1,250+ C2 Servers Mapped Across Russian Hosting Across 165 Providers
ID: 9ed93c7f-914f-5983-b234-e6ad0f37d2a7
STIX ID: report--9ed93c7f-914f-5983-b234-e6ad0f37d2a7
Feed Name: cybersecurityNews.com
Researchers using Host Radar and HuntSQL observed roughly 1,250+ active C2 servers and ~1,290 malicious artifacts hosted across 165 Russian commercial providers between Jan 1 and Apr 1, 2026; the infrastructure supports a wide range of malware families and campaigns (Keitaro, Hajime, Mozi, Mirai, Cobalt Strike variants, Remcos, Latrodectus, Lumma Stealer, BoryptGrab, SHADOWSNIFF, SALATSTEALER) and is concentrated in high-volume providers (TimeWeb, WebHost1, REG.RU, VDSina, PROSPERO OOO), prompting recommendations to prioritize provider-level monitoring, restrict vulnerable execution chains, and monitor outbound connections to Russian ASNs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
