Executive Summary

Julian Achter, a sole proprietor operating from a residential house in Ismaning (Munich suburb), runs one of Europe's most consequential anonymous infrastructure services. His brand "Aluy" โ€” themed around the 1998 anime Serial Experiments Lain โ€” offers ASN sponsoring at โ‚ฌ71/year with Monero payment and no mandatory identity verification. The result: a functional anonymous ASN marketplace where anyone can acquire legitimate RIPE-registered internet routing resources with zero trace.

His AS211507 has been completely blacklisted by Spamhaus (ASN-DROP โ€” all 2,304 IPv4 addresses), has hosted confirmed Sliver C2 command-and-control servers, and provides infrastructure for 31+ Tor relays including the "Satanist" (2cb.li) network. Yet it remains operational, serving customers who specifically seek infrastructure that ignores reputation.

2,304IPs on Spamhaus ASN-DROP
โ‚ฌ71/yrASN sponsoring price
5Countries with infrastructure
31+Tor relays hosted
2Confirmed C2 servers (2026)
7IXPs peered

Confidence: HIGH โ€” Primary source is Achter's own published legal documentation (imprint, ToS, AUP, privacy policy), cross-referenced with RIPE STAT, PeeringDB, Spamhaus ASN-DROP list, Shodan C2 intelligence feeds, OrNetStats Tor relay data, and our honeypot observations.

Chapter 1: The Man Behind the Mask

Unlike the corporate obfuscation of 1337 Services GmbH (TI-2026-030A), Julian Achter publishes his identity openly. His legal imprint page reads like a deliberate act of transparency:

Legal Identity โ€” aluy.net/legal/imprint

FieldValueVerification
Full NameJulian AchterLegal imprint (German Impressumspflicht)
Business FormEinzelunternehmen (sole proprietorship)No corporate veil; unlimited personal liability
Trading As"Aluy"PeeringDB org 40917
AddressAm Hang 55, 85737 Ismaning, BayernNominatim: class=building, type=house (residential)
VAT IDDE357114586Registered with Finanzamt Mรผnchen
Contactlain@aluy.net / +4915118462887Telekom/congstar mobile prefix

Am Hang 55 is a residential house in Ismaning โ€” an affluent Munich suburb 15km northeast of the city center. OpenStreetMap/Nominatim returns coordinates (48.2216ยฐN, 11.6621ยฐE) that precisely match PeeringDB's registered location for his organization. He runs bulletproof hosting infrastructure blacklisted across the entire internet from his home.

The choice of Einzelunternehmer (sole proprietor) is significant. Unlike a GmbH which limits liability to share capital, Achter personally carries unlimited liability for all business debts and legal judgments. This is either extremely reckless for someone hosting C2 infrastructure โ€” or demonstrates absolute confidence that jurisdictional friction will prevent enforcement from ever reaching his doorstep.

The Transparency Paradox: Achter publishes more identifying information than any other actor in this investigation series. His name, address, VAT number, and phone number are all public. Yet his customers can remain completely anonymous. The transparency applies only to the marketplace operator โ€” not to those who use it.

Chapter 2: "We Love Lain" โ€” The Cultural Signal

Every element of Achter's infrastructure carries the Serial Experiments Lain branding:

  • RIPE NIC handle: LAIN
  • RIPE AS description: "LAIN we love lain, cats and the world wide web, DE"
  • PTR record pattern: lain.[IP].aluy.net
  • Email prefix: lain@aluy.net
  • PeeringDB notes: "we love lain, cats and the world wide web โ€” privacy | free speech | anonymity โ€” ^^ if you dont like those, go away ^^"

Serial Experiments Lain (1998) explores the dissolution of boundaries between physical and digital identity โ€” its protagonist discovers she IS the Wired (the internet). In cypherpunk circles, referencing "Lain" signals:

  1. Ideological alignment with anonymity, decentralization, identity-as-performance
  2. Community membership in specific IRC/Matrix/imageboards where the anime is canonical
  3. A post-cypherpunk aesthetic popular in 2010s/2020s privacy communities

The phrase "if you dont like those, go away" is not marketing copy โ€” it's a boundary statement. This is ideological infrastructure. The anime reference functions as a cultural passport: those who recognize it understand the service's nature without it needing to be stated explicitly.

His PeeringDB organization was created 2021-10-21 โ€” over three years before AS211507 was allocated (2025-03-17). This suggests Achter was active in the hobbyist BGP community well before obtaining his own ASN, likely operating under someone else's infrastructure first.

Chapter 3: The Anonymous ASN Marketplace

Achter's Aluy offers a complete stack for anonymous internet presence:

Service Offering

  • VPS (Virtual Private Servers)
  • Dedicated servers (resells Hetzner auction hardware + own equipment)
  • ASN sponsoring via RIPE LIR โ€” โ‚ฌ71/year
  • IPv4/IPv6 address allocation
  • BGP transit

Payment Methods

  • PayPal, credit card, Klarna, Apple Pay, Google Pay
  • Monero (privacy cryptocurrency โ€” ring signatures, stealth addresses, effectively untraceable)

The KYC Gap

From the Terms of Service:

"Identity verification may be required when fraud prevention measures indicate it is necessary."

From the Privacy Policy:

"Verification may be requested when legally required or when fraud prevention measures indicate it is necessary."

The critical word is "may". Identity verification is discretionary, not mandatory. This creates a functional payment-to-ASN pipeline:

Anonymous ASN Procurement Chain

Customer โ†’ Monero payment (untraceable) โ†’ Aluy receives XMR
    โ†’ No KYC verification (discretionary, not triggered)
    โ†’ RIPE LIR sponsoring application filed
    โ†’ ASN assigned to customer-provided identity
    โ†’ Customer has legitimate RIPE-registered routing resources
    โ†’ Zero link between payment and RIPE registration

Under RIPE NCC policy, a sponsoring LIR is responsible for vouching for End User legitimacy and ensuring resources are used as specified. Achter's "may verify" policy effectively delegates this RIPE compliance obligation to a discretionary process that, by design, rarely triggers.

Pricing Economics

ParameterValue
RIPE NCC LIR annual fee~โ‚ฌ1,400โ€“2,000/year
ASN sponsoring price (Aluy)โ‚ฌ71/year per client
Break-even (LIR fees only)~20โ€“28 clients
Revenue at 50 clientsโ‚ฌ3,550/year
Competitor pricing (SnapServ etc.)โ‚ฌ100โ€“300/year

At โ‚ฌ71/year โ€” significantly below competitors โ€” ASN sponsoring is either a loss leader for VPS hosting revenue, an ideological commitment to accessibility, or both. The price point makes anonymous internet routing resources available to anyone with a Monero wallet and โ‚ฌ71.

Chapter 4: The Nuclear Option โ€” Spamhaus ASN-DROP

Spamhaus ASN-DROP is the internet's most severe reputation sanction. Unlike individual IP listings, ASN-DROP blacklists an entire autonomous system โ€” every IP announced by that ASN is null-routed by any network accepting Spamhaus feeds.

Spamhaus ASN-DROP Listing โ€” AS211507 (LAIN)

; Julian Achter
; AS211507

45.67.138.0/24      ; Amsterdam, NL
45.133.73.0/24      ; Hong Kong, HK
45.137.69.0/24      ; Turku, FI
45.137.201.0/24     ; Sofia, BG
45.141.117.0/24     ; Amsterdam, NL
45.141.119.0/24     ; Zug, CH
92.119.164.0/23     ; Amsterdam, NL (two /24s)
185.132.53.0/24     ; Amsterdam, NL โ€” Sliver C2 + primary Tor exits

Source: borestad/iplists โ€” spamhaus/spamhaus-asndrop.ipv4

All 2,304 IPv4 addresses are blacklisted. This is the internet equivalent of excommunication โ€” and yet the infrastructure remains fully operational. The customers who choose LAIN are specifically seeking hosting that ignores reputation sanctions. Being on Spamhaus DROP is not a bug; for the target demographic, it's a feature that confirms the infrastructure's bulletproof nature.

The Bulletproof Paradox: A legitimate hosting provider would treat ASN-DROP as an existential threat requiring immediate remediation. For LAIN, the blacklisting actually validates the service's value proposition to its customer base. The worse the reputation, the stronger the signal that abuse reports are ignored.

Chapter 5: Command and Control โ€” The Sliver Evidence

The Shodan C2 Intelligence Feed documents two confirmed Sliver command-and-control servers on LAIN infrastructure in 2026:

IPPortProductSSL CNDate DetectedPTR Record
185.132.53.831337Sliver C2"multiplayer"2026-03-27lain.185.132.53.8.aluy.net
185.132.53.7631337Sliver C2"multiplayer"2026-05-15lain.185.132.53.76.aluy.net

Sliver is an open-source adversary simulation framework increasingly adopted by real threat actors (replacing Cobalt Strike). The "multiplayer" SSL common name is a Sliver default. Port 31337 ("elite" in hacker culture) is a deliberate cultural choice.

Both instances are in the 185.132.53.0/24 Amsterdam block โ€” the same subnet that hosts primary Tor exits (tor-exit.nl.2cb.li at .121). This co-location of C2 infrastructure with Tor exits on the same /24 creates perfect cover: the high volume of Tor traffic masks C2 communications.

JARM fingerprint (both): 00000000000000000043d43d00043de2a97eabb398317329f027c66e4c1b01

Achter's own AUP explicitly prohibits: "Malware, ransomware, botnet C2, exploit kits." Two confirmed violations in two months demonstrates that stated policy and actual enforcement are entirely disconnected.

Chapter 6: The Transit Architecture โ€” Friction by Design

AS211507's BGP transit chain reveals a deliberate choice of routing through small, hobbyist ASNs rather than major carriers:

BGP Transit Paths

DestinationTransit Chain
Netherlands (4 prefixes)...โ†’ AS216265 (ARISTO) โ†’ AS50917 (de Zee) โ†’ AS216078 (Trivox/Kremer) โ†’ AS211507
Switzerland (2 prefixes)...โ†’ AS51395 (Datasource AG) โ†’ AS211507
Finland (1 prefix)...โ†’ AS207003 (Web1 Oy) โ†’ AS213468 (tietokettu) โ†’ AS211507
Bulgaria (1 prefix)...โ†’ AS57344 โ†’ AS203380 (DA International) โ†’ AS211507
Hong Kong (1 prefix)...โ†’ AS135330 (ADCDATA.COM) โ†’ AS211507

The Netherlands path โ€” carrying 4 of 9 prefixes including the high-abuse 185.132.53.0/24 โ€” transits through three small/hobbyist ASNs before reaching LAIN. Each hop is a separate legal entity, often a sole proprietor in a different jurisdiction. An abuse complaint must traverse: reporter โ†’ ARISTO โ†’ de Zee โ†’ Trivox โ†’ LAIN โ€” each with different response times and procedures.

AS216078 โ€” The Trivox Node

Liam Kremer / Trivox is the critical upstream. This ASN appears in:

  • AS211507's BGP path (multiple NL prefixes)
  • AS199428's BGP path (Navas/Achter customer)
  • Tor Project "Good Bad ISPs" database โ€” listed immediately after Aluy in Germany section

The clustering of LAIN, Trivox, and 1337 Services in the same Tor Project endorsement list suggests a tight European privacy-infrastructure community sharing ideological alignment and, in some cases, direct transit relationships.

IXP Presence

7 Internet Exchange Points across 4 countries โ€” all community/free exchanges:

IXPLocation
BGP.ExchangeAmsterdam + Zurich
Lynqia IXAmsterdam
BEE-IXBelgium
Protocol 7 IXHong Kong + Tokyo
DataSphere IXHong Kong

Notably absent: AMS-IX, DE-CIX, NL-IX โ€” the major European exchanges. LAIN exclusively uses free/community exchange points, consistent with a small operator minimizing costs while maximizing routing diversity.

Chapter 7: The Tenant Ecosystem

2cb.li / "Satanist" โ€” The Tor Exit Operator

The most documented tenant on LAIN infrastructure operates under the handle "Satanist" with contact admin@2cb.network. Their Tor relays on AS211507:

Relay NameIPCountrySpeedVerified Hostname
"dismal"185.132.53.121๐Ÿ‡ณ๐Ÿ‡ฑ NL92 Mbit/stor-exit.nl.2cb.li
"dim"45.137.201.5๐Ÿ‡ง๐Ÿ‡ฌ BG175 Mbit/sโ€”
"die"45.141.119.80๐Ÿ‡จ๐Ÿ‡ญ CH106 Mbit/sโ€”
"dreary"45.137.69.9๐Ÿ‡ซ๐Ÿ‡ฎ FI102 Mbit/sโ€”

Part of a 22-relay family. The naming convention ("dismal", "dim", "die", "dreary") follows a dark aesthetic. The relays are distributed across all four of LAIN's European countries โ€” matching the geofeed segments exactly.

sy.st โ€” Achter Himself as Tor Operator

Our passive reconnaissance revealed that tor-01.sy.st resolves to 185.102.217.65 โ€” an IP that also hosts aluy.net services. The sy.st domain:

  • Runs XMPP servers (groups.xmpp.sy.st)
  • Uses ProtonMail for email
  • Shares IP infrastructure with aluy.net

This means Achter doesn't merely host Tor exits โ€” he operates them personally under the sy.st domain. He is simultaneously the infrastructure provider, LIR sponsor, AND a Tor exit operator on his own network.

AS199428 โ€” Alvaro Navas (Granada, Spain)

The only confirmed sponsored ASN via RIPE STAT data:

  • Maintained by lir-de-lain-1-MNT (Achter's LIR)
  • Created: 2026-04-02
  • IPv4: 87.121.79.0/24 (via Neterra, Bulgaria)
  • IPv6: 2a14:c380:280::/44 โ€” carved directly from Achter's own 2a14:c380::/29
  • Transit: AS216078 (Trivox) โ€” same upstream as LAIN itself
  • Confirmed Tor exit at 87.121.79.14

Achter is simultaneously the RIPE LIR sponsor, IPv6 allocator, and connected-network peer for Navas โ€” complete vertical integration of the LIR service stack.

The "Forest" Operator โ€” 40 Unidentified Relays

An unidentified operator (contact: forest-relay-contact@cryptolab.net) runs approximately 40 Tor relays (15 middle + 16 exit) across LAIN's NL/BG/FI/CH infrastructure. This is the largest relay family on AS211507 by count. The operator's identity is not established. If "Forest" is a state actor or criminal group positioning for traffic correlation, LAIN's bulletproof nature provides perfect operational cover.

Chapter 8: Geographic and Jurisdictional Engineering

Five-Country Infrastructure Distribution

CountryPrefixesStrategic Logic
๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands4 ร— /24 + /23Cheap dedicated servers; Tor-friendly jurisdiction; largest concentration
๐Ÿ‡จ๐Ÿ‡ญ Switzerland (Zug)2 ร— /24Strong privacy laws; "Crypto Valley"; premium jurisdiction
๐Ÿ‡ซ๐Ÿ‡ฎ Finland (Turku)1 ร— /24Privacy-protective legislation; Nordic DC facilities
๐Ÿ‡ง๐Ÿ‡ฌ Bulgaria (Sofia)1 ร— /24Very low server costs; Neterra colocation
๐Ÿ‡ญ๐Ÿ‡ฐ Hong Kong1 ร— /24Asian market reach; historically less regulated

No infrastructure in Five Eyes countries. The AUP explicitly states: "rented dedicated servers in NL, BG, CH, and FI." Hong Kong is absent from this statement despite being present in the geofeed โ€” suggesting a newer or different arrangement.

Geofeed Manipulation

The domain geo.aluy.net serves a geofeed file via BunnyCDN (aluy-geofeed.b-cdn.net). This self-reported geolocation data is consumed by MaxMind, IPinfo, and other geolocation databases. The technique allows Achter to declare where his IPs "are" โ€” which may or may not match physical server location.

This is the exact same technique documented in TI-2026-030A for 1337 Services (rdp.sh geofeed). Two independent actors in the same ecosystem using identical geolocation manipulation methods suggests either shared knowledge, shared tooling, or the technique being well-known within this community.

The Cryptocurrency Layer

DNS records for aluy.net reveal:

  • seed.aluy.net (92.119.164.86) โ€” cryptocurrency seed node on AS211507
  • seed2.aluy.net, seed3.aluy.net โ€” additional seed nodes
  • PawPayments integration (TXT records) โ€” crypto payment processing
  • Monero acceptance explicitly advertised

The cryptocurrency seed nodes on his own bulletproof infrastructure suggest Achter operates within the privacy-cryptocurrency ecosystem not merely as a payment acceptor but as infrastructure provider for cryptocurrency networks themselves.

Chapter 9: Legal Architecture โ€” The Sole Proprietor's Gambit

German Law Obligations

Achter's privacy policy explicitly cites ยง100j TKG (Telecommunications Act) as legal basis for law enforcement data disclosure. As an LIR/ISP, he likely qualifies as a "Telekommunikationsdienst" under TKG 2021, triggering:

  • Traffic data retention obligations (ยง174 TKG โ€” legally disputed in Germany)
  • Law enforcement cooperation requirements (ยง170 et seq. TKG)
  • Abuse handling obligations

No evidence of BNetzA (Federal Network Agency) registration was found. The absence may be legal for non-telephone IP services, or may represent a compliance gap.

RIPE NCC Accountability

Per RIPE policy, a sponsoring LIR is responsible for resources it sponsors to End Users. If abuse is demonstrated, RIPE NCC can:

  1. Issue warnings
  2. Require remediation
  3. Terminate LIR membership
  4. Revoke all sponsored resources

This is the key enforcement lever. RIPE NCC could revoke LAIN's LIR status, stripping all sponsored ASNs (including AS199428/Navas) of their legitimacy. That this hasn't happened despite ASN-DROP status and documented C2 suggests either: RIPE hasn't received formal complaints through proper channels, or the process is slow.

The Unlimited Liability Calculation

As Einzelunternehmer, Achter has no corporate veil. Any judgment against Aluy can be enforced against his personal assets โ€” including the residential property at Am Hang 55. Either:

  1. He genuinely believes enforcement will never reach him (jurisdictional confidence)
  2. He has structured personal assets to be judgment-proof (common in Germany via family trusts)
  3. He is young enough that personal asset exposure is minimal

Given the PeeringDB account from 2021 and the cultural signaling, option 3 seems most probable โ€” a young operator (likely early-to-mid 20s) with minimal assets to protect and strong ideological commitment to privacy infrastructure.

Chapter 10: The Ecosystem Position

LAIN vs. 1337 Services โ€” Parallel, Not Subordinate

Our investigation definitively establishes that LAIN and 1337 Services are parallel actors, not collaborators:

DimensionLAIN (AS211507)1337 Services (AS210558)
LIR Maintainerlir-de-lain-1-MNTlir-de-1337services-1-MNT (separate)
Primary TransitAS216078 (Trivox)AS14315 (1GSERVERS, LLC)
Business FormEinzelunternehmenGmbH (HRB 164175)
Capacity10-20 Gbps50-100 Gbps
LocationIsmaning (Munich)Hamburg
IdentityOpenly publishedCorporate shell + SHA1 hash

The connection is cultural and demographic โ€” both serve the same European privacy-infrastructure community, both are endorsed by the Tor Project, both explicitly allow Tor exits, both use geofeed manipulation. But their RIPE structures, transit chains, and corporate forms are entirely independent.

The European Privacy-Hosting Cluster

The Tor Project's "Good Bad ISPs" database reveals a tight cluster of German-based operators:

  1. 1337 Services GmbH (Hamburg) โ€” AS210558
  2. Aluy / LAIN (Ismaning) โ€” AS211507
  3. Trivox / Liam Kremer โ€” AS216078 (LAIN's upstream)
  4. SnapServ Interaktiv โ€” Germany

These operators share: Tor-friendly policies, privacy-cryptocurrency acceptance, hobbyist BGP community membership, and the "Serial Experiments Lain" / cypherpunk cultural aesthetic. They are nodes in a European privacy-infrastructure network that functions as a distributed anonymity factory โ€” each independent, but collectively providing the ecosystem that makes anonymous internet presence possible.

Chapter 11: Honeypot Correlation

Our honeypot infrastructure tracked 20 IPs on AS211507 with the following profile:

MetricValue
IPs observed20
Threat score range5.0 โ€“ 55.4
AbuseIPDB confidence range33% โ€“ 100%
Countries (by geofeed)NL, CH, BG, FI
Primary activitySSH bruteforce, port scanning

The threat scores cluster below 60 โ€” lower than typical bulletproof hosting (cf. 1337 Services IPs scoring 70-90+). This suggests LAIN's abuse profile is more "neglected enforcement" than "actively malicious operation." The C2 instances are customer-operated; the scanning may be Tor exit traffic rather than intentional attacks.

Entity link analysis reveals ORG-JA600-RIPE (Julian Achter's RIPE organization) connecting all 20 IPs through shared RDAP registration โ€” confirming single-operator ownership of the entire IP footprint.

Conclusions

What Julian Achter Built

A functional anonymous ASN marketplace operating under German sole proprietorship law. For โ‚ฌ71/year and a Monero payment, anyone can acquire legitimate RIPE-registered internet routing resources with no identity verification. The infrastructure is explicitly designed to be immune to reputation-based enforcement (Spamhaus, AbuseIPDB) โ€” because the customers specifically seek that immunity.

The LIR Marketplace Model

This is the third position in our Anonymity Factory series: not the corporate shell (030A), not the complicit small ISP (030B), but the ideologically-committed sole proprietor who openly publishes his identity while enabling anonymous internet presence for others. The marketplace operator's transparency is the mechanism that enables customer opacity.

Key Intelligence Findings

  1. AS211507 is fully Spamhaus ASN-DROP blacklisted โ€” all 2,304 IPs, the nuclear option
  2. Confirmed Sliver C2 on two IPs in 2026, violating Achter's own AUP
  3. Achter operates Tor exits personally (sy.st domain shares IP with aluy.net)
  4. No mandatory KYC + Monero = functional anonymous ASN procurement pipeline
  5. 31+ Tor relays including 2cb.li ("Satanist"), sy.st (Achter), and "Forest" (40 unidentified)
  6. Geofeed manipulation identical to 1337 Services technique (geo.aluy.net โ†’ BunnyCDN)
  7. Residential address operation with unlimited personal liability โ€” maximum exposure, maximum ideological commitment
  8. Five-country distribution avoids Five Eyes, optimizes for privacy jurisdictions

Series Position

If 1337 Services (030A) is the factory and SERVPERSO (030B) is the negligent supplier, then LAIN is the marketplace โ€” the storefront where anonymous actors can acquire the building blocks of internet identity. The โ‚ฌ71 price point and Monero acceptance make this accessible to anyone. No corporate complexity required. No intermediaries. Just a young man in a Munich suburb, a residential internet connection, and an ideology that says anonymity is a right worth providing โ€” regardless of what that anonymity enables.

Next in series: TI-2026-030D โ€” The Satanist (the anonymous Tor exit operator 2cb.li who is LAIN's most documented tenant).

Methodology & Sources

This investigation combines:

  • Primary sources: aluy.net legal pages (imprint, ToS, AUP, privacy policy), RIPE STAT whois data, PeeringDB API, BGP looking glass
  • Threat intelligence feeds: Spamhaus ASN-DROP list, Shodan C2 Intelligence Feed (acquiredsecurity), AbuseIPDB
  • Tor network data: nusenu/OrNetStats relay statistics, Tor Project Good Bad ISPs database
  • Passive reconnaissance: DNS records (A, MX, TXT, CNAME), certificate transparency, reverse DNS
  • Geolocation verification: OpenStreetMap/Nominatim geocoding, PeeringDB coordinates
  • Honeypot observations: 20 IPs tracked on AS211507 via LSN Cowrie deployment
  • Existing dossier corpus: Cross-references with TI-2026-030A (1337 Services) and TI-2026-030B (SERVPERSO)

All claims are sourced. Confidence levels: HIGH (documented evidence from multiple sources), MEDIUM (single reliable source or strong inference), LOW (circumstantial or unverified). Implications are tagged [DOCUMENTED] or [INFERRED].

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Anonymity Factory โ€” 3 / 12 Next โ†’