Thursday, August 20, 2026

Russian Hosting Tied to 1,250+ C2 Servers Across 165 Providers

More than 1,250 C2 servers were identified across 165 Russian infrastructure providers within the past 3 months. Infrastructure analytics and ISP mapping are exposing the hidden backbone of cyber threats operating inside Russian networks.

By looking beyond single IPs or one-off indicators, analysts used Host Radar and HuntSQL to map more than 1,250 active command‑and‑control (C2) servers across 165 Russian providers between 1 January and 1 April 2026.

This provider‑level view turns raw indicators into infrastructure‑centric intelligence that security teams can actually act on.

Instead of starting from malware samples or isolated domains, Host Radar correlates C2 servers, phishing sites, malicious open directories, and public IOCs back to the networks that host them.

In Russia, this approach shows that malicious activity is not limited to a handful of “bulletproof” hosts but is spread across shared hosting, VPS platforms, cloud providers, and major telecom networks.

Over the last three months, new infrastructure analytics from Hunt.io reveal the extent to which Russian hosting providers are involved in global cyber operations.

The result is a clearer picture of which organizations repeatedly appear across unrelated campaigns, even as individual indicators are cycled or burned.

Across 165 Russian infrastructure providers, Hunt.io recorded about 1,290 malicious artifacts in the three‑month window, including 1,252 C2 servers, 75 malicious open directories, 69 phishing sites, and 17 public IOCs.

Russian providers with 311 detected over 90 days, alongside 7 malicious open directories, 91 port scanners, 0 IOCs, 3 IOC Hunter posts, and 9 phishing sites.

TimeWeb - Host Radar Detailed View: Per-provider Host Radar breakdown for TimeWeb (Source : Hunt.io).
TimeWeb – Host Radar Detailed View: Per-provider Host Radar breakdown for TimeWeb (Source : Hunt.io).

C2 infrastructure dominates this landscape, accounting for roughly 88.6% of observed artifacts, while phishing and exposed directories remain a secondary but persistent layer of abuse.

This confirms that Russian networks are primarily being used to run and coordinate operations rather than host static lure content.

Top Russian providers by C2 activity

A small group of providers hosts a disproportionate share of Russian‑based C2 infrastructure over the 90‑day window.

TimeWeb leads the dataset with 311 detected C2 servers, together with scanning infrastructure and a smaller number of phishing sites and open directories.

WebHost1 and REG.RU follow with 140 and 138 C2 servers, respectively, reflecting how large shared and VPS platforms are repeatedly leveraged for malware command‑and‑control and reconnaissance.

VDSina and PROSPERO OOO also appear among the most frequently abused environments, with 86 and 80 C2 servers respectively, alongside various scanners, phishing sites, and malicious open directories.

VDSina - Host Radar Detailed View(Source : Hunt.io).
VDSina – Host Radar Detailed View (Source : Hunt.io).

Other prominent providers in the top ten include Selectel, Beget, Proton66 OOO, Er‑Telecom, and Rostelecom, indicating that both commercial cloud platforms and backbone telecom networks play a role in sustaining malicious infrastructure.

For defenders, these concentrations make it possible to prioritize specific networks for monitoring, blocking, and escalation.

HuntSQL queries over Russian ASN telemetry show that a small set of malware families accounts for much of the observed C2 footprint.

Keitaro dominates the dataset with 587 unique C2 IPs, reflecting heavy use of this framework for traffic distribution and campaign management.

In comparison, malicious open directories represent about 5.3%, phishing infrastructure accounts for roughly 4.9%, while publicly reported IOCs contribute approximately 1.2% of the dataset.

Aggregate breakdown of C2 servers (1,252), phishing sites (69), malicious open directories (75), and public IOCs (17) detected within Russian hosting environments (Source : Hunt.io).
Aggregate breakdown of C2 servers (1,252), phishing sites (69), malicious open directories (75), and public IOCs (17) detected within Russian hosting environments (Source : Hunt.io).

IoT‑oriented botnets such as Hajime, Mozi, and Mirai remain active, highlighting ongoing abuse of compromised routers and embedded devices inside Russian networks.

Focusing on this small, high‑impact set of tooling allows defenders to track shared infrastructure rather than chasing every new payload variant.

Infrastructure‑centric detection

By aggregating telemetry at the organization level, HuntSQL identifies providers that host both the highest C2 volumes and the widest malware diversity.

The presence of both commercial hosting companies and large telecommunications providers within the top rankings illustrates how virtual server platforms, cloud environments, and ISP networks can all be leveraged for malware C2 infrastructure deployment.

Top 10 Russian infrastructure providers by number of detected C2 servers over a three-month window (Source : Hunt.io).
Top 10 Russian infrastructure providers by number of detected C2 servers over a three-month window (Source : Hunt.io).

Offensive security frameworks and post‑exploitation platforms also appear prominently, including Tactical RMM, Cobalt Strike (and unverified variants), Sliver, and Ligolo‑ng.

Yandex.Cloud LLC leads on malware family diversity, while TimeWeb and PROSPERO OOO combine high C2 counts with broad family coverage, making them strategically important for monitoring and takedown efforts.

The IP 85.239.54[.]130 was associated with a campaign analyzed by CERT Polska, where attackers leveraged a fake CAPTCHA “ClickFix” technique to trick users into executing a curl-to-PowerShell command.

Hunt.io IP intelligence highlighting JSC TimeWeb infrastructure (AS9123) with ClickFix (Fake CAPTCHA Attack) risk indicators (Source : Hunt.io).
Hunt.io IP intelligence highlighting JSC TimeWeb infrastructure (AS9123) with ClickFix (Fake CAPTCHA Attack) risk indicators (Source : Hunt.io).

Similar work against “bulletproof” providers has already led to sanctions and enforcement actions, illustrating how infrastructure‑level attribution can translate into real‑world disruption.

For security teams, this research underlines that the most effective choke points often sit in the hosting and ISP layer, not at the endpoint alone.

Mapping 1,250+ C2 servers across 165 Russian providers turns a noisy indicator feed into a prioritized view of high‑risk networks, enabling better detection, faster triage, and pressure on the providers that repeatedly enable abuse at scale.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

ToxicPanda 2.0 Steals PINs From 140+ Banking and Cryptocurrency Apps Using Invisible Overlays

ToxicPanda 2.0, an evolved Android banking Trojan that significantly...

Cisco BroadWorks Vulnerability Allows Remote Attackers to Access Sensitive Files

Cisco has issued security updates for a high-severity vulnerability...

Hackers Use Fake CAPTCHA to Deploy Malware That Shuts Down Endpoint Security

Threat actors are pairing fake CAPTCHA verification pages with...

Red Hat Kubernetes Flaw Lets Unauthenticated Attackers Access Internal Cluster Services

Red Hat has disclosed CVE-2026-66794, an important-severity server-side request...

Splunk Fixes 17 Vulnerabilities Including Critical MCP Server RCE

Splunk has released a security hardening update addressing 17...

Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud

Threat actors are increasingly abusing Microsoft 365 identity sessions...

CyberPanel Pre-Auth RCE Flaws Let Attackers Gain Remote Server Access

Researchers have revealed a pre-authentication remote code execution (RCE)...

Related Articles

Recent News