Hunt.io Maps More Than 1,250 C2 Servers Across 165 Russian Providers

Summary
Hunt.io’s three-month analysis identified 1,252 active C2 servers across 165 Russian infrastructure providers, with activity concentrated among a few hosts and spanning botnets, malware frameworks, phishing, and intrusion campaigns.
Key points
- Host Radar telemetry from Jan. 1 to Apr. 1, 2026, identified 1,252 C2 servers across 165 Russian infrastructure providers.
- The reported artifact breakdown includes 75 malicious open directories, 69 phishing sites, and 17 public IOCs; C2 servers account for about 88.6% of the reported activity.
- TimeWeb had the most detected C2 servers (311), followed by WebHost1 (140) and REG.RU (138).
- Keitaro led the malware-family results with 587 unique C2 IPs; IoT botnets Hajime, Mozi, and Mirai were also observed.
- Campaign examples linked hosting infrastructure to activity involving Latrodectus, Lumma Stealer, Remcos RAT, infostealers, phishing, and targeted intrusions.
- The analysis argues that mapping activity to hosting providers can help security teams prioritize infrastructure for monitoring and disruption.
Article Details
- Publisher
- Hunt IO
- Report Period
- 2026-01-01 to 2026-04-01
- Scope
- Malicious infrastructure and malware C2 telemetry associated with Russian hosting, cloud, and telecommunications providers.
- Sample Size
- 165 infrastructure providers; 1,252 detected C2 servers.
- Key Statistics
- The three-month analysis identified 1,252 C2 servers across 165 Russian infrastructure providers.
- The source reports approximately 1,290 malicious artifacts, comprising 1,252 C2 servers, 75 malicious open directories, 17 public-research IOCs, and 69 phishing sites. These component counts total 1,413, not 1,290; the reported shares are approximately 88.6%, 5.3%, 1.2%, and 4.9%, respectively.
- Over 90 days, the five highest-ranked providers by C2 detections were TimeWeb with 311, WebHost1 with 140, REG.RU with 138, VDSina with 86, and PROSPERO OOO with 80.
- The malware-family analysis reported 587 unique C2 IPs associated with Keitaro and 191 associated with Hajime during the three-month window.
- The malware-diversity query identified 11 distinct malware families across 39 unique C2 endpoints at Yandex.Cloud LLC, the highest reported family diversity.
- Recommendations
- Correlate C2 endpoints, phishing infrastructure, malicious open directories, and public IOCs with hosting providers and network operators.
- Use a host-centric view to prioritize high-risk providers, track infrastructure and malware reuse, and guide infrastructure-level mitigation.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | fadoklismokley[.]com | Attacker-controlled domain contacted by Latrodectus v2.3. |
| DOMAIN | gasrobariokley[.]com | Attacker-controlled domain contacted by Latrodectus v2.3. |
| IPV4 | 178[.]255[.]127[.]65 | LLC Smart Ape-hosted infrastructure associated with targeted intrusion operations attributed to Head Mare. |
| IPV4 | 188[.]127[.]227[.]46 | LLC Smart Ape-hosted infrastructure associated with targeted intrusion operations attributed to Head Mare. |
| IPV4 | 188[.]127[.]254[.]233 | LLC Smart Ape-hosted infrastructure associated with targeted intrusion operations attributed to Head Mare. |
| IPV4 | 193[.]143[.]1[.]104 | Proton66 OOO-hosted infrastructure linked to a BoryptGrab infostealer distribution operation abusing public GitHub repositories. |
| IPV4 | 193[.]178[.]170[.]155 | Hosting Technology LTD infrastructure tied to SmartApeSG activity delivering Remcos RAT. |
| IPV4 | 217[.]114[.]15[.]253 | Beget LLC-hosted infrastructure linked to a GrayCharlie-attributed operation distributing NetSupport RAT through compromised websites. |
| IPV4 | 45[.]130[.]41[.]81 | Beget LLC-hosted infrastructure linked to the Diesel Vortex phishing-as-a-service operation targeting logistics and transportation companies. |
| IPV4 | 45[.]146[.]164[.]110 | Beget LLC-hosted IP observed in SSH honeypot telemetry associated with coordinated botnet activity. |
| IPV4 | 45[.]153[.]191[.]245 | Beget LLC-hosted infrastructure linked to a GrayCharlie-attributed operation distributing NetSupport RAT through compromised websites. |
| IPV4 | 85[.]198[.]98[.]75 | Beget LLC-hosted infrastructure associated with UAC-0252 phishing activity deploying SHADOWSNIFF, SALATSTEALER, and DEAFTICK. |
| IPV4 | 85[.]239[.]54[.]130 | JSC TIMEWEB-hosted malicious endpoint associated with Latrodectus activity and a ClickFix campaign analyzed by CERT Polska. |
| IPV4 | 89[.]111[.]170[.]100 | REG.RU-hosted infrastructure linked to the Lumma Stealer and Ninja Browser operation documented by CTM360. |
MITRE ATT&CK
T1027.001 · Binary PaddingThe Lumma Stealer operation delivered large padded archives to Windows victims.T1053.005 · Scheduled TaskAccording to Kaspersky's analysis, Head Mare activity established persistence through scheduled tasks.T1059.001 · PowerShellThe Latrodectus ClickFix operation induced execution of a curl-to-PowerShell command; Head Mare activity also deployed a PowerShell backdoor.T1189 · Drive-by CompromiseCompromised WordPress sites in GrayCharlie-attributed activity injected JavaScript that redirected visitors to NetSupport RAT payloads.T1203 · Exploitation for Client ExecutionUAC-0252 exploited the WinRAR vulnerability CVE-2025-8088 to facilitate infection.T1204.002 · Malicious FileUAC-0252 distributed archives containing executable files that deployed infostealers and a backdoor.T1572 · Protocol TunnelingHead Mare activity used reverse SSH tunneling to maintain access within compromised environments.T1573.001 · Symmetric CryptographyAccording to Kaspersky's analysis, malware used in Head Mare activity employed AES-encrypted C2 communications.T1574.002 · DLL Side-LoadingThe SmartApeSG operation installed Remcos RAT through DLL sideloading.T1598.004 · Spearphishing VoiceThe Diesel Vortex operation included voice phishing as part of credential harvesting and social engineering.
CVE
Threat Actors
GrayCharlieRecorded Future attributed an operation using compromised WordPress sites to distribute NetSupport RAT to this actor. A separate figure caption describes possible GrayCharlie APT involvement in SmartApeSG activity.Head MareThreat group associated with targeted intrusions using LLC Smart Ape infrastructure; Kaspersky's analysis described deployment of PhantomHeart and PhantomProxyLite.UAC-0252Tracked adversarial activity impersonating Ukrainian government institutions and distributing SHADOWSNIFF, SALATSTEALER, and DEAFTICK; the source links it to exploitation of CVE-2025-8088.
Malware
BoryptGrabinfrastructure hosted by Proton66 OOO, where the IP 193.143.1[.]104 was linked to a large-scale BoryptGrab infostealer operation. Researchers identified more than 100 public GitHub repositories being abused toDEAFTICKexecutable files that ultimately deployed SHADOWSNIFF and SALATSTEALER infostealers, alongside a DEAFTICK backdoor. The operation relied on GitHub-hosted payloads and exploited a WinRAR vulnerabilityHajimeA small set of malware families (Keitaro, Hajime, Tactical RMM, Cobalt Strike, Sliver, and Ligolo-ng) showing framework-driven, repeatable abuse.KeitaroA small set of malware families (Keitaro, Hajime, Tactical RMM, Cobalt Strike, Sliver, and Ligolo-ng) showing framework-driven, repeatable abuse.Latrodectus(C2) endpoints hosted across Russian infrastructure providers, beginning with activity linked to Latrodectus malware hosted on JSC TIMEWEB infrastructure. The IP 85.239.54[.]130 was associated with a campaignLumma Stealerexample involved infrastructure hosted on REG.RU, where the IP 89.111.170[.]100 was linked to a Lumma Stealer malware campaign documented by CTM360. The operation abused Google Groups and Google-hostedMiraiIoT-focused botnets (Hajime, Mozi, and Mirai) remain present within Russian infrastructure, reflecting ongoing abuse of compromised embedded devices and routers.MoziIoT-focused botnets (Hajime, Mozi, and Mirai) remain present within Russian infrastructure, reflecting ongoing abuse of compromised embedded devices and routers.NetSupport RATGrayCharlie, where compromised WordPress sites injected malicious JavaScript redirecting visitors to NetSupport RAT payloads. Infrastructure linked to this campaign included 217.114.15[.]253 and 45.153.191[.]245, bothNinja BrowserLumma Stealer payloads, while Linux users were targeted with a trojanized Chromium variant known as Ninja Browser that installed malicious extensions and enabled persistent remote control of infected systems.PhantomHeartthreat group. According to Kaspersky's analysis, the campaign deployed a PowerShell backdoor called PhantomHeart alongside a rewritten proxy tool PhantomProxyLite. The malware leveraged AES-encrypted C2Remcos RATHosting Technology LTD, where the IP 193.178.170[.]155 was tied to the SmartApeSG campaign delivering Remcos RAT. In this campaign, attackers injected malicious JavaScript into compromised websites that displayedSalatStealerand distributed archives containing executable files that ultimately deployed SHADOWSNIFF and SALATSTEALER infostealers, alongside a DEAFTICK backdoor. The operation relied on GitHub-hosted payloads andSHADOWSNIFFgovernment institutions and distributed archives containing executable files that ultimately deployed SHADOWSNIFF and SALATSTEALER infostealers, alongside a DEAFTICK backdoor. The operation relied on GitHub-hosted
Vendors
BegetOther prominent providers include Selectel (80), Beget (58), Proton66 OOO (52), Er-Telecom (ETC) (35), and Rostelecom (27).Beget LLCcampaign delivering Remcos RAT and possible GrayCharlie APT activity.Infrastructure hosted by Beget LLC appeared repeatedly across several campaigns. One example includes 85.198.98[.]75, which was associatedEr-Telecom (ETC)Other prominent providers include Selectel (80), Beget (58), Proton66 OOO (52), Er-Telecom (ETC) (35), and Rostelecom (27).Hosting Technology LTDOther providers with notable malware diversity include Proton66 OOO (9 malware families), Hosting Technology LTD (8), LLC Baxet (8), and Selectel Network (7).Hunt.ioHost Radar, a core module of Hunt.io, was designed to address this gap by correlating command-and-control servers, phishing infrastructure, malicious open directories, and public IOCs back to the hosting providers andJSC Datacenterendpoints. PROSPERO OOO also hosts 10 malware families associated with 25 unique C2 endpoints, while JSC Datacenter hosts 9 malware families across 18 C2 endpoints.JSC TIMEWEBin malware diversity, hosting 11 distinct malware families across 39 unique C2 endpoints, followed by JSC TIMEWEB, which hosts 10 distinct malware families across 102 unique C2 endpoints. PROSPERO OOO also hosts 10LLC BaxetOther providers with notable malware diversity include Proton66 OOO (9 malware families), Hosting Technology LTD (8), LLC Baxet (8), and Selectel Network (7).LLC Smart ApeA targeted intrusion activity was identified within infrastructure hosted by LLC Smart Ape, where multiple IPs, including 178.255.127[.]65, 188.127.227[.]46, and 188.127.254[.]233 were associated with operationsPROSPERO OOOA small set of hosting providers accounts for a disproportionate share of malicious infrastructure, with TimeWeb, WebHost1, REG.RU, VDSina, and PROSPERO OOO hosting the largest volumes of detected C2 servers.Proton66 OOOOther prominent providers include Selectel (80), Beget (58), Proton66 OOO (52), Er-Telecom (ETC) (35), and Rostelecom (27).REG.RUA small set of hosting providers accounts for a disproportionate share of malicious infrastructure, with TimeWeb, WebHost1, REG.RU, VDSina, and PROSPERO OOO hosting the largest volumes of detected C2 servers.RostelecomOther prominent providers include Selectel (80), Beget (58), Proton66 OOO (52), Er-Telecom (ETC) (35), and Rostelecom (27).SelectelOther prominent providers include Selectel (80), Beget (58), Proton66 OOO (52), Er-Telecom (ETC) (35), and Rostelecom (27).Selectel NetworkOther providers with notable malware diversity include Proton66 OOO (9 malware families), Hosting Technology LTD (8), LLC Baxet (8), and Selectel Network (7).TimeWebA small set of hosting providers accounts for a disproportionate share of malicious infrastructure, with TimeWeb, WebHost1, REG.RU, VDSina, and PROSPERO OOO hosting the largest volumes of detected C2 servers.VDSinaA small set of hosting providers accounts for a disproportionate share of malicious infrastructure, with TimeWeb, WebHost1, REG.RU, VDSina, and PROSPERO OOO hosting the largest volumes of detected C2 servers.WebHost1A small set of hosting providers accounts for a disproportionate share of malicious infrastructure, with TimeWeb, WebHost1, REG.RU, VDSina, and PROSPERO OOO hosting the largest volumes of detected C2 servers.Yandex.Cloud LLCYandex.Cloud LLC leads in malware diversity, hosting 11 distinct malware families across 39 unique C2 endpoints, followed by JSC TIMEWEB, which hosts 10 distinct malware families across 102 unique C2 endpoints. PROSPERO
Products
Chromiumreconstructing AutoIt-based Lumma Stealer payloads, while Linux users were targeted with a trojanized Chromium variant known as Ninja Browser that installed malicious extensions and enabled persistent remote controlGoogle Groupswas linked to a Lumma Stealer malware campaign documented by CTM360. The operation abused Google Groups and Google-hosted redirectors to distribute malicious payloads across both Windows and Linux systems.LinuxGoogle Groups and Google-hosted redirectors to distribute malicious payloads across both Windows and Linux systems. Windows victims received large padded archives reconstructing AutoIt-based Lumma StealerMicrosoft Windowsabused Google Groups and Google-hosted redirectors to distribute malicious payloads across both Windows and Linux systems. Windows victims received large padded archives reconstructing AutoIt-based LummaWinRARalongside a DEAFTICK backdoor. The operation relied on GitHub-hosted payloads and exploited a WinRAR vulnerability (CVE-2025-8088) to facilitate infection.WordPressby Recorded Future, the researchers identified a campaign attributed to GrayCharlie, where compromised WordPress sites injected malicious JavaScript redirecting visitors to NetSupport RAT payloads. Infrastructure
Tools
AcunetixScanning and phishing infrastructure tools such as Acunetix (71) and Interactsh (21) indicate vulnerability scanning, while Gophish (56) demonstrates the continued presence of phishing campaign infrastructure operatingCobalt StrikeA small set of malware families (Keitaro, Hajime, Tactical RMM, Cobalt Strike, Sliver, and Ligolo-ng) showing framework-driven, repeatable abuse.Gophishinfrastructure tools such as Acunetix (71) and Interactsh (21) indicate vulnerability scanning, while Gophish (56) demonstrates the continued presence of phishing campaign infrastructure operating from RussianHASSHinfrastructure.Another IP 45.146.164[.]110 appeared in SSH honeypot telemetry, where analysts used HASSH fingerprinting to identify coordinated botnet activity leveraging the same libssh-based tooling acrossHost RadarHost Radar, a core module of Hunt.io, was designed to address this gap by correlating command-and-control servers, phishing infrastructure, malicious open directories, and public IOCs back to the hosting providers andHuntSQLUsing HuntSQL, we analyzed the distribution of command-and-control (C2) infrastructure across malware families hosted within Russian networks over three months.InteractshScanning and phishing infrastructure tools such as Acunetix (71) and Interactsh (21) indicate vulnerability scanning, while Gophish (56) demonstrates the continued presence of phishing campaign infrastructure operatingLigolo-ngA small set of malware families (Keitaro, Hajime, Tactical RMM, Cobalt Strike, Sliver, and Ligolo-ng) showing framework-driven, repeatable abuse.PhantomProxyLitethe campaign deployed a PowerShell backdoor called PhantomHeart alongside a rewritten proxy tool PhantomProxyLite. The malware leveraged AES-encrypted C2 communications, persistence through scheduled tasks, andSliverA small set of malware families (Keitaro, Hajime, Tactical RMM, Cobalt Strike, Sliver, and Ligolo-ng) showing framework-driven, repeatable abuse.Tactical RMMA small set of malware families (Keitaro, Hajime, Tactical RMM, Cobalt Strike, Sliver, and Ligolo-ng) showing framework-driven, repeatable abuse.
Countries
Industries
logisticsVortex operation, a phishing-as-a-service platform branded Global Profit / MC Profit Always targeting logistics and transportation companies. Researchers recovered campaign infrastructure revealing Telegram-basedTransportationa phishing-as-a-service platform branded Global Profit / MC Profit Always targeting logistics and transportation companies. Researchers recovered campaign infrastructure revealing Telegram-based coordination