
Passive DNS resolution for the HBING IPs reveals hostnames that add another layer to the story:
102.129.200.117โclient.nodomain.vip,mag-tv.net,vodnew.nodomain.vip45.88.0.252โs120.likea8bitboss.xyz45.148.145.60โ45-148-145-60.ipv4.staticdns1.io
The domains tell a story: nodomain.vip is a domain parking service. mag-tv.net and vodnew.nodomain.vip suggest IPTV or streaming content โ a common use case for IP addresses leased to avoid geolocation enforcement. likea8bitboss.xyz is a domain name that doesn't inspire confidence in legitimate business operations. staticdns1.io is a generic reverse DNS service used by hosting providers who haven't configured proper PTR records.
The libssh2 Fingerprint
All five HBING IPs share the same SSH client fingerprint: HASSH 14b2ddda386a4d10, identified as libssh2_1.11.0. This fingerprint appears in our database across 628 IPs in 48 countries โ it's part of a massive scanning campaign using the libssh2 library.
The shared fingerprint means one of two things: either all five HBING IPs are using the same scanning toolkit (suggesting central coordination), or the HBING infrastructure was compromised and co-opted into a larger botnet. Given that the IPs run Hitrow management panels and share the same corporate infrastructure, central coordination is the more parsimonious explanation.
๐ด Finding: HBING as Coordinated Attack Platform
Five IPs, all on the same bulletproof ASN (risk 95/100), all sharing the same scanning fingerprint (libssh2_1.11.0), all geolocating to the Netherlands despite registrations in 5 different countries, all with 100% AbuseIPDB confidence scores, some running Hitrow management panels, some resolving to IPTV-related hostnames, and all linked to either IPXO or IT WEB LTD (BVI) โ this is not accidental misconfiguration. This is a coordinated scanning and credential-testing platform operating through IPXO-managed IP address space.
The 168 attacks on our honeypot over 25 days represent one honeypot's view. If this scanning operation targets the entire IPv4 space (as the 48-country campaign membership suggests), the total attack volume from this infrastructure runs to millions of attempts per day.
Confidence: HIGH โ Direct evidence from honeypot data, RDAP, BGP routing, active recon, and passive DNS.
๐ฎ The Conspirationist Asks
There's a thought experiment that clarifies the IPXO-HBING relationship. Imagine you own a parking garage. A customer rents a space every month. You notice that the customer's car always has fresh scratches, that its license plates change frequently, and that its registration traces to a company at a mail-forwarding address in the British Virgin Islands. Other tenants complain about break-ins near the customer's space. You receive letters from the police asking about the car. You continue renting the space and collecting the monthly payment. Now: are you responsible for what the customer does with the car? Most people would say no โ you rent spaces, not supervise driving. But if you also volunteered to be the contact person for traffic violations โ if you told the authorities "report any problems to me, I'll handle it" โ then the calculation changes. By accepting the abuse contact role, IPXO moved from passive landlord to active intermediary. The question is whether the intermediation is genuine (they actually try to resolve abuse) or performative (the contact role exists to absorb reports without acting on them). Our honeypot data โ 168 attacks over 25 days with no apparent mitigation โ suggests the latter.
Chapter 9: The Numbers That Matter
Let's talk money. The IP address market is one of the internet's most opaque financial ecosystems, but enough data exists to reconstruct the economics โ and they are staggering.
The IPv4 Exhaustion Premium
IPv4 address exhaustion is, by any measure, one of the most foreseeable infrastructure crises in computing history. Engineers have been warning about it since the early 1990s. IPv6 was designed specifically to solve it. The exhaustion timeline was:
๐ IPv4 Exhaustion Timeline
| Registry | Exhaustion Date | Region |
|---|---|---|
| IANA | January 31, 2011 | Central pool |
| APNIC | April 15, 2011 | Asia-Pacific |
| LACNIC | June 10, 2014 | Latin America |
| ARIN | September 24, 2015 | North America |
| AFRINIC | April 21, 2017 | Africa |
| RIPE NCC | November 25, 2019 | Europe/Middle East |
Source: IANA records, verified via Wikipedia IPv4 address exhaustion.
After exhaustion, new allocations effectively stopped (only tiny fragments remain). Any organization needing IPv4 addresses must now acquire them on the secondary market โ through purchases or leases. This transformed IPv4 addresses from free administrative resources into tradeable financial assets.
The Price History
The price trajectory tells the story of a market bubble and its partial deflation:
| Year | Avg Transfer Price/IP | Avg Lease Price/IP/month | Market Event |
|---|---|---|---|
| 2018 | $18 | $0.45 | Early market formation |
| 2019 | $24 | $0.50 | RIPE NCC exhaustion |
| 2020 | $28 | $0.55 | COVID demand surge |
| 2021 | $45 | $0.60 | Peak speculation; IPXO launches |
| 2022 | $48 | $0.60 | Market peak |
| 2023 | $41 | $0.50 | Hyperscaler pullback begins |
| 2024 | $34 | $0.43 | Large-block price erosion |
| 2025 | $25 | $0.40 | 58M addresses transferred (record) |
| 2026 | $11-20 | $0.35 | Current market |
Sources: IPXO Market Stats (June 18, 2026), Brander Group market analysis.
IPXO's Revenue Model
IPXO's revenue comes from commissions on leases. With approximately 6 million IPs actively leased on the platform at ~$0.35/IP/month, the gross lease revenue flowing through the platform is approximately:
This is conservative. It doesn't include IPAM (IP Address Management) software fees, premium services, or revenue from the transfer brokerage side of the business. The $55M "paid to IP owners" figure, spread over approximately 4 years of operation, is consistent with this revenue model (the commission sits on top of the $55M).
The Global Market
IPXO is the largest player, but the total IP leasing market is bigger. Academic research (CAIDA, 2024) found that 4.1% of all advertised IPv4 prefixes are leased โ approximately 45+ million IP addresses. At current lease rates:
๐ The Global IP Leasing Economy
45 million IPs ร $0.35/IP/month ร 12 months = ~$189 million/year
This is the minimum estimate for the global IP leasing market. The actual figure is higher because: (a) not all leases are detected by academic crawlers, (b) short-term leases can command premium rates ($0.50-1.00/IP/month), and (c) private/off-platform leases are invisible to researchers. A reasonable estimate for the total addressable market: $200-300 million per year in lease revenue alone, plus $1-2 billion in transfer transactions.
For context: this market barely existed before 2015. IPv4 exhaustion created an asset class from nothing โ and the companies that positioned themselves as marketplace operators captured the most valuable position in the value chain.
Who Pays for Abuse?
Here's the critical economic insight: the costs of IP address abuse are externalized. The IP owner earns lease income. IPXO earns commission. The lessee earns whatever revenue their operations generate (legitimate or otherwise). But the costs โ abuse reports, blocklisting, credential theft, botnet damage โ are borne by the targets of the abuse, by ISPs who process abuse reports, by security researchers who track the threats, and by the internet community at large.
This is a textbook negative externality. The IP leasing market generates private profits while imposing public costs. No mechanism exists to price the externality โ there's no "pollution tax" on IP address abuse. The closest equivalent, Spamhaus blocklisting, imposes costs on the IP owner (reduced reputation of their address block) but does not impose costs on the marketplace operator (IPXO's platform reputation is separate from the reputation of individual leased blocks).
๐ฎ The Conspirationist Asks
Follow the money and you arrive at a paradox. IPXO's business model is optimized for a world where IPv4 addresses are scarce, demand is high, and compliance overhead is low. Everything that increases demand โ including demand from abusive operators โ increases IPXO's revenue. Everything that decreases abuse โ stricter screening, slower onboarding, aggressive lessee monitoring โ increases IPXO's costs while reducing its addressable market. The economic incentives point, with mechanical precision, toward permissive due diligence. Not because IPXO wants to facilitate abuse, but because the market rewards it. This is not a moral judgment. It is a structural observation. The IP leasing market, as currently designed, rewards exactly the behavior that the security community deplores. No amount of ISO 27001 certification, no number of blog posts about "how IPXO handles abuse," no RIPE governance participation changes this fundamental economic reality. The incentives are the incentives. And until the externality is priced โ until the costs of abuse are borne by those who profit from enabling it โ the behavior will continue.
Chapter 10: The Uncomfortable Questions
Every dossier in this series arrives at a point where the evidence demands questions that polite industry discourse avoids. The Lithuanian Connection is no different. The evidence has been presented. The corporate structures have been mapped. The honeypot data has been analyzed. Now we ask the questions that matter.
๐ฎ The Big Questions
The uncomfortable truth about the Lithuanian connection is that it works because everything is legal. Lithuanian incorporation: legal. UK shell companies: legal. BVI entities: legal. IP address leasing: legal. RIPE database manipulation: technically compliant with policy. Abuse report handling (or non-handling): not subject to enforceable standards. Every component of the system is individually lawful. It is only when you assemble the components โ Lithuanian operations, UK credibility, BVI opacity, RIPE permissiveness, marketplace commission incentives, ISO 27001 cover, serial rebranding โ that the pattern becomes visible. And the pattern is this: the IP leasing market has created a legally compliant mechanism for distributing internet resources to operators who use them for attacks. No law is broken. No regulation is violated. No enforcement action is possible under current frameworks. The attackers hitting our honeypot did so from infrastructure that is, by every formal measure, legitimately operated. The system works exactly as designed. It's just that the design serves the marketplace operators, not the internet community.
Chapter 11: Final Assessment โ The Architecture of Plausible Deniability
This dossier has traced a single thread โ IPXO UAB and its role in the IP address leasing ecosystem โ from a Kaunas office to our honeypot's log files. The journey passed through corporate structures spanning five jurisdictions, governance bodies whose policies are shaped by the entities they govern, certification frameworks that certify process but not outcomes, and an economic model where abuse is a revenue driver disguised as a compliance problem.
What We Found
โ๏ธ Strategic Findings
Finding 1: IPXO is the largest IP address marketplace on Earth, and its abuse controls are demonstrably inadequate.
Managing 14 million IPv4 addresses (~0.4% of the entire usable IPv4 space) through 63,000+ leases, IPXO has achieved market dominance. But our honeypot data shows IPXO-managed addresses (specifically, addresses where IPXO is the named abuse contact) participating in sustained scanning campaigns from a bulletproof ASN with a 95/100 risk score. IPXO's own disclosure acknowledges "nearly 100" Spamhaus listings at peak. Academic research confirms that leased IP space is 5ร more likely to encounter abuse. The conclusion is inescapable: IPXO's due diligence and abuse response capabilities do not scale with its marketplace volume.
Finding 2: The corporate structure is designed for insulation, not transparency.
Lithuanian operations (low cost, light regulation) + UK entity (RIPE credibility, establishment legitimacy) + Texas LLC (ARIN access) + BVI connections (via customers like IT WEB LTD) = a jurisdictional architecture where no single regulator sees the complete picture. This is legal, common in international business, and devastatingly effective at preventing accountability. The rebrand from Digital Energy Technologies โ Heficed โ IPXO adds a temporal dimension to the insulation: even within a single jurisdiction, historical abuse records are effectively erased by corporate name changes.
Finding 3: RIPE NCC governance has a structural conflict of interest.
IPXO's VP of Strategic Alliances, Paulius Judickas, was elected to the RIPE Programme Committee in June 2026. IPXO's co-founder Vincentas Grinius has been active in RIPE governance. These are the people who benefit from permissive IP leasing policies sitting on the bodies that set those policies. This is not corruption โ it's structural capture. The policy gap that allows temporary IP delegations to bypass transfer-level due diligence exists because the entities that profit from the gap participate in the governance that could close it.
Finding 4: ISO 27001 certification provides legitimacy disproportionate to its security value.
IPXO's ISO 27001 certification certifies its internal security management system. It does not certify that its marketplace is safe, that its lessees are legitimate, or that its abuse response is effective. The certification is used as a general-purpose credibility signal โ "we're certified, therefore we're trustworthy" โ but the scope of what it certifies is dramatically narrower than what stakeholders infer. This inferential gap is exploited, whether intentionally or not, to deflect scrutiny.
Finding 5: The IP leasing market has created a negative externality that no current mechanism prices.
IP address owners earn lease income. IPXO earns commission. Lessees earn operational revenue. The costs of abuse โ blocklisting, credential theft, botnet damage, security operations โ are borne entirely by the targets and the broader internet community. This is a classic externality: private profit, public cost. Until the externality is priced (through regulation, liability assignment, or market mechanisms), the IP leasing market will continue to optimize for volume over safety.
What We Didn't Find
This dossier does not prove that IPXO is a criminal organization. It does not prove that Vincentas Grinius or any IPXO employee knowingly facilitates cybercrime. It does not prove that HBING LIMITED is an IPXO subsidiary. What it proves is that the IP leasing marketplace, as IPXO has built and operates it, creates the conditions under which abuse flourishes โ and that the incentives of the marketplace align with perpetuating, not preventing, that abuse.
The Lithuanian connection is not a scandal. It's a structure. And structures, unlike scandals, don't resolve themselves when exposed. They continue operating, invisibly, as long as the incentives that created them remain unchanged.
Recommendations
๐ก๏ธ For Network Defenders
- Monitor IPXO-managed address space with heightened scrutiny โ RDAP queries for "IPXO" or "Internet Utilities Europe" in abuse contacts should trigger enhanced logging
- Track RIPE database changes on known IPXO LIR objects (ORG-IL687-RIPE) for new prefix delegations
- Block or rate-limit AS208949 (HBING LIMITED) โ our data shows 100% malicious activity from all observed IPs
- Treat IT WEB LTD (BVI) entities and the
abuse.webltd@gmail.comcontact as indicators of bulletproof infrastructure - Deploy HASSH-based detection for
14b2ddda386a4d10(libssh2_1.11.0) โ this fingerprint spans 628 IPs across 48 countries
๐๏ธ For Policy Makers
- Close the temporary delegation loophole in RIPE NCC transfer policy โ require equivalent due diligence for leases and permanent transfers
- Classify IP address marketplaces under NIS2 Directive as essential service providers
- Mandate abuse reputation transfer across corporate rebrands โ RIPE and other RIRs should track organizational genealogy
- Require conflict of interest declarations for RIPE governance participants with commercial interests in the topics being discussed
- Expand ISO 27001 scope expectations for marketplace operators to include customer due diligence
Sources & Methodology
๐ Primary Sources
- Honeypot data: Cowrie SSH honeypot, 25-day observation window (May 21 โ June 15, 2026)
- Threat intelligence database: 8,000+ enriched IPs with multi-source correlation (AbuseIPDB, Shodan, GreyNoise, RDAP, Cymru, OTX, Censys, VirusTotal, Pulsedive)
- Active reconnaissance: Tor-routed nmap/httpx scans of attacker infrastructure
- RIPE NCC database: REST API queries for organization, ASN, and inetnum records
- IPXO public disclosures: Blog posts (August 2024 abuse handling, March 2026 ARIN community, June 2026 RIPE Programme Committee)
- IPXO Market Stats: https://www.ipxo.com/market-stats/ (updated June 18, 2026)
- Academic research: CAIDA "Sublet Your Subnet: Inferring IP Leasing in the Wild" (2024)
- Market data: Brander Group IPv4 market analysis, IPXO RIR policy comparison (October 2025)
- Companies House (UK): Company numbers 12540160, 13836998
- IPv4 exhaustion data: IANA/RIR official records
๐ Methodology
This dossier follows the Phantom ASN Ecosystem methodology established in TI-2026-026A:
- Evidence hierarchy: Direct observation (honeypot logs) โ Technical enrichment (multi-source OSINT) โ Structural analysis (corporate/BGP/RIPE records) โ Inference (patterns that require interpretation)
- Confidence calibration: HIGH = direct evidence + multi-source corroboration. MEDIUM = strong indicators, limited corroboration. LOW = pattern-based inference. All findings are tagged.
- Conspirative analysis: Every significant finding is examined from both the "legitimate explanation" and "adversarial explanation" perspectives. The dossier does not assume malice where incompetence suffices, but it also does not assume incompetence where structural incentives point toward deliberate facilitation.
- Limitations: This research uses publicly available data and our own honeypot observations. We have not contacted IPXO, HBING LIMITED, or IT WEB LTD for comment. We have not accessed non-public corporate registries (Lithuanian Registrลณ centras, UK Companies House detailed filings). Corporate beneficial ownership information beyond public records has not been verified.
The Phantom ASN Ecosystem Series
๐ Complete Series Navigation
- 026A โ The Phantom ASN Ecosystem
- 026B โ The Credential Economy
- 026C โ The Botnet Cartography
- 026D โ The Silent Probes
- 026E โ The Infrastructure Archipelago
- 026F โ The Malware Supply Chain
- 026G โ The Chinese Nexus
- 026H โ The Russian Theater
- 026I โ The American Paradox
- 026J โ The Abuse Report Graveyard
- 026K โ The Cloud Cover
- 026L โ The Supply Chain
- 026M โ The Temporal Dimension
- 026N โ The Lithuanian Connection โ You are here
- 026O โ The Go Scanner
- 026O โ The Convergence (Finale)
This dossier is part of an independent threat intelligence research project. All findings are based on publicly available data, honeypot observations, and open-source intelligence. No classified or proprietary data was used. Published at shuffle-on.com/threat-intel.