AUTO-UPDATED

One Telecom Provider Hosted Most of the Middle East ’s Active C2 Infrastructure

A new Hunt.io report reveals that malicious command-and-control infrastructure in the Middle East is highly concentrated, with a few providers hosting the vast majority of regional attacker activity.

Key Points

  • Researchers identified over 1,350 command-and-control (C2) servers across 98 providers in 14 countries during a three-month analysis.
  • Saudi Telecom Company (STC) hosts 72.4% of all detected regional C2 infrastructure, primarily through compromised customer systems.
  • Türk Telekom exhibited the highest malware diversity, while Iraq-based Regxa was identified as a primary hub for "bulletproof" hosting services.
  • Observed malicious activity includes espionage campaigns like Eagle Werewolf, DYNOWIPER attacks on energy sectors, and various botnets such as Mirai and Hajime.
  • Attackers frequently leverage legitimate commercial networks and VPS providers rather than isolated, dark infrastructure to blend in with normal traffic.

Why it Matters

This research highlights a strategic shift in threat hunting, moving away from tracking short-lived malware indicators toward monitoring stable infrastructure patterns. By focusing on provider-level telemetry, security teams can better prioritize defenses against persistent attacker habits that remain consistent even when payloads and domains rotate.
Securityaffairs.com Published by Pierluigi Paganini
Read original