One Telecom Provider Hosted Most of the Middle East's Active C2 Infrastructure

C2 Infrastructure Threat Intelligence Telecom Hosting Abuse Middle East
Overview
Hunt.io researchers reported that a large percentage of active malicious command-and-control (C2) infrastructure in the Middle East was hosted through a small number of telecom and hosting providers. Saudi Telecom Company (STC) alone reportedly hosted approximately 72.4% of observed active C2 servers in the region during the study period.
The infrastructure was associated with malware campaigns, espionage operations, phishing activity, botnets, and post-exploitation frameworks.

Technical Specifications
| Attribute | Details |
|---|---|
| Study Scope | More than 1,350 active C2 servers |
| Provider Coverage | 98 providers across 14 Middle Eastern countries |
| Observation Period | Three months |
| Highest Reported Concentration | STC hosted ~72.4% of observed active C2 servers |
| Threat Frameworks / Malware Observed | Cobalt Strike, AsyncRAT, Sliver, Mirai, Mozi, Hajime, Tactical RMM, Gophish |
| Abuse Methods | Malicious VPS use, compromised servers, telecom-hosted infrastructure abuse |
| Attributed / Linked Activity (Reported) | Eagle Werewolf espionage ops, DYNOWIPER-related infrastructure, RondoDox botnet activity |
| Additional Provider Note | Turk Telekom reportedly hosted infrastructure tied to at least six malware families |
Affected Products
- Telecom-hosted VPS and cloud infrastructure in the Middle East
- Public-facing enterprise systems targeted by C2-managed malware and phishing operations
- Organizations relying only on static blocklists for C2 prevention
Attack Scenario
-
Infrastructure Acquisition: Threat actors rent or compromise servers hosted by telecom and cloud providers in the region.
-
C2 Deployment: Systems are configured as command-and-control nodes to manage malware operations.
-
Operational Use: Attackers use the infrastructure to control infections, deliver phishing payloads, exfiltrate data, and coordinate botnet actions.
-
Blended Traffic Evasion: Malicious communications blend with legitimate telecom-hosted traffic, reducing defender visibility and complicating blocking.
Impact Assessment
- Espionage risk against government, telecom, and industrial sectors
- Malware deployment, credential theft, and persistent unauthorized access
- Botnet growth and sustained phishing campaign enablement
- Harder attribution when infrastructure is co-located with trusted providers
- Reduced effectiveness of simple IP/domain deny-list strategies
- Increased need for behavioral and telemetry-based detection at scale
Mitigation Strategies
Detection and Visibility
- Monitor outbound traffic for suspicious beaconing and C2 patterns.
- Deploy network detection and response (NDR) with high-quality threat intelligence feeds.
- Use behavioral analytics rather than relying only on IP/domain blocklists.
Hardening and Containment
- Implement segmentation and least-privilege controls.
- Continuously scan hosted infrastructure for compromise indicators.
- Enforce MFA and strong credential hygiene.
- Monitor VPS and cloud assets for unauthorized services or malware frameworks.
Resources and References
Open-Source Reporting
Last Updated: May 24, 2026