The Phantom ASN Ecosystem โ€” Part 14 of 16

๐Ÿ‡ฑ๐Ÿ‡น The Lithuanian Connection

How a Small Baltic Nation Became the IP Address Laundering Capital of Europe

TI-2026-026N | Published June 2026 | ~95 min read

14M
IPv4 Addresses Managed by IPXO
$55M
Paid to IP Address Owners
63,000+
IP Leases Facilitated
2.8M
Lithuania's Population

Chapter 1: From Kaunas to Everywhere

Lithuania is a country of 2.8 million people on the Baltic coast, sandwiched between Latvia, Belarus, Poland, and the Russian exclave of Kaliningrad. It's known for basketball, amber, medieval architecture, and โ€” in a development that would have been unthinkable during the Soviet occupation โ€” for becoming one of Europe's most aggressive fintech and technology jurisdictions.

Vilnius hosts Revolut's European banking license. Lithuania issued more fintech licenses in 2023 than the rest of the EU combined. The country's pitch is simple: low taxes, fast regulation, English-speaking workforce, EU membership. For legitimate fintech companies, Lithuania is what Ireland was to tech multinationals in the 2000s โ€” a regulatory gateway to the European market.

But the same attributes that attract legitimate fintech โ€” light regulation, fast incorporation, EU single market access โ€” also attract something else. And in Kaunas, Lithuania's second city (population 315,000), a company called IPXO UAB has built what it describes as "the world's first full-stack IP address management marketplace."

IPXO doesn't sell servers. It doesn't host websites. It doesn't carry data traffic. It does something more fundamental: it leases the addresses that make the internet work. And in doing so, it has become a critical node in the infrastructure that enables everything from legitimate cloud computing to bulletproof hosting, from CDN operations to botnet command and control.

๐Ÿ“Š IPXO by the Numbers

MetricValueContext
IPv4 addresses managed14 million~0.4% of all IPv4 addresses (3.7 billion total)
Leases facilitated63,000+Each lease can cover /24 to /16 blocks (256 to 65,536 IPs)
Payouts to IP owners$55 millionAt ~$0.40-0.60/IP/month, consistent with market rates
Founded2021 (rebrand from Heficed)Predecessor entities date to ~2015
CEOVincentas GriniusPreviously CEO of Heficed/Digital Energy Technologies
HeadquartersKaunas, LithuaniaWith entities in Austin TX and London UK

๐Ÿ”ฎ The Conspirationist Asks

Why would the world's largest IP address marketplace be headquartered in Lithuania's second city?
The official answer: Lithuania offers competitive operating costs, EU market access, and a tech-friendly regulatory environment. Kaunas has a university pipeline (Kaunas University of Technology) and lower costs than Vilnius. The conspiratorial observation: Kaunas is also outside the direct scrutiny of Vilnius-based regulators. Lithuania's communications regulatory authority (RRT) and data protection authority (VDAI) are both headquartered in Vilnius. A 100km distance is trivial logistically but meaningful bureaucratically โ€” site inspections require travel, informal relationships are harder to maintain, and regulatory oversight is less intensive than for companies literally down the street from the regulator. Whether this is coincidence or strategic is unverifiable. That it's convenient is undeniable.
What does it mean that one company manages 0.4% of all IPv4 addresses?
The total IPv4 address space is approximately 3.7 billion addresses (after removing reserved/private/multicast blocks). IPXO manages 14 million โ€” roughly 1 in every 264 usable IPv4 addresses on Earth flows through their leasing platform at some point. For a company in a city of 315,000 people, this is an extraordinary concentration of internet infrastructure control. No other IP address marketplace approaches this scale. The question isn't whether this is impressive โ€” it is. The question is whether the due diligence on 63,000 leases can possibly keep pace with the volume, or whether scale itself becomes the cover for abuse.

Every good hiding place has two qualities: it must be overlooked by those who seek, and it must be ordinary to those who pass by. Lithuania is both. To the EU, it's a model member state โ€” fast-growing, digitally ambitious, militarily committed to NATO. To the global internet governance community, it's barely visible โ€” a small country with a few LIRs and no major internet exchange. To an IP address marketplace operator, it's perfect: EU legitimacy, minimal regulatory friction, and an address โ€” both physical and digital โ€” that no one thinks twice about. The Lithuanian connection isn't about Lithuania being corrupt. It's about Lithuania being convenient.

Chapter 2: The Corporate Matryoshka

To understand IPXO, you must first understand what it is not. It is not a single company. It is a corporate matryoshka โ€” nested entities across multiple jurisdictions, each layer serving a specific purpose in the overall architecture of legal insulation.

Layer 1: IPXO UAB โ€” The Lithuanian Front

IPXO UAB is the operational entity. UAB (Uลพdaroji Akcinฤ— Bendrovฤ—) is Lithuania's equivalent of a limited liability company. It's registered in Kaunas, employs the staff, runs the marketplace platform, and handles day-to-day operations. This is the entity that signs contracts with IP address owners and lessees. This is the entity that handles abuse complaints. This is the entity whose ISO 27001 certification gets prominently displayed on the website.

Lithuania was chosen not by accident but by design. Lithuanian corporate law requires minimal capitalization (โ‚ฌ2,500 for a UAB), allows single-person boards, imposes no residency requirements on directors, and โ€” critically โ€” does not require public disclosure of beneficial ownership beyond what the EU's Anti-Money Laundering Directives mandate. For a company managing 14 million IP addresses, the regulatory burden is lighter than what a food truck operator faces in most EU capitals.

Layer 2: IPXO LLC โ€” The American Address

IPXO LLC is registered in Austin, Texas. The RDAP records for IPXO-managed IP space list a Dallas address: 3132 State Street, Dallas, TX 75204-3500. Texas LLCs are among the easiest corporate structures in the world to establish โ€” no operating agreement required, no annual report filing, no requirement to disclose members or managers publicly. An IPXO LLC exists primarily for one purpose: to hold ARIN-delegated IP address resources. ARIN (American Registry for Internet Numbers) requires US or Canadian entities for resource membership. The Texas LLC is the ARIN membership vehicle.

Layer 3: Internet Utilities Europe and Asia Ltd โ€” The London Mystery

Then there's Internet Utilities Europe and Asia Ltd, registered at Companies House in London (Company No. 12540160). This entity was incorporated on March 18, 2020 โ€” during the COVID-19 lockdowns. Its registered address is a virtual office in London. Its directors and persons with significant control connect back to the Heficed/IPXO corporate constellation.

Why London? Because RIPE NCC (Rรฉseaux IP Europรฉens Network Coordination Centre) โ€” the Regional Internet Registry for Europe, the Middle East, and parts of Central Asia โ€” is headquartered in Amsterdam but operates under Dutch law with English as its working language. A UK entity, despite Brexit, maintains credibility in the European internet governance community. London is where the internet's old money lives โ€” LINX (London Internet Exchange), the legacy ISPs, the standards bodies. Having a London entity signals establishment credibility that a Kaunas address cannot.

Layer 4: The Heficed Predecessor

Before IPXO, there was Heficed. Before Heficed, there was Digital Energy Technologies Ltd. The corporate lineage is:

Corporate Evolution Timeline

YearEntityJurisdictionActivity
~2015Digital Energy Technologies LtdUKVPS/dedicated hosting, IP address management
~2018Heficed (rebrand)Lithuania/UKHosting + IP leasing platform launch
2020Internet Utilities Europe and Asia LtdUKIncorporated (Companies House 12540160)
2021IPXO UAB (rebrand from Heficed)LithuaniaFull pivot to IP address marketplace
2021+IPXO LLCTexas, USAARIN membership vehicle

Each rebrand coincided with a shift in business model โ€” and a distancing from the abuse reports associated with the previous brand name. Digital Energy Technologies accumulated hosting abuse reports. Heficed accumulated IP leasing abuse reports. IPXO launched as the "clean" marketplace brand, leaving the accumulated negative reputation of Heficed behind while maintaining the same infrastructure, the same people, and the same IP address blocks.

๐Ÿ”ด Finding: Multi-Jurisdictional Insulation Architecture

The IPXO corporate structure spans at minimum four jurisdictions (Lithuania, USA, UK, and through lessee relationships, dozens more). This is not unusual for a technology company, but the specific pattern โ€” Lithuanian operations, US registry vehicle, UK governance credibility, serial rebranding โ€” creates a structure where no single regulator has complete oversight. Lithuania's Communications Regulatory Authority (RRT) sees the operations. ARIN sees the American entity. Companies House sees the UK shell. None of them sees the complete picture. This is a feature, not a bug.

Confidence: HIGH โ€” Based on corporate registry records, RDAP data, and documented rebrand timeline.

๐Ÿ”ฎ The Conspirationist Asks

Why does a company rebrand twice in six years if it's doing nothing wrong?
The charitable explanation: the business model evolved. Hosting became less profitable; IP leasing became the growth market. The brand needed to reflect the new focus. This happens in business regularly. The less charitable observation: each rebrand coincided with a period of heightened abuse complaints. Digital Energy Technologies was associated with hosting abuse. Heficed was associated with IP leasing to abusive operators. IPXO launched with a clean slate, a new website, and no mention of the previous brands. The corporate structure โ€” the employees, the IP blocks, the RIPE memberships โ€” transferred intact. What changed was the searchability of past complaints.
Is the Texas address a real office or a mailbox?
3132 State Street, Dallas, TX 75204 is a building that hosts multiple registered agents and virtual office services. It is unlikely that IPXO maintains significant operations there. The purpose of the Texas LLC is functional, not operational โ€” it exists to satisfy ARIN's requirement for a US entity to hold US-delegated IP address resources. This is legal and common. What's unusual is that the entity managing 14 million IP addresses globally โ€” making it one of the largest IP address holders on Earth โ€” has no meaningful physical presence at its registered address in the world's largest IP address market.
Why was Internet Utilities Europe and Asia Ltd incorporated during COVID lockdowns?
The timing may be coincidental. COVID drove massive demand for internet infrastructure, IP addresses, and cloud services. Incorporating a new entity to capture that demand makes business sense. The conspiratorial observation: COVID lockdowns also meant that Companies House was operating with reduced due diligence capacity. Incorporation checks that normally took weeks were processed in days. The period from March 2020 to June 2021 saw record numbers of company formations in the UK, many of which were later identified as fraudulent or shell entities. We are not asserting that Internet Utilities Europe and Asia Ltd is such an entity โ€” only that it was incorporated at a time when scrutiny was at its lowest.

There is a pattern in the internet infrastructure industry that goes like this: a company accumulates abuse reports under Brand A. It creates Brand B as a "marketplace" or "platform" entity. It transfers the operations, the staff, and the IP address blocks to Brand B. Brand B has no abuse history. Brand A is quietly dissolved or left dormant. The abuse reports associated with Brand A become historical curiosities, findable only by researchers who know to look. The customers of Brand B, when they Google the company, find a clean record. This is not fraud. It's not even deception, strictly speaking โ€” the company genuinely is new. What it is, precisely, is reputation laundering. The product hasn't changed. The management hasn't changed. The IP blocks haven't changed. Only the name has changed. And that's enough, because search engines don't track corporate genealogy.

Chapter 3: The Man From Heficed

Vincentas Grinius is the CEO and co-founder of IPXO. His LinkedIn describes him as a serial entrepreneur in the internet infrastructure space. He previously led Heficed and Digital Energy Technologies. He sits on RIPE NCC committees. He speaks at industry events. He has been quoted in press releases announcing IPXO's funding rounds and milestones.

Let's examine what is publicly known about the man behind 14 million IP addresses.

The Public Profile

Grinius presents himself as a technologist turned entrepreneur. His career arc follows a pattern common in Eastern European tech: technical education, early work in hosting/infrastructure, followed by a pivot to IP address management as the IPv4 exhaustion crisis made existing address blocks valuable assets. His LinkedIn shows connections across the Baltic tech ecosystem โ€” Kaunas-based companies, Lithuanian tech accelerators, and the broader European hosting community.

He has been active in RIPE NCC governance. RIPE NCC is a member-based organization; any entity holding IP address resources in the RIPE region can participate in its governance. This means that the person whose companies lease IP addresses to customers โ€” including customers who attack honeypots โ€” also participates in setting the policies that govern how those IP addresses are allocated and managed.

The Governance Problem

This is not corruption. It is structural conflict of interest. The same dynamic exists across internet governance: the people who build the infrastructure also set its rules. The Internet Engineering Task Force (IETF) is dominated by engineers from the companies whose products implement the standards. RIPE NCC's governance is dominated by the LIRs (Local Internet Registries) who hold the resources. ARIN's governance is dominated by US ISPs and hosting companies.

But there's a difference between a large ISP like Deutsche Telekom sitting on RIPE governance (inevitable, given their resource holdings) and an IP address marketplace operator whose business model depends on fluidity of resource transfers sitting on governance. Deutsche Telekom wants stable, long-term allocations. An IP marketplace wants flexibility, easy transfers, and minimal oversight of how leased addresses are used. Their governance incentives point in opposite directions.

๐Ÿ“Š RIPE NCC Governance & IP Leasing Conflict

RIPE NCC's Transfer Policy (RIPE-786) governs how IP address resources can be transferred between organizations. The policy was designed for permanent transfers โ€” ISP A sells its address block to ISP B. IP leasing platforms like IPXO operate in a grey area: they don't permanently transfer addresses, they temporarily delegate them. This delegation uses RIPE database objects (route objects, inetnum objects) to authorize BGP announcements, but the underlying allocation remains with the original holder.

The governance question is: should RIPE NCC require the same due diligence for temporary delegations as for permanent transfers? The IP leasing industry's answer is no โ€” that would add friction and reduce marketplace velocity. The security community's answer is yes โ€” because a temporarily delegated IP address used for botnet C&C is just as dangerous as a permanently transferred one.

Vincentas Grinius participates in the governance structure that determines which answer prevails. He has a direct financial interest in the outcome. This is documented, public, and legal. It is also a textbook case of regulatory capture.

๐Ÿ”ฎ The Conspirationist Asks

Is one person's governance participation really that significant?
In an organization with 20,000+ members but where governance participation rarely exceeds 200-300 at any general meeting? Yes. RIPE NCC governance operates on the principle of rough consensus, and rough consensus is shaped by those who show up. Most RIPE members are small ISPs who don't attend governance meetings or participate in policy discussions. The handful of people who do participate โ€” routinely, consistently, across multiple working groups and general meetings โ€” have outsized influence on outcomes. A persistent presence on RIPE governance committees, combined with the industry visibility that comes from running the world's largest IP marketplace, creates influence that is disproportionate to vote share.
What would it take for a governance participant to actually block regulation harmful to their business?
Nothing dramatic. RIPE NCC policy proposals go through a multi-step process: proposal, discussion on mailing lists, working group sessions, community consensus call. At any stage, a well-organized opposition can delay or dilute a proposal. You don't need to "block" anything โ€” you need to add qualifications, extend timelines, insert "further study required" clauses, or simply ensure that your position is represented in the "rough consensus." This is how governance capture works everywhere โ€” not through corruption, but through persistent, professional participation by parties with aligned interests. It's legal. It's effective. And it's invisible to outsiders who aren't reading RIPE policy discussion archives.
Has Grinius personally intervened in any RIPE policy discussion related to IP leasing?
RIPE NCC mailing list archives and general meeting transcripts are public. We have not conducted an exhaustive analysis of every Grinius intervention (this is future research). What is known: RIPE NCC discussions about "IP address market regulation" and "temporary resource transfers" have been active since approximately 2019. The IP leasing industry โ€” IPXO, Heficed, and competitors โ€” have been active participants in these discussions. The outcome so far: no additional regulatory burden on temporary delegations. Whether this outcome reflects community consensus or industry capture is a matter of perspective. What it definitely reflects is effective industry participation in governance.

The history of internet governance is the history of managed conflicts of interest. The same people who build the protocols sit on the standards bodies that standardize them. The same companies that profit from address scarcity sit on the registries that manage address allocation. This is not a scandal โ€” it's the architecture. The question is never "does conflict of interest exist?" (it always does) but rather "is the conflict managed transparently?" In the case of IP leasing and RIPE governance, the answer is: barely. There are no public recusal policies for RIPE NCC governance participants who have commercial interests in the topics being discussed. There is no register of interests. There is no requirement to declare potential conflicts before voting or contributing to consensus. The system relies on trust and good faith. In a community of 20,000 members managing $150+ billion in IP address assets, this is perhaps... optimistic.

Chapter 4: Heficed โ†’ IPXO โ€” The Rebrand That Changed Nothing

In 2021, Heficed became IPXO. The press releases spoke of "a new chapter," "marketplace innovation," and "IP address lifecycle management." The reality was simpler: the Heficed brand had accumulated too much baggage.

The Heficed Era

Heficed operated as both a hosting provider and an IP address leasing platform. This combination was problematic. As a hosting provider, Heficed operated servers, managed infrastructure, and dealt with abuse complaints about content hosted on those servers. As an IP address lessor, Heficed leased address blocks to other hosting providers, who then hosted their own content โ€” and generated their own abuse.

The dual role created a convenient ambiguity. When abuse was reported on a Heficed IP, the response could be: "We don't host that content โ€” we leased the address to another provider. Contact them." When the other provider was contacted, their response could be: "The address isn't ours โ€” it's leased from Heficed. Contact them." The abuse report circulated between two entities, neither claiming responsibility, until the reporter gave up.

This pattern โ€” known in the industry as "abuse report ping-pong" โ€” is not unique to Heficed. It's endemic in the IP leasing market. But Heficed's scale made it more visible than most. By 2020, Heficed appeared regularly on abuse tracking databases. The brand was, in industry terms, "burned."

The Clean Slate Maneuver

The IPXO rebrand solved this problem entirely. A new company name. A new website. New marketing materials. New press coverage. The Google search results for "IPXO abuse" in 2021 returned zero relevant results. The Google search results for "Heficed abuse" returned thousands. Same company. Same people. Same IP blocks. Different searchability.

๐Ÿ”ด Finding: Brand Discontinuity as Abuse History Erasure

The Heficed โ†’ IPXO rebrand demonstrates a structural weakness in internet governance: abuse reputation is tied to brand names, not to underlying infrastructure or personnel. When Heficed became IPXO, every abuse database, every blocklist maintainer, every security researcher who had flagged Heficed had to start from scratch with IPXO. The IP address blocks remained the same. The BGP announcements remained the same. The RIPE database objects remained the same. But the human-readable identifier โ€” the name that researchers search for, that appears in abuse reports, that gets discussed on mailing lists โ€” reset to zero.

This is not an IPXO-specific problem. It is a systemic vulnerability in how the internet governance community tracks and responds to abuse. Any organization can rebrand. No mechanism exists to transfer abuse reputation across corporate rebrands.

Confidence: HIGH โ€” Based on documented rebrand timeline, public archive searches, and confirmed continuity of IP address resources.

What Changed โ€” and What Didn't

AspectChanged?Details
Company nameโœ… YesHeficed โ†’ IPXO
CEOโŒ NoVincentas Grinius remained
Core teamโŒ NoKey staff transferred
IP address blocksโŒ NoSame RIPE allocations
RIPE LIR membershipโŒ NoSame ORG-IL687-RIPE
Business modelโš ๏ธ PartialHosting deprecated, marketplace emphasized
Customer baseโŒ NoExisting lessees continued
Abuse response SLAโŒ NoSame 24-hour target
Brand reputationโœ… ResetClean search results
Abuse historyโœ… ErasedHistorical reports not transferred

๐Ÿ”ฎ The Conspirationist Asks

Is rebranding to escape abuse reputation legal?
Completely. There is no law anywhere in the world that prevents a company from changing its name. There is no requirement to carry forward abuse reports under a new brand. There is no RIPE NCC policy that tracks reputation across corporate restructuring. There is no ARIN policy either. The internet governance system assumes that IP address resources are managed by entities acting in good faith. When good faith is absent, the system has no mechanism to detect or respond โ€” because it was never designed for adversarial actors operating within the governance framework.
If the same people run the same IP blocks under a new name, isn't this just fraud?
No. Fraud requires deception that causes financial harm. IPXO does not claim to be unrelated to Heficed โ€” it simply doesn't mention the connection. There's a legal and practical difference between "we have no connection to Heficed" (which would be false) and silence on the topic (which is a marketing choice). IPXO's website, as of this writing, makes no mention of Heficed or Digital Energy Technologies in its About section. This is omission, not commission. In most legal frameworks, you have no obligation to volunteer unflattering history unless specifically asked. The internet governance community's mistake is not asking.
Could this pattern be applied systematically โ€” rebrand every 3 years to reset reputation?
It already is. The Heficed โ†’ IPXO pattern is one of many. The hosting industry โ€” particularly the bulletproof and semi-bulletproof segments โ€” has been doing this for decades. The typical cycle: incorporate entity, accumulate abuse, get noticed by researchers, rebrand, repeat. The innovation in the IP leasing space is that you don't even need to rebrand the infrastructure โ€” only the management company. The IP blocks stay the same. The BGP routes stay the same. The RIPE objects can be updated with a new contact organization in minutes. The entire rebranding, from a technical perspective, is a text change in a database.

Chapter 5: The IP Leasing Machine

To understand why IPXO matters for threat intelligence, you need to understand the mechanics of IP address leasing โ€” and why it's the perfect vehicle for enabling abuse while maintaining plausible deniability.

How IP Leasing Works

An IP address lease, in simplified terms, works like this:

IP Address Leasing Flow

  1. The Owner holds a block of IP addresses (e.g., a /16 = 65,536 addresses) allocated by a Regional Internet Registry (RIR). These addresses were historically free; today they trade at $40-55/address on the transfer market.
  2. The Marketplace (IPXO) connects owners with lessees. The owner lists their unused blocks on the platform. IPXO handles the technical mechanics of delegation.
  3. The Lessee requests a block of addresses for a specified period. They might be an ISP, a hosting company, a CDN, or โ€” and here's the problem โ€” a bulletproof hosting operation, a spammer, or a botnet operator.
  4. The Delegation happens via RIPE database objects. The owner (or IPXO on their behalf) creates route objects and inetnum objects that authorize the lessee's ASN to announce the addresses. This is a database change, not a physical transfer โ€” the addresses don't move anywhere. What moves is the authorization to announce them.
  5. The Revenue flows: lessee pays IPXO, IPXO takes a commission (industry standard: 10-20%), IPXO pays the owner.

The Due Diligence Problem

IPXO claims to perform due diligence on lessees. Its website mentions "IP abuse prevention" and "reputation monitoring." But the fundamental tension is this: thoroughness slows velocity, and velocity is revenue.

If IPXO processes 63,000 leases, each requiring genuine due diligence โ€” background checks on the lessee, verification of use case, monitoring of announced routes, analysis of traffic patterns โ€” the operational cost would be enormous. A single compliance analyst can handle perhaps 10-20 thorough reviews per day. At 63,000 leases, that's 3,150-6,300 analyst-days, or 12-25 full-time compliance staff working every business day of the year, assuming each lease needs only one review.

But leases aren't static. They need ongoing monitoring. A lessee who passes initial due diligence can start using the addresses for abuse the day after the check. Continuous monitoring of 14 million addresses for abuse indicators would require a security operations center rivaling those of major ISPs โ€” an investment that would wipe out the margins of a marketplace business model.

63,000
Leases to Review
~250/day
Working Days per Year
252
Leases per Day Average
14M
Addresses to Monitor

The HBING Connection

Here's where IPXO's due diligence claims meet our honeypot data. Consider AS208949 โ€” HBING LIMITED, registered in the UK:

๐Ÿ”ด Finding: IPXO as Abuse Contact for Bulletproof ASN

Our honeypot recorded 5 IPs from AS208949 (HBING LIMITED), all with threat scores of 78-93 and abuse scores of 100%. All 5 IPs geolocate to the Netherlands. The RDAP abuse contact for two of these IPs is support@ipxo.com โ€” IPXO's own support email, listed as the "IPXO Incident Response Team." The other three IPs list abuse.webltd@gmail.com โ€” a Gmail address associated with "IT WEB LTD" registered in the British Virgin Islands.

AS208949 is flagged as bulletproof in our intelligence database with a risk score of 95.26 out of 100. Every single IP we've observed from this ASN has a 100% abuse score on AbuseIPDB. This ASN's 10 announced prefixes include ranges from Africa (102.129.x.x), Europe (45.x.x.x, 93.x.x.x, 185.x.x.x, 193.x.x.x, 195.x.x.x), and various other ranges โ€” a geographic dispersion that suggests acquired rather than allocated address space.

Confidence: HIGH โ€” Direct evidence from honeypot, RDAP, BGP, and AbuseIPDB data.

Let's break down what the data shows:

IP AddressThreatAbuseHitsRDAP OrgAbuse ContactAbuseIPDB ISP
102.129.200.11793100%42IPXO Incident Response Teamsupport@ipxo.comDigital Energy Technologies Ltd
102.129.200.10188100%24IPXO Incident Response Teamsupport@ipxo.comDigital Energy Technologies Ltd
45.88.0.25283100%30lir-vg-itweb-1-MNTabuse.webltd@gmail.comIT WEB LTD
45.148.146.5279100%36lir-vg-itweb-1-MNTabuse.webltd@gmail.comIT WEB LTD
45.148.145.6078100%36lir-vg-itweb-1-MNTabuse.webltd@gmail.comIT WEB LTD

The Geography Discrepancy

Notice something critical: all 5 IPs geolocate to the Netherlands. But the registrant data tells a different story:

  • RDAP country for 102.129.200.x: US (registered via IPXO's Dallas address)
  • RDAP country for 45.88.0.252: Poland
  • RDAP country for 45.148.146.52: Poland
  • RDAP country for 45.148.145.60: Belgium
  • ASN registration country: United Kingdom
  • Actual geolocation: Netherlands

Five countries involved โ€” US, Poland, Belgium, UK, Netherlands โ€” and the corporate entities span Lithuania, Texas, British Virgin Islands, and London. This is not a network. This is a jurisdictional labyrinth.

๐Ÿ“Š The Digital Energy Technologies Persistence

AbuseIPDB identifies the ISP for the 102.129.200.x range as "Digital Energy Technologies Limited" โ€” the pre-Heficed corporate entity. This means that even after two rebrands (Digital Energy โ†’ Heficed โ†’ IPXO), the underlying infrastructure still carries fingerprints of the original entity in third-party databases. The IPXO rebrand cleaned the company website and press coverage, but it couldn't clean AbuseIPDB, Shodan, or other databases that crawl and index network infrastructure independently of corporate marketing.

The IT WEB LTD / BVI Connection

Three of the five HBING IPs list their RDAP organization as lir-vg-itweb-1-MNT, with the abuse email abuse.webltd@gmail.com and a phone number +14708099233 (a US number, area code 470 = Atlanta, Georgia). The entity "IT WEB LTD" is registered in the British Virgin Islands.

The BVI is the world's most popular offshore incorporation jurisdiction, with more registered companies than residents. BVI corporate registrations do not require disclosure of beneficial ownership, directors, or financial statements. A BVI company operating IP address resources through a UK-registered ASN, managed via IPXO's Lithuanian platform, with addresses geolocating to the Netherlands โ€” this is jurisdictional complexity that serves no legitimate technical purpose.

๐Ÿ“‘ The IT WEB LTD Footprint

Searching our threat intelligence database for abuse.webltd@gmail.com reveals 7 IPs across 3 ASNs, all geolocating to the Netherlands:

ASNNameCountryRisk ScoreBulletproof?IPs
208949HBING LIMITEDGB95.26โœ… Yes3
215224NovoServe B.V.NL88.79โœ… Yes3
200313IT WEB LTDVG1.2โŒ No1

A single Gmail address connects a BVI shell company to two bulletproof ASNs (combined risk scores: 95 and 89) and its own low-risk ASN. The Gmail address โ€” not a corporate domain โ€” as the abuse contact for IP addresses serving 7 attackers suggests that abuse handling is not a priority. This is infrastructure designed to appear managed while being effectively unaccountable.

๐Ÿ”ฎ The Conspirationist Asks

If IPXO performs due diligence, how did HBING LIMITED โ€” a bulletproof ASN with 95/100 risk score โ€” become their customer?
There are three possible explanations. First: IPXO's due diligence is genuine but HBING LIMITED passed it, meaning the due diligence process is too weak to catch obvious bulletproof operators. Second: HBING LIMITED was a customer before it became bulletproof โ€” it accumulated abuse over time, and IPXO's ongoing monitoring failed to detect or act on it. Third: IPXO's due diligence is performative โ€” it exists on paper to satisfy auditors and governance requirements but does not effectively screen lessees. In all three scenarios, the outcome is the same: IPXO's name appears as the abuse contact for a bulletproof network with a 95/100 risk score, and 168 attacks from those IPs hit our honeypot over 25 days.
Why would a legitimate company use a Gmail address for abuse reports?
It wouldn't. A Gmail address as an abuse contact is a signal โ€” not definitive, but strong โ€” that the entity is not seriously invested in abuse handling. Domain-specific email (abuse@company.com) signals organizational infrastructure: an email server, a domain registration, a minimum investment in corporate identity. A Gmail address signals the opposite: maximum anonymity, minimum investment, and โ€” critically โ€” the ability to abandon the address without losing any infrastructure. If abuse.webltd@gmail.com becomes too well-known to blocklist operators, a new Gmail address can be created in 30 seconds.
What is the relationship between IPXO and IT WEB LTD?
IPXO appears as the abuse contact for some IPs on AS208949 (HBING LIMITED), while IT WEB LTD appears as the RDAP organization for other IPs on the same ASN. This suggests that IT WEB LTD is a RIPE NCC member (LIR) that holds IP address resources, some of which are announced through HBING LIMITED's ASN. IPXO may be the marketplace through which IT WEB LTD acquired or leased some of these resources. The precise corporate relationship is unclear โ€” which is, of course, the point. When the corporate structure is a nesting doll of Lithuanian, American, British, BVI, and Dutch entities, determining who is responsible for what becomes an exercise that outlasts most investigators' patience.
Is IPXO profiting from bulletproof hosting through IP leasing?
If IPXO leases IP addresses to entities that operate bulletproof networks โ€” and the evidence shows IPXO as the abuse contact for a bulletproof ASN โ€” then IPXO earns commission on those leases. The question of whether this constitutes "profiting from bulletproof hosting" depends on what IPXO knew and when. If IPXO knew that HBING LIMITED was bulletproof and continued the lease, that's complicity. If IPXO didn't know, that's incompetence โ€” their due diligence failed to detect a network with a 95/100 risk score that AbuseIPDB flagged at 100% abuse confidence. Either way, the revenue flowed.

The IP leasing market has created what economists call a "moral hazard" โ€” a situation where one party can take risks because another party bears the consequences. The IP address owner collects lease payments while IPXO handles compliance. IPXO collects commissions while the lessees handle operations. The lessees operate bulletproof networks while law enforcement struggles to identify who is responsible. At each layer, the entity closest to the abuse has the least liability, and the entity with the most liability has the least knowledge of the abuse. This isn't a design flaw. This is the design. The IP leasing market works precisely because it distributes responsibility until no single entity bears enough of it to trigger enforcement action. IPXO didn't invent this structure. But IPXO, managing 14 million addresses and 63,000 leases, has scaled it to a degree that makes it a systemic risk to internet security governance.

Chapter 6: The RIPE Committee Problem

RIPE NCC is not a regulator. This fact โ€” stated repeatedly by RIPE NCC itself โ€” is the foundation of both its strength and its vulnerability. RIPE NCC is a registry: it records who holds what IP addresses, maintains the technical databases that make internet routing work, and facilitates community governance of numbering resources. It does not police how those resources are used.

This distinction matters enormously for the IP leasing market. If RIPE NCC were a regulator, it could revoke allocations from entities that facilitated abuse. It could impose due diligence requirements on resource transfers. It could audit marketplace operators like IPXO. But as a registry, it does none of these things โ€” because its community has not reached consensus that it should.

The Governance Structure

RIPE NCC governance operates through several mechanisms:

RIPE NCC Governance Layers

BodyFunctionComposition
General MeetingSets overall direction, elects boardAll 20,000+ members can participate
Executive BoardStrategic oversightElected members (typically 7-9)
Working GroupsPolicy developmentSelf-selecting, open to all participants
RIPE NCC StaffOperations~350 employees (Amsterdam HQ)

The critical layer is the Working Groups. This is where IP address allocation policy, transfer policy, and abuse handling guidelines are developed. Working groups are open โ€” anyone can participate. They operate on "rough consensus" โ€” no formal voting, but rather the chairs' assessment of the room's opinion.

This openness is both RIPE's greatest democratic achievement and its greatest vulnerability to capture. When an IP leasing marketplace operator participates consistently in working groups that discuss transfer policy, their voice carries weight not because of a formal vote but because of persistent presence. Most RIPE members โ€” small ISPs, university networks, research institutes โ€” don't have the resources or interest to participate in policy discussions about IP address markets. The marketplace operators do. Their livelihoods depend on the outcomes.

The Specific Policy Gap

RIPE's Transfer Policy (RIPE-786) governs permanent transfers of IP address resources. It requires documentation, verification of the receiving entity's need, and a cooling-off period. These requirements exist because permanent transfers were identified as a vector for address space fraud.

But IP leasing โ€” temporary delegation of address usage rights โ€” operates largely outside this policy framework. A temporary delegation doesn't trigger transfer policy requirements because technically, no transfer occurs. The addresses remain allocated to the original holder. What changes is the routing authorization โ€” the RIPE database objects that tell the global routing system "this ASN is authorized to announce this prefix."

This policy gap means that IPXO can facilitate thousands of temporary delegations per month with zero RIPE NCC oversight of the individual transactions. The only point of governance contact is the RIPE member agreement itself, which requires members to maintain accurate database records. Whether a member is leasing its addresses to bulletproof operators or legitimate cloud providers is, from RIPE NCC's perspective, outside its mandate.

๐Ÿ”ด Finding: Regulatory Gap in Temporary IP Address Delegations

RIPE NCC's policy framework creates a two-tier system: permanent transfers are subject to due diligence and verification; temporary delegations (leases) are not. IPXO's business model โ€” leasing 14 million addresses via 63,000 temporary delegations โ€” operates entirely in the unregulated tier. The IP leasing industry benefits from this gap. Members of the IP leasing industry participate in the governance process that would need to close it. The gap has existed since IP leasing became a significant market (~2017-2018). No policy proposal to subject temporary delegations to transfer-equivalent oversight has reached consensus.

Confidence: HIGH โ€” Based on RIPE policy documentation, governance structure analysis, and observable policy gap.

๐Ÿ”ฎ The Conspirationist Asks

Is this regulatory capture, or just how consensus governance works?
Both. Regulatory capture doesn't require corruption โ€” it requires asymmetric participation. When the entities most affected by a policy are also the most active participants in the policy-making process, outcomes naturally skew toward their interests. The IP leasing industry has every incentive to participate in RIPE governance: their business model depends on permissive policies. Small ISPs and network operators โ€” who bear the costs of abuse enabled by IP leasing โ€” have much weaker incentives to participate: each individual abuse incident is small, dispersed, and not worth the travel cost to a RIPE meeting. This is textbook Mancur Olson: concentrated benefits and dispersed costs produce regulatory outcomes that favor the concentrated interest group.
Has anyone actually proposed closing the temporary delegation loophole?
There have been discussions โ€” the RIPE Anti-Abuse Working Group has debated IP leasing accountability at multiple meetings. But "discussion" and "policy change" are different animals. Proposals to increase oversight of temporary delegations have been characterized as "adding burden to legitimate businesses" and "scope creep beyond RIPE NCC's mandate." These objections are not wrong โ€” they're just convenient. Every oversight mechanism adds burden. Every expansion of a registry's mandate is scope creep. The question is whether the burden is justified by the harm, and whether the scope expansion is necessary. The IP leasing industry's answer, consistently, has been "no." And since they're the ones who show up to the meetings, their answer has prevailed.
Could a state actor exploit this governance gap?
Easily. A state intelligence service wanting to acquire untraceable IP infrastructure would create a shell company (BVI, Seychelles, Nevis โ€” pick your jurisdiction), register it as a RIPE NCC member, acquire IP address resources through the transfer market, and then lease them to operational units through IPXO or a similar marketplace. At no point in this process would RIPE NCC's governance mechanisms detect the state connection. The shell company would pass whatever due diligence exists. The leases would be processed as routine marketplace transactions. The IP addresses would be announced from infrastructure in the Netherlands or Germany or Romania โ€” countries with excellent connectivity and limited real-time traffic monitoring. This is not theoretical. It is the exact workflow that our honeypot data suggests is already occurring, whether by state actors or by criminal organizations sophisticated enough to use the same techniques.

Chapter 7: The ISO 27001 Shield

IPXO holds ISO 27001 certification. This is prominently displayed on its website, referenced in press releases, and cited in response to questions about security and due diligence. ISO 27001 has become the cybersecurity equivalent of a doctor's diploma on the wall โ€” it signals competence to non-experts and provides comfort to business partners who lack the ability to independently assess security practices.

But ISO 27001 does not certify what most people think it certifies.

What ISO 27001 Actually Certifies

ISO 27001 certifies that an organization has an Information Security Management System (ISMS). Specifically, it certifies that:

  • The organization has identified its information security risks
  • The organization has documented policies and procedures to manage those risks
  • The organization has implemented controls from Annex A (a menu of 114 possible controls)
  • The organization conducts internal audits and management reviews
  • The organization pursues continuous improvement

What ISO 27001 does not certify:

  • That the organization's products or services are secure
  • That the organization's customers are legitimate
  • That the organization's IP addresses are not being used for abuse
  • That the organization's due diligence on lessees is effective
  • That the organization's abuse response is timely or adequate
  • That the organization is not facilitating cybercrime through its marketplace

The critical distinction: ISO 27001 certifies process, not outcomes. You can have a perfectly certified ISMS that documents, reviews, and continuously improves a due diligence process that is fundamentally inadequate. As long as the process exists, is documented, is reviewed, and is improved (even marginally), the certification holds.

The Certification Scope Question

Every ISO 27001 certification has a defined scope โ€” the specific processes, systems, and services covered by the certification. The scope statement determines what the auditor examines. What falls outside the scope is not assessed.

For an IP address marketplace, the relevant question is: does the certification scope include lessee due diligence? If the scope is "management of the IPXO marketplace platform" โ€” the servers, the databases, the internal processes โ€” then the certification means IPXO keeps its own systems secure. It says nothing about whether the IP addresses flowing through the marketplace are used securely by the lessees.

This is like certifying that a gun shop has excellent inventory management while saying nothing about whether it performs background checks on buyers.

๐Ÿ“Š The Certification Gap Analysis

What ISO 27001 CoversWhat It Doesn't Cover
IPXO's internal network securityHow leased IPs are used by customers
Employee access controlsCustomer vetting effectiveness
Data backup and recoveryWhether abuse reports are actually resolved
Incident management proceduresWhether bulletproof operators are screened out
Physical security of officesGeographic accuracy of RIPE database objects
Change management processesWhether leased addresses facilitate cybercrime

๐Ÿ”ฎ The Conspirationist Asks

Is ISO 27001 deliberately designed to be useless for this purpose?
No โ€” ISO 27001 is designed for a different purpose. It was created to certify that organizations manage their own information security risks. It was never intended as a certification for marketplace safety or customer vetting. The problem is not that ISO 27001 is bad โ€” it's that it's being used as a proxy for something it doesn't measure. When IPXO displays its ISO 27001 badge and a potential customer or partner concludes "this company must be doing proper due diligence on its lessees," that conclusion is not supported by the certification. But it's the conclusion that most non-experts draw. And that inferential gap โ€” between what the certification certifies and what people believe it certifies โ€” is enormously valuable to the certified entity.
How much does ISO 27001 certification cost?
For a company of IPXO's size, the initial certification process costs approximately $20,000-50,000 (consultant preparation, auditor fees, documentation). Annual surveillance audits cost $10,000-20,000. For a company claiming $55M in payouts to IP owners โ€” implying revenues in the hundreds of millions โ€” this is a rounding error. The return on investment is enormous: the certification provides legitimacy disproportionate to its cost, deflects due diligence questions from partners and customers, and creates a legal defense ("we followed certified best practices") in the event of liability claims. ISO 27001 is the cheapest insurance policy in the industry.
Could IPXO include lessee due diligence in its ISO 27001 scope?
Yes. ISO 27001's scope is voluntary. A company can define its scope as broadly or narrowly as it chooses. IPXO could include "lessee vetting and ongoing monitoring" in its ISMS scope, which would require auditor assessment of those processes. The fact that this is presumably not in scope is itself informative โ€” it suggests that either the lessee vetting process would not survive audit scrutiny, or that IPXO has made a deliberate decision to keep it outside the certified perimeter. In either case, the ISO 27001 badge tells you about IPXO's internal security, not about the safety of the internet resources flowing through its marketplace.

Certifications are a language. They communicate trustworthiness in a world too complex for individual verification. When you see a pilot's license, you trust that the pilot can fly. When you see an ISO 27001 badge, you trust that the organization manages security responsibly. But the analogy breaks down in a critical way: a pilot's license certifies the ability to do a specific, dangerous thing safely. ISO 27001 certifies the existence of a management system โ€” not the effectiveness of that system in preventing specific harms. A company can be ISO 27001 certified and simultaneously facilitate massive cybercrime through its IP leasing marketplace, provided its internal processes for doing so are properly documented, reviewed, and continuously improved. The certification doesn't prevent harm. It certifies the documentation of the process that causes harm. This is not a flaw in ISO 27001. It's a flaw in how ISO 27001 is interpreted โ€” and the interpretation gap is actively exploited by entities whose business models benefit from the appearance of compliance without its substance.

Chapter 8: The PIO-HBING Pipeline โ€” When Leased IPs Attack

The theory is one thing. The evidence is another. Let's look at what our honeypot actually recorded from IP addresses connected to the IPXO ecosystem.

The HBING Network in Detail

AS208949 (HBING LIMITED) is a UK-registered company (Companies House 13836998) with its registered address at 124 City Road, London, EC1V 2NX โ€” a generic company formation agency address used by thousands of shell and nominee companies. Its RIPE record was created on April 2, 2023, making it barely three years old. Its abuse contact is hbinglimited@mail.com โ€” a free email address from mail.com, which is itself a significant indicator.

HBING LIMITED announces 10 IPv4 prefixes via BGP โ€” a modest network, but the prefixes reveal something interesting:

๐Ÿ“‘ HBING LIMITED BGP Announcements

PrefixRegion OriginNotes
102.129.200.0/24Africa (AFRINIC)IPXO as abuse contact
102.165.51.0/24Africa (AFRINIC)African IP space via UK company
45.88.0.0/24RIPE (Netherlands)IT WEB LTD (BVI) as registrant
45.148.145.0/24RIPE (Belgium/NL)IT WEB LTD (BVI) as registrant
45.148.146.0/24RIPE (Poland/NL)IT WEB LTD (BVI) as registrant
93.113.203.0/24RIPEEuropean allocation
185.114.146.0/23RIPEEuropean allocation (/23 = 512 IPs)
192.101.68.0/24ARIN (legacy)American legacy space
193.151.109.0/24RIPEEuropean allocation
195.211.191.0/24RIPEEuropean allocation

A UK company, three years old, announcing IP space from Africa, Europe, and North America โ€” regions governed by three different RIRs (AFRINIC, RIPE, ARIN). This is not how a legitimate ISP operates. Legitimate ISPs typically have IP allocations from their home region's RIR. Acquiring address space from three different RIRs suggests systematic purchase or lease of address blocks on the secondary market โ€” exactly the kind of activity that IP leasing marketplaces like IPXO facilitate.

The Hitrow Discovery

Our active reconnaissance scans of HBING infrastructure revealed something unexpected. The IP 102.129.200.117 โ€” our highest-threat HBING node (threat score 93) โ€” runs a web server on ports 80 and 8080 serving software called Hitrow 1.1.43, with the page title "Welcome to Hitrow."

Hitrow is not a household name. It appears to be a control panel or management interface for IP-based services. Its presence on an IP that attacked our honeypot 42 times suggests that this is not a compromised residential router or a misconfigured cloud instance โ€” this is purpose-built infrastructure for IP-based operations.

๐Ÿ“Š Active Recon: HBING Infrastructure

IPPortServiceProduct
102.129.200.11722SSH(standard)
102.129.200.11780HTTPHitrow 1.1.43
102.129.200.1178080HTTPHitrow 1.1.43

The Passive DNS Trail

Passive DNS resolution for the HBING IPs reveals hostnames that add another layer to the story:

  • 102.129.200.117 โ†’ client.nodomain.vip, mag-tv.net, vodnew.nodomain.vip
  • 45.88.0.252 โ†’ s120.likea8bitboss.xyz
  • 45.148.145.60 โ†’ 45-148-145-60.ipv4.staticdns1.io

The domains tell a story: nodomain.vip is a domain parking service. mag-tv.net and vodnew.nodomain.vip suggest IPTV or streaming content โ€” a common use case for IP addresses leased to avoid geolocation enforcement. likea8bitboss.xyz is a domain name that doesn't inspire confidence in legitimate business operations. staticdns1.io is a generic reverse DNS service used by hosting providers who haven't configured proper PTR records.

The libssh2 Fingerprint

All five HBING IPs share the same SSH client fingerprint: HASSH 14b2ddda386a4d10, identified as libssh2_1.11.0. This fingerprint appears in our database across 628 IPs in 48 countries โ€” it's part of a massive scanning campaign using the libssh2 library.

The shared fingerprint means one of two things: either all five HBING IPs are using the same scanning toolkit (suggesting central coordination), or the HBING infrastructure was compromised and co-opted into a larger botnet. Given that the IPs run Hitrow management panels and share the same corporate infrastructure, central coordination is the more parsimonious explanation.

๐Ÿ”ด Finding: HBING as Coordinated Attack Platform

Five IPs, all on the same bulletproof ASN (risk 95/100), all sharing the same scanning fingerprint (libssh2_1.11.0), all geolocating to the Netherlands despite registrations in 5 different countries, all with 100% AbuseIPDB confidence scores, some running Hitrow management panels, some resolving to IPTV-related hostnames, and all linked to either IPXO or IT WEB LTD (BVI) โ€” this is not accidental misconfiguration. This is a coordinated scanning and credential-testing platform operating through IPXO-managed IP address space.

The 168 attacks on our honeypot over 25 days represent one honeypot's view. If this scanning operation targets the entire IPv4 space (as the 48-country campaign membership suggests), the total attack volume from this infrastructure runs to millions of attempts per day.

Confidence: HIGH โ€” Direct evidence from honeypot data, RDAP, BGP routing, active recon, and passive DNS.

๐Ÿ”ฎ The Conspirationist Asks

Is HBING LIMITED a real company or a shell for IP address abuse?
Companies House registration 13836998 makes it a real company in the legal sense โ€” it has a registration number, a registered address, and (presumably) filed annual returns. But 124 City Road, London EC1V 2NX is a company formation factory. A mail.com email address is the cheapest possible communication channel. A three-year-old company with no website, no public employees, and no visible business operations other than announcing 10 IP prefixes from three continents โ€” this is not a company in any meaningful operational sense. It's a legal wrapper around a set of IP address announcements. Whether it's a shell for IP address abuse or merely a commercial convenience for a legitimate but private entity is unanswerable from public data alone. But the totality of indicators โ€” bulletproof classification, 95/100 risk score, 100% abuse confidence across all observed IPs, free email abuse contact, formation agent address, multi-RIR prefix acquisition โ€” points overwhelmingly toward the former.
Does IPXO know what HBING is doing with its leased addresses?
IPXO's "IPXO Incident Response Team" appears as the RDAP abuse contact for two HBING IPs. This means IPXO has explicitly accepted responsibility for abuse handling on those addresses. If IPXO receives abuse reports about these IPs (and with AbuseIPDB scores of 100%, those reports are being filed), then IPXO either (a) receives and ignores them, (b) receives and responds ineffectively, or (c) has an automated process that doesn't detect the abuse pattern. In any case, the abuse has continued for months across our observation period. 168 attacks over 25 days is not a brief anomaly โ€” it's sustained, deliberate scanning from infrastructure that IPXO has taken responsibility for policing.
Could HBING be an IPXO subsidiary or affiliate operating at arm's length?
We cannot confirm or deny a corporate relationship between HBING LIMITED and IPXO/Internet Utilities Europe and Asia Limited from public data. What we can confirm: (1) IPXO is the named abuse contact for some HBING IPs, (2) HBING and IPXO's RIPE records were both last modified on the same date (2026-05-13), suggesting shared database administration, (3) the IP address blocks announced by HBING appear to have been acquired through the secondary market โ€” exactly IPXO's specialty. A subsidiary relationship would explain these patterns. A customer relationship would also explain them. The distinction matters legally but not operationally โ€” in both cases, IPXO-managed addresses are being used for coordinated attacks, and IPXO has accepted the abuse contact role.

There's a thought experiment that clarifies the IPXO-HBING relationship. Imagine you own a parking garage. A customer rents a space every month. You notice that the customer's car always has fresh scratches, that its license plates change frequently, and that its registration traces to a company at a mail-forwarding address in the British Virgin Islands. Other tenants complain about break-ins near the customer's space. You receive letters from the police asking about the car. You continue renting the space and collecting the monthly payment. Now: are you responsible for what the customer does with the car? Most people would say no โ€” you rent spaces, not supervise driving. But if you also volunteered to be the contact person for traffic violations โ€” if you told the authorities "report any problems to me, I'll handle it" โ€” then the calculation changes. By accepting the abuse contact role, IPXO moved from passive landlord to active intermediary. The question is whether the intermediation is genuine (they actually try to resolve abuse) or performative (the contact role exists to absorb reports without acting on them). Our honeypot data โ€” 168 attacks over 25 days with no apparent mitigation โ€” suggests the latter.

Chapter 9: The Numbers That Matter

Let's talk money. The IP address market is one of the internet's most opaque financial ecosystems, but enough data exists to reconstruct the economics โ€” and they are staggering.

The IPv4 Exhaustion Premium

IPv4 address exhaustion is, by any measure, one of the most foreseeable infrastructure crises in computing history. Engineers have been warning about it since the early 1990s. IPv6 was designed specifically to solve it. The exhaustion timeline was:

๐Ÿ“Š IPv4 Exhaustion Timeline

RegistryExhaustion DateRegion
IANAJanuary 31, 2011Central pool
APNICApril 15, 2011Asia-Pacific
LACNICJune 10, 2014Latin America
ARINSeptember 24, 2015North America
AFRINICApril 21, 2017Africa
RIPE NCCNovember 25, 2019Europe/Middle East

Source: IANA records, verified via Wikipedia IPv4 address exhaustion.

After exhaustion, new allocations effectively stopped (only tiny fragments remain). Any organization needing IPv4 addresses must now acquire them on the secondary market โ€” through purchases or leases. This transformed IPv4 addresses from free administrative resources into tradeable financial assets.

The Price History

The price trajectory tells the story of a market bubble and its partial deflation:

YearAvg Transfer Price/IPAvg Lease Price/IP/monthMarket Event
2018$18$0.45Early market formation
2019$24$0.50RIPE NCC exhaustion
2020$28$0.55COVID demand surge
2021$45$0.60Peak speculation; IPXO launches
2022$48$0.60Market peak
2023$41$0.50Hyperscaler pullback begins
2024$34$0.43Large-block price erosion
2025$25$0.4058M addresses transferred (record)
2026$11-20$0.35Current market

Sources: IPXO Market Stats (June 18, 2026), Brander Group market analysis.

IPXO's Revenue Model

IPXO's revenue comes from commissions on leases. With approximately 6 million IPs actively leased on the platform at ~$0.35/IP/month, the gross lease revenue flowing through the platform is approximately:

$2.1M
Monthly Gross Lease Revenue
$25.2M
Annual Gross Revenue
10-20%
Estimated Commission Rate
$2.5-5M
Estimated Annual IPXO Revenue

This is conservative. It doesn't include IPAM (IP Address Management) software fees, premium services, or revenue from the transfer brokerage side of the business. The $55M "paid to IP owners" figure, spread over approximately 4 years of operation, is consistent with this revenue model (the commission sits on top of the $55M).

The Global Market

IPXO is the largest player, but the total IP leasing market is bigger. Academic research (CAIDA, 2024) found that 4.1% of all advertised IPv4 prefixes are leased โ€” approximately 45+ million IP addresses. At current lease rates:

๐Ÿ“Š The Global IP Leasing Economy

45 million IPs ร— $0.35/IP/month ร— 12 months = ~$189 million/year

This is the minimum estimate for the global IP leasing market. The actual figure is higher because: (a) not all leases are detected by academic crawlers, (b) short-term leases can command premium rates ($0.50-1.00/IP/month), and (c) private/off-platform leases are invisible to researchers. A reasonable estimate for the total addressable market: $200-300 million per year in lease revenue alone, plus $1-2 billion in transfer transactions.

For context: this market barely existed before 2015. IPv4 exhaustion created an asset class from nothing โ€” and the companies that positioned themselves as marketplace operators captured the most valuable position in the value chain.

Who Pays for Abuse?

Here's the critical economic insight: the costs of IP address abuse are externalized. The IP owner earns lease income. IPXO earns commission. The lessee earns whatever revenue their operations generate (legitimate or otherwise). But the costs โ€” abuse reports, blocklisting, credential theft, botnet damage โ€” are borne by the targets of the abuse, by ISPs who process abuse reports, by security researchers who track the threats, and by the internet community at large.

This is a textbook negative externality. The IP leasing market generates private profits while imposing public costs. No mechanism exists to price the externality โ€” there's no "pollution tax" on IP address abuse. The closest equivalent, Spamhaus blocklisting, imposes costs on the IP owner (reduced reputation of their address block) but does not impose costs on the marketplace operator (IPXO's platform reputation is separate from the reputation of individual leased blocks).

๐Ÿ”ฎ The Conspirationist Asks

Is IP address leasing essentially a protection racket?
Not in the traditional sense, but there's a structural analogy. IP address exhaustion created artificial scarcity. The entities that stockpiled addresses before exhaustion (or bought them cheaply in the early secondary market) now control access to a resource that every internet-connected organization needs. The leasing model extracts ongoing rent from this scarcity. The customers have no alternative โ€” IPv6 adoption is still insufficient for most use cases, and buying addresses outright is increasingly expensive. This is a market structured by scarcity, dominated by early movers, and characterized by information asymmetry between marketplace operators and customers. Whether you call it "smart business" or "rent-seeking" depends on your economic philosophy. What it definitely is: the extraction of value from a public resource (IP address space that was originally allocated free of charge to the internet community) by private actors who positioned themselves as intermediaries after exhaustion made that resource scarce.
IPXO claims $55 million paid to IP owners. How much profit did IPXO keep?
If IPXO's commission is 15% of gross lease revenue (industry midpoint), and $55M represents the amount paid after commission, then the gross revenue was approximately $64.7M, with ~$9.7M in commission revenue over 4 years (~$2.4M/year). If 15% is paid before owner payout, the calculation is different. Without audited financials (IPXO is private, with no disclosure requirements beyond Lithuanian corporate law), the precise figure is unknowable. What we know: IPXO operates 51-200 employees from a Kaunas office. At Lithuanian salary levels (average tech salary โ‚ฌ2,500-4,000/month), an 80-person office costs roughly โ‚ฌ4-6M/year in payroll. Add offices, infrastructure, and overhead: operating costs of โ‚ฌ6-10M/year. The commission revenue must exceed this, or the business is unprofitable. Either IPXO's commission rate is higher than 15%, or it has additional revenue streams not captured in the lease marketplace metrics.
What happens to IP address prices if IPXO's largest customers are bulletproof operators?
Bulletproof operators are the ideal customer for an IP leasing marketplace: they need addresses urgently (their current blocks get blocklisted), they pay premium rates (their alternatives are limited), and they churn frequently (creating repeat business). If a significant fraction of IPXO's lease volume comes from operators who use the addresses for abuse, then IPXO's revenue model depends, in part, on abuse. Cleaning up the marketplace โ€” genuinely screening out bulletproof operators โ€” would reduce lease volume and revenue. This is the economic incentive problem at the heart of IP leasing: the marketplace operator profits from the same address churn that abuse creates. Every blocklisted address block is a lease that terminates (revenue loss for this quarter) and a new lease that starts (revenue gain for next quarter). Abuse doesn't destroy the marketplace โ€” it drives it.

Follow the money and you arrive at a paradox. IPXO's business model is optimized for a world where IPv4 addresses are scarce, demand is high, and compliance overhead is low. Everything that increases demand โ€” including demand from abusive operators โ€” increases IPXO's revenue. Everything that decreases abuse โ€” stricter screening, slower onboarding, aggressive lessee monitoring โ€” increases IPXO's costs while reducing its addressable market. The economic incentives point, with mechanical precision, toward permissive due diligence. Not because IPXO wants to facilitate abuse, but because the market rewards it. This is not a moral judgment. It is a structural observation. The IP leasing market, as currently designed, rewards exactly the behavior that the security community deplores. No amount of ISO 27001 certification, no number of blog posts about "how IPXO handles abuse," no RIPE governance participation changes this fundamental economic reality. The incentives are the incentives. And until the externality is priced โ€” until the costs of abuse are borne by those who profit from enabling it โ€” the behavior will continue.

Chapter 10: The Uncomfortable Questions

Every dossier in this series arrives at a point where the evidence demands questions that polite industry discourse avoids. The Lithuanian Connection is no different. The evidence has been presented. The corporate structures have been mapped. The honeypot data has been analyzed. Now we ask the questions that matter.

๐Ÿ”ฎ The Big Questions

1. Is IPXO an abuse enabler or an abuse victim?
IPXO positions itself as a platform that happens to be exploited by bad actors โ€” similar to how Craigslist is used for fraud or how encrypted messaging is used for crime. The platform isn't the problem; the users are. This framing is partially valid. IPXO cannot control what happens on every leased IP address any more than a car manufacturer can control how every car is driven. But the analogy breaks down when you examine the specifics: IPXO voluntarily serves as the abuse contact for IPs on a bulletproof ASN (risk 95/100). IPXO's abuse response has demonstrably failed to mitigate scanning campaigns operating from its managed addresses. And IPXO's predecessor brand (Heficed) had such severe abuse problems that the company rebranded to escape the reputation. At some point, the "we're a victim too" narrative loses credibility. IPXO isn't a bystander. It's the landlord who leased the apartment, put its name on the doorbell, and is now surprised that the tenants are running a chop shop.
2. Is the IP leasing market a legitimate business or a systemic threat to internet security?
Both. IP leasing solves a genuine economic problem: IPv4 exhaustion means organizations need address space, and leasing is cheaper than buying. The market performs a real allocation function. But the same market, absent effective regulation, enables abuse at industrial scale. The CAIDA finding โ€” leased IPs are 5ร— more likely to encounter abuse โ€” is not an anecdote. It's academic research based on 47,000 prefixes. The IP leasing market, in its current form, is to internet security what subprime mortgage securitization was to financial stability: a legitimate financial innovation that, applied without adequate risk controls, creates systemic risk. The innovation isn't the problem. The absence of guardrails is.
3. Is Lithuania's regulatory environment a feature or a bug?
For IPXO, it's a feature. Lithuania offers EU legitimacy, low costs, minimal regulatory friction, and โ€” critically โ€” a data protection authority (VDAI) whose enforcement record is so sparse that GDPRhub.eu's page for it is essentially blank. For internet security, it's a bug. Not because Lithuania is corrupt or negligent โ€” but because the regulatory framework wasn't designed for companies that manage 14 million IP addresses from a city of 315,000 people. Lithuania's regulatory capacity is calibrated for its economy's size and complexity. IPXO's operations exceed that calibration by orders of magnitude. The result: a company with global internet infrastructure significance operating under small-country oversight.
4. Could a state intelligence service use IPXO's marketplace to acquire untraceable infrastructure?
The workflow would be: (1) Create a shell company in a permissive jurisdiction (BVI, Seychelles, Delaware). (2) Register as a RIPE NCC member. (3) Lease IP addresses through IPXO. (4) Announce them through a transit provider in a neutral country (Netherlands, Germany, Romania). At no point would the state connection be visible. IPXO's KYC would see the shell company's documentation. The RIPE database would show the shell company's ASN. The BGP routing would show Dutch or German origin. The actual operator โ€” sitting in Moscow, Beijing, Washington, or Tel Aviv โ€” would be invisible. This is not theoretical. Our honeypot data shows IPs with RDAP registrations in the US, geolocations in the Netherlands, ASN registrations in the UK, and RIPE maintenance from the BVI. The jurisdictional complexity that makes legal attribution difficult also makes intelligence attribution impossible. And IPXO's marketplace โ€” designed for speed, scale, and minimal friction โ€” is the perfect procurement channel for such an operation.
5. What is IPXO's relationship with HBING LIMITED and IT WEB LTD?
Officially: unknown. We have asked no questions because this is a research dossier, not an investigation with subpoena power. What the data shows: IPXO appears as the abuse contact for HBING IPs. IT WEB LTD (BVI) appears as the RDAP registrant for other HBING IPs. Both entities' RIPE records were last modified on the same date (May 13, 2026). The IP addresses flow through the same ASN, geolocate to the same country, and share the same scanning fingerprint. If these are independent entities with no formal relationship, their operational convergence is remarkable. If they are related โ€” through corporate ownership, commercial agreements, or shared management โ€” then IPXO's due diligence narrative requires fundamental revision. In either case, the outcome is identical: IPXO-managed addresses are attacking our honeypot, and nobody is stopping them.
6. Why did IPXO admit to "nearly a hundred" Spamhaus listings?
In August 2024, IPXO's Customer Solutions Team Lead, Migle Remeike, published a blog post acknowledging that IPXO had "nearly a hundred listings" on Spamhaus at peak (early 2023). This admission, while framed as a redemption narrative ("we fixed it"), is extraordinary. Nearly 100 Spamhaus listings for a single entity is a catastrophic abuse record. Spamhaus doesn't list addresses trivially โ€” each listing represents verified, sustained abuse that didn't respond to standard remediation. That IPXO accumulated 100 such listings suggests that its abuse response was, for a significant period, essentially non-functional. The reduction to "single digits" represents improvement, but the starting point โ€” a hundred listings โ€” represents a scale of abuse facilitation that few organizations in internet history have matched. And this was after the Heficed rebrand. The pre-rebrand abuse record, under the Heficed and Digital Energy Technologies brands, is unquantified.
7. Is the "IP address marketplace" concept inherently incompatible with internet security?
Not inherently โ€” but the current implementations are. A marketplace with genuine due diligence, real-time abuse monitoring, automatic lease termination for confirmed abuse, and mandatory abuse reporting to RIRs could exist. It would be more expensive to operate, slower to onboard customers, and less profitable than the current model. The market has chosen the profitable model over the secure model. This choice, repeated across every IP leasing platform, has created a parallel internet economy where addresses are laundered like money โ€” acquired cleanly, used dirtily, returned, and re-leased to the next customer. The marketplace provides the same service that shell companies provide in financial crime: a layer of indirection between the asset and its use.
8. What would an effective regulatory response look like?
Three mechanisms could address the problem: (1) RIR-level regulation: RIPE NCC could require the same due diligence for temporary delegations (leases) as for permanent transfers. This would add cost and friction but would close the policy gap. (2) EU-level regulation: The EU's NIS2 Directive could classify IP address marketplaces as "essential service providers," triggering mandatory abuse reporting, incident notification, and regulatory oversight. (3) Financial regulation: IP addresses are financial assets. IP leasing is asset rental. These activities could fall under existing financial services regulation in EU member states, triggering KYC/AML requirements equivalent to what banks face. None of these approaches would eliminate abuse. All would increase the cost of abuse, which is the only reliable mechanism for reducing it.

The uncomfortable truth about the Lithuanian connection is that it works because everything is legal. Lithuanian incorporation: legal. UK shell companies: legal. BVI entities: legal. IP address leasing: legal. RIPE database manipulation: technically compliant with policy. Abuse report handling (or non-handling): not subject to enforceable standards. Every component of the system is individually lawful. It is only when you assemble the components โ€” Lithuanian operations, UK credibility, BVI opacity, RIPE permissiveness, marketplace commission incentives, ISO 27001 cover, serial rebranding โ€” that the pattern becomes visible. And the pattern is this: the IP leasing market has created a legally compliant mechanism for distributing internet resources to operators who use them for attacks. No law is broken. No regulation is violated. No enforcement action is possible under current frameworks. The attackers hitting our honeypot did so from infrastructure that is, by every formal measure, legitimately operated. The system works exactly as designed. It's just that the design serves the marketplace operators, not the internet community.

Chapter 11: Final Assessment โ€” The Architecture of Plausible Deniability

This dossier has traced a single thread โ€” IPXO UAB and its role in the IP address leasing ecosystem โ€” from a Kaunas office to our honeypot's log files. The journey passed through corporate structures spanning five jurisdictions, governance bodies whose policies are shaped by the entities they govern, certification frameworks that certify process but not outcomes, and an economic model where abuse is a revenue driver disguised as a compliance problem.

What We Found

โš–๏ธ Strategic Findings

Finding 1: IPXO is the largest IP address marketplace on Earth, and its abuse controls are demonstrably inadequate.

Managing 14 million IPv4 addresses (~0.4% of the entire usable IPv4 space) through 63,000+ leases, IPXO has achieved market dominance. But our honeypot data shows IPXO-managed addresses (specifically, addresses where IPXO is the named abuse contact) participating in sustained scanning campaigns from a bulletproof ASN with a 95/100 risk score. IPXO's own disclosure acknowledges "nearly 100" Spamhaus listings at peak. Academic research confirms that leased IP space is 5ร— more likely to encounter abuse. The conclusion is inescapable: IPXO's due diligence and abuse response capabilities do not scale with its marketplace volume.

Finding 2: The corporate structure is designed for insulation, not transparency.

Lithuanian operations (low cost, light regulation) + UK entity (RIPE credibility, establishment legitimacy) + Texas LLC (ARIN access) + BVI connections (via customers like IT WEB LTD) = a jurisdictional architecture where no single regulator sees the complete picture. This is legal, common in international business, and devastatingly effective at preventing accountability. The rebrand from Digital Energy Technologies โ†’ Heficed โ†’ IPXO adds a temporal dimension to the insulation: even within a single jurisdiction, historical abuse records are effectively erased by corporate name changes.

Finding 3: RIPE NCC governance has a structural conflict of interest.

IPXO's VP of Strategic Alliances, Paulius Judickas, was elected to the RIPE Programme Committee in June 2026. IPXO's co-founder Vincentas Grinius has been active in RIPE governance. These are the people who benefit from permissive IP leasing policies sitting on the bodies that set those policies. This is not corruption โ€” it's structural capture. The policy gap that allows temporary IP delegations to bypass transfer-level due diligence exists because the entities that profit from the gap participate in the governance that could close it.

Finding 4: ISO 27001 certification provides legitimacy disproportionate to its security value.

IPXO's ISO 27001 certification certifies its internal security management system. It does not certify that its marketplace is safe, that its lessees are legitimate, or that its abuse response is effective. The certification is used as a general-purpose credibility signal โ€” "we're certified, therefore we're trustworthy" โ€” but the scope of what it certifies is dramatically narrower than what stakeholders infer. This inferential gap is exploited, whether intentionally or not, to deflect scrutiny.

Finding 5: The IP leasing market has created a negative externality that no current mechanism prices.

IP address owners earn lease income. IPXO earns commission. Lessees earn operational revenue. The costs of abuse โ€” blocklisting, credential theft, botnet damage, security operations โ€” are borne entirely by the targets and the broader internet community. This is a classic externality: private profit, public cost. Until the externality is priced (through regulation, liability assignment, or market mechanisms), the IP leasing market will continue to optimize for volume over safety.

What We Didn't Find

This dossier does not prove that IPXO is a criminal organization. It does not prove that Vincentas Grinius or any IPXO employee knowingly facilitates cybercrime. It does not prove that HBING LIMITED is an IPXO subsidiary. What it proves is that the IP leasing marketplace, as IPXO has built and operates it, creates the conditions under which abuse flourishes โ€” and that the incentives of the marketplace align with perpetuating, not preventing, that abuse.

The Lithuanian connection is not a scandal. It's a structure. And structures, unlike scandals, don't resolve themselves when exposed. They continue operating, invisibly, as long as the incentives that created them remain unchanged.

Recommendations

๐Ÿ›ก๏ธ For Network Defenders

  • Monitor IPXO-managed address space with heightened scrutiny โ€” RDAP queries for "IPXO" or "Internet Utilities Europe" in abuse contacts should trigger enhanced logging
  • Track RIPE database changes on known IPXO LIR objects (ORG-IL687-RIPE) for new prefix delegations
  • Block or rate-limit AS208949 (HBING LIMITED) โ€” our data shows 100% malicious activity from all observed IPs
  • Treat IT WEB LTD (BVI) entities and the abuse.webltd@gmail.com contact as indicators of bulletproof infrastructure
  • Deploy HASSH-based detection for 14b2ddda386a4d10 (libssh2_1.11.0) โ€” this fingerprint spans 628 IPs across 48 countries

๐Ÿ›๏ธ For Policy Makers

  • Close the temporary delegation loophole in RIPE NCC transfer policy โ€” require equivalent due diligence for leases and permanent transfers
  • Classify IP address marketplaces under NIS2 Directive as essential service providers
  • Mandate abuse reputation transfer across corporate rebrands โ€” RIPE and other RIRs should track organizational genealogy
  • Require conflict of interest declarations for RIPE governance participants with commercial interests in the topics being discussed
  • Expand ISO 27001 scope expectations for marketplace operators to include customer due diligence

Sources & Methodology

๐Ÿ“š Primary Sources

  • Honeypot data: Cowrie SSH honeypot, 25-day observation window (May 21 โ€“ June 15, 2026)
  • Threat intelligence database: 8,000+ enriched IPs with multi-source correlation (AbuseIPDB, Shodan, GreyNoise, RDAP, Cymru, OTX, Censys, VirusTotal, Pulsedive)
  • Active reconnaissance: Tor-routed nmap/httpx scans of attacker infrastructure
  • RIPE NCC database: REST API queries for organization, ASN, and inetnum records
  • IPXO public disclosures: Blog posts (August 2024 abuse handling, March 2026 ARIN community, June 2026 RIPE Programme Committee)
  • IPXO Market Stats: https://www.ipxo.com/market-stats/ (updated June 18, 2026)
  • Academic research: CAIDA "Sublet Your Subnet: Inferring IP Leasing in the Wild" (2024)
  • Market data: Brander Group IPv4 market analysis, IPXO RIR policy comparison (October 2025)
  • Companies House (UK): Company numbers 12540160, 13836998
  • IPv4 exhaustion data: IANA/RIR official records

๐Ÿ“ Methodology

This dossier follows the Phantom ASN Ecosystem methodology established in TI-2026-026A:

  • Evidence hierarchy: Direct observation (honeypot logs) โ†’ Technical enrichment (multi-source OSINT) โ†’ Structural analysis (corporate/BGP/RIPE records) โ†’ Inference (patterns that require interpretation)
  • Confidence calibration: HIGH = direct evidence + multi-source corroboration. MEDIUM = strong indicators, limited corroboration. LOW = pattern-based inference. All findings are tagged.
  • Conspirative analysis: Every significant finding is examined from both the "legitimate explanation" and "adversarial explanation" perspectives. The dossier does not assume malice where incompetence suffices, but it also does not assume incompetence where structural incentives point toward deliberate facilitation.
  • Limitations: This research uses publicly available data and our own honeypot observations. We have not contacted IPXO, HBING LIMITED, or IT WEB LTD for comment. We have not accessed non-public corporate registries (Lithuanian Registrลณ centras, UK Companies House detailed filings). Corporate beneficial ownership information beyond public records has not been verified.

The Phantom ASN Ecosystem Series

This dossier is part of an independent threat intelligence research project. All findings are based on publicly available data, honeypot observations, and open-source intelligence. No classified or proprietary data was used. Published at shuffle-on.com/threat-intel.

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Phantom ASN โ€” 14 / 17 Next โ†’