logo

Chinese Hackers Control 18,000 Active Servers Across 48 Hosting Providers

ID: 32efe084-6ed5-5a97-8998-b10f6ea51913

STIX ID: report--32efe084-6ed5-5a97-8998-b10f6ea51913

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-01-15

Date Updated: 2026-04-22

Author: Varshini

...
...

The report presents analysis showing over 18,000 active C2 servers and 21,629 malicious artifacts hosted across 48 Chinese ISPs/providers during a three-month period, with heavy concentration at China Unicom, Alibaba Cloud, and Tencent; dominant malware families (Mozi, ARL, Cobalt Strike, Vshell, Mirai) and coexistence of cybercrime and APT activity are emphasized, illustrating large-scale infrastructure reuse that complicates attribution and takedown efforts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.