logo

Middle East Telecom Networks Exploited In Command-and-Control Campaign

ID: 5c24b3a2-25c3-5aae-8623-6c022ac76635

STIX ID: report--5c24b3a2-25c3-5aae-8623-6c022ac76635

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Varshini

...
...

Hunt.io analysis (Feb–May 2026) found 1,357 active C2 servers across 14 Middle Eastern countries—concentrated heavily in Saudi Telecom Company—hosting a mix of commodity malware, IoT botnets, RATs, Cobalt Strike/Sliver, and ransomware (including LockBit Black). The report documents real-world campaigns (phishing, Telegram lures, exploit chains such as CVE-2025-11953/Metro4Shell), MaaS activity, and recommends defenders prioritize tracking infrastructure providers and ASN-level resources rather than ephemeral IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.