Hunt.io Report Maps 1,357 C2 Servers Across 98 Middle Eastern Providers

· Original article ↗

Summary

Hunt.io analyzed Middle Eastern infrastructure from February to May 2026, identifying 1,357 C2 servers across 98 providers. The report details provider concentrations, malware detections, and campaigns, while cautioning that tool fingerprints alone do not prove abuse.

Key points

  • The three-month analysis covered infrastructure in 14 countries and identified 1,357 C2 servers among 1,459 total artifacts across 98 providers.
  • STC accounted for 981 C2 detections, or 72.4% of the dataset; the report says this likely reflects its large subscriber network and compromised customer endpoints.
  • C2 detections made up 93% of observed artifacts. Other findings included 45 malicious open directories, 43 IOC Hunter posts, seven phishing sites, and seven publicly referenced IOCs.
  • Frequently detected tools and malware included Tactical RMM, Keitaro, Acunetix, Gophish, Mozi, and Hajime; the report notes that some tools are dual-use and detections do not establish malicious use.
  • Examples linked regional infrastructure to varied activity, including botnets, phishing, espionage, ransomware delivery, destructive campaigns, and exploitation of CVE-2025-11953.
  • Hunt.io recommends tracking provider- and network-level patterns alongside individual indicators to help defenders prioritize monitoring and response.

Article Details

Publisher
Hunt IO
Report Period
2026-02-01 to 2026-05-01
Scope
Infrastructure detections across 98 Middle Eastern providers in 14 countries. Software fingerprints alone do not establish malicious use.
Sample Size
1,459 recorded artifacts, including 1,357 potential C2 servers.
Key Statistics
  • The dataset contained 1,357 C2 detections, 45 malicious open directories, 43 IOC Hunter posts, 7 publicly reported IOCs, and 7 phishing sites.
  • C2 detections accounted for 93.0% of artifacts; malicious open directories accounted for 3.1%, IOC Hunter posts 2.9%, phishing sites 0.5%, and publicly reported IOCs 0.5%.
  • STC recorded 981 detections over 90 days, reported as 72.4% of the regional C2 total; the report considers this most consistent with compromised customer endpoints rather than provider intent.
  • Other leading providers recorded 111 C2 detections at SERVERS TECH FZCO, 62 at OMC, 44 at Türk Telekom, and 38 at Regxa Company for Information Technology Ltd.
  • The family/tool query returned 92 unique Tactical RMM detections and 71 Keitaro detections; these dual-use software fingerprints do not independently prove malicious activity.
Recommendations
  • Correlate software fingerprints with resolved domains, certificate or SSH overlaps, and previously reported IP activity before assessing maliciousness.
  • Track hosting environments, ASNs, and recurring provider patterns to prioritize monitoring and blocking rather than relying only on frequently rotating individual indicators.

Indicators of compromise

TypeIndicatorContext
IPV4197[.]51[.]170[.]131Source IP on TE Data infrastructure associated with the AWS intrusion documented by Sysdig researchers.
IPV437[.]32[.]15[.]8RondoDox exploitation server on AbrArvan CDN and IaaS infrastructure documented by Bitsight TRACE.
IPV45[.]109[.]182[.]231Source IP on Mobily infrastructure observed actively exploiting CVE-2025-11953 and delivering encoded PowerShell payloads.
IPV493[.]113[.]62[.]247IP on Netinternet Bilisim Teknolojileri AS linked to phishing impersonating Cloud Storage services to harvest payment details.
IPV494[.]252[.]245[.]193Phorpiex (Twizt) botnet C2 server observed on Syrian Telecom infrastructure.

MITRE ATT&CK

CVE

Threat Actors

Malware

Amateratrick users into running base64-encoded osascript droppers via Terminal. The campaign may be linked to Amatera botnet activity and is tentatively attributed to APT28. Similarly, the CyberProof researchers identifiedAquilaRATSliver implant via DLL side-loading through Fondue.exe, SoullessRAT via fake AlphaFly installer, and AquilaRAT (Rust backdoor) leveraging multiple rotating C2 domains.AsyncRATand post-exploitation platforms also appear prominently in the dataset. These include Prism X (13), AsyncRAT (12), Sliver (10), Cobalt Strike (8), and Mirai (8), indicating that both commodity malware andDYNOWIPERexploitation campaign.Infrastructure observed on CLODO CLOUD SERVICE CO. L.L.C (UAE) was linked to the DYNOWIPER destructive campaign targeting Poland's energy sector. Per CERT Polska and ESET, the wiper was blockedEchoGather RATentities using Starlink registration and drone training lures. The multi-stage attack chain deployed EchoGather RAT via Telegram channels and phishing pages, Sliver implant via DLL side-loading through Fondue.exe,HajimeThe most common detections fall into two groups: IoT botnets like Hajime, Mozi, and Mirai, which are malware, and Threat Activity Enablers like Tactical RMM, Cobalt Strike, and Sliver, which are dual-use tools that showHellsUcheckerAdditionally, another research detailed a 10-stage campaign delivering the HellsUchecker backdoor via fake Cloudflare CAPTCHA (ClickFix) that tricks users into executing caret-obfuscated commands.LockBit Blackdelivered encrypted high-entropy payloads, including XMRig miner, and has previously distributed LockBit Black ransomware.MiraiThe most common detections fall into two groups: IoT botnets like Hajime, Mozi, and Mirai, which are malware, and Threat Activity Enablers like Tactical RMM, Cobalt Strike, and Sliver, which are dual-use tools that showMoziThe most common detections fall into two groups: IoT botnets like Hajime, Mozi, and Mirai, which are malware, and Threat Activity Enablers like Tactical RMM, Cobalt Strike, and Sliver, which are dual-use tools that showNetSupport RAThow the actor compromises WordPress sites to inject external JavaScript redirecting users to NetSupport RAT payloads.PhorpiexOver the observation period, Hunt.io tracking surfaced Phorpiex (Twizt) botnet C2 server at 94.252.245[.]193 hosted on Syrian Telecom infrastructure, operating a hybrid C2 architecture combining HTTP endpoints with aRondoDox30+ facilities, and expose the growing risks to SCADA/OT environments.Bitsight TRACE documented the RondoDox botnet leveraging exploitation server infrastructure at 37.32.15[.]8 on Iranian provider AbrArvan CDNSoullessRATRAT via Telegram channels and phishing pages, Sliver implant via DLL side-loading through Fondue.exe, SoullessRAT via fake AlphaFly installer, and AquilaRAT (Rust backdoor) leveraging multiple rotating C2 domains.Termitecsc.exe) to fetch masqueraded PDF archives and stage follow-on payloads. The tradecraft aligns with Termite ransomware operations, though no encryption event occurred during the observation window.TwiztOver the observation period, Hunt.io tracking surfaced Phorpiex (Twizt) botnet C2 server at 94.252.245[.]193 hosted on Syrian Telecom infrastructure, operating a hybrid C2 architecture combining HTTP endpoints with aXMRigpeer-to-peer UDP layer on port 40,500. The campaign delivered encrypted high-entropy payloads, including XMRig miner, and has previously distributed LockBit Black ransomware.

Vendors

AbrArvan CDN and IaaSRondoDox botnet leveraging exploitation server infrastructure at 37.32.15[.]8 on Iranian provider AbrArvan CDN and IaaS, active since May 2025 and peaked at 15,000 daily exploit attempts against internet-exposedBlueVPS OUOther providers with notable malware diversity include BlueVPS OU (4 malware families), Private Customer (4), SUNUCUN BILGI (4), NTT DATA (3), Oracle Corporation (3), Microsoft Corporation (3), TE Data (3), and severalCLODO CLOUD SERVICE CO. L.L.C(Saudi Arabia), linked to Metro4Shell RCE exploitation campaign.Infrastructure observed on CLODO CLOUD SERVICE CO. L.L.C (UAE) was linked to the DYNOWIPER destructive campaign targeting Poland's energy sector. PerDEDIK SERVICES LIMITEDIntelligence reports the CLICKSMOKE MaaS platform remains active with its C2 panel hosted on DEDIK SERVICES LIMITED infrastructure, while previously exposed builds were rotated out. Another attack reported byHosting DünyamOther prominent providers include SERV.HOST GROUP LTD (Cyprus, 25), Hosting Dünyam (Turkey, 15), SUNUCUN BILGI (Turkey, 7), IHS Kurumsal Teknoloji (Turkey, 6), and Paltel (Palestine, 6).IHS Kurumsal TeknolojiOther prominent providers include SERV.HOST GROUP LTD (Cyprus, 25), Hosting Dünyam (Turkey, 15), SUNUCUN BILGI (Turkey, 7), IHS Kurumsal Teknoloji (Turkey, 6), and Paltel (Palestine, 6).Microsoftmalware families), Private Customer (4), SUNUCUN BILGI (4), NTT DATA (3), Oracle Corporation (3), Microsoft Corporation (3), TE Data (3), and several others.Mobily(Metro4Shell) in React Native CLI was observed with source IP 5.109.182[.]231 on Saudi Arabia's Mobily network (AS35819), delivering Base64-encoded PowerShell scripts that added Microsoft Defender AntivirusNetinternet Bilisim Teknolojileri AShosting Eagle Werewolf APT C2 domains targeting state entities and drone communities.On Netinternet Bilisim Teknolojileri AS (Turkey), the IP 93.113.62[.]247 was observed in a phishing campaign impersonating genericNTT DATAmalware diversity include BlueVPS OU (4 malware families), Private Customer (4), SUNUCUN BILGI (4), NTT DATA (3), Oracle Corporation (3), Microsoft Corporation (3), TE Data (3), and several others.OMCfor a disproportionate share of potential malicious infrastructure, with STC, SERVERS TECH FZCO (UAE), OMC (Israel), Türk Telekom, and Regxa (Iraq) hosting the largest volumes of detected C2 servers.Oracleinclude BlueVPS OU (4 malware families), Private Customer (4), SUNUCUN BILGI (4), NTT DATA (3), Oracle Corporation (3), Microsoft Corporation (3), TE Data (3), and several others.PaltelOther prominent providers include SERV.HOST GROUP LTD (Cyprus, 25), Hosting Dünyam (Turkey, 15), SUNUCUN BILGI (Turkey, 7), IHS Kurumsal Teknoloji (Turkey, 6), and Paltel (Palestine, 6).Regxa Company for Information Technology Ltdmalicious open directories within Turkey's primary telecommunications network.Regxa Company for Information Technology Ltd, an Iraqi IT solutions provider, shows 38 C2 detections, 1 malicious open directory, 1SERV.HOST GROUP LTDOther prominent providers include SERV.HOST GROUP LTD (Cyprus, 25), Hosting Dünyam (Turkey, 15), SUNUCUN BILGI (Turkey, 7), IHS Kurumsal Teknoloji (Turkey, 6), and Paltel (Palestine, 6).SERVERS TECH FZCOproviders accounts for a disproportionate share of potential malicious infrastructure, with STC, SERVERS TECH FZCO (UAE), OMC (Israel), Türk Telekom, and Regxa (Iraq) hosting the largest volumes of detected C2STCset of hosting providers accounts for a disproportionate share of potential malicious infrastructure, with STC, SERVERS TECH FZCO (UAE), OMC (Israel), Türk Telekom, and Regxa (Iraq) hosting the largest volumes ofSUNUCUN BILGIOther prominent providers include SERV.HOST GROUP LTD (Cyprus, 25), Hosting Dünyam (Turkey, 15), SUNUCUN BILGI (Turkey, 7), IHS Kurumsal Teknoloji (Turkey, 6), and Paltel (Palestine, 6).Syrian Telecomperiod, Hunt.io tracking surfaced Phorpiex (Twizt) botnet C2 server at 94.252.245[.]193 hosted on Syrian Telecom infrastructure, operating a hybrid C2 architecture combining HTTP endpoints with a resilientTürk Telekomshare of potential malicious infrastructure, with STC, SERVERS TECH FZCO (UAE), OMC (Israel), Türk Telekom, and Regxa (Iraq) hosting the largest volumes of detected C2 servers.TE DataCustomer (4), SUNUCUN BILGI (4), NTT DATA (3), Oracle Corporation (3), Microsoft Corporation (3), TE Data (3), and several others.

Products

Amazon Bedrockprivilege escalation to admin account "frick," persistence across 19 AWS principals, Amazon Bedrock LLMjacking, and deployment of p4d.24xlarge instance with public JupyterLab on port 8888.AWSresearchers documented a November 2025 intrusion where attackers leveraged AI to compress an AWS attack chain to under 10 minutes, with activity originating from 197.51.170[.]131 on Egyptian ISP TE DataHost RadarHost Radar, a core module of Hunt.io, was designed to address this gap by correlating C2 servers, phishing infrastructure, malicious open directories, and public IOCs back to the hosting providers and network operatorsKeitaroMany of the detections here are Threat Activity Enablers, tools like Tactical RMM, Keitaro, Gophish, Acunetix, Cobalt Strike and Sliver. Each one has legitimate, unwanted, and malicious use cases, and the balanceMicrosoft Defender AntivirusArabia's Mobily network (AS35819), delivering Base64-encoded PowerShell scripts that added Microsoft Defender Antivirus exclusions before establishing TCP connections to download Rust-based binaries withReact Native CLICloud Storage impersonation phishing campaign.Active exploitation of CVE-2025-11953 (Metro4Shell) in React Native CLI was observed with source IP 5.109.182[.]231 on Saudi Arabia's Mobily network (AS35819), deliveringTactical RMMMany of the detections here are Threat Activity Enablers, tools like Tactical RMM, Keitaro, Gophish, Acunetix, Cobalt Strike and Sliver. Each one has legitimate, unwanted, and malicious use cases, and the balanceWordPressreport on GrayCharlie, a threat actor overlapping with SmartApeSG, documented how the actor compromises WordPress sites to inject external JavaScript redirecting users to NetSupport RAT payloads.

Tools

AcunetixMany of the detections here are Threat Activity Enablers, tools like Tactical RMM, Keitaro, Gophish, Acunetix, Cobalt Strike and Sliver. Each one has legitimate, unwanted, and malicious use cases, and the balanceCLICKSMOKEGrayCharlie WordPress compromise campaign targeting U.S. law firms.Breakglass Intelligence reports the CLICKSMOKE MaaS platform remains active with its C2 panel hosted on DEDIK SERVICES LIMITED infrastructure, whileCobalt Strikedetections here are Threat Activity Enablers, tools like Tactical RMM, Keitaro, Gophish, Acunetix, Cobalt Strike and Sliver. Each one has legitimate, unwanted, and malicious use cases, and the balance between thoseGophishMany of the detections here are Threat Activity Enablers, tools like Tactical RMM, Keitaro, Gophish, Acunetix, Cobalt Strike and Sliver. Each one has legitimate, unwanted, and malicious use cases, and the balanceHuntSQLUsing HuntSQL, we analyzed the distribution of command-and-control (C2) infrastructure across malware families hosted within Middle Eastern networks over three months.Needleexposed builds were rotated out. Another attack reported by Breakglass intelligence, mapped nine live Needle Malware-as-a-Service customer panels confirmed on April 22, 2026, showing consistent HTTP fingerprintsPrism Xframeworks and post-exploitation platforms also appear prominently in the dataset. These include Prism X (13), AsyncRAT (12), Sliver (10), Cobalt Strike (8), and Mirai (8), indicating that both commoditySliverhere are Threat Activity Enablers, tools like Tactical RMM, Keitaro, Gophish, Acunetix, Cobalt Strike and Sliver. Each one has legitimate, unwanted, and malicious use cases, and the balance between those depends on the

Countries

Bahrainthe UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not only the scale of active C2 infrastructure, but also the dominance ofCypruswith Middle Eastern infrastructure providers across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not only the scale ofEgyptMiddle Eastern infrastructure providers across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not only the scale of activeIranwith Middle Eastern infrastructure providers across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not only theIraqassociated with Middle Eastern infrastructure providers across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not onlyIsraeltelemetry associated with Middle Eastern infrastructure providers across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results revealJordanacross the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not only the scale of active C2 infrastructure, but also theKuwaitEastern infrastructure providers across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not only the scale of active C2Lebanonproviders across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not only the scale of active C2Palestineproviders across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not only the scale of active C2 infrastructure, but alsoPolandon CLODO CLOUD SERVICE CO. L.L.C (UAE) was linked to the DYNOWIPER destructive campaign targeting Poland's energy sector. Per CERT Polska and ESET, the wiper was blocked before causing damage: more than 30 windSaudi ArabiaRadar, we analyzed telemetry associated with Middle Eastern infrastructure providers across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria.SyriaSaudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The results reveal not only the scale of active C2 infrastructure, but also the dominance of specificTurkeyanalyzed telemetry associated with Middle Eastern infrastructure providers across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, and Syria. The resultsUAEUsing Host Radar, we analyzed telemetry associated with Middle Eastern infrastructure providers across the UAE, Saudi Arabia, Turkey, Israel, Iraq, Iran, Cyprus, Egypt, Kuwait, Lebanon, Palestine, Jordan, Bahrain, andUnited States20. Hunt.io IOC Hunter showing a brief summary of the GrayCharlie WordPress compromise campaign targeting U.S. law firms.Breakglass Intelligence reports the CLICKSMOKE MaaS platform remains active with its C2 panel

Industries

Related Articles