I never understood why not the upstreams of "bulletproof hosts" simply disconnect / de-peer the entire AS until they clean up their act? Why won't their BGP neighbors take action? If you can't get ScumBagISP-A to clean up their act, go to ScumBagISP-Upstream-B, and then the next hop ScumBagISP-Upstream-Nexthop-C, and the next, until you find a responsible carrier who can de-peer?
That was tried about 5 years ago against the "Russian Business Network", AS40898. http://blog.washingtonpost.com/securityfix/2007/11/russian_b... As far as I know it only worked temporarily.
http://blog.washingtonpost.com/securityfix/2007/11/russian_b...