Home / Blogs

Thirty-Five Years Later, Moscow Comes Looking for the Soviet Union’s Domain

A Cold War ccTLD nobody can switch off is about to be pulled into a Russian identity system—and it will not be the last legacy domain this happens to.

On 1 September 2026, a Russian statute with the flat bureaucratic name 569-FZ takes effect, and for the first time since 1990, anyone who wants to register, renew, transfer or even edit the DNS records of a domain ending in .su will first have to prove their identity to the Russian state. The domain was assigned to the Union of Soviet Socialist Republics in September 1990, fourteen months before the country it named ceased to exist. It is still running, and it will still be running on 2 September. What changes is who is watching.

We have spent recent months mapping that namespace—WHOIS, DNS, hosting footprints and registration-timing data across a ranked snapshot of over 100,000 .su domains, valid as of July 2026. We did not set out looking for a Soviet ccTLD—.su kept surfacing at the edges of unrelated work on fraud, impersonation and recruitment scams until it became the investigation in its own right.

What follows is what a domain-level pass across the whole namespace turns up, why 1 September matters less as a single date than as the start of a year-long countdown, and why the same mechanics now overtaking .su are already visible, in different shapes, at both ends of the domain name system.

A domain that should not exist

Formally, .su should not exist. ICANN ties every country-code top-level domain to a live entry on the ISO 3166-1 list. When a territory’s code is withdrawn, the ccTLD becomes eligible for retirement—by default, a five-year transition, extendable once to ten if the registry shows “meaningful activity toward decommissioning” rather than simply preferring to keep it. The USSR’s code came off that list in the early 1990s. Thirty-five years on, .su still resolves because retirement is a request ICANN can make of an operator, not an order it can enforce. ICANN can remove .su from the global root, but it cannot compel Russia’s Technical Center of Internet (TCI)—a subsidiary of state telecom operator Rostelecom, which has run .su since 2009 alongside .ru and .рф—to stop answering queries for it. In February 2025, ICANN’s technical operator gave the .su administrator formal notice of a planned phase-out under a ccTLD retirement policy adopted in 2022, with a default 2030 date, extendable to 2035. Few who work in this space expect the extension to be declined.

Even a global delisting might not end it. Russia’s 2019 “sovereign internet” law built a National Domain Name System that Russian ISPs must consult. In February 2026, regulator Roskomnadzor began actively using it to strip specific services from what Russian users can resolve. The same infrastructure could keep .su fully functional inside Russia after any ICANN delisting—retired on paper, live and enforceable-against only inside one jurisdiction, which would relocate this piece’s central ambiguity rather than resolve it.

Reading the IP Address

A server’s IP address is not a fingerprint. It does not name a registrant, confirm a nationality, or establish where an operator is physically sitting—a .su domain registered through a Russian registrar and hosted in Frankfurt tells you nothing directly about who is running it or from where. What it tells you is which piece of infrastructure someone chose to route through, and that choice is rarely accidental. Bad actors gravitate toward hosts that ask few questions and respond slowly to abuse reports; legitimate operators mostly don’t think about it at all.

Hosting location matters here for a narrower, more practical reason: it is the one layer of a Russian-administered ccTLD that a non-Russian authority can actually reach—whichever country’s hosting provider, abuse-report process and law enforcement could, in principle, be asked to act. Russia hosts 77% of the ranked domains we examined; the rest sits across 79 other jurisdictions, led at real scale by the United States, Australia, the Netherlands and Germany.

Figure 1: Top 10 non-Russian hosting jurisdictions for .su domains. Source: NSSG analysis of Webatla.com dataset, snapshot July 2026.

The Netherlands and Germany carry two of the largest non-Russian concentrations for exactly the reasons laid out above—established homes for VPN providers, permissive hosts and shell-registered resellers that sit as an intermediary layer between the crime and any jurisdiction that could, in principle, be asked to stop it.

Dozens of websites, minutes apart

Most jurisdictions in the dataset show the ordinary noise of organic registration. Some did not. In a single nine-day window in mid-February 2026, Malaysia, Seychelles, Singapore, Japan and Hong Kong each saw a disproportionate share of their entire all-time .su history register at once—86% of Malaysia’s, 67% of Seychelles’, over half of Singapore’s and Japan’s.

Figure 2: The February 2026 registration burst, five hosting jurisdictions. Source: NSSG analysis of Webatla.com dataset, snapshot July 2026.

The naming pattern gives it away. The Seychelles batch we examined in detail—84 domains created between 18:33 UTC on 19 February and 17:37 UTC on 20 February 2026, arriving roughly every four to eight seconds—consists almost entirely of meaningless five-character strings and five-digit numbers, with no established web presence. Many domains, automated, at regular sub-minute intervals, algorithmic names, no organic footprint: that combination is the textbook signature of domain-generation-algorithm (DGA) infrastructure, in which malware computes a rotating list of candidate command-and-control addresses so that seizing any one domain never takes down the network. The timing is suggestive rather than proven, but it lands roughly three weeks after Google’s Threat Intelligence Group, working with Cloudflare and Lumen’s Black Lotus Labs, dismantled large parts of the IPIDEA residential-proxy network in late January 2026—a network Google identified as directly feeding the Aisuru and Kimwolf botnets, whose .su-hosted command infrastructure had, months earlier, briefly driven more DNS traffic through Cloudflare’s global measurements than .com. Losing a proxy backbone does not end an operation. It forces a scramble to re-provision, and disposable, algorithmically-named domains registered through low-oversight offshore hosts are exactly what that scramble looks like from outside.

What is actually on it

Content ranges from Soviet-nostalgia archives, through grey-market streaming and gambling sites, to live criminal infrastructure. One storefront we examined operates as a hub-and-spoke directory pointing to affiliated “shops” on adjacent TLDs, openly advertising stolen card dumps and CVVs, compromised bank logins tied to named institutions, cash-out services and EMV skimmer software—the trade known as carding, in which stolen payment-card data is bought, sold, tested and cashed out at scale, largely outside any real payment network until the fraudulent charge itself lands. Carding sites of this kind have historically lived on Tor hidden services—what we found on .su looks like part of a broader shift toward indexable, shareable clearnet storefronts on cheap, loosely regulated TLDs—faster to stand up and abandon than a hidden service, and outside the reputation systems built around mainstream gTLDs.

A separate cluster we mapped on German-hosted .su infrastructure runs recruitment scams impersonating real staffing agencies and global employers, one arm of which pivots into harvesting a face photograph, a passport scan and a proof of address under GDPR-flavoured consent language—raw material for opening verified “mule” accounts that real know-your-customer checks would otherwise stop.

None of this is exotic. The exotic part is that it happens on a namespace whose parent state does not, on paper, exist.

Outside the UDRP

None of this is easy to act on, because .su sits entirely outside ICANN’s Uniform Domain-Name Dispute-Resolution Policy. Disputes route instead through Russian commercial courts, require trademark rights recognised in Russia, and often depend on the registrar’s own cooperation to identify who is behind a domain. As Andre Stadelmaier, senior director of sales at the domain-monitoring firm eBrand, put it in mid-2025: enforcement against .su “is certainly less successful compared with our usual enforcement work.” That structural gap is the backdrop against which 569-FZ now arrives.

A gate, not a kill switch

569-FZ is not a kill switch. From 1 September, the registry system for .ru, .рф and .su will refuse a new registration, renewal, transfer, administrator change or DNS edit unless the requesting party has verified their identity through ESIA, the Gosuslugi national identification platform. A domain not due for any of those actions keeps resolving exactly as before. What actually bites is each domain’s own renewal date, not the calendar date everyone is fixated on—so exposure spreads across the following twelve months, with the largest wave landing as 2027 renewals echo this year’s registration surge.

That mechanism produces a legible map of gains and losses. Russian registrars and their new “trusted administrator” trustee products for non-residents gain fee revenue; IP and domain law firms with Russia practices gain compliance work; and the Russian state gains something no fee captures—far clearer visibility, via ESIA, into who actually controls .ru/.рф/.su infrastructure, alongside real anti-abuse gains officials have cited, including malicious-domain takedown times reportedly cut to around five hours. On the other side, non-resident holders without the budget for a trustee simply lose low-value registrations; unsophisticated criminal operators lose infrastructure outright, while sophisticated ones route around identification via shell identities or migrate on.

The ccTLD graveyard

.su is not the first ccTLD to survive its country, and the ones that did not survive show what “retirement” actually looks like. Czechoslovakia’s .cs was deleted in 1995, two years after the country split. Zaire’s .zr followed in 2001, four years after the country became the Democratic Republic of the Congo. Yugoslavia’s .yu held on the longest, persisting until 2010 as successor states were carved out one at a time. The Netherlands Antilles’ .an and East Timor’s .tp were both gone by 2015—the latter a full decade after the country renamed itself Timor-Leste and received .tl.

The domain worth watching alongside .su, for the opposite reason, is .io. The British Indian Ocean Territory’s ISO status is entangled with the UK-Mauritius sovereignty transfer over the Chagos Archipelago, announced in October 2024. Per ICANN’s most recent public statement, “IO persists in the ISO 3166-1 standard, and there has been no change,” and a sovereignty change is explicitly “not a foregone conclusion” to trigger any change to the domain. If IO were ever removed from the standard, the same five-to-ten-year mechanism now closing in on .su would apply.

The commercial stakes are far higher: .io’s read as “input/output” made it the default choice for a generation of tech startups, in a way .su’s Soviet branding never achieved outside a narrower audience. .su is institutional inertia outliving a state; .io is what happens when that same machinery meets a live, valuable commercial namespace—and however .su’s 2030 review lands, it may be read as a signal for how ICANN would handle the harder case.

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By Mihaela Vata, Head of Corporate Intelligence Practice at NSSG

Filed Under

Comments

Comment Title:

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

IPv4 Markets

Sponsored byIPv4.Global

Brand Protection

Sponsored byCSC

DNS

Sponsored byDNIB.com

Domain Names

Sponsored byVerisign

DNS Security

Sponsored byWhoisXML API

Cybersecurity

Sponsored byVerisign

New TLDs

Sponsored byRadix