logo

Chinese Threat Actors Hosted 18,000 Active C2 Servers Across 48 Hosting Providers

ID: e368b5a3-b0ba-57e1-ab32-54240a886e95

STIX ID: report--e368b5a3-b0ba-57e1-ab32-54240a886e95

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-15

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Research using the Host Radar platform identified a massive network of over 18,000 active C2 servers across 48 Chinese hosting providers, accounting for roughly 84% of observed malicious activity during the analysed period; China Unicom, Alibaba Cloud, and Tencent disproportionately host this infrastructure. Major malware families (Mozi, ARL, Cobalt Strike, Vshell, Mirai) drive the activity, demonstrating that threat actors exploit cloud and hosting services for resilient command-and-control, complicating indicator-based detection and creating a concentrated, high-scale abuse ecosystem.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.