Hunt.io Maps 3,923 Potentially Malicious Infrastructure Endpoints Across Eastern Europe

· Original article ↗

Summary

Hunt.io analyzed three months of telemetry across 10 Eastern European countries, identifying 3,923 potentially malicious infrastructure endpoints. After provider feedback, it clarified that software presence—especially Keitaro—does not prove C2 or malicious use.

Key points

  • The report covers March 12–June 12, 2026, across 302 providers in 10 countries. It records 4,331 total detections, including 3,923 threat-activity-enabling servers.
  • Russia had the most unique threat-activity-enabling IPs in the country breakdown (929), followed by Poland (438), Bulgaria (298), Romania (199), and Ukraine (170).
  • Keitaro was the most frequently identified software, with 1,277 unique IPs, followed by Tactical RMM (232) and Acunetix (173). The report cautions that software presence alone does not establish malicious use or C2 activity.
  • The report associates infrastructure in the region with varied activity, including Cloud Atlas campaigns, FreePBX toll fraud, ShinyHunters-linked PeopleSoft exploitation, ransomware, phishing, and malware operations.
  • After Friendhosting LTD reviewed the data, Hunt.io clarified that credible concerns involving its infrastructure related to traffic distribution, not servers identified as hosting C2. Friendhosting said the review prompted tighter abuse detection.
  • Hunt.io said its counts were unchanged but revised its language and acknowledged that the original post overstated what software presence and infrastructure associations demonstrated.

Article Details

Publisher
Hunt.io
Report Period
2026-03-12 to 2026-06-12
Scope
Infrastructure signals across hosting providers in Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.
Sample Size
302 infrastructure providers; 4,331 potentially malicious detections, including 3,923 servers classified as threat activity enabling.
Key Statistics
  • Hunt.io recorded 3,923 threat activity enabling servers, 146 IOC Hunter posts, 111 potentially malicious open directories, 90 phishing sites, and 61 publicly reported IOC IPs.
  • Threat activity enabling servers accounted for approximately 90.6% of the 4,331 detections. The update cautions that the presence of software used in threat activity does not itself establish malicious use or C2 hosting.
  • Keitaro was detected on 1,277 unique IPs, Tactical RMM on 232, and Acunetix on 173; these software detections do not by themselves establish malicious use.
  • In the country-level malware-associated IP query, Russia had 929 unique IPs and Poland had 438, representing 45.7% and 21.5%, respectively, of the reported top-five country total.
  • According to Horizon3.ai attribution cited by the article, exploitation of CVE-2026-35273 targeted approximately 300 PeopleSoft instances across more than 100 organizations between 2026-05-27 and 2026-06-09.
Recommendations
  • Assess alerts using a source ASN's history and provider-level context, while distinguishing software presence from evidence of malicious use.
  • Use provider, country, and infrastructure analysis to hunt for persistent hosting patterns rather than relying solely on short-lived IP indicators.
  • Use provider-level visibility to support infrastructure risk assessments and monitor changes over time.

Indicators of compromise

TypeIndicatorContext
IPV4109[.]172[.]88[.]38IP linked to a Black Basta affiliate campaign using vishing and registration-bombing spam.
IPV4130[.]204[.]1[.]83IP associated with Silent Ransom Group DNS fast-flux infrastructure.
IPV4141[.]98[.]83[.]86Source of valid-credential authentication in a documented Nemesys ransomware intrusion.
IPV4146[.]70[.]53[.]171Potentially malicious endpoint on M247 Europe SRL associated with Cloud Atlas activity; the article cites historical intelligence hits.
IPV4176[.]120[.]22[.]24IP linked to active exploitation of CVE-2026-35273 against Oracle PeopleSoft Enterprise PeopleTools.
IPV4185[.]178[.]208[.]153IP associated with the Pink data-theft and extortion group.
IPV4185[.]203[.]116[.]18IP linked to DevilNFC Android malware activity.
IPV4185[.]22[.]154[.]73IP on Baxet identified as part of similar Cloud Atlas-associated campaign infrastructure.
IPV4194[.]87[.]196[.]163IP on Baxet identified as part of similar Cloud Atlas-associated campaign infrastructure.
IPV4194[.]87[.]92[.]109Exfiltration server identified by Unit 42 as receiving data stolen by Gremlin Stealer.
IPV4195[.]2[.]67[.]129IP associated with Fluffy Wolf phishing campaigns targeting Russian organizations.
IPV4195[.]58[.]49[.]9IP on Baxet identified as part of similar Cloud Atlas-associated campaign infrastructure.
IPV4195[.]58[.]49[.]99IP on Baxet identified as part of similar Cloud Atlas-associated campaign infrastructure.
IPV4195[.]62[.]53[.]253IP associated with ProxyCB botnet command-and-control infrastructure.
IPV446[.]17[.]44[.]125IP on Baxet identified as part of similar Cloud Atlas-associated campaign infrastructure.
IPV446[.]17[.]44[.]212IP on Baxet identified as part of similar Cloud Atlas-associated campaign infrastructure.
IPV483[.]168[.]110[.]191Infrastructure referenced in Iranian-linked exploitation staging for CVE-2026-0257.
IPV487[.]225[.]105[.]217IP linked to WantToCry ransomware operations, according to reporting cited by the article.
IPV489[.]36[.]224[.]5Staging server for a potentially malicious npm package that deployed minirat.
IPV492[.]39[.]211[.]142IP that generated an active XenoRAT signal connected to Gentlemen Ransomware operations.

MITRE ATT&CK

CVE

People

Threat Actors

Malware

DevilNFCSilent Ransom Group (SRG) DNS fast-flux infrastructure, while 185.203.116[.]18 (Belcloud) was linked to DevilNFC Android malware activity. IP 92.39.211[.]142 (MTS) generated an active XenoRAT signal connected toGentlemen RansomwareAndroid malware activity. IP 92.39.211[.]142 (MTS) generated an active XenoRAT signal connected to Gentlemen Ransomware operations.Gremlin Stealerthe IP 194.87.92[.]109 was directly identified by Unit 42 as an exfiltration server for the evolved Gremlin Stealer variant. The stealer hides its payload and configuration in a .NET resource section using XORHajimeIoT botnets such as Hajime (106), Mozi (82), and Mirai (27) continue to exploit embedded devices and consumer routers across the region, consistent with Eastern Europe's large installed base of internet-exposed IoTJOMANGYattributed to INJ3CTOR3 that deploys a multi-stage Bash dropper to install the previously undocumented JOMANGY PHP webshell alongside ZenharR.miniratmalicious npm package (@velora-dex/sdk version 9.4.1) that deployed a Go-based remote access trojan (minirat) targeting macOS developers in the DeFi/Web3 space, attributed to JINX-0164 threat actor.MiraiIoT botnets such as Hajime (106), Mozi (82), and Mirai (27) continue to exploit embedded devices and consumer routers across the region, consistent with Eastern Europe's large installed base of internet-exposed IoTMoziIoT botnets such as Hajime (106), Mozi (82), and Mirai (27) continue to exploit embedded devices and consumer routers across the region, consistent with Eastern Europe's large installed base of internet-exposed IoTNemesysIP 141.98.83[.]86 hosted on FlyServers S.A. (AS209588) was directly associated with a documented Nemesys ransomware intrusion analyzed in threat research. The attacker authenticated using valid credentialsProxyCBfollowing the June 2026 escalation period. Additionally, 195.62.53[.]253 (IPServer) was associated with ProxyCB botnet command-and-control infrastructure and showed historical links to the TeamSpy cyber-espionageWantToCry(Part 3): More Traffic, More Findings".Another IP 87.225.105[.]217 (Vladivostok, AS12389) is linked to WantToCry ransomware operations, as stated in Cybersecurity News.XenoRAT(Belcloud) was linked to DevilNFC Android malware activity. IP 92.39.211[.]142 (MTS) generated an active XenoRAT signal connected to Gentlemen Ransomware operations.ZenharRdeploys a multi-stage Bash dropper to install the previously undocumented JOMANGY PHP webshell alongside ZenharR.

Vendors

A1 Bulgariaseveral IPs with links to active cybercriminal and state-aligned operations. IP 130.204.1[.]83 (A1 Bulgaria) was associated with the Silent Ransom Group (SRG) DNS fast-flux infrastructure, while 185.203.116[.]18AlexHostMoldovan providers such as AlexHost and PQ Hosting together account for 299 threat activity enabling servers and carry high bulletproof ratings.Baxet185.22.154[.]73, 194.87.196[.]163, 195.58.49[.]9, 46.17.44[.]125, and 46.17.44[.]212 were also found on Baxet (LLC Baxet, AS51659) during the analysis window.Belcloudwas associated with the Silent Ransom Group (SRG) DNS fast-flux infrastructure, while 185.203.116[.]18 (Belcloud) was linked to DevilNFC Android malware activity. IP 92.39.211[.]142 (MTS) generated an active XenoRATDDoS-Guardoperating as a Gremlin Stealer exfiltration server used to receive stolen victim data.On DDoS-Guard (DDOS-GUARD LTD, AS57724), the IP 185.178.208[.]153 (Global Anycast, AS57724) is associated with theFlyServers S.A.tied to ShinyHunters' Oracle PeopleSoft exploitation campaigns.The IP 141.98.83[.]86 hosted on FlyServers S.A. (AS209588) was directly associated with a documented Nemesys ransomware intrusion analyzed in threatFriendhosting LTDFriendhosting LTD reviewed the data we shared with them and came back to us.ICI BucurestiICI Bucuresti leads in malware diversity with 12 distinct families across just 15 threat activity enabling endpoints, the highest diversity-to-volume ratio in the dataset.IPServerto weaponize the vulnerability following the June 2026 escalation period. Additionally, 195.62.53[.]253 (IPServer) was associated with ProxyCB botnet command-and-control infrastructure and showed historical links toJSC TIMEWEBPROSPERO OOO (24 threat activity enabling, 9 families) and JSC TIMEWEB (84 threat activity enabling, 9 families) show that dedicated Russian VPS and hosting providers serve multiple simultaneous threat actor campaigns,M247 Europe SRLEuropean infrastructure providers, beginning with activity linked to 146.70.53[.]171 hosted on M247 Europe SRL (AS9009), which is associated with Cloud Atlas APT campaigns targeting government and diplomaticMicrosoftAnother IP 109.172.88[.]38 (Moscow, AS48282) was linked to a Black Basta affiliate campaign using Microsoft Teams vishing and registration-bombing spam to pressure victims into installing AnyDesk.MTSwhile 185.203.116[.]18 (Belcloud) was linked to DevilNFC Android malware activity. IP 92.39.211[.]142 (MTS) generated an active XenoRAT signal connected to Gentlemen Ransomware operations.MTWIntelligence shows IP 109.172.88[.]38 linked to activity associated with the Black Basta threat group.On MTW (JSC Mediasoft ekspert, AS48347), the IP 194.87.92[.]109 was directly identified by Unit 42 as anOracleProton66 OOO was linked to active exploitation of CVE-2026-35273, a critical Oracle PeopleSoft zero-day attributed to the ShinyHunters group, with threat activity enabling infrastructure directly traceable to thisOVH PolandYandex.Cloud (37 threat activity enabling, 11 malware families) and OVH Poland (32 threat activity enabling, 10 families) represent large cloud providers whose scale naturally attracts diverse potentially maliciousPalo Alto Networksreferenced in Iranian-linked activity involving exploitation staging for CVE-2026-0257 (Palo Alto Networks GlobalProtect authentication bypass), with Pioneer Kitten assessed as a likely actor to weaponizePQ HostingMoldovan providers such as AlexHost and PQ Hosting together account for 299 threat activity enabling servers and carry high bulletproof ratings.PROSPERO OOOPROSPERO OOO (24 threat activity enabling, 9 families) and JSC TIMEWEB (84 threat activity enabling, 9 families) show that dedicated Russian VPS and hosting providers serve multiple simultaneous threat actor campaigns,Proton66 OOOProton66 OOO was linked to active exploitation of CVE-2026-35273, a critical Oracle PeopleSoft zero-day attributed to the ShinyHunters group, with threat activity enabling infrastructure directly traceable to thisRostelecomto a Nemesys ransomware attack leveraging credential dumping, persistence, and rapid encryption.On Rostelecom (PJSC Rostelecom, AS12389), the IP 78.85.31[.]182 (Izhevsk, AS12389) was found associated with theSkyPass Solutions Sp. z.o.o.Meanwhile, 83.168.110[.]191 (SkyPass Solutions Sp. z.o.o.) was identified as infrastructure referenced in Iranian-linked activity involving exploitation staging for CVE-2026-0257 (Palo Alto Networks GlobalProtectUkrtelecomUkraine (170, 8.4%) shows a comparatively even spread across telecommunications carriers (Ukrtelecom, Webinvest Plus) rather than a single dominant host.VDSinaOn VDSina (Hosting technology LTD, AS48282), the IP 195.2.67[.]129 associated with Fluffy Wolf phishing campaigns targeting Russian organizations between March and May 2026 was found. Another IP 109.172.88[.]38 (Moscow,Webinvest PlusUkraine (170, 8.4%) shows a comparatively even spread across telecommunications carriers (Ukrtelecom, Webinvest Plus) rather than a single dominant host.Yandex.CloudYandex.Cloud (37 threat activity enabling, 11 malware families) and OVH Poland (32 threat activity enabling, 10 families) represent large cloud providers whose scale naturally attracts diverse potentially malicious

Products

AnyDeskcampaign using Microsoft Teams vishing and registration-bombing spam to pressure victims into installing AnyDesk.FreePBX(Czech Republic, AS9009) flagged as a probable Mullvad VPN node associated with an active FreePBX toll-fraud campaign attributed to INJ3CTOR3 that deploys a multi-stage Bash dropper to install theGlobalProtectin Iranian-linked activity involving exploitation staging for CVE-2026-0257 (Palo Alto Networks GlobalProtect authentication bypass), with Pioneer Kitten assessed as a likely actor to weaponize the vulnerabilityKeitaroThat is the distinction we did not draw clearly enough when this post first went out. Keitaro is a commercial traffic distribution system. Its presence on a network tells you the software is there. It does not tell youMicrosoft 365the IP 185.178.208[.]153 (Global Anycast, AS57724) is associated with the Pink extortion group, a Microsoft 365-focused data theft and extortion operation with tradecraft similarities to ShinyHunters and Blackfile.Microsoft SharePointimpersonates internal IT over phone calls to capture credentials and MFA sessions, then exfiltrates SharePoint and OneDrive data via Microsoft Graph APIs.Microsoft TeamsAnother IP 109.172.88[.]38 (Moscow, AS48282) was linked to a Black Basta affiliate campaign using Microsoft Teams vishing and registration-bombing spam to pressure victims into installing AnyDesk.Ollama(PJSC Rostelecom, AS12389), the IP 78.85.31[.]182 (Izhevsk, AS12389) was found associated with the Ollama Honeypot campaign series (Bleeding Llama, CVE-2026-7482), where attackers exploited exposed Ollama APIOneDriveinternal IT over phone calls to capture credentials and MFA sessions, then exfiltrates SharePoint and OneDrive data via Microsoft Graph APIs.Oracle PeopleSoft Enterprise PeopleToolsof CVE-2026-35273, a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools (versions 8.61 and 8.62). Horizon3.ai attributes this exploitation campaign toTactical RMMKeitaro leads Eastern European threat activity enablement with 1,277 unique threat activity enabling IPs, followed by Tactical RMM (232) and Acunetix (173).

Tools

AcunetixKeitaro leads Eastern European threat activity enablement with 1,277 unique threat activity enabling IPs, followed by Tactical RMM (232) and Acunetix (173).Automimresearch. The attacker authenticated using valid credentials originating from this IP, then deployed an Automim credential-harvesting toolkit including Mimikatz, LaZagne, and multiple NirSoft tools. Persistence wasCobalt StrikeCobalt Strike (35 verified + 44 unverified) and Sliver (35) represent the adversary simulation and post-exploitation framework layer, indicating both criminal and state-adjacent operations operating from EasternGophishAcunetix (173 threat activity enabling) and Gophish (122 threat activity enabling) indicate a scanning and vulnerability-discovery infrastructure, reflecting active reconnaissance operations targeting external assets.Host Radarcarrier accounted for nearly three-quarters of all regional threat activity enabling infrastructure. Host Radar exists precisely to surface that kind of provider-level signal automatically, instead of requiringHuntSQLUsing HuntSQL, we analyzed the distribution of command-and-control (threat activity enabling) infrastructure across malware families hosted within Eastern European networks over three months.LaZagneoriginating from this IP, then deployed an Automim credential-harvesting toolkit including Mimikatz, LaZagne, and multiple NirSoft tools. Persistence was established via HKCU Run key reexecution.Mimikatzcredentials originating from this IP, then deployed an Automim credential-harvesting toolkit including Mimikatz, LaZagne, and multiple NirSoft tools. Persistence was established via HKCU Run key reexecution.SliverCobalt Strike (35 verified + 44 unverified) and Sliver (35) represent the adversary simulation and post-exploitation framework layer, indicating both criminal and state-adjacent operations operating from Eastern

Countries

Belarus12, 2026, we mapped potentially malicious infrastructure across 10 countries in the region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.Bulgariawe mapped potentially malicious infrastructure across 10 countries in the region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.Hungaryinfrastructure across 10 countries in the region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.Moldovaacross 10 countries in the region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.Polandacross 10 countries in the region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.Romania10 countries in the region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.Russiain the region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.Slovakiathe region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.the Czech Republicpotentially malicious infrastructure across 10 countries in the region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.Ukrainecovering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine.

Industries

Related Articles