216.73.217.22

Middle East Malicious Infrastructure Report: 1,350+ C2 Servers Mapped Across 98 Providers

· Published 21/05/2026 23:03 · Modified 22/05/2026 07:13

Export JSON

Essential information

Published
21/05/2026 23:03
Modified
22/05/2026 07:13
Tags
2026-05-21 CVE-2025-11953 acunetix aquilarat asyncrat bulletproof hosting c2 infrastructure cobalt strike dynowiper echogather espionage campaigns gophish hajime hellsuchecker iot botnets keitaro lockbit black maas platforms middle east mirai mozi netsupport rat offensive frameworks phexia phorpiex prism x rondodox sliver soullessrat tactical rmm telecommunications termite twizt xmrig
Related entities
1 vulnerabilities (cve), 5 observables, 1 intrusion sets (apt), 21 techniques (mitre), 24 malware, 2 others

Description

Between February and May 2026, over 1,350 active command-and-control servers were identified across 98 infrastructure providers spanning 14 Middle Eastern countries. Saudi Arabia's STC hosted 981 C2 servers, representing 72.4% of all regional malicious infrastructure, the largest concentration globally. dominated at 96.8% of detected activity, with IoT-focused botnets like , , and , alongside including , , and representing the primary malware families. The infrastructure supported diverse operations from state-sponsored like Eagle Werewolf targeting state entities, to Malware-as-a-Service platforms, cryptomining operations, and destructive attacks such as . Key providers included SERVERS TECH FZCO in UAE, OMC in Israel, Türk Telekom, and Regxa in Iraq, demonstrating how giants and specialized hosting services enable both commodity cybercrime and advanced persistent threat op...

External references