Middle East Telecom Networks Exploited In Command-and-Control Campaign

The Middle East telecom and hosting infrastructure has emerged as a major backbone for global cybercrime operations, with more than 1,350 active command-and-control (C2) servers identified across the region in just three months, according to new analysis from Hunt.io.

The study, covering activity between February 1 and May 1, 2026, highlights how threat actors increasingly rely on regional telecommunications networks, cloud platforms, and VPS providers to host malware infrastructure.

Researchers warn that traditional IOC-driven detection models are proving ineffective, as attackers rapidly rotate indicators while continuing to reuse the same underlying infrastructure providers.

Telecom Networks Exploited

The analysis identified 1,357 C2 servers across 98 infrastructure providers spanning 14 Middle Eastern countries, including Saudi Arabia, UAE, Turkey, Israel, Iran, and Iraq.

Notably, C2 infrastructure accounted for approximately 96.8% of all observed malicious artifacts, far exceeding the share of phishing sites and publicly reported indicators.

STC (Saudi Telecom Company) - Host Radar Detailed View: Per-provider Host Radar breakdown for STC, highlighting the unprecedented concentration of C2 activity across Saudi Arabia's largest telecommunications network (Source: hunt.io)
STC (Saudi Telecom Company) – Host Radar Detailed View: Per-provider Host Radar breakdown for STC, highlighting the unprecedented concentration of C2 activity across Saudi Arabia’s largest telecommunications network (Source: hunt.io)

Saudi Telecom Company (STC) alone hosted 981 C2 servers, accounting for 72.4% of all detected C2 activity in the dataset.

Researchers attribute this concentration to the scale of STC’s network and its large customer base, suggesting that compromised endpoints within the telecom environment are being leveraged rather than the direct compromise of the provider.

TECH FZCO - Host Radar Detailed View: Host Radar metrics for SERVERS TECH FZCO illustrating elevated C2 infrastructure presence alongside malicious open directories and documented IOC references (Source: hunt.io)
TECH FZCO – Host Radar Detailed View: Host Radar metrics for SERVERS TECH FZCO illustrating elevated C2 infrastructure presence alongside malicious open directories and documented IOC references (Source: hunt.io)

The dataset reveals a mix of commodity malware, botnets, and advanced post-exploitation frameworks operating across the region.

Tactical RMM led all malware families with 92 unique C2 IPs, reflecting widespread abuse of legitimate remote management tools.

Other prominent families included Keitaro (traffic distribution system), Acunetix, Gophish, and IoT botnets such as Mozi, Hajime, and Mirai.

OMC - Host Radar Detailed View: Detailed Host Radar metrics showing OMC's moderate C2 infrastructure concentration with limited associated malicious artifacts (Source: hunt.io)
OMC – Host Radar Detailed View: Detailed Host Radar metrics showing OMC’s moderate C2 infrastructure concentration with limited associated malicious artifacts (Source: hunt.io)

Advanced offensive frameworks, including Cobalt Strike, Sliver, and AsyncRAT, were also observed, indicating overlap between cybercriminal and state-linked operations.

Several real-world campaigns illustrate how this infrastructure is actively used:

  • A Phorpiex (Twizt) botnet C2 server hosted on Syrian Telecom infrastructure (94.252.245[.]193) delivered encrypted payloads, including XMRig cryptominers and LockBit Black ransomware.
  • Infrastructure linked to Regxa in Iraq supported a February 2026 espionage campaign attributed to the “Eagle Werewolf” cluster, which deployed multiple RAT families, including EchoGather and Sliver, via phishing and Telegram-based lures.
  • Exploitation of CVE-2025-11953 (Metro4Shell) was traced to an IP on Saudi Arabia’s Mobily network, delivering Base64-encoded PowerShell payloads and Rust-based malware.
  • Iranian infrastructure (AbrArvan CDN) hosted RondoDox botnet operations, which launched up to 15,000 daily exploit attempts using Mirai-like techniques across 174 vulnerabilities.

The research also identified ongoing MaaS operations, phishing campaigns, and destructive malware activity, including infrastructure linked to DYNOWIPER attacks and ClickFix social engineering chains, Hunt.io said.

Beyond individual campaigns, the report emphasizes a critical shift in defensive strategy: tracking infrastructure providers rather than individual indicators.

While IPs and domains change rapidly, attackers consistently return to the same hosting environments, telecom networks, and ASN-level resources.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories