Hunt.io Report Maps 1,357 C2 Servers Across 98 Middle Eastern Providers

Summary
Hunt.io analyzed Middle Eastern infrastructure from February to May 2026, identifying 1,357 C2 servers across 98 providers. The report details provider concentrations, malware detections, and campaigns, while cautioning that tool fingerprints alone do not prove abuse.
Key points
- The three-month analysis covered infrastructure in 14 countries and identified 1,357 C2 servers among 1,459 total artifacts across 98 providers.
- STC accounted for 981 C2 detections, or 72.4% of the dataset; the report says this likely reflects its large subscriber network and compromised customer endpoints.
- C2 detections made up 93% of observed artifacts. Other findings included 45 malicious open directories, 43 IOC Hunter posts, seven phishing sites, and seven publicly referenced IOCs.
- Frequently detected tools and malware included Tactical RMM, Keitaro, Acunetix, Gophish, Mozi, and Hajime; the report notes that some tools are dual-use and detections do not establish malicious use.
- Examples linked regional infrastructure to varied activity, including botnets, phishing, espionage, ransomware delivery, destructive campaigns, and exploitation of CVE-2025-11953.
- Hunt.io recommends tracking provider- and network-level patterns alongside individual indicators to help defenders prioritize monitoring and response.
Article Details
- Publisher
- Hunt IO
- Report Period
- 2026-02-01 to 2026-05-01
- Scope
- Infrastructure detections across 98 Middle Eastern providers in 14 countries. Software fingerprints alone do not establish malicious use.
- Sample Size
- 1,459 recorded artifacts, including 1,357 potential C2 servers.
- Key Statistics
- The dataset contained 1,357 C2 detections, 45 malicious open directories, 43 IOC Hunter posts, 7 publicly reported IOCs, and 7 phishing sites.
- C2 detections accounted for 93.0% of artifacts; malicious open directories accounted for 3.1%, IOC Hunter posts 2.9%, phishing sites 0.5%, and publicly reported IOCs 0.5%.
- STC recorded 981 detections over 90 days, reported as 72.4% of the regional C2 total; the report considers this most consistent with compromised customer endpoints rather than provider intent.
- Other leading providers recorded 111 C2 detections at SERVERS TECH FZCO, 62 at OMC, 44 at Türk Telekom, and 38 at Regxa Company for Information Technology Ltd.
- The family/tool query returned 92 unique Tactical RMM detections and 71 Keitaro detections; these dual-use software fingerprints do not independently prove malicious activity.
- Recommendations
- Correlate software fingerprints with resolved domains, certificate or SSH overlaps, and previously reported IP activity before assessing maliciousness.
- Track hosting environments, ASNs, and recurring provider patterns to prioritize monitoring and blocking rather than relying only on frequently rotating individual indicators.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 197[.]51[.]170[.]131 | Source IP on TE Data infrastructure associated with the AWS intrusion documented by Sysdig researchers. |
| IPV4 | 37[.]32[.]15[.]8 | RondoDox exploitation server on AbrArvan CDN and IaaS infrastructure documented by Bitsight TRACE. |
| IPV4 | 5[.]109[.]182[.]231 | Source IP on Mobily infrastructure observed actively exploiting CVE-2025-11953 and delivering encoded PowerShell payloads. |
| IPV4 | 93[.]113[.]62[.]247 | IP on Netinternet Bilisim Teknolojileri AS linked to phishing impersonating Cloud Storage services to harvest payment details. |
| IPV4 | 94[.]252[.]245[.]193 | Phorpiex (Twizt) botnet C2 server observed on Syrian Telecom infrastructure. |
MITRE ATT&CK
T1059.001 · PowerShellThe Metro4Shell exploitation activity delivered Base64-encoded PowerShell scripts.T1059.002 · AppleScriptThe macOS-focused activity used encoded osascript droppers executed through Terminal.T1059.004 · Unix ShellRondoDox executed shell scripts through unauthenticated remote code execution vulnerabilities.T1078 · Valid AccountsThe AWS intrusion used credentials stolen from public S3 RAG datasets.T1189 · Drive-by CompromiseGrayCharlie compromised WordPress sites and injected JavaScript that redirected visitors to NetSupport RAT payloads.T1485 · Data DestructionDYNOWIPER activity attempted destructive attacks against Poland's energy sector; CERT Polska and ESET reported that the wiper was blocked without successful data destruction.T1496 · Resource HijackingPhorpiex and RondoDox activity included delivery of XMRig for cryptocurrency mining.T1562.001 · Disable or Modify ToolsScripts delivered during Metro4Shell exploitation added Microsoft Defender Antivirus exclusions.T1574.002 · DLL Side-LoadingThe Eagle Werewolf attack chain deployed a Sliver implant through DLL side-loading using Fondue.exe.
CVE
Threat Actors
APT28Tentatively attributed actor for the macOS-focused Phexia activity, which may also be linked to Amatera.Eagle WerewolfCluster to which a February 2026 espionage operation targeting state and industrial entities was attributed.Energetic BearThe source identifies Static Tundra as an alias of Energetic Bear in the disputed attribution of DYNOWIPER activity.GrayCharlieRecorded Future documented this actor compromising WordPress sites to redirect users to NetSupport RAT payloads; the report describes overlap with SmartApeSG, not an established alias relationship.SandwormESET and Dragos attributed the DYNOWIPER activity to this actor with moderate confidence, differing from CERT Polska.SmartApeSGNamed as overlapping with GrayCharlie in Recorded Future's reporting on WordPress compromises and NetSupport RAT delivery.Static TundraCERT Polska attribution for the DYNOWIPER activity; the source identifies this name as an Energetic Bear alias. Attribution remains unsettled.Velvet TempestDeception.Pro linked a 12-day intrusion involving malvertising and fake CAPTCHA commands to this actor; no encryption event was observed.
Malware
Amateratrick users into running base64-encoded osascript droppers via Terminal. The campaign may be linked to Amatera botnet activity and is tentatively attributed to APT28. Similarly, the CyberProof researchers identifiedAquilaRATSliver implant via DLL side-loading through Fondue.exe, SoullessRAT via fake AlphaFly installer, and AquilaRAT (Rust backdoor) leveraging multiple rotating C2 domains.AsyncRATand post-exploitation platforms also appear prominently in the dataset. These include Prism X (13), AsyncRAT (12), Sliver (10), Cobalt Strike (8), and Mirai (8), indicating that both commodity malware andDYNOWIPERexploitation campaign.Infrastructure observed on CLODO CLOUD SERVICE CO. L.L.C (UAE) was linked to the DYNOWIPER destructive campaign targeting Poland's energy sector. Per CERT Polska and ESET, the wiper was blockedEchoGather RATentities using Starlink registration and drone training lures. The multi-stage attack chain deployed EchoGather RAT via Telegram channels and phishing pages, Sliver implant via DLL side-loading through Fondue.exe,HajimeThe most common detections fall into two groups: IoT botnets like Hajime, Mozi, and Mirai, which are malware, and Threat Activity Enablers like Tactical RMM, Cobalt Strike, and Sliver, which are dual-use tools that showHellsUcheckerAdditionally, another research detailed a 10-stage campaign delivering the HellsUchecker backdoor via fake Cloudflare CAPTCHA (ClickFix) that tricks users into executing caret-obfuscated commands.LockBit Blackdelivered encrypted high-entropy payloads, including XMRig miner, and has previously distributed LockBit Black ransomware.MiraiThe most common detections fall into two groups: IoT botnets like Hajime, Mozi, and Mirai, which are malware, and Threat Activity Enablers like Tactical RMM, Cobalt Strike, and Sliver, which are dual-use tools that showMoziThe most common detections fall into two groups: IoT botnets like Hajime, Mozi, and Mirai, which are malware, and Threat Activity Enablers like Tactical RMM, Cobalt Strike, and Sliver, which are dual-use tools that showNetSupport RAThow the actor compromises WordPress sites to inject external JavaScript redirecting users to NetSupport RAT payloads.PhorpiexOver the observation period, Hunt.io tracking surfaced Phorpiex (Twizt) botnet C2 server at 94.252.245[.]193 hosted on Syrian Telecom infrastructure, operating a hybrid C2 architecture combining HTTP endpoints with aRondoDox30+ facilities, and expose the growing risks to SCADA/OT environments.Bitsight TRACE documented the RondoDox botnet leveraging exploitation server infrastructure at 37.32.15[.]8 on Iranian provider AbrArvan CDNSoullessRATRAT via Telegram channels and phishing pages, Sliver implant via DLL side-loading through Fondue.exe, SoullessRAT via fake AlphaFly installer, and AquilaRAT (Rust backdoor) leveraging multiple rotating C2 domains.Termitecsc.exe) to fetch masqueraded PDF archives and stage follow-on payloads. The tradecraft aligns with Termite ransomware operations, though no encryption event occurred during the observation window.TwiztOver the observation period, Hunt.io tracking surfaced Phorpiex (Twizt) botnet C2 server at 94.252.245[.]193 hosted on Syrian Telecom infrastructure, operating a hybrid C2 architecture combining HTTP endpoints with aXMRigpeer-to-peer UDP layer on port 40,500. The campaign delivered encrypted high-entropy payloads, including XMRig miner, and has previously distributed LockBit Black ransomware.
Vendors
AbrArvan CDN and IaaSRondoDox botnet leveraging exploitation server infrastructure at 37.32.15[.]8 on Iranian provider AbrArvan CDN and IaaS, active since May 2025 and peaked at 15,000 daily exploit attempts against internet-exposedBlueVPS OUOther providers with notable malware diversity include BlueVPS OU (4 malware families), Private Customer (4), SUNUCUN BILGI (4), NTT DATA (3), Oracle Corporation (3), Microsoft Corporation (3), TE Data (3), and severalCLODO CLOUD SERVICE CO. L.L.C(Saudi Arabia), linked to Metro4Shell RCE exploitation campaign.Infrastructure observed on CLODO CLOUD SERVICE CO. L.L.C (UAE) was linked to the DYNOWIPER destructive campaign targeting Poland's energy sector. PerDEDIK SERVICES LIMITEDIntelligence reports the CLICKSMOKE MaaS platform remains active with its C2 panel hosted on DEDIK SERVICES LIMITED infrastructure, while previously exposed builds were rotated out. Another attack reported byHosting DünyamOther prominent providers include SERV.HOST GROUP LTD (Cyprus, 25), Hosting Dünyam (Turkey, 15), SUNUCUN BILGI (Turkey, 7), IHS Kurumsal Teknoloji (Turkey, 6), and Paltel (Palestine, 6).IHS Kurumsal TeknolojiOther prominent providers include SERV.HOST GROUP LTD (Cyprus, 25), Hosting Dünyam (Turkey, 15), SUNUCUN BILGI (Turkey, 7), IHS Kurumsal Teknoloji (Turkey, 6), and Paltel (Palestine, 6).Microsoftmalware families), Private Customer (4), SUNUCUN BILGI (4), NTT DATA (3), Oracle Corporation (3), Microsoft Corporation (3), TE Data (3), and several others.Mobily(Metro4Shell) in React Native CLI was observed with source IP 5.109.182[.]231 on Saudi Arabia's Mobily network (AS35819), delivering Base64-encoded PowerShell scripts that added Microsoft Defender AntivirusNetinternet Bilisim Teknolojileri AShosting Eagle Werewolf APT C2 domains targeting state entities and drone communities.On Netinternet Bilisim Teknolojileri AS (Turkey), the IP 93.113.62[.]247 was observed in a phishing campaign impersonating genericNTT DATAmalware diversity include BlueVPS OU (4 malware families), Private Customer (4), SUNUCUN BILGI (4), NTT DATA (3), Oracle Corporation (3), Microsoft Corporation (3), TE Data (3), and several others.OMCfor a disproportionate share of potential malicious infrastructure, with STC, SERVERS TECH FZCO (UAE), OMC (Israel), Türk Telekom, and Regxa (Iraq) hosting the largest volumes of detected C2 servers.Oracleinclude BlueVPS OU (4 malware families), Private Customer (4), SUNUCUN BILGI (4), NTT DATA (3), Oracle Corporation (3), Microsoft Corporation (3), TE Data (3), and several others.PaltelOther prominent providers include SERV.HOST GROUP LTD (Cyprus, 25), Hosting Dünyam (Turkey, 15), SUNUCUN BILGI (Turkey, 7), IHS Kurumsal Teknoloji (Turkey, 6), and Paltel (Palestine, 6).Regxa Company for Information Technology Ltdmalicious open directories within Turkey's primary telecommunications network.Regxa Company for Information Technology Ltd, an Iraqi IT solutions provider, shows 38 C2 detections, 1 malicious open directory, 1SERV.HOST GROUP LTDOther prominent providers include SERV.HOST GROUP LTD (Cyprus, 25), Hosting Dünyam (Turkey, 15), SUNUCUN BILGI (Turkey, 7), IHS Kurumsal Teknoloji (Turkey, 6), and Paltel (Palestine, 6).SERVERS TECH FZCOproviders accounts for a disproportionate share of potential malicious infrastructure, with STC, SERVERS TECH FZCO (UAE), OMC (Israel), Türk Telekom, and Regxa (Iraq) hosting the largest volumes of detected C2STCset of hosting providers accounts for a disproportionate share of potential malicious infrastructure, with STC, SERVERS TECH FZCO (UAE), OMC (Israel), Türk Telekom, and Regxa (Iraq) hosting the largest volumes ofSUNUCUN BILGIOther prominent providers include SERV.HOST GROUP LTD (Cyprus, 25), Hosting Dünyam (Turkey, 15), SUNUCUN BILGI (Turkey, 7), IHS Kurumsal Teknoloji (Turkey, 6), and Paltel (Palestine, 6).Syrian Telecomperiod, Hunt.io tracking surfaced Phorpiex (Twizt) botnet C2 server at 94.252.245[.]193 hosted on Syrian Telecom infrastructure, operating a hybrid C2 architecture combining HTTP endpoints with a resilientTürk Telekomshare of potential malicious infrastructure, with STC, SERVERS TECH FZCO (UAE), OMC (Israel), Türk Telekom, and Regxa (Iraq) hosting the largest volumes of detected C2 servers.TE DataCustomer (4), SUNUCUN BILGI (4), NTT DATA (3), Oracle Corporation (3), Microsoft Corporation (3), TE Data (3), and several others.
Products
Amazon Bedrockprivilege escalation to admin account "frick," persistence across 19 AWS principals, Amazon Bedrock LLMjacking, and deployment of p4d.24xlarge instance with public JupyterLab on port 8888.AWSresearchers documented a November 2025 intrusion where attackers leveraged AI to compress an AWS attack chain to under 10 minutes, with activity originating from 197.51.170[.]131 on Egyptian ISP TE DataHost RadarHost Radar, a core module of Hunt.io, was designed to address this gap by correlating C2 servers, phishing infrastructure, malicious open directories, and public IOCs back to the hosting providers and network operatorsKeitaroMany of the detections here are Threat Activity Enablers, tools like Tactical RMM, Keitaro, Gophish, Acunetix, Cobalt Strike and Sliver. Each one has legitimate, unwanted, and malicious use cases, and the balanceMicrosoft Defender AntivirusArabia's Mobily network (AS35819), delivering Base64-encoded PowerShell scripts that added Microsoft Defender Antivirus exclusions before establishing TCP connections to download Rust-based binaries withReact Native CLICloud Storage impersonation phishing campaign.Active exploitation of CVE-2025-11953 (Metro4Shell) in React Native CLI was observed with source IP 5.109.182[.]231 on Saudi Arabia's Mobily network (AS35819), deliveringTactical RMMMany of the detections here are Threat Activity Enablers, tools like Tactical RMM, Keitaro, Gophish, Acunetix, Cobalt Strike and Sliver. Each one has legitimate, unwanted, and malicious use cases, and the balanceWordPressreport on GrayCharlie, a threat actor overlapping with SmartApeSG, documented how the actor compromises WordPress sites to inject external JavaScript redirecting users to NetSupport RAT payloads.
Tools
AcunetixMany of the detections here are Threat Activity Enablers, tools like Tactical RMM, Keitaro, Gophish, Acunetix, Cobalt Strike and Sliver. Each one has legitimate, unwanted, and malicious use cases, and the balanceCLICKSMOKEGrayCharlie WordPress compromise campaign targeting U.S. law firms.Breakglass Intelligence reports the CLICKSMOKE MaaS platform remains active with its C2 panel hosted on DEDIK SERVICES LIMITED infrastructure, whileCobalt Strikedetections here are Threat Activity Enablers, tools like Tactical RMM, Keitaro, Gophish, Acunetix, Cobalt Strike and Sliver. Each one has legitimate, unwanted, and malicious use cases, and the balance between thoseGophishMany of the detections here are Threat Activity Enablers, tools like Tactical RMM, Keitaro, Gophish, Acunetix, Cobalt Strike and Sliver. Each one has legitimate, unwanted, and malicious use cases, and the balanceHuntSQLUsing HuntSQL, we analyzed the distribution of command-and-control (C2) infrastructure across malware families hosted within Middle Eastern networks over three months.Needleexposed builds were rotated out. Another attack reported by Breakglass intelligence, mapped nine live Needle Malware-as-a-Service customer panels confirmed on April 22, 2026, showing consistent HTTP fingerprintsPrism Xframeworks and post-exploitation platforms also appear prominently in the dataset. These include Prism X (13), AsyncRAT (12), Sliver (10), Cobalt Strike (8), and Mirai (8), indicating that both commoditySliverhere are Threat Activity Enablers, tools like Tactical RMM, Keitaro, Gophish, Acunetix, Cobalt Strike and Sliver. Each one has legitimate, unwanted, and malicious use cases, and the balance between those depends on the
Countries
Bahrainthe UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not only the scale of active C2 infrastructure, but also the dominance ofCypruswith Middle Eastern infrastructure providers across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not only the scale ofEgyptMiddle Eastern infrastructure providers across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not only the scale of activeIranwith Middle Eastern infrastructure providers across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not only theIraqassociated with Middle Eastern infrastructure providers across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not onlyIsraeltelemetry associated with Middle Eastern infrastructure providers across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results revealJordanacross the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not only the scale of active C2 infrastructure, but also theKuwaitEastern infrastructure providers across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not only the scale of active C2Lebanonproviders across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not only the scale of active C2Palestineproviders across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not only the scale of active C2 infrastructure, but alsoPolandon CLODO CLOUD SERVICE CO. L.L.C (UAE) was linked to the DYNOWIPER destructive campaign targeting Poland's energy sector. Per CERT Polska and ESET, the wiper was blocked before causing damage: more than 30 windSaudi ArabiaRadar, we analyzed telemetry associated with Middle Eastern infrastructure providers across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria.SyriaSaudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not only the scale of active C2 infrastructure, but also the dominance of specificTurkeyanalyzed telemetry associated with Middle Eastern infrastructure providers across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The resultsUAEUsing Host Radar, we analyzed telemetry associated with Middle Eastern infrastructure providers across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, andUnited States20. Hunt.io IOC Hunter showing a brief summary of the GrayCharlie WordPress compromise campaign targeting U.S. law firms.Breakglass Intelligence reports the CLICKSMOKE MaaS platform remains active with its C2 panel
Industries
EnergyCLODO CLOUD SERVICE CO. L.L.C (UAE) was linked to the DYNOWIPER destructive campaign targeting Poland's energy sector. Per CERT Polska and ESET, the wiper was blocked before causing damage: more than 30 wind andhostingand evasion. Shifting focus to provider-level infrastructure breaks that cycle. It surfaces the hosting providers, cloud platforms, and telecom networks where potential malicious infrastructure keeps turningIndustrialC2 for a February 2026 espionage campaign attributed to the Eagle Werewolf cluster, targeting state and industrial entities using Starlink registration and drone training lures. The multi-stage attack chain deployedLaw firmsIOC Hunter showing a brief summary of the GrayCharlie WordPress compromise campaign targeting U.S. law firms.Breakglass Intelligence reports the CLICKSMOKE MaaS platform remains active with its C2 panel hosted onTelecommunicationsEast infrastructure providers, spanning shared hosting platforms, virtual server providers, and telecommunications networks across 14 countries.