Chinese Threat Actors Hosted 18,000 Active C2 Servers Across 48 Hosting Providers
ID: e368b5a3-b0ba-57e1-ab32-54240a886e95
STIX ID: report--e368b5a3-b0ba-57e1-ab32-54240a886e95
Feed Name: cybersecurityNews.com
Research using the Host Radar platform identified a massive network of over 18,000 active C2 servers across 48 Chinese hosting providers, accounting for roughly 84% of observed malicious activity during the analysed period; China Unicom, Alibaba Cloud, and Tencent disproportionately host this infrastructure. Major malware families (Mozi, ARL, Cobalt Strike, Vshell, Mirai) drive the activity, demonstrating that threat actors exploit cloud and hosting services for resilient command-and-control, complicating indicator-based detection and creating a concentrated, high-scale abuse ecosystem.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
