Middle East Malicious Infrastructure Report: 1,350+ C2 Servers Mapped Across 98 Providers
· Published 21/05/2026 23:03 · Modified 22/05/2026 07:13
Essential information
- Published
- 21/05/2026 23:03
- Modified
- 22/05/2026 07:13
- Tags
- 2026-05-21 CVE-2025-11953 acunetix aquilarat asyncrat bulletproof hosting c2 infrastructure cobalt strike dynowiper echogather espionage campaigns gophish hajime hellsuchecker iot botnets keitaro lockbit black maas platforms middle east mirai mozi netsupport rat offensive frameworks phexia phorpiex prism x rondodox sliver soullessrat tactical rmm telecommunications termite twizt xmrig
- Related entities
- 1 vulnerabilities (cve), 5 observables, 1 intrusion sets (apt), 21 techniques (mitre), 24 malware, 2 others
Description
Between February and May 2026, over 1,350 active command-and-control servers were identified across 98 infrastructure providers spanning 14 Middle Eastern countries. Saudi Arabia's STC hosted 981 C2 servers, representing 72.4% of all regional malicious infrastructure, the largest concentration globally. C2 infrastructure dominated at 96.8% of detected activity, with IoT-focused botnets like Hajime, Mozi, and Mirai, alongside offensive frameworks including Tactical RMM, Cobalt Strike, and Sliver representing the primary malware families. The infrastructure supported diverse operations from state-sponsored espionage campaigns like Eagle Werewolf targeting state entities, to Malware-as-a-Service platforms, cryptomining operations, and destructive attacks such as DYNOWIPER. Key providers included SERVERS TECH FZCO in UAE, OMC in Israel, Türk Telekom, and Regxa in Iraq, demonstrating how telecommunications giants and specialized hosting services enable both commodity cybercrime and advanced persistent threat op...
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Vulnerabilities (CVE) (1)
CVE-2025-11953
KEV
9.8
Critical
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes …
- Attack vector
- NETWORK
- Published
- 03/11/2025
- Modified
- 07/02/2026
Observables (5)
197.51.170.1315.109.182.23194.252.245.19337.32.15.893.113.62.247
Intrusion sets (APT) (1)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 22/05/2026 09:12 · Modified 22/05/2026 09:12
Techniques (MITRE) (21)
-
Malicious Link
-
Valid Accounts
-
Virtualization/Sandbox Evasion
-
Masquerading
-
Process Injection
-
Scheduled Task/Job
-
Encrypted Channel
-
Web Protocols
-
PowerShell
-
Spearphishing Attachment
-
Native API
-
Create or Modify System Process
-
Obfuscated Files or Information
-
Exploit Public-Facing Application
-
Ingress Tool Transfer
-
Account Manipulation
-
Create Account
-
Disable or Modify Tools
-
Domains
-
Deobfuscate/Decode Files or Information
-
DNS
Malware (24)
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
FamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
FamilyPublished 22/05/2026 13:08 · Modified 22/05/2026 13:08
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:39 · Modified 27/05/2026 21:40
-
FamilyPublished 11/06/2026 16:31 · Modified 11/06/2026 16:31
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
FamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
FamilyPublished 28/05/2026 10:56 · Modified 28/05/2026 10:56
Others (2)
- Energy
- Government