logo

Inside China’s Hosting Ecosystem: 18,000+ Malware C2 Servers Mapped Across Major ISPs

ID: 0867b8aa-48dc-5747-9e91-9810d51019fd

STIX ID: report--0867b8aa-48dc-5747-9e91-9810d51019fd

Feed Name: Hunt.io Blog

Threat Score
88/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This report presents a country-scale, host-centric analysis of malicious infrastructure observed across Chinese ISPs and cloud providers, identifying more than 18,000 C2 servers concentrated within a small set of large providers (notably China Unicom, Alibaba Cloud, and Tencent). It maps malware family prevalence (Mozi, ARL, Cobalt Strike, Mirai, Vshell), active exploitation of vulnerabilities (including Gogs CVE-2025-8110 and React2Shell), and real-world campaigns—showing that state-linked APTs and cybercriminal operations coexist and repeatedly reuse the same hosting infrastructure, amplifying systemic risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.