Hunt.io Maps More Than 18,000 Malware C2 Servers Across Chinese Hosting Providers

Summary
Hunt.io’s three-month analysis identified more than 18,000 C2 servers across 48 Chinese providers, with activity concentrated in major telecom and cloud networks and led by malware families including Mozi and ARL.
Key points
- Hunt.io recorded 21,629 malicious artifacts across 48 Chinese infrastructure providers over three months, including 18,130 C2 servers and 2,837 phishing sites.
- C2 servers made up about 84% of observed artifacts; phishing sites accounted for about 13%.
- China Unicom hosted roughly half of detected C2 servers, while Alibaba Cloud and Tencent each had about 3,300.
- Mozi led the identified C2 malware families with 9,427 unique IPs, followed by ARL with 2,878.
- The analysis found commodity malware, botnets, phishing operations, and state-linked tooling hosted across the same provider ecosystem.
- Hunt.io says mapping infrastructure to providers and networks can reveal recurring patterns despite IP and domain changes.
Article Details
- Publisher
- Hunt IO
- Report Period
- Three-month observation period; exact dates not disclosed
- Scope
- Malicious infrastructure observed across 48 Chinese infrastructure providers and network entities, including C2 servers, phishing sites, malicious open directories, and public IOCs.
- Sample Size
- 21,629 malicious artifacts: 18,130 C2 servers, 2,837 phishing sites, 528 malicious open directories, and 134 public IOCs.
- Key Statistics
- C2 infrastructure accounted for approximately 84% of observed malicious artifacts; phishing infrastructure accounted for approximately 13%.
- China Unicom had 9,100 C2 server detections in the aggregate provider comparison, nearly half of observed C2 activity.
- Mozi accounted for 9,427 unique C2 IPs, more than half of observed C2 activity in the malware-family analysis.
- Tencent Cloud Computing (Beijing) Co., Ltd. was associated with 60 malware families; Aliyun Computing Co., LTD with 52.
- The article reports that an automated campaign exploiting CVE-2025-8110 had compromised approximately 50% of exposed Gogs instances.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 101[.]33[.]78[.]145 | Tencent-operated infrastructure hosting a phishing campaign targeting Indian vehicle owners. |
| IPV4 | 106[.]126[.]3[.]56 | IP associated with the BRONZE HIGHLAND (Evasive Panda) campaign deploying MgBot. |
| IPV4 | 106[.]126[.]3[.]78 | IP associated with the BRONZE HIGHLAND (Evasive Panda) campaign deploying MgBot. |
| IPV4 | 106[.]53[.]108[.]81 | Supershell C2 payload infrastructure used for persistent reverse SSH access in a Gogs exploitation campaign. |
| IPV4 | 115[.]190[.]200[.]230 | IP associated with suspicious Vshell infrastructure in VirusTotal-indexed telemetry. |
| IPV4 | 117[.]72[.]242[.]9 | IP hosting a Cobalt Strike Beacon, described as post-exploitation infrastructure. |
| IPV4 | 123[.]60[.]143[.]74 | IP identified as suspicious infrastructure in Huawei Cloud Service data centers. |
| IPV4 | 124[.]70[.]52[.]134 | IP in suspicious Huawei Cloud Service infrastructure linked to L3MON RAT. |
| IPV4 | 160[.]202[.]245[.]232 | Endpoint associated with AsyncRAT activity and flagged via threatfox.abuse.ch. |
| IPV4 | 185[.]245[.]35[.]68 | IP associated with Mirai botnet activity. |
| IPV4 | 202[.]120[.]234[.]124 | IP associated with RondoDox botnet activity and React2Shell exploitation. |
| IPV4 | 202[.]120[.]234[.]163 | IP associated with RondoDox botnet activity and React2Shell exploitation. |
| IPV4 | 23[.]177[.]185[.]39 | IP associated with router-targeted attacks on exposed networking devices. |
| IPV4 | 43[.]130[.]12[.]41 | Tencent-operated infrastructure hosting a phishing campaign targeting Indian vehicle owners. |
| IPV4 | 43[.]154[.]170[.]196 | Campaign infrastructure associated with Gold Eye Dog and delivery of certificate-signed backdoors. |
| IPV4 | 43[.]247[.]134[.]215 | Endpoint associated with React2Shell exploitation delivering XMRig cryptominers and Cobalt Strike. |
| IPV4 | 45[.]113[.]192[.]102 | IP tied to phishing infrastructure delivering NSecRTS.exe in an Indian income-tax-themed campaign. |
| IPV4 | 45[.]155[.]220[.]44 | IP identified in Cobalt Strike campaign infrastructure on Starry Network Limited. |
| IPV4 | 58[.]144[.]143[.]27 | China169 Backbone infrastructure supporting malicious browser-extension activity in the DarkSpectre campaign. |
CVE
Threat Actors
APT-Q-27Alternate name explicitly given for Gold Eye Dog, described as delivering certificate-signed backdoors through AWS S3 buckets.BRONZE HIGHLANDThreat group associated with the campaign deploying MgBot; the article identifies Evasive Panda as an alternate name.Evasive PandaAlternate name explicitly given for BRONZE HIGHLAND, associated with the campaign deploying MgBot.Gold Eye DogGroup described as leveraging AWS S3 buckets to deliver certificate-signed backdoors; the article also names it APT-Q-27.Silver FoxGroup described as targeting Indian organizations with Income Tax-themed lures to deploy Valley RAT.
Malware
ARLA small set of malware families (Mozi, ARL, Cobalt Strike, Mirai, Vshell) accounts for most C2 activity, showing framework-driven, repeatable abuse.AsyncRATHunt.io further correlated AsyncRAT activity with Hubei Feixun Network Co., Ltd, where the endpoint 160.202.245[.]232 was flagged via threatfox.abuse.ch. Additional suspicious infrastructure (vshell) surfaced on BeijingL3MON RATdata centers, including infrastructure at 123.60.143[.]74 and 124.70.52[.]134, the latter linked to L3MON RAT.MgBotinfrastructure attributed to Quanzhou were tied to the BRONZE HIGHLAND (Evasive Panda) campaign deploying MgBot, confirming the presence of state-aligned threat activity within the broader Chinese hosting ecosystem.MiraiA small set of malware families (Mozi, ARL, Cobalt Strike, Mirai, Vshell) accounts for most C2 activity, showing framework-driven, repeatable abuse.MoziA small set of malware families (Mozi, ARL, Cobalt Strike, Mirai, Vshell) accounts for most C2 activity, showing framework-driven, repeatable abuse.NanoCore(C2) endpoints associated with commodity RATs and legacy malware families, beginning with NanoCore infrastructure hosted on Wowrack.com. Cobalt Strike campaigns were identified on Starry Network Limited,NSecRTS.exeCo., Ltd, where 45.113.192[.]102 was tied to an Indian income-tax themed phishing campaign delivering NSecRTS.exe. Botnet and OT-focused threats were identified on ZhouyiSat Communications, including Mirai botnetRondoDoxresearch infrastructure was not immune. The China Education and Research Network Center (CERNET) hosted RondoDox botnet activity at 202.120.234[.]124 and 202.120.234[.]163, both linked to React2Shell exploitationSupershellAn automated campaign has already compromised approximately 50% of exposed instances, deploying the Supershell C2 (106.53.108[.]81) payload for persistent reverse SSH access.Valley RATtoward Indian organizations, utilizing highly convincing Income Tax-themed lures to deploy the modular Valley RAT. This campaign is notable for its sophisticated multi-stage execution and successful evasion ofVshellA small set of malware families (Mozi, ARL, Cobalt Strike, Mirai, Vshell) accounts for most C2 activity, showing framework-driven, repeatable abuse.XMRigXNNET LLC, one endpoint 43.247.134[.]215 was associated with React2Shell exploitation chains delivering XMRig cryptominers and Cobalt Strike, reflecting post-exploitation monetization and red-team framework abuse on
Vendors
Alibaba CloudChina Unicom alone hosts nearly half of all observed C2 servers, with Alibaba Cloud and Tencent following, highlighting heavy concentration in large, high-capacity networks.China Telecommalicious footprint across C2 servers, phishing sites, open directories, and IOCs.In contrast, China Telecom shows moderate C2 activity with 617 servers and 42 open directories over the same period, reflectingChina UnicomChina Unicom alone hosts nearly half of all observed C2 servers, with Alibaba Cloud and Tencent following, highlighting heavy concentration in large, high-capacity networks.Huaweiis observed within Asia Pacific Network Information Centre (APNIC), linked to 27 malware families, and Huawei Public Cloud Service, which accounts for 20 distinct families, underscoring how a few large providers areJD.comHost Radar metrics for China Telecom reflecting moderate but persistent malicious infrastructure presence.JD.com, primarily an e-commerce provider, exhibits minimal malicious activity, with 385 C2 servers and no openTencentChina Unicom alone hosts nearly half of all observed C2 servers, with Alibaba Cloud and Tencent following, highlighting heavy concentration in large, high-capacity networks.
Products
AWS S3The Gold Eye Dog (APT-Q-27) group is leveraging AWS S3 buckets to deliver sophisticated, certificate-signed backdoors that employ extensive anti-evasion checks and persistent remote-control capabilities. This campaignGogsResearchers have identified active exploitation of a zero-day vulnerability in Gogs (CVE-2025-8110) that allows authenticated users to achieve Remote Code Execution (RCE) by bypassing symlink protections. An automatedHost RadarHost Radar was built to analyze infrastructure-level abuse at country and ISP scale by correlating command-and-control servers, phishing infrastructure, malicious open directories, and public IOCs back to the hosting
Tools
Cobalt StrikeA small set of malware families (Mozi, ARL, Cobalt Strike, Mirai, Vshell) accounts for most C2 activity, showing framework-driven, repeatable abuse.GophishThe presence of Gophish and Acunetix further shows that phishing operations and vulnerability scanning infrastructure are actively deployed as part of broader attack chains. Overall, the top 10 malware families aloneHuntSQLUsing HuntSQL, we analyzed the distribution of command-and-control (C2) infrastructure across malware families hosted within Chinese networks over three months.
Countries
ChinaChina Unicom alone hosts nearly half of all observed C2 servers, with Alibaba Cloud and Tencent following, highlighting heavy concentration in large, high-capacity networks.Indiainfrastructure emerged as one of the most heavily abused environments. A phishing campaign in India targeting vehicle owners through SMS messages that threaten legal action for unpaid e-challans was hosted
Industries
Cloud ComputingTencent Cloud Computing (Beijing) Co., Ltd. leads the list, hosting 60 malware families and nearly 2,000 C2 endpoints, followed closely by Aliyun Computing Co., LTD with 52 malware families across approximately 1,956 C2E-commerceheavy abuse of its broad array of internet-facing services, including social media, gaming, and e-commerce platforms.Education and researchThe academic and research infrastructure was not immune. The China Education and Research Network Center (CERNET) hosted RondoDox botnet activity at 202.120.234[.]124 and 202.120.234[.]163, both linked to React2ShellTelecommunicationsChina Unicom, one of the largest telecommunications providers in China, exhibits the highest number of C2 servers, with 9,000 detected over 90 days, alongside 30 malicious open directories and 11 IOCs.