A recent Hunt.io infrastructure analysis reveals a massive network of cyber threats operating within Russian hosting environments.
Over three months from January to April 2026, researchers identified more than 1,250 active command-and-control (C2) servers distributed across 165 Russian infrastructure providers.
This discovery highlights how shared hosting platforms, virtual server providers, and telecommunications networks form the hidden backbone for persistent malware and phishing campaigns.
Top Providers and Malware Families
According to Hunt.io’s Host Radar telemetry, C2 infrastructure accounts for an overwhelming 88.6% of observed malicious activity in these environments.
The analysis shows that a small group of providers harbors a disproportionate share of these malicious servers.
TimeWeb emerged as the top source with 311 detected C2 servers, followed closely by WebHost1 with 140, and REG.RU with 138.

The data exposes a heavy concentration of specific malware frameworks dominating these networks. Threat actors are utilizing these platforms to establish repeatable, framework-driven attacks. Key technical findings regarding malware distribution include:
- Dominant Frameworks: Keitaro leads the dataset with 587 unique C2 IPs, representing the largest concentration of infrastructure.
- IoT Botnets: Embedded device networks remain highly active, with Hajime (191 C2S), Mozi (48 C2S), and Mirai (13 C2S) showing significant presence.
- Offensive Security Tools: Post-exploitation platforms such as Tactical RMM, Cobalt Strike, and Sliver are frequently abused by attackers to maintain persistent access.
- Scanning and Phishing: Tools such as Acunetix and Gophish are widely used for vulnerability scanning and credential harvesting.
Interestingly, while TimeWeb hosts the highest volume of C2 servers, Yandex. Cloud supports the widest diversity, hosting 11 distinct malware families across 39 unique endpoints.

Active Cyber Campaigns and Infrastructure Abuse
The concentration of C2 servers within Russian hosting providers actively supports a diverse range of malicious operations.
Hunt.io researchers mapped several ongoing campaigns directly to these hosting environments, demonstrating the operational impact of this infrastructure.

Notable campaigns tracked during this period include:
- Latrodectus Malware: Attackers used a fake CAPTCHA “ClickFix” technique hosted on TimeWeb infrastructure to trick users into downloading malicious payloads.
- Lumma Stealer: REG.RU infrastructure was linked to campaigns abusing Google Groups to distribute Lumma Stealer to Windows users and Ninja Browser trojans to Linux systems.
- Remcos RAT: Hosting Technology LTD servers supported the SmartApeSG campaign, which delivered the Remcos Remote Access Trojan through disguised PDF files.
According to Hunt.io research, by tracking the infrastructure layer rather than chasing individual disposable indicators, security teams can better understand the overarching threat landscape.
This provider-level intelligence allows defenders to prioritize high-risk networks, implement large-scale disruption strategies, and effectively counter the diverse malicious operations sustained by Russian hosting environments.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.