Through concrete use cases and practical examples we will learn how to track criminal hosting infrastructures and we will understand the taxonomy and business models of bulletproof hosters that shelter ransomware, trojans, phishing, cybercrime forums, stolen credentials shops and other toxic content. A special light will be shed on criminal abuse in European IP space to understand trends and propose mitigation approaches.Learning Outcomes:Proven approaches to upgrade your threat intelligence from being IOC-driven to being more proactive with a longer-lasting advantage.How to extract behaviors of criminal-hosting infrastructures used for malware, phishing, crimeware forums, and various toxic content, and how to track evolving evasion patterns used by adversaries.Go over taxonomies of criminal hosting space, their business model, and various concrete use cases of criminal abuse of European spaceRecent findings to motivate the discussion about the topic in order to define more efficient ways to fight cybercrime and its enabling technologies.Useful tips for security practitioners, threat analysts, and law enforcement personnel, and it will provide actionable best practices to improve security controls in protecting organisations.