They said it’s impossible? Challenge us!
All of our services are bespoke and flexible to meet our clients’ unique requirements. Contact us for risk management solutions across the globe.
Our first brief mapped the .su namespace globally and flagged two Western European jurisdictions where what we called infrastructure distance concentrates most heavily: the Netherlands and Germany. This brief takes Germany on its own terms.
Of roughly 109,000 domains in the global dataset, close to 2,000 currently resolve to a German IP address, the second-largest Western European concentration, and by far the oldest. We selected a working sample for individual investigation through WHOIS, DNS, TLS certificates and live content, and report below what we found, and what we could not resolve.
We grouped domains by where their servers currently sit, not by who registered them. Hosting location cannot tell you a registrant’s nationality or whereabouts. What it tells you is which infrastructure an operator chose, and that choice is rarely accidental.
Bad actors gravitate toward hosts that ask few questions and act slowly on abuse reports. So when dozens of near-identical sites cluster on the same server, the same nameservers, the same jurisdiction, that is rarely a coincidence of geography. It is a shared playbook. Hosting clusters do not by themselves reveal who is behind a scam. They reveal where the shadows fall, and which corners of the internet keep attracting the same kind of trouble.
Germany’s curve tells a different story from other slices of the namespace. Activity begins in the early 2000s, spikes once in 2007, then holds steady for two decades at 40 to 88 new registrations a year, a rhythm consistent with defensive brand registrations, hobbyist purchases and small-scale investing.
Then the pattern breaks: 126 in 2024, 386 in 2025, and 361 in the first half of 2026 alone. On that run rate, 2026 will be the busiest year for German-hosted .su registration in the zone’s history.
This is not a pre-deadline rush against a mature base. It is a mature base that recently began accelerating sharply.
The most operationally revealing cluster follows a single alphabetical naming convention: 27 domains registered progressively through 2025, all through the same Russian registrar, all resolving to one IPv4 address on Hetzner infrastructure in Germany. Every domain shares the same nameservers, the same SOA record, and an unusual SPF configuration distinctive enough to attribute all 27 to one operator.
What separates this from ordinary domain squatting is the mail configuration. Every domain in the series carries its own MX record, and none carries DMARC. This is a mail-enabled infrastructure set built for two-way correspondence with real people, not a dormant brand-defence portfolio.
The pages themselves present a Russian-language recruitment pitch offering work in the European Union at attractive monthly earnings, each funnelling visitors to a single Telegram or WhatsApp contact. Historical captures show the front-end template has stayed fixed while the human contact layer underneath has already been rotated at least once, a hallmark of operational security in scam and trafficking-adjacent recruitment networks, not of a legitimate employment agency.
One domain inside the same letter sequence does something different. Rather than a job pitch, it presents a page requesting a face photograph, scanned identity documents and proof of residence, wrapped in consent language designed to look like routine account onboarding. That is not recruitment. It is an identity and biometric harvesting mechanism, the raw material criminal networks use to bypass Know-Your-Customer checks and open verified accounts under someone else’s identity.
Two further domains on the identical infrastructure fingerprint impersonate a real, established visa-processing service, and one of them displayed a third pitch entirely: a Russian-language crypto “education” page promising high annual returns from staking, funnelling every visitor to a single private chat contact.
One IP address, one operator, three storefronts: a job abroad, a visa service, a crypto course, each a different lure pointed at a different anxiety, all running on infrastructure built to send and receive mail nobody can verify. That is what makes this class of network resilient: block one storefront, and the mail-enabled infrastructure underneath keeps running.
Not every notable domain in the footprint fits the recruitment-and-impersonation model. Three others show how wide the abuse surface really is.
Country-by-IP slices of the .su namespace do not behave uniformly, which is exactly why each has to be investigated on its own terms. What looks in one country’s footprint like a harmless collection of defensive brand registrations looks, in another, like an active fraud cluster on shared, mail-enabled infrastructure. Germany’s footprint contains both.
The only responsible way to tell which is which is the discipline we applied here: rank the domains, date them, match the names, verify through WHOIS and DNS, and report honestly on what the evidence does and does not support.
The September 2026 deadline turns that discipline into a live decision point. Every Western brand holder, law firm or security team currently managing a defensive .su registration through German infrastructure now faces a genuine choice: complete Russian state identity verification to keep the domain, or let it lapse into the redemption pool, where, as the sections above show, it can be picked up within hours by the next operator waiting for exactly that kind of opening.
All of our services are bespoke and flexible to meet our clients’ unique requirements. Contact us for risk management solutions across the globe.
Close to 2,000 currently resolve to a German IP address, the second-largest Western European concentration in our census.
Keeping the registrar Russian while moving hosting to Western Europe lets an operator sidestep the default suspicion and geo-blocking that corporate firewalls and threat-intelligence feeds increasingly apply to Russian-origin IP space.
No. Hosting location tells you which infrastructure an operator chose, not their nationality or whereabouts. Attribution requires corroborating evidence across WHOIS, DNS and content.
Establish whether it holds any .su registrations, decide whether to complete verification or let them lapse, and understand that a lapsed brand-name domain can be re-registered by a third party within hours.
The .su top-level domain was assigned to the Soviet Union in September 1990, fourteen months before the country ceased to exist. It should not still be running in 2026. It is, with over 109,000 active domains, registered across 80 countries.
This is the first of three intelligence briefs in which NSSG examines the .su ecosystem: its governance, its ownership structure, and the risk it presents to organisations that have never given it a second thought. The summary below sets out what we found. The full brief is available to download.
Other collapsed states had their country codes retired. East Germany’s .dd was never fully implemented, Czechoslovakia’s .cs was deleted in 1995, Yugoslavia’s .yu was removed in 2010. .su persisted.
The reason is structural rather than accidental. ICANN can remove .su from the root zone, but it cannot compel Russia to stop operating the domain’s nameservers. Since 2009 the zone has been maintained by Technical Center of Internet LLC, a subsidiary of the state-owned telecommunications operator Rostelecom, which also runs the .ru and .рф registries. That makes .su a component of Russia’s national internet infrastructure rather than an orphaned relic.
The Moscow-based Foundation for Internet Development, one of the entities responsible for managing the domain, has publicly acknowledged shortcomings in its regulatory framework and limits on its ability to remove malicious content.
Four distinct groups have an interest in .su continuing to operate.
The ecosystem is more varied than its reputation suggests, which is precisely what makes it difficult to assess at a glance. Our taxonomy covers five categories:
Enforcement is unusually difficult. The .su dispute resolution process is not aligned with standard WIPO procedures, and takedown requests depend on cooperation from Russian-controlled infrastructure operators.
From that date, Federal Law No. 569-FZ requires every administrator of a .ru, .рф or .su domain to verify their identity through Gosuslugi, Russia’s national identification platform. Registration, renewal, transfer, even a DNS change, all of it requires a verified account. Domains that cannot complete verification will not renew.
Roughly 80,000 non-resident clients at a single registrar hold domains they cannot verify without a Russian account, which typically requires physical presence in Russia to create. A trusted-administrator mechanism has been created to bridge that gap, under which a verified entity holds formal administrative responsibility while DNS management and renewal rights stay with the non-resident holder.
The first organisations to show interest in that service were international companies providing intellectual property and digital asset protection to global brands, which tells you that major brands already hold defensive .su registrations, and are now managing a compliance problem attached to them.
Three developments follow predictably from the deadline.
The practical question for most organisations is simpler than any of this: do you know whether your brand name is registered in the .su space, and by whom? Most do not.
All of our services are bespoke and flexible to meet our clients’ unique requirements. Contact us for risk management solutions across the globe.
A country-code top-level domain assigned to the Soviet Union in September 1990. The state dissolved in December 1991; the domain was never decommissioned and remains in active use.
Yes. Over 109,000 domains were active as of June 2026, and ICANN’s projected retirement date for the zone is 2030.
Technical Center of Internet LLC, a subsidiary of the Russian state-owned telecommunications operator Rostelecom, has maintained the zone since 2009.
Jurisdictional ambiguity, limited enforcement capacity and a dispute-resolution process not aligned with standard WIPO procedure make takedowns unusually difficult, which has historically attracted criminal and extremist infrastructure.
Every administrator must verify their identity through Russia’s national ESIA platform. Domains that cannot complete verification will not renew.