logo

Hackers Abuse Middle East Telecom Networks for Large-Scale Command-and-Control Operations

ID: 62ab1f2d-2190-5211-b734-3f7e94d53985

STIX ID: report--62ab1f2d-2190-5211-b734-3f7e94d53985

Feed Name: cybersecurityNews.com

Threat Score
86/100

Date Published: 2026-05-22

Date Updated: 2026-05-23

Author: Tushar Subhra Dutta

...
...

Threat intelligence from Hunt.io reports the discovery of more than 1,350 active C2 servers across 98 Middle Eastern ISPs and hosting providers—heavily concentrated in Saudi Arabia’s STC—and identifies a wide range of malicious activity including IoT botnets, RATs, phishing kits, ransomware (LockBit Black), and espionage campaigns (Eagle Werewolf). The report links active exploitation of CVE-2025-11953, large-scale exploit activity (RondoDox with up to 15,000 daily attempts), and numerous IoCs to specific providers and urges defenders to monitor provider/ASN-level infrastructure rather than only chasing individual indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.