Hackers Abuse Middle East Telecom Networks for Large-Scale Command-and-Control Operations
ID: 62ab1f2d-2190-5211-b734-3f7e94d53985
STIX ID: report--62ab1f2d-2190-5211-b734-3f7e94d53985
Feed Name: cybersecurityNews.com
Threat intelligence from Hunt.io reports the discovery of more than 1,350 active C2 servers across 98 Middle Eastern ISPs and hosting providers—heavily concentrated in Saudi Arabia’s STC—and identifies a wide range of malicious activity including IoT botnets, RATs, phishing kits, ransomware (LockBit Black), and espionage campaigns (Eagle Werewolf). The report links active exploitation of CVE-2025-11953, large-scale exploit activity (RondoDox with up to 15,000 daily attempts), and numerous IoCs to specific providers and urges defenders to monitor provider/ASN-level infrastructure rather than only chasing individual indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
