logo

1,250+ C2 Servers Mapped Across Russian Hosting Across 165 Providers

ID: 9ed93c7f-914f-5983-b234-e6ad0f37d2a7

STIX ID: report--9ed93c7f-914f-5983-b234-e6ad0f37d2a7

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-04-16

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Researchers using Host Radar and HuntSQL observed roughly 1,250+ active C2 servers and ~1,290 malicious artifacts hosted across 165 Russian commercial providers between Jan 1 and Apr 1, 2026; the infrastructure supports a wide range of malware families and campaigns (Keitaro, Hajime, Mozi, Mirai, Cobalt Strike variants, Remcos, Latrodectus, Lumma Stealer, BoryptGrab, SHADOWSNIFF, SALATSTEALER) and is concentrated in high-volume providers (TimeWeb, WebHost1, REG.RU, VDSina, PROSPERO OOO), prompting recommendations to prioritize provider-level monitoring, restrict vulnerable execution chains, and monitor outbound connections to Russian ASNs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.