logo

One Telecom Provider Hosted Most of the Middle East ’s Active C2 Infrastructure

ID: 7e861d05-1f04-52d2-b507-275500c3c884

STIX ID: report--7e861d05-1f04-52d2-b507-275500c3c884

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Pierluigi Paganini

...
...

Hunt.io mapped 1,350+ C2 servers across 98 providers in 14 Middle Eastern countries over a three-month window and found extreme concentration of malicious infrastructure—over 72% of regional C2s were hosted by a single provider (Saudi Telecom Company). The analysis catalogues observed malware families (Cobalt Strike, AsyncRAT, Mirai, Sliver, Mozi, Hajime, Tactical RMM, Gophish, etc.), links infrastructure to campaigns and espionage activity (including the Eagle Werewolf cluster, DYNOWIPER, and RondoDox), and recommends prioritizing provider-level telemetry because attackers repeatedly reuse hosting providers and compromised customer systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.