A Belgrade firm sanctioned last year by the United States for aiding an alleged Russia-based cybercrime service provider was founded in 2022 by Kazakh-born German citizen Andreas Maul, who has since become a city councillor for the far-right Alternative for Germany party, AfD, BIRN can reveal.
Maul, 38, opened Smart Digital Ideas D.O.O. in a dilapidated nineties-era shopping mall in the New Belgrade district of the Serbian capital in October 2022, according to the Serbian Business Register.
The company was registered as an IT retailer, but the US Treasury says its real activities are more sinister.
On November 19 last year, the Treasury’s Office of Foreign Assets Control, OFAC, announced it had ‘designated’ Smart Digital Ideas for abetting Russia-based Aeza Group LLC, which was sanctioned four months earlier as a so-called ‘bulletproof hosting service provider’, a term used for companies that sell access to specialised servers and other IT infrastructure specifically designed to evade detection and conceal cybercrime activities.
OFAC said Smart Digital Ideas had been utilised by Aeza “to evade sanctions and set up technical infrastructure that is not publicly associated with the Aeza brand”.
Currently, the company has no registered employees and, according to Serbia’s central bank, has been unable to access its bank deposits since December 2025. The bank did not specify why.
On November 1, a little more than two weeks before his Serbian venture was hit by US sanctions, Maul became a city councillor in the German town of Selm, some 20 kilometres north of Dortmund, on behalf of AfD, the second biggest party in the German parliament.
Maul did not respond to requests for comment.
His connection to Smart Digital Ideas, and by extension to Aeza Group, will only fuel accusations from some German MPs about the AfD’s perceived ‘loyalty’ to Russia and its intentions should the party come to power.
Ties to Aeza Group
Aeza Group was sanctioned by the US in July last year for allegedly providing infrastructure for cybercrime groups involved in ransomware, personal information theft and the drug trade.
A year earlier, the German investigative media outlet CORRECTIV, based on an analysis by the Swedish digital forensics NGO Qurium, reported that Aeza Group had supported a wide-ranging, ongoing Russian covert influence and disinformation campaign launched after Russia’s full-scale invasion of Ukraine in 2022 and known as ‘Doppelganger’.
According to a November 2025 report by Insikt Group, the threat intelligence research arm of cybersecurity firm Recorded Future, within 24 hours of being sanctioned, Aeza began to reallocate its US IP resources to Smart Digital Ideas.
Days later, Smart Digital Ideas transferred the resources to the British company Hypercore Ltd. The likely purpose, according to the Insikt Group report, was “to retain control of any assets affected” by the sanctions.
Hypercore Ltd was sanctioned by the US alongside Smart Digital Ideas on November 19.
The Insikt Group report further states that IP ranges used by Aeza, Hypercore, Smart Digital Ideas and several other bulletproof hosting service providers were allocated from a larger address space that belonged to the Iranian Research Organisation for Science and Technology, IROST, which is controlled by Iran’s Ministry of Science.
Who is Andreas Maul?
Maul was born in the Kazakh city of Rudny, near the Central Asian state’s northern border with Russia.
On his private TikTok and Telegram profiles, Maul goes by the name Андрей, or Andrej.
Flight data obtained by BIRN shows that in November 2022, the month after he set up Smart Digital Ideas in Belgrade, Maul travelled from Moscow to Kaliningrad, a Russian exclave sandwiched on the Baltic Sea between Poland and Lithuania.
Maul holds a German passport and lives in Selm, where he runs two companies – cleaning firm Maul Services UG, opened in 2018, and the business consultancy PHRIS Consulting, registered in January 2021. Both are registered at Maul’s residential address.
On the official website of the Selm local authority, Maul is listed as a member of several committees of the Selm local assembly since November 13, 2025. On a Facebook page of the local AfD branch, Maul is shown at an AfD event in Selm in May this year inviting people to register as stem cell donors.
According to a late-2025 screenshot taken by Insikt Group, documents from RIPE NCC, which acts as the Regional Internet Registry providing Internet resources and related services to internet service providers in Europe, the Middle East and parts of Central Asia, show that Smart Digital Ideas listed Qwarta, a Moscow-based web hosting provider and virtual private server rental company, as having administrative control and editing rights over its public records.
Qwarta was listed in RIPE NCC registry documents as performing the same role for Aeza Group.
Qurium has identified Qwarta as part of the support infrastructure for the ‘Doppelganger’ disinformation campaign.
According to the findings of this investigation, Qwarta is listed as providing the same service to a Saratov-based company called IP Odintsov Stepan Vladimirovich, whose owner, 22-year-old Russian national Stepan Odintsov, also registered a company bearing his name in Belgrade in September 2025.
IP Odintsov Stepan Vladimirovich advertises one IP range that belongs to Qwarta. It also advertises one of its own IP ranges that hosted phishing websites in 2021.
In early 2026, according to real-time routing data from BGP Tools, Odintsov began routing internet traffic from Serbia. As of May, the Belgrade firm is listed as dormant. Onditsov also routes traffic for DDoS-Guard LTD, a Russian provider that hosted the official website of the Palestinian militant group Hamas, channels used to discredit Hong Kong pro-democracy activists, and provided DDoS protection for the Doppelganger campaign.
Odintsov did not respond to BIRN requests for comment.
Registered at the same address
Maul’s Smart Digital Ideas is registered at the same address in Belgrade as another entity previously identified as being repeatedly linked to cyberattacks – Cipher Operations, founded in December 2022 by 29-year-old Aleksandr Gennadyevich Yenakiyev.
Last year, France-based cybersecurity firm Intrinsec said there was a high probability that Cipher Operations was a rebranded version of Iranian bulletproof hosting service provider Robat Blue Diamond Network.
Intrinsec said that Cipher Operations had been placed on a blocklist by Andorra-based non-profit Spamhaus Project.
Some IP ranges used by Cipher Operations are among the most active sources of mass internet scanning, according to data from the WhatToBlock platform.
Nevertheless, the firm remains active in Serbia and currently advertises an IP range from the same larger IP block controlled by Iran’s Ministry of Science, from which allocations were also received by sanctioned Smart Digital Ideas, Aeza and Hypercore.
According to Intrinsec’s findings, companies in Lithuania, Iran, and the United Aram Emirates, as well as Cipher Operations, were advertising the same IP range; the UAE company then transferred part of the range to Cipher Operations, Aeza and IT-Hostline, a company that Intrinsec said still provides infrastructure to Aeza Group.
Yenakiyev told BIRN he had no knowledge of Robat Blue Diamond Network or any of the other companies mentioned in Intrinsec’s report.
“None of the names you’ve listed in this question, except for Cipher Operations, mean anything to me,” he said in a written response for this story.
“Although I am aware of an incident with another company getting their ASN blacklisted due to it also being connected with the same entities Cipher Operation is connected with through previous ownership of some of the IPv4 networks. I am unaware of any intentional connection, however. All of it was a result of leasing a network that had previously been in use by the problematic company/under a problematic ASN.”
He said Spamhaus, which Intrinsec said had placed Cipher Operations on a blocklist, was “a questionable source of authority”.
“There are countless – easily googlable – cases of entities and assets being placed on their list by mistake/in defiance of evidence contrasting with Spamhaus’ claims of malicious activity, with Spamhaus failing to adequately respond and cooperate with the said entities.”
He added that, “when faced with abuse reports, action is taken to halt the activities that cause them”.
Concerning the IP range from a larger block controlled by Iran’s Ministry of Science, Yenakiyev said: “We indeed have IPv4 ranges originating from a block controlled by Iranian entities. The owners and controllers of the larger block are of no interest to us, and never were. I don’t know if you’ve ever been in a telecom business – outside of being a snoop for hire – but you often use brokers to source the cheapest networks you can afford that keep your VPSes running. That often means getting networks that were previously used for various illicit activities.”
How BIRN traced the digital fingerprints
To identify and link individuals, digital traces, and other relevant information, BIRN used the OSINT tools osint.industries and Intelligence X, searching publicly available data associated with email addresses, usernames, domains and other digital identifiers. PimEyes was used to verify and link visual identities. The investigation also relied on previously leaked databases containing information on Russian citizens and their travel data. Relevant information was further checked and verified through official registries, publicly available documents and other independent sources.







