logo

Hackers Exploit Middle East Telecoms for Massive C2 Operations

ID: d0bac5b2-4759-5889-8dc4-45d006f9a1d0

STIX ID: report--d0bac5b2-4759-5889-8dc4-45d006f9a1d0

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Mayura Kathir

...
...

The Hunt.io report finds that attackers are extensively abusing Middle Eastern telecom and hosting providers to host large-scale C2 infrastructure—1,357 C2 servers across 98 providers, with Saudi Telecom Company accounting for the majority—supporting both commodity botnets and advanced post-exploitation tools (e.g., Cobalt Strike, Sliver) to enable ransomware, cryptomining, and espionage campaigns; it recommends prioritizing infrastructure- and provider-level tracking (ASNs, hosting patterns) to proactively detect and disrupt operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.