The Middle East telecom and hosting infrastructure has emerged as a major backbone for global cybercrime operations, with more than 1,350 active command-and-control (C2) servers identified across the region in just three months, according to new analysis from Hunt.io.
The study, covering activity between February 1 and May 1, 2026, highlights how threat actors increasingly rely on regional telecommunications networks, cloud platforms, and VPS providers to host malware infrastructure.
Researchers warn that traditional IOC-driven detection models are proving ineffective, as attackers rapidly rotate indicators while continuing to reuse the same underlying infrastructure providers.
Telecom Networks Exploited
The analysis identified 1,357 C2 servers across 98 infrastructure providers spanning 14 Middle Eastern countries, including Saudi Arabia, UAE, Turkey, Israel, Iran, and Iraq.
Notably, C2 infrastructure accounted for approximately 96.8% of all observed malicious artifacts, far exceeding the share of phishing sites and publicly reported indicators.

Saudi Telecom Company (STC) alone hosted 981 C2 servers, accounting for 72.4% of all detected C2 activity in the dataset.
Researchers attribute this concentration to the scale of STC’s network and its large customer base, suggesting that compromised endpoints within the telecom environment are being leveraged rather than the direct compromise of the provider.

The dataset reveals a mix of commodity malware, botnets, and advanced post-exploitation frameworks operating across the region.
Tactical RMM led all malware families with 92 unique C2 IPs, reflecting widespread abuse of legitimate remote management tools.
Other prominent families included Keitaro (traffic distribution system), Acunetix, Gophish, and IoT botnets such as Mozi, Hajime, and Mirai.

Advanced offensive frameworks, including Cobalt Strike, Sliver, and AsyncRAT, were also observed, indicating overlap between cybercriminal and state-linked operations.
Several real-world campaigns illustrate how this infrastructure is actively used:
- A Phorpiex (Twizt) botnet C2 server hosted on Syrian Telecom infrastructure (94.252.245[.]193) delivered encrypted payloads, including XMRig cryptominers and LockBit Black ransomware.
- Infrastructure linked to Regxa in Iraq supported a February 2026 espionage campaign attributed to the “Eagle Werewolf” cluster, which deployed multiple RAT families, including EchoGather and Sliver, via phishing and Telegram-based lures.
- Exploitation of CVE-2025-11953 (Metro4Shell) was traced to an IP on Saudi Arabia’s Mobily network, delivering Base64-encoded PowerShell payloads and Rust-based malware.
- Iranian infrastructure (AbrArvan CDN) hosted RondoDox botnet operations, which launched up to 15,000 daily exploit attempts using Mirai-like techniques across 174 vulnerabilities.
The research also identified ongoing MaaS operations, phishing campaigns, and destructive malware activity, including infrastructure linked to DYNOWIPER attacks and ClickFix social engineering chains, Hunt.io said.
Beyond individual campaigns, the report emphasizes a critical shift in defensive strategy: tracking infrastructure providers rather than individual indicators.
While IPs and domains change rapidly, attackers consistently return to the same hosting environments, telecom networks, and ASN-level resources.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.