Chinese Hackers Control 18,000 Active Servers Across 48 Hosting Providers
ID: 32efe084-6ed5-5a97-8998-b10f6ea51913
STIX ID: report--32efe084-6ed5-5a97-8998-b10f6ea51913
Feed Name: GBHackers
Threat Score
The report presents analysis showing over 18,000 active C2 servers and 21,629 malicious artifacts hosted across 48 Chinese ISPs/providers during a three-month period, with heavy concentration at China Unicom, Alibaba Cloud, and Tencent; dominant malware families (Mozi, ARL, Cobalt Strike, Vshell, Mirai) and coexistence of cybercrime and APT activity are emphasized, illustrating large-scale infrastructure reuse that complicates attribution and takedown efforts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
