Hunt.io Maps 3,923 Potentially Malicious Infrastructure Endpoints Across Eastern Europe

Summary
Hunt.io analyzed three months of telemetry across 10 Eastern European countries, identifying 3,923 potentially malicious infrastructure endpoints. After provider feedback, it clarified that software presence—especially Keitaro—does not prove C2 or malicious use.
Key points
- The report covers March 12–June 12, 2026, across 302 providers in 10 countries. It records 4,331 total detections, including 3,923 threat-activity-enabling servers.
- Russia had the most unique threat-activity-enabling IPs in the country breakdown (929), followed by Poland (438), Bulgaria (298), Romania (199), and Ukraine (170).
- Keitaro was the most frequently identified software, with 1,277 unique IPs, followed by Tactical RMM (232) and Acunetix (173). The report cautions that software presence alone does not establish malicious use or C2 activity.
- The report associates infrastructure in the region with varied activity, including Cloud Atlas campaigns, FreePBX toll fraud, ShinyHunters-linked PeopleSoft exploitation, ransomware, phishing, and malware operations.
- After Friendhosting LTD reviewed the data, Hunt.io clarified that credible concerns involving its infrastructure related to traffic distribution, not servers identified as hosting C2. Friendhosting said the review prompted tighter abuse detection.
- Hunt.io said its counts were unchanged but revised its language and acknowledged that the original post overstated what software presence and infrastructure associations demonstrated.
Article Details
- Publisher
- Hunt.io
- Report Period
- 2026-03-12 to 2026-06-12
- Scope
- Infrastructure signals across hosting providers in Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.
- Sample Size
- 302 infrastructure providers; 4,331 potentially malicious detections, including 3,923 servers classified as threat activity enabling.
- Key Statistics
- Hunt.io recorded 3,923 threat activity enabling servers, 146 IOC Hunter posts, 111 potentially malicious open directories, 90 phishing sites, and 61 publicly reported IOC IPs.
- Threat activity enabling servers accounted for approximately 90.6% of the 4,331 detections. The update cautions that the presence of software used in threat activity does not itself establish malicious use or C2 hosting.
- Keitaro was detected on 1,277 unique IPs, Tactical RMM on 232, and Acunetix on 173; these software detections do not by themselves establish malicious use.
- In the country-level malware-associated IP query, Russia had 929 unique IPs and Poland had 438, representing 45.7% and 21.5%, respectively, of the reported top-five country total.
- According to Horizon3.ai attribution cited by the article, exploitation of CVE-2026-35273 targeted approximately 300 PeopleSoft instances across more than 100 organizations between 2026-05-27 and 2026-06-09.
- Recommendations
- Assess alerts using a source ASN's history and provider-level context, while distinguishing software presence from evidence of malicious use.
- Use provider, country, and infrastructure analysis to hunt for persistent hosting patterns rather than relying solely on short-lived IP indicators.
- Use provider-level visibility to support infrastructure risk assessments and monitor changes over time.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 109[.]172[.]88[.]38 | IP linked to a Black Basta affiliate campaign using vishing and registration-bombing spam. |
| IPV4 | 130[.]204[.]1[.]83 | IP associated with Silent Ransom Group DNS fast-flux infrastructure. |
| IPV4 | 141[.]98[.]83[.]86 | Source of valid-credential authentication in a documented Nemesys ransomware intrusion. |
| IPV4 | 146[.]70[.]53[.]171 | Potentially malicious endpoint on M247 Europe SRL associated with Cloud Atlas activity; the article cites historical intelligence hits. |
| IPV4 | 176[.]120[.]22[.]24 | IP linked to active exploitation of CVE-2026-35273 against Oracle PeopleSoft Enterprise PeopleTools. |
| IPV4 | 185[.]178[.]208[.]153 | IP associated with the Pink data-theft and extortion group. |
| IPV4 | 185[.]203[.]116[.]18 | IP linked to DevilNFC Android malware activity. |
| IPV4 | 185[.]22[.]154[.]73 | IP on Baxet identified as part of similar Cloud Atlas-associated campaign infrastructure. |
| IPV4 | 194[.]87[.]196[.]163 | IP on Baxet identified as part of similar Cloud Atlas-associated campaign infrastructure. |
| IPV4 | 194[.]87[.]92[.]109 | Exfiltration server identified by Unit 42 as receiving data stolen by Gremlin Stealer. |
| IPV4 | 195[.]2[.]67[.]129 | IP associated with Fluffy Wolf phishing campaigns targeting Russian organizations. |
| IPV4 | 195[.]58[.]49[.]9 | IP on Baxet identified as part of similar Cloud Atlas-associated campaign infrastructure. |
| IPV4 | 195[.]58[.]49[.]99 | IP on Baxet identified as part of similar Cloud Atlas-associated campaign infrastructure. |
| IPV4 | 195[.]62[.]53[.]253 | IP associated with ProxyCB botnet command-and-control infrastructure. |
| IPV4 | 46[.]17[.]44[.]125 | IP on Baxet identified as part of similar Cloud Atlas-associated campaign infrastructure. |
| IPV4 | 46[.]17[.]44[.]212 | IP on Baxet identified as part of similar Cloud Atlas-associated campaign infrastructure. |
| IPV4 | 83[.]168[.]110[.]191 | Infrastructure referenced in Iranian-linked exploitation staging for CVE-2026-0257. |
| IPV4 | 87[.]225[.]105[.]217 | IP linked to WantToCry ransomware operations, according to reporting cited by the article. |
| IPV4 | 89[.]36[.]224[.]5 | Staging server for a potentially malicious npm package that deployed minirat. |
| IPV4 | 92[.]39[.]211[.]142 | IP that generated an active XenoRAT signal connected to Gentlemen Ransomware operations. |
MITRE ATT&CK
T1003 · OS Credential DumpingThe Nemesys intrusion deployed credential-dumping tools including Mimikatz.T1059.001 · PowerShellLNK shortcuts in the reported Cloud Atlas activity launched PowerShell.T1078 · Valid AccountsAn attacker in the documented Nemesys intrusion authenticated with valid credentials.T1190 · Exploit Public-Facing ApplicationThe article describes active exploitation of an unauthenticated Oracle PeopleSoft Enterprise PeopleTools remote code execution vulnerability.T1505.003 · Web ShellThe INJ3CTOR3-attributed FreePBX campaign installed the JOMANGY PHP webshell.T1547.001 · Registry Run Keys / Startup FolderThe documented Nemesys intrusion established persistence through an HKCU Run key.T1566.001 · Spearphishing AttachmentCloud Atlas activity reportedly used phishing ZIP attachments containing LNK shortcuts.
CVE
CVE-2018-0802with LNK shortcuts launching PowerShell, alongside potentially malicious Office documents exploiting CVE-2018-0802.CVE-2026-0257identified as infrastructure referenced in Iranian-linked activity involving exploitation staging for CVE-2026-0257 (Palo Alto Networks GlobalProtect authentication bypass), with Pioneer Kitten assessed as a likelyCVE-2026-35273Proton66 OOO was linked to active exploitation of CVE-2026-35273, a critical Oracle PeopleSoft zero-day attributed to the ShinyHunters group, with threat activity enabling infrastructure directly traceable to thisCVE-2026-7482(Izhevsk, AS12389) was found associated with the Ollama Honeypot campaign series (Bleeding Llama, CVE-2026-7482), where attackers exploited exposed Ollama API services to execute coinminer scripts, perform GGUF
People
ChrisSigned the editorial update acknowledging that the original article did not adequately distinguish software presence from malicious use.EstebanSigned the editorial update acknowledging that the original article did not adequately distinguish software presence from malicious use.PavloFriendhosting LTD contact thanked for questions that prompted review of the article's characterization of software detections.Tom SpringSecurity Point Break contact thanked for questions that prompted review of the article.
Threat Actors
Black BastaA campaign linked to an affiliate of this group used Microsoft Teams vishing and registration-bombing spam.Cloud AtlasAPT group associated with infrastructure and reported phishing activity targeting government and diplomatic entities.Fluffy WolfActor associated with phishing campaigns targeting Russian organizations.INJ3CTOR3Attributed actor in the FreePBX toll-fraud campaign that deployed JOMANGY.JINX-0164Attributed actor in the campaign that used a potentially malicious npm package to deploy minirat.PinkExtortion group associated with Microsoft 365-focused data theft and an IP identified in the article.ShinyHuntersHorizon3.ai attributes the cited Oracle PeopleSoft exploitation campaign to this group.Silent Ransom GroupGroup associated with DNS fast-flux infrastructure; the article also names it SRG.SRGAbbreviation explicitly given for Silent Ransom Group, which the article associates with DNS fast-flux infrastructure.
Malware
DevilNFCSilent Ransom Group (SRG) DNS fast-flux infrastructure, while 185.203.116[.]18 (Belcloud) was linked to DevilNFC Android malware activity. IP 92.39.211[.]142 (MTS) generated an active XenoRAT signal connected toGentlemen RansomwareAndroid malware activity. IP 92.39.211[.]142 (MTS) generated an active XenoRAT signal connected to Gentlemen Ransomware operations.Gremlin Stealerthe IP 194.87.92[.]109 was directly identified by Unit 42 as an exfiltration server for the evolved Gremlin Stealer variant. The stealer hides its payload and configuration in a .NET resource section using XORHajimeIoT botnets such as Hajime (106), Mozi (82), and Mirai (27) continue to exploit embedded devices and consumer routers across the region, consistent with Eastern Europe's large installed base of internet-exposed IoTJOMANGYattributed to INJ3CTOR3 that deploys a multi-stage Bash dropper to install the previously undocumented JOMANGY PHP webshell alongside ZenharR.miniratmalicious npm package (@velora-dex/sdk version 9.4.1) that deployed a Go-based remote access trojan (minirat) targeting macOS developers in the DeFi/Web3 space, attributed to JINX-0164 threat actor.MiraiIoT botnets such as Hajime (106), Mozi (82), and Mirai (27) continue to exploit embedded devices and consumer routers across the region, consistent with Eastern Europe's large installed base of internet-exposed IoTMoziIoT botnets such as Hajime (106), Mozi (82), and Mirai (27) continue to exploit embedded devices and consumer routers across the region, consistent with Eastern Europe's large installed base of internet-exposed IoTNemesysIP 141.98.83[.]86 hosted on FlyServers S.A. (AS209588) was directly associated with a documented Nemesys ransomware intrusion analyzed in threat research. The attacker authenticated using valid credentialsProxyCBfollowing the June 2026 escalation period. Additionally, 195.62.53[.]253 (IPServer) was associated with ProxyCB botnet command-and-control infrastructure and showed historical links to the TeamSpy cyber-espionageWantToCry(Part 3): More Traffic, More Findings".Another IP 87.225.105[.]217 (Vladivostok, AS12389) is linked to WantToCry ransomware operations, as stated in Cybersecurity News.XenoRAT(Belcloud) was linked to DevilNFC Android malware activity. IP 92.39.211[.]142 (MTS) generated an active XenoRAT signal connected to Gentlemen Ransomware operations.ZenharRdeploys a multi-stage Bash dropper to install the previously undocumented JOMANGY PHP webshell alongside ZenharR.
Vendors
A1 Bulgariaseveral IPs with links to active cybercriminal and state-aligned operations. IP 130.204.1[.]83 (A1 Bulgaria) was associated with the Silent Ransom Group (SRG) DNS fast-flux infrastructure, while 185.203.116[.]18AlexHostMoldovan providers such as AlexHost and PQ Hosting together account for 299 threat activity enabling servers and carry high bulletproof ratings.Baxet185.22.154[.]73, 194.87.196[.]163, 195.58.49[.]9, 46.17.44[.]125, and 46.17.44[.]212 were also found on Baxet (LLC Baxet, AS51659) during the analysis window.Belcloudwas associated with the Silent Ransom Group (SRG) DNS fast-flux infrastructure, while 185.203.116[.]18 (Belcloud) was linked to DevilNFC Android malware activity. IP 92.39.211[.]142 (MTS) generated an active XenoRATDDoS-Guardoperating as a Gremlin Stealer exfiltration server used to receive stolen victim data.On DDoS-Guard (DDOS-GUARD LTD, AS57724), the IP 185.178.208[.]153 (Global Anycast, AS57724) is associated with theFlyServers S.A.tied to ShinyHunters' Oracle PeopleSoft exploitation campaigns.The IP 141.98.83[.]86 hosted on FlyServers S.A. (AS209588) was directly associated with a documented Nemesys ransomware intrusion analyzed in threatFriendhosting LTDFriendhosting LTD reviewed the data we shared with them and came back to us.ICI BucurestiICI Bucuresti leads in malware diversity with 12 distinct families across just 15 threat activity enabling endpoints, the highest diversity-to-volume ratio in the dataset.IPServerto weaponize the vulnerability following the June 2026 escalation period. Additionally, 195.62.53[.]253 (IPServer) was associated with ProxyCB botnet command-and-control infrastructure and showed historical links toJSC TIMEWEBPROSPERO OOO (24 threat activity enabling, 9 families) and JSC TIMEWEB (84 threat activity enabling, 9 families) show that dedicated Russian VPS and hosting providers serve multiple simultaneous threat actor campaigns,M247 Europe SRLEuropean infrastructure providers, beginning with activity linked to 146.70.53[.]171 hosted on M247 Europe SRL (AS9009), which is associated with Cloud Atlas APT campaigns targeting government and diplomaticMicrosoftAnother IP 109.172.88[.]38 (Moscow, AS48282) was linked to a Black Basta affiliate campaign using Microsoft Teams vishing and registration-bombing spam to pressure victims into installing AnyDesk.MTSwhile 185.203.116[.]18 (Belcloud) was linked to DevilNFC Android malware activity. IP 92.39.211[.]142 (MTS) generated an active XenoRAT signal connected to Gentlemen Ransomware operations.MTWIntelligence shows IP 109.172.88[.]38 linked to activity associated with the Black Basta threat group.On MTW (JSC Mediasoft ekspert, AS48347), the IP 194.87.92[.]109 was directly identified by Unit 42 as anOracleProton66 OOO was linked to active exploitation of CVE-2026-35273, a critical Oracle PeopleSoft zero-day attributed to the ShinyHunters group, with threat activity enabling infrastructure directly traceable to thisOVH PolandYandex.Cloud (37 threat activity enabling, 11 malware families) and OVH Poland (32 threat activity enabling, 10 families) represent large cloud providers whose scale naturally attracts diverse potentially maliciousPalo Alto Networksreferenced in Iranian-linked activity involving exploitation staging for CVE-2026-0257 (Palo Alto Networks GlobalProtect authentication bypass), with Pioneer Kitten assessed as a likely actor to weaponizePQ HostingMoldovan providers such as AlexHost and PQ Hosting together account for 299 threat activity enabling servers and carry high bulletproof ratings.PROSPERO OOOPROSPERO OOO (24 threat activity enabling, 9 families) and JSC TIMEWEB (84 threat activity enabling, 9 families) show that dedicated Russian VPS and hosting providers serve multiple simultaneous threat actor campaigns,Proton66 OOOProton66 OOO was linked to active exploitation of CVE-2026-35273, a critical Oracle PeopleSoft zero-day attributed to the ShinyHunters group, with threat activity enabling infrastructure directly traceable to thisRostelecomto a Nemesys ransomware attack leveraging credential dumping, persistence, and rapid encryption.On Rostelecom (PJSC Rostelecom, AS12389), the IP 78.85.31[.]182 (Izhevsk, AS12389) was found associated with theSkyPass Solutions Sp. z.o.o.Meanwhile, 83.168.110[.]191 (SkyPass Solutions Sp. z.o.o.) was identified as infrastructure referenced in Iranian-linked activity involving exploitation staging for CVE-2026-0257 (Palo Alto Networks GlobalProtectUkrtelecomUkraine (170, 8.4%) shows a comparatively even spread across telecommunications carriers (Ukrtelecom, Webinvest Plus) rather than a single dominant host.VDSinaOn VDSina (Hosting technology LTD, AS48282), the IP 195.2.67[.]129 associated with Fluffy Wolf phishing campaigns targeting Russian organizations between March and May 2026 was found. Another IP 109.172.88[.]38 (Moscow,Webinvest PlusUkraine (170, 8.4%) shows a comparatively even spread across telecommunications carriers (Ukrtelecom, Webinvest Plus) rather than a single dominant host.Yandex.CloudYandex.Cloud (37 threat activity enabling, 11 malware families) and OVH Poland (32 threat activity enabling, 10 families) represent large cloud providers whose scale naturally attracts diverse potentially malicious
Products
AnyDeskcampaign using Microsoft Teams vishing and registration-bombing spam to pressure victims into installing AnyDesk.FreePBX(Czech Republic, AS9009) flagged as a probable Mullvad VPN node associated with an active FreePBX toll-fraud campaign attributed to INJ3CTOR3 that deploys a multi-stage Bash dropper to install theGlobalProtectin Iranian-linked activity involving exploitation staging for CVE-2026-0257 (Palo Alto Networks GlobalProtect authentication bypass), with Pioneer Kitten assessed as a likely actor to weaponize the vulnerabilityKeitaroThat is the distinction we did not draw clearly enough when this post first went out. Keitaro is a commercial traffic distribution system. Its presence on a network tells you the software is there. It does not tell youMicrosoft 365the IP 185.178.208[.]153 (Global Anycast, AS57724) is associated with the Pink extortion group, a Microsoft 365-focused data theft and extortion operation with tradecraft similarities to ShinyHunters and Blackfile.Microsoft SharePointimpersonates internal IT over phone calls to capture credentials and MFA sessions, then exfiltrates SharePoint and OneDrive data via Microsoft Graph APIs.Microsoft TeamsAnother IP 109.172.88[.]38 (Moscow, AS48282) was linked to a Black Basta affiliate campaign using Microsoft Teams vishing and registration-bombing spam to pressure victims into installing AnyDesk.Ollama(PJSC Rostelecom, AS12389), the IP 78.85.31[.]182 (Izhevsk, AS12389) was found associated with the Ollama Honeypot campaign series (Bleeding Llama, CVE-2026-7482), where attackers exploited exposed Ollama APIOneDriveinternal IT over phone calls to capture credentials and MFA sessions, then exfiltrates SharePoint and OneDrive data via Microsoft Graph APIs.Oracle PeopleSoft Enterprise PeopleToolsof CVE-2026-35273, a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools (versions 8.61 and 8.62). Horizon3.ai attributes this exploitation campaign toTactical RMMKeitaro leads Eastern European threat activity enablement with 1,277 unique threat activity enabling IPs, followed by Tactical RMM (232) and Acunetix (173).
Tools
AcunetixKeitaro leads Eastern European threat activity enablement with 1,277 unique threat activity enabling IPs, followed by Tactical RMM (232) and Acunetix (173).Automimresearch. The attacker authenticated using valid credentials originating from this IP, then deployed an Automim credential-harvesting toolkit including Mimikatz, LaZagne, and multiple NirSoft tools. Persistence wasCobalt StrikeCobalt Strike (35 verified + 44 unverified) and Sliver (35) represent the adversary simulation and post-exploitation framework layer, indicating both criminal and state-adjacent operations operating from EasternGophishAcunetix (173 threat activity enabling) and Gophish (122 threat activity enabling) indicate a scanning and vulnerability-discovery infrastructure, reflecting active reconnaissance operations targeting external assets.Host Radarcarrier accounted for nearly three-quarters of all regional threat activity enabling infrastructure. Host Radar exists precisely to surface that kind of provider-level signal automatically, instead of requiringHuntSQLUsing HuntSQL, we analyzed the distribution of command-and-control (threat activity enabling) infrastructure across malware families hosted within Eastern European networks over three months.LaZagneoriginating from this IP, then deployed an Automim credential-harvesting toolkit including Mimikatz, LaZagne, and multiple NirSoft tools. Persistence was established via HKCU Run key reexecution.Mimikatzcredentials originating from this IP, then deployed an Automim credential-harvesting toolkit including Mimikatz, LaZagne, and multiple NirSoft tools. Persistence was established via HKCU Run key reexecution.SliverCobalt Strike (35 verified + 44 unverified) and Sliver (35) represent the adversary simulation and post-exploitation framework layer, indicating both criminal and state-adjacent operations operating from Eastern
Countries
Belarus12, 2026, we mapped potentially malicious infrastructure across 10 countries in the region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.Bulgariawe mapped potentially malicious infrastructure across 10 countries in the region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.Hungaryinfrastructure across 10 countries in the region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.Moldovaacross 10 countries in the region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.Polandacross 10 countries in the region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.Romania10 countries in the region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.Russiain the region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.Slovakiathe region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.the Czech Republicpotentially malicious infrastructure across 10 countries in the region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.Ukrainecovering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.
Industries
DeFi/Web39.4.1) that deployed a Go-based remote access trojan (minirat) targeting macOS developers in the DeFi/Web3 space, attributed to JINX-0164 threat actor.EducationGovernmenthosted on M247 Europe SRL (AS9009), which is associated with Cloud Atlas APT campaigns targeting government and diplomatic entities in Russia and Belarus. Kaspersky reporting documents renewed Cloud Atlas