More than 1,250 C2 servers were identified across 165 Russian infrastructure providers within the past 3 months. Infrastructure analytics and ISP mapping are exposing the hidden backbone of cyber threats operating inside Russian networks.
By looking beyond single IPs or one-off indicators, analysts used Host Radar and HuntSQL to map more than 1,250 active command‑and‑control (C2) servers across 165 Russian providers between 1 January and 1 April 2026.
This provider‑level view turns raw indicators into infrastructure‑centric intelligence that security teams can actually act on.
Instead of starting from malware samples or isolated domains, Host Radar correlates C2 servers, phishing sites, malicious open directories, and public IOCs back to the networks that host them.
In Russia, this approach shows that malicious activity is not limited to a handful of “bulletproof” hosts but is spread across shared hosting, VPS platforms, cloud providers, and major telecom networks.
Over the last three months, new infrastructure analytics from Hunt.io reveal the extent to which Russian hosting providers are involved in global cyber operations.
The result is a clearer picture of which organizations repeatedly appear across unrelated campaigns, even as individual indicators are cycled or burned.
Across 165 Russian infrastructure providers, Hunt.io recorded about 1,290 malicious artifacts in the three‑month window, including 1,252 C2 servers, 75 malicious open directories, 69 phishing sites, and 17 public IOCs.
Russian providers with 311 detected over 90 days, alongside 7 malicious open directories, 91 port scanners, 0 IOCs, 3 IOC Hunter posts, and 9 phishing sites.

C2 infrastructure dominates this landscape, accounting for roughly 88.6% of observed artifacts, while phishing and exposed directories remain a secondary but persistent layer of abuse.
This confirms that Russian networks are primarily being used to run and coordinate operations rather than host static lure content.
Top Russian providers by C2 activity
A small group of providers hosts a disproportionate share of Russian‑based C2 infrastructure over the 90‑day window.
TimeWeb leads the dataset with 311 detected C2 servers, together with scanning infrastructure and a smaller number of phishing sites and open directories.
WebHost1 and REG.RU follow with 140 and 138 C2 servers, respectively, reflecting how large shared and VPS platforms are repeatedly leveraged for malware command‑and‑control and reconnaissance.
VDSina and PROSPERO OOO also appear among the most frequently abused environments, with 86 and 80 C2 servers respectively, alongside various scanners, phishing sites, and malicious open directories.

Other prominent providers in the top ten include Selectel, Beget, Proton66 OOO, Er‑Telecom, and Rostelecom, indicating that both commercial cloud platforms and backbone telecom networks play a role in sustaining malicious infrastructure.
For defenders, these concentrations make it possible to prioritize specific networks for monitoring, blocking, and escalation.
HuntSQL queries over Russian ASN telemetry show that a small set of malware families accounts for much of the observed C2 footprint.
Keitaro dominates the dataset with 587 unique C2 IPs, reflecting heavy use of this framework for traffic distribution and campaign management.
In comparison, malicious open directories represent about 5.3%, phishing infrastructure accounts for roughly 4.9%, while publicly reported IOCs contribute approximately 1.2% of the dataset.

IoT‑oriented botnets such as Hajime, Mozi, and Mirai remain active, highlighting ongoing abuse of compromised routers and embedded devices inside Russian networks.
Focusing on this small, high‑impact set of tooling allows defenders to track shared infrastructure rather than chasing every new payload variant.
Infrastructure‑centric detection
By aggregating telemetry at the organization level, HuntSQL identifies providers that host both the highest C2 volumes and the widest malware diversity.
The presence of both commercial hosting companies and large telecommunications providers within the top rankings illustrates how virtual server platforms, cloud environments, and ISP networks can all be leveraged for malware C2 infrastructure deployment.

Offensive security frameworks and post‑exploitation platforms also appear prominently, including Tactical RMM, Cobalt Strike (and unverified variants), Sliver, and Ligolo‑ng.
Yandex.Cloud LLC leads on malware family diversity, while TimeWeb and PROSPERO OOO combine high C2 counts with broad family coverage, making them strategically important for monitoring and takedown efforts.
The IP 85.239.54[.]130 was associated with a campaign analyzed by CERT Polska, where attackers leveraged a fake CAPTCHA “ClickFix” technique to trick users into executing a curl-to-PowerShell command.

Similar work against “bulletproof” providers has already led to sanctions and enforcement actions, illustrating how infrastructure‑level attribution can translate into real‑world disruption.
For security teams, this research underlines that the most effective choke points often sit in the hosting and ISP layer, not at the endpoint alone.
Mapping 1,250+ C2 servers across 165 Russian providers turns a noisy indicator feed into a prioritized view of high‑risk networks, enabling better detection, faster triage, and pressure on the providers that repeatedly enable abuse at scale.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





