Hackers are turning Middle East telecom networks into large-scale C2 hubs


Hackers are abusing telecom networks and hosting providers across the Middle East to run large-scale command-and-control infrastructure for malware, phishing, botnets, espionage campaigns, and post-exploitation tools.

A new Hunt.io report found more than 1,350 active C2 servers across 98 infrastructure providers in 14 Middle Eastern countries during a three-month window from February 1 to May 1, 2026.

The report shows that attackers are not only relying on obscure bulletproof hosts. They are also using large telecom networks, regional hosting companies, cloud providers, and compromised customer endpoints to keep malicious infrastructure online.

STC accounts for most detected C2 servers

The most striking finding involves Saudi Arabia’s STC, also known as Saudi Telecom Company. Hunt.io found 981 C2 servers tied to STC infrastructure, representing 72.4% of the regional C2 servers in the dataset.

Researchers said this likely reflects abuse of compromised customer endpoints rather than infrastructure directly operated as malicious hosting by the provider. That distinction matters because large telecom networks have huge customer bases, broad IP ranges, and legitimate traffic patterns that can help attackers blend in.

Coverage from SC World also noted that the concentration challenges traditional threat intelligence workflows that focus mainly on individual indicators, which attackers can rotate quickly.

ProviderCountry or regionDetected C2 serversWhy it matters
STCSaudi Arabia981Largest concentration in the regional dataset
SERVERS TECH FZCOUAE111Specialized hosting provider with notable C2 activity
OMCIsrael62Moderate C2 concentration in hosting infrastructure
Türk TelekomTurkey44Telecom network with both C2 servers and exposed malicious directories
RegxaIraq38Highest bulletproof rating in the dataset

C2 servers dominate the malicious activity

Across all 98 providers, Hunt.io recorded 1,459 malicious artifacts. That included 1,357 C2 servers, 45 malicious open directories, 43 IOC Hunter posts, seven phishing sites, and seven publicly referenced indicators of compromise.

This means C2 servers represented 93.0% of the observed malicious artifacts. The numbers show that Middle Eastern infrastructure is being used more heavily for malware control and post-compromise operations than for visible phishing pages or exposed directories.

A separate summary from Security Affairs described the same trend as a reason for defenders to watch hosting infrastructure instead of relying only on malware families and disposable IP addresses.

Attackers are using both telecoms and hosting providers

The dataset shows a mixed infrastructure picture. Large telecom operators appear alongside VPS companies, cloud providers, hosting firms, and services with weaker abuse-response patterns.

SERVERS TECH FZCO in the UAE had 111 detected C2 servers, four malicious open directories, one phishing site, and a medium bulletproof rating. Regxa in Iraq had 38 C2 servers and the highest bulletproof rating observed in the report.

Türk Telekom stood out for malware diversity. Hunt.io said the Turkish provider hosted six distinct malware families across nine unique C2 endpoints, giving it the highest malware-to-C2 ratio in the dataset.

What malware families appeared in the networks

The most common malware and tool clusters included Tactical RMM, Keitaro, Acunetix, Gophish, Mozi, and Hajime. Offensive tools such as Sliver, Cobalt Strike, AsyncRAT, and Prism X also appeared in the regional dataset.

This mix shows that the same underlying infrastructure can support different types of attackers. Commodity botnet operators, phishing crews, penetration-testing tool abusers, ransomware affiliates, and state-linked groups can all use overlapping hosting environments.

  • Tactical RMM led the dataset with 92 unique C2 IPs.
  • Keitaro appeared with 71 C2 servers tied to traffic distribution activity.
  • Acunetix appeared with 38 C2 servers linked to scanning activity.
  • Gophish appeared with 31 C2 servers tied to phishing infrastructure.
  • Mozi and Hajime showed continued IoT botnet activity.
  • Cobalt Strike, Sliver, AsyncRAT, and Mirai also appeared in the dataset.

Several active campaigns were tied to the infrastructure

The report connected multiple live or recently observed campaigns to regional hosting environments. One example involved the Phorpiex, or Twizt, botnet running on Syrian Telecom infrastructure through a hybrid HTTP and peer-to-peer C2 setup.

Malicious infrastructure detected across 98 Middle Eastern ISPs (Source – Hunt.io)

Another campaign used Regxa infrastructure in Iraq for activity associated with the Eagle Werewolf cluster. That campaign used Starlink registration and drone training lures to deliver multiple remote access tools, including EchoGather RAT, AquilaRAT, and SoullessRAT.

Researchers also observed exploitation of CVE-2025-11953 from Saudi Arabia’s Mobily network. The activity involved encoded scripts that added Microsoft Defender Antivirus exclusions before downloading malicious binaries.

RondoDox and other botnet activity add pressure

Iran-hosted infrastructure was linked to RondoDox, a Mirai-like botnet that peaked at 15,000 daily exploit attempts against internet-exposed devices. The botnet used many exploit paths and targeted multiple processor architectures.

The regional data also included phishing infrastructure in Turkey, destructive malware activity tied to UAE-hosted infrastructure, and an AWS intrusion campaign that originated from Egyptian ISP TE Data infrastructure.

The Hunt.io report argues that these examples show why infrastructure-level tracking can reveal attacker behavior before a specific attack becomes visible through traditional indicators.

Why provider-level tracking matters

Traditional threat intelligence often starts with IP addresses, domains, file hashes, and malware names. Those indicators help, but attackers can replace them quickly.

Provider-level analysis looks at the hosting companies, ASNs, telecom networks, and infrastructure patterns that attackers return to repeatedly. That approach can help security teams prioritize monitoring, blocking, and abuse-reporting work.

SC World noted that the concentration of C2 servers, especially around STC, creates a challenge for defenders because malicious traffic can sit inside legitimate regional networks.

Defensive focusTraditional approachProvider-level approach
Network indicatorsBlock known malicious IPs and domainsTrack repeat abuse across providers and ASNs
Threat intelligenceSort by malware family or campaign nameMap infrastructure patterns across campaigns
Response speedReact after new indicators appearPrioritize networks that repeatedly host malicious activity
Risk viewFocus on isolated artifactsIdentify concentrated abuse zones

What security teams should monitor

Organizations should not treat every IP address inside a large telecom network as malicious. They should instead use the report as a signal to strengthen telemetry around suspicious outbound connections, unusual C2 beacons, and provider patterns that appear repeatedly in threat data.

Teams with exposure in the Middle East should review traffic to and from regional telecom and hosting providers, especially when it involves unusual ports, rare protocols, encrypted payload delivery, or repeated connections to newly observed infrastructure.

  • Monitor outbound traffic to suspicious C2 endpoints across high-abuse providers.
  • Track ASNs and hosting providers that repeatedly appear in incident data.
  • Correlate C2 alerts with malware family, provider, country, and campaign context.
  • Review connections to uncommon ports and long-lived beaconing patterns.
  • Watch for abused remote management tools such as Tactical RMM.
  • Investigate phishing kits, open directories, and malware staging paths tied to the same providers.
  • Use provider-level intelligence to support blocking, sinkholing, and abuse-reporting decisions.

The bigger risk for regional infrastructure

The findings do not mean that Middle Eastern telecom providers are intentionally supporting attackers. In many cases, attackers may abuse compromised customers, poorly secured servers, infected routers, exposed devices, rented VPS instances, or weakly monitored hosting environments.

Still, the concentration of C2 servers creates a practical security problem. When attackers repeatedly use the same networks, those networks become important parts of the threat landscape even if the providers themselves run legitimate businesses.

Security Affairs also highlighted the report’s wider message: defenders should stop chasing only disposable indicators and start watching the infrastructure layer that attackers keep reusing.

Why this matters now

The Middle East remains a high-value region for cybercriminals, espionage groups, hacktivists, and ransomware-linked actors. The region’s telecom networks and hosting providers connect governments, energy companies, financial institutions, logistics firms, and cloud workloads.

That makes infrastructure abuse more than a local hosting problem. A C2 server in one country can control malware on victims in another region, host tooling for a global phishing campaign, or support reconnaissance against critical infrastructure.

The clearest takeaway is that defenders need a wider view of malicious infrastructure. IPs and domains still matter, but provider-level concentration can show where attackers are building, hiding, and returning over time.

FAQ

What did Hunt.io find in Middle East telecom and hosting networks?

Hunt.io found more than 1,350 active command-and-control servers across 98 infrastructure providers in 14 Middle Eastern countries during a three-month observation window from February 1 to May 1, 2026.

Which provider had the most detected C2 servers?

Saudi Arabia’s STC had the largest concentration, with 981 detected C2 servers. Hunt.io said this represented 72.4% of the regional C2 infrastructure in the dataset.

Does this mean telecom providers are running malicious servers?

Not necessarily. Hunt.io said the STC concentration likely reflects abuse of compromised customer endpoints rather than provider-managed malicious infrastructure. Attackers can also abuse rented servers, infected devices, and poorly secured systems inside legitimate networks.

What malware families were found across the regional infrastructure?

The dataset included Tactical RMM, Keitaro, Acunetix, Gophish, Mozi, Hajime, Prism X, AsyncRAT, Sliver, Cobalt Strike, and Mirai, showing activity from both commodity criminals and more advanced threat actors.

How should defenders use this research?

Defenders should monitor provider-level patterns, ASNs, repeat hosting abuse, suspicious outbound connections, C2 beaconing, and infrastructure reused across campaigns. This approach can help teams move beyond chasing disposable indicators.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages