惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
Vercel News
Vercel News
博客园 - 叶小钗
大猫的无限游戏
大猫的无限游戏
MyScale Blog
MyScale Blog
P
Proofpoint News Feed
量子位
Engineering at Meta
Engineering at Meta
B
Blog RSS Feed
博客园 - 【当耐特】
Recent Announcements
Recent Announcements
Google DeepMind News
Google DeepMind News
D
DataBreaches.Net
Stack Overflow Blog
Stack Overflow Blog
博客园 - 聂微东
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
人人都是产品经理
人人都是产品经理
IT之家
IT之家
T
The Blog of Author Tim Ferriss
Last Week in AI
Last Week in AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Jina AI
Jina AI
博客园 - 三生石上(FineUI控件)

Security Affairs

Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844) CISA reports persistent FIRESTARTER backdoor on Cisco ASA device in federal network 12-year-old Pack2TheRoot bug lets Linux users gain root privileges Signal phishing campaign targets Germany’s Bundestag President Julia Klöckner
One Telecom Provider Hosted Most of the Middle East ’s Ac...
Pierluigi Paganini · 2026-05-22 · via Security Affairs

Hunt.io mapped 1,350+ C2 servers across the Middle East, revealing how a small group of providers quietly supports major malware activity.

For years, threat intelligence focused mostly on malware families, phishing domains, and individual indicators. But a new report from Hunt.io shows why defenders may need to pay closer attention to something more boring, hosting infrastructure.

After spending roughly three months mapping malicious infrastructure across the Middle East, researchers identified more than 1,350 command-and-control servers spread across 98 providers in 14 countries. What stands out is not just the scale of the activity, but how concentrated it is.

One provider alone, Saudi Telecom Company (STC), accounted for more than 72% of all observed regional C2 activity during the period analyzed. Most of that infrastructure appears to consist of compromised customer systems rather than intentionally malicious hosting, but the result is the same: a huge amount of attacker traffic flowing through a relatively small slice of infrastructure.

“The same providers keep showing up across completely unrelated campaigns and malware families.” reads the report published by Hunt.io “Provider-level tracking beats chasing individual indicators that rotate daily.”

That’s probably the most important takeaway from the report. Attackers rotate domains, IPs, and payloads constantly. Infrastructure patterns move much more slowly.

The report also highlights how different providers tend to attract different types of activity. Türk Telekom, for example, showed the highest malware diversity in the dataset, hosting infrastructure associated with six separate malware families across multiple C2 endpoints. Researchers also flagged Regxa, an Iraqi provider, as having the highest “bulletproof hosting” profile observed in the analysis.

“Infrastructure hosted on Regxa Company for Information Technology Ltd (regxa.iq) was identified as hosting C2 associated with a February 2026 espionage campaign attributed to the Eagle Werewolf cluster, targeting state and industrial entities using Starlink registration and drone training lures.” states Hunt.io.”The multi-stage attack chain deployed EchoGather RAT via Telegram channels and phishing pages, Sliver implant via DLL side-loading through Fondue.exe, SoullessRAT via fake AlphaFly installer, and AquilaRAT (Rust backdoor) leveraging multiple rotating C2 domains.”

The malware itself is a mix of commodity tooling, botnets, phishing infrastructure, and post-exploitation frameworks. Families observed in the dataset include Cobalt Strike, AsyncRAT, Mirai, Sliver, Mozi, Hajime, Tactical RMM, and Gophish.

Some of the associated campaigns are more interesting than the malware names themselves. Hunt.io linked parts of the infrastructure to operations involving Eagle Werewolf espionage activity, DYNOWIPER attacks targeting Poland’s energy sector, and RondoDox botnet activity hosted on Iranian infrastructure.

“Saudi Arabia’s STC (Saudi Telecom Company) hosts 981 C2 servers, representing 72.4% of all detected C2 infrastructure in the region, the largest concentration observed across any single provider globally.” continues the report.

“A small set of hosting providers accounts for a disproportionate share of malicious infrastructure, with STC, SERVERS TECH FZCO (UAE), OMC (Israel), Türk Telekom, and Regxa (Iraq) hosting the largest volumes of detected C2 servers.”

That idea reflects a broader shift happening in threat hunting. Many security teams are overloaded with short-lived indicators that become useless within hours or days. Infrastructure-level analysis tends to survive longer because attackers often reuse providers, VPS environments, certificates, hosting resellers, and operational habits even when malware changes.

Another important point is that malicious infrastructure increasingly blends into legitimate environments. The report notes that much of the observed activity sits inside trusted commercial networks rather than isolated “dark” infrastructure.

That creates a difficult problem for defenders. Blocking an individual IP is easy. Blocking entire providers or regions is often impossible for operational and business reasons, especially when those networks also host legitimate customers and services.

The report doesn’t suggest that providers themselves are necessarily complicit. In many cases, attackers are abusing compromised servers or inexpensive VPS instances rented through ordinary commercial channels.

“The presence of telecommunications giants alongside cryptocurrency-accepting VPS providers within the top rankings illustrates how diverse infrastructure types, from consumer ISP networks to bulletproof hosting environments, can all be leveraged for malware C2 infrastructure deployment across the Middle East.” continues the report.

But the concentration patterns still matter because they reveal where malicious infrastructure tends to survive longest and where attackers repeatedly return.

In practical terms, the findings reinforce something many threat hunters already suspect: infrastructure telemetry often tells a more stable story than malware samples alone.

Attackers may change payloads every week. Their infrastructure habits usually change much more slowly.

“The data from this three-month window makes one thing clear: malicious infrastructure in the Middle East is not evenly distributed. Over 1,350 C2 servers across 98 providers, with a single telecom carrier accounting for nearly three quarters of all regional C2 activity, points to a threat landscape where concentration is the pattern, not the exception.” concludes the report. “Knowing which providers consistently appear in the data changes how defenders prioritize, block, and monitor.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Middle East)