Summary
Key Points:
- A recent report by Hunt.io reveals that Saudi Telecom Company (STC) hosts over 72% of the Middle East's command-and-control (C2) servers, indicating a significant concentration of malicious infrastructure.
- The impact is substantial, as attackers exploit compromised customer systems for malware activity, complicating defense efforts due to the blending of malicious and legitimate traffic within trusted networks.
- Security teams should focus on provider-level tracking rather than short-lived indicators, enhancing their ability to monitor and block malicious infrastructure effectively.
Technical Details: The report identifies 1,350+ C2 servers linked to various malware families including Cobalt Strike, AsyncRAT, and Sliver. It highlights the use of compromised systems and inexpensive VPS instances for hosting malicious operations.
MITRE ATT&CK Techniques:
- T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
- T1203 - Exploitation for Client Execution (Execution)
- T1046 - Network Service Discovery (Discovery)
IOCs Mentioned: None mentioned
Join the discussion — sign up to comment, upvote, and save articles.