← Back to news

One Telecom Provider Hosted Most of the Middle East ’s Active C2 Infrastructure

Security Affairs22/05/2026, 07:29
Read full article →

Summary

AI-Generated

Key Points:

  • A recent report by Hunt.io reveals that Saudi Telecom Company (STC) hosts over 72% of the Middle East's command-and-control (C2) servers, indicating a significant concentration of malicious infrastructure.
  • The impact is substantial, as attackers exploit compromised customer systems for malware activity, complicating defense efforts due to the blending of malicious and legitimate traffic within trusted networks.
  • Security teams should focus on provider-level tracking rather than short-lived indicators, enhancing their ability to monitor and block malicious infrastructure effectively.

Technical Details: The report identifies 1,350+ C2 servers linked to various malware families including Cobalt Strike, AsyncRAT, and Sliver. It highlights the use of compromised systems and inexpensive VPS instances for hosting malicious operations.

MITRE ATT&CK Techniques:

  • T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
  • T1203 - Exploitation for Client Execution (Execution)
  • T1046 - Network Service Discovery (Discovery)

IOCs Mentioned: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.