Hunt.io Maps More Than 18,000 Malware C2 Servers Across Chinese Hosting Providers

· Original article ↗

Summary

Hunt.io’s three-month analysis identified more than 18,000 C2 servers across 48 Chinese providers, with activity concentrated in major telecom and cloud networks and led by malware families including Mozi and ARL.

Key points

  • Hunt.io recorded 21,629 malicious artifacts across 48 Chinese infrastructure providers over three months, including 18,130 C2 servers and 2,837 phishing sites.
  • C2 servers made up about 84% of observed artifacts; phishing sites accounted for about 13%.
  • China Unicom hosted roughly half of detected C2 servers, while Alibaba Cloud and Tencent each had about 3,300.
  • Mozi led the identified C2 malware families with 9,427 unique IPs, followed by ARL with 2,878.
  • The analysis found commodity malware, botnets, phishing operations, and state-linked tooling hosted across the same provider ecosystem.
  • Hunt.io says mapping infrastructure to providers and networks can reveal recurring patterns despite IP and domain changes.

Article Details

Publisher
Hunt IO
Report Period
Three-month observation period; exact dates not disclosed
Scope
Malicious infrastructure observed across 48 Chinese infrastructure providers and network entities, including C2 servers, phishing sites, malicious open directories, and public IOCs.
Sample Size
21,629 malicious artifacts: 18,130 C2 servers, 2,837 phishing sites, 528 malicious open directories, and 134 public IOCs.
Key Statistics
  • C2 infrastructure accounted for approximately 84% of observed malicious artifacts; phishing infrastructure accounted for approximately 13%.
  • China Unicom had 9,100 C2 server detections in the aggregate provider comparison, nearly half of observed C2 activity.
  • Mozi accounted for 9,427 unique C2 IPs, more than half of observed C2 activity in the malware-family analysis.
  • Tencent Cloud Computing (Beijing) Co., Ltd. was associated with 60 malware families; Aliyun Computing Co., LTD with 52.
  • The article reports that an automated campaign exploiting CVE-2025-8110 had compromised approximately 50% of exposed Gogs instances.

Indicators of compromise

TypeIndicatorContext
IPV4101[.]33[.]78[.]145Tencent-operated infrastructure hosting a phishing campaign targeting Indian vehicle owners.
IPV4106[.]126[.]3[.]56IP associated with the BRONZE HIGHLAND (Evasive Panda) campaign deploying MgBot.
IPV4106[.]126[.]3[.]78IP associated with the BRONZE HIGHLAND (Evasive Panda) campaign deploying MgBot.
IPV4106[.]53[.]108[.]81Supershell C2 payload infrastructure used for persistent reverse SSH access in a Gogs exploitation campaign.
IPV4115[.]190[.]200[.]230IP associated with suspicious Vshell infrastructure in VirusTotal-indexed telemetry.
IPV4117[.]72[.]242[.]9IP hosting a Cobalt Strike Beacon, described as post-exploitation infrastructure.
IPV4123[.]60[.]143[.]74IP identified as suspicious infrastructure in Huawei Cloud Service data centers.
IPV4124[.]70[.]52[.]134IP in suspicious Huawei Cloud Service infrastructure linked to L3MON RAT.
IPV4160[.]202[.]245[.]232Endpoint associated with AsyncRAT activity and flagged via threatfox.abuse.ch.
IPV4185[.]245[.]35[.]68IP associated with Mirai botnet activity.
IPV4202[.]120[.]234[.]124IP associated with RondoDox botnet activity and React2Shell exploitation.
IPV4202[.]120[.]234[.]163IP associated with RondoDox botnet activity and React2Shell exploitation.
IPV423[.]177[.]185[.]39IP associated with router-targeted attacks on exposed networking devices.
IPV443[.]130[.]12[.]41Tencent-operated infrastructure hosting a phishing campaign targeting Indian vehicle owners.
IPV443[.]154[.]170[.]196Campaign infrastructure associated with Gold Eye Dog and delivery of certificate-signed backdoors.
IPV443[.]247[.]134[.]215Endpoint associated with React2Shell exploitation delivering XMRig cryptominers and Cobalt Strike.
IPV445[.]113[.]192[.]102IP tied to phishing infrastructure delivering NSecRTS.exe in an Indian income-tax-themed campaign.
IPV445[.]155[.]220[.]44IP identified in Cobalt Strike campaign infrastructure on Starry Network Limited.
IPV458[.]144[.]143[.]27China169 Backbone infrastructure supporting malicious browser-extension activity in the DarkSpectre campaign.

CVE

Threat Actors

Malware

ARLA small set of malware families (Mozi, ARL, Cobalt Strike, Mirai, Vshell) accounts for most C2 activity, showing framework-driven, repeatable abuse.AsyncRATHunt.io further correlated AsyncRAT activity with Hubei Feixun Network Co., Ltd, where the endpoint 160.202.245[.]232 was flagged via threatfox.abuse.ch. Additional suspicious infrastructure (vshell) surfaced on BeijingL3MON RATdata centers, including infrastructure at 123.60.143[.]74 and 124.70.52[.]134, the latter linked to L3MON RAT.MgBotinfrastructure attributed to Quanzhou were tied to the BRONZE HIGHLAND (Evasive Panda) campaign deploying MgBot, confirming the presence of state-aligned threat activity within the broader Chinese hosting ecosystem.MiraiA small set of malware families (Mozi, ARL, Cobalt Strike, Mirai, Vshell) accounts for most C2 activity, showing framework-driven, repeatable abuse.MoziA small set of malware families (Mozi, ARL, Cobalt Strike, Mirai, Vshell) accounts for most C2 activity, showing framework-driven, repeatable abuse.NanoCore(C2) endpoints associated with commodity RATs and legacy malware families, beginning with NanoCore infrastructure hosted on Wowrack.com. Cobalt Strike campaigns were identified on Starry Network Limited,NSecRTS.exeCo., Ltd, where 45.113.192[.]102 was tied to an Indian income-tax themed phishing campaign delivering NSecRTS.exe. Botnet and OT-focused threats were identified on ZhouyiSat Communications, including Mirai botnetRondoDoxresearch infrastructure was not immune. The China Education and Research Network Center (CERNET) hosted RondoDox botnet activity at 202.120.234[.]124 and 202.120.234[.]163, both linked to React2Shell exploitationSupershellAn automated campaign has already compromised approximately 50% of exposed instances, deploying the Supershell C2 (106.53.108[.]81) payload for persistent reverse SSH access.Valley RATtoward Indian organizations, utilizing highly convincing Income Tax-themed lures to deploy the modular Valley RAT. This campaign is notable for its sophisticated multi-stage execution and successful evasion ofVshellA small set of malware families (Mozi, ARL, Cobalt Strike, Mirai, Vshell) accounts for most C2 activity, showing framework-driven, repeatable abuse.XMRigXNNET LLC, one endpoint 43.247.134[.]215 was associated with React2Shell exploitation chains delivering XMRig cryptominers and Cobalt Strike, reflecting post-exploitation monetization and red-team framework abuse on

Vendors

Products

Tools

Countries

Industries

Related Articles