{"id":12154,"date":"2026-04-16T10:03:39","date_gmt":"2026-04-16T10:03:39","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/16\/1250-c2-servers-mapped-across-russian-hosting-across-165-providers\/"},"modified":"2026-04-16T10:03:39","modified_gmt":"2026-04-16T10:03:39","slug":"1250-c2-servers-mapped-across-russian-hosting-across-165-providers","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/16\/1250-c2-servers-mapped-across-russian-hosting-across-165-providers\/","title":{"rendered":"1,250+ C2 Servers Mapped Across Russian Hosting Across 165 Providers"},"content":{"rendered":"<p>    1,250+ C2 Servers Mapped Across Russian Hosting Across 165 Providers<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybersecurity researchers have uncovered a large and organized network of malicious infrastructure quietly running inside Russia\u2019s commercial hosting ecosystem. <\/p>\n<p>Over a three-month window from January 1 to April 1, 2026, more than 1,250 active command-and-control (C2) servers were detected across 165 Russian infrastructure providers, spanning shared hosting platforms, virtual server environments, and telecommunications networks.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/77fcd6c7-a878-417c-bf0d-fe04eec71bb1\/1250-C2-Servers-Mapped-Across-Russian-Hosting-Across-165-Providers.pdf?AWSAccessKeyId=ASIA2F3EMEYE7U6H4COB&amp;Signature=BMkz2VFX1GbzGfGn%2FbygZEnD5MA%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEO3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIAv7OyYzVQ8gYRcPpVQYxLOxS2bteWDlIdMEeXPjJOC0AiAcGS8mMrGJRtJA9q6q9EoO2kL3RJd2vBvqRGXwk%2FPjYSr8BAi1%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIM%2FAQ3h53yw3orUjItKtAEIXLUCvdvmnrt705RVwfRGIaxvMUHVNmP7D3owBZq2g5J9qVVzr3Bj3fnK%2BWSbswf%2B7JP%2F2Ez3bAjV4E2iLeOK1DzTdk9FlyQFGHR4rIQttfLLuNvUA6%2F65L0cJNbXRFMFOtSu3PpkIXoBeYu5QTR6nQw9jhUQNDGF8u6cdGea3vLl%2BeMMxgBmh4UgkJHzTdjFDzuEV5N1FA8yrvOyn6B0IvpH31iU9tpq8mXWAzY%2FO%2F7SckOOHMYe8c7lcAj%2Fj%2BnzaHnaIUbnYtTyOYeGOrjvdB1sUX60rxuNEPCTL6mRHphut7AkhApivSqy8wFQcHNB1Mn8rkl2vzLSIJDzEljB92APtryZAbiRymenc3VwI4Gh%2FQ%2BbXM8J%2FWazt5EcBJc21fNbRNhMQeo5%2BYVg7RFb5FIrBYIVZzaqDXQZOHfiD4AIs%2FyRcTht55sl%2FxRW9VETNQHereL9O1ueIIwji5WjISQs%2FHmxNpviODH7DdRF6I2qq%2B3QftOTOviyJLYkj%2BABePYYBen3TUyTwmkuv3kDFJ2P9i%2BRA8LnZ3122qpfxPIPRuLUOq9lvA0jVvDXoEQ3EnMuitxoWN2Zkm8dQSPYjThxcUNWVpbm%2FceuvE%2FrU6VmUJn7OJ1juXM5e%2Bhu9v0GpVZNALLp5n1ULC3QLVNJGAz9gyND%2FCWv87rivKr3hR%2FU8VV3z5wnFxfaPI9EqDpY%2BuLtF%2B7p%2FXOy8Q5hIqQ3byAphVWMB3YnYXwm4D%2BSIQX7g%2FBmWf9WGwOJCX4JCwju1uZcjEOUFJifDcUtr7q5TDswYHPBjqZAQ15QTKDocGO9sc4zRzb5Ag7nkmr7%2FxCrUW06mBmFSaZi1haZDwaAMZO%2FP9Q%2BejjN2OHjDEVK%2FlsPV%2BLD6g5yDniDFhEhF9JeSPA1%2FWXNeZzO2TgOdKSaONMlnSrs%2FQ25n32y%2FeWHGIDwxFbommOqUP4NTx4nBEHoVj%2BvZkSCeSdkVleRz73hXrBvHzxf%2BEQQdRaFCgtFlT5EQ%3D%3D&amp;Expires=1776315486\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>A command-and-control server is the backbone of most cyberattacks \u2014 the system attackers use to send instructions to infected machines and retrieve stolen data. <\/p>\n<p>Finding over 1,250 of these servers active at once, all housed within Russian hosting providers, shows how deeply malicious infrastructure has embedded itself into legitimate commercial networks. <\/p>\n<p>The servers are not concentrated in one or two obscure corners of the internet; they are distributed across 165 separate providers, making them harder to block and easier to maintain without drawing attention.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/77fcd6c7-a878-417c-bf0d-fe04eec71bb1\/1250-C2-Servers-Mapped-Across-Russian-Hosting-Across-165-Providers.pdf?AWSAccessKeyId=ASIA2F3EMEYE7U6H4COB&amp;Signature=BMkz2VFX1GbzGfGn%2FbygZEnD5MA%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEO3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIAv7OyYzVQ8gYRcPpVQYxLOxS2bteWDlIdMEeXPjJOC0AiAcGS8mMrGJRtJA9q6q9EoO2kL3RJd2vBvqRGXwk%2FPjYSr8BAi1%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIM%2FAQ3h53yw3orUjItKtAEIXLUCvdvmnrt705RVwfRGIaxvMUHVNmP7D3owBZq2g5J9qVVzr3Bj3fnK%2BWSbswf%2B7JP%2F2Ez3bAjV4E2iLeOK1DzTdk9FlyQFGHR4rIQttfLLuNvUA6%2F65L0cJNbXRFMFOtSu3PpkIXoBeYu5QTR6nQw9jhUQNDGF8u6cdGea3vLl%2BeMMxgBmh4UgkJHzTdjFDzuEV5N1FA8yrvOyn6B0IvpH31iU9tpq8mXWAzY%2FO%2F7SckOOHMYe8c7lcAj%2Fj%2BnzaHnaIUbnYtTyOYeGOrjvdB1sUX60rxuNEPCTL6mRHphut7AkhApivSqy8wFQcHNB1Mn8rkl2vzLSIJDzEljB92APtryZAbiRymenc3VwI4Gh%2FQ%2BbXM8J%2FWazt5EcBJc21fNbRNhMQeo5%2BYVg7RFb5FIrBYIVZzaqDXQZOHfiD4AIs%2FyRcTht55sl%2FxRW9VETNQHereL9O1ueIIwji5WjISQs%2FHmxNpviODH7DdRF6I2qq%2B3QftOTOviyJLYkj%2BABePYYBen3TUyTwmkuv3kDFJ2P9i%2BRA8LnZ3122qpfxPIPRuLUOq9lvA0jVvDXoEQ3EnMuitxoWN2Zkm8dQSPYjThxcUNWVpbm%2FceuvE%2FrU6VmUJn7OJ1juXM5e%2Bhu9v0GpVZNALLp5n1ULC3QLVNJGAz9gyND%2FCWv87rivKr3hR%2FU8VV3z5wnFxfaPI9EqDpY%2BuLtF%2B7p%2FXOy8Q5hIqQ3byAphVWMB3YnYXwm4D%2BSIQX7g%2FBmWf9WGwOJCX4JCwju1uZcjEOUFJifDcUtr7q5TDswYHPBjqZAQ15QTKDocGO9sc4zRzb5Ag7nkmr7%2FxCrUW06mBmFSaZi1haZDwaAMZO%2FP9Q%2BejjN2OHjDEVK%2FlsPV%2BLD6g5yDniDFhEhF9JeSPA1%2FWXNeZzO2TgOdKSaONMlnSrs%2FQ25n32y%2FeWHGIDwxFbommOqUP4NTx4nBEHoVj%2BvZkSCeSdkVleRz73hXrBvHzxf%2BEQQdRaFCgtFlT5EQ%3D%3D&amp;Expires=1776315486\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p><a href=\"https:\/\/hunt.io\/blog\/russian-malicious-infrastructure-c2-servers-mapped\" id=\"https:\/\/hunt.io\/blog\/russian-malicious-infrastructure-c2-servers-mapped\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Hunt.io analysts and researchers identified these patterns<\/a> using Host Radar, a core intelligence module built to correlate C2 servers, phishing infrastructure, open malicious directories, and public indicators of compromise back to the hosting providers that sustain them. <\/p>\n<p>Their analysis surfaced repeatable patterns in how malicious infrastructure is distributed and reused across Russian hosting environments, providing provider-level visibility that separates actionable intelligence from a stream of disposable IP addresses.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/77fcd6c7-a878-417c-bf0d-fe04eec71bb1\/1250-C2-Servers-Mapped-Across-Russian-Hosting-Across-165-Providers.pdf?AWSAccessKeyId=ASIA2F3EMEYE7U6H4COB&amp;Signature=BMkz2VFX1GbzGfGn%2FbygZEnD5MA%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEO3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIAv7OyYzVQ8gYRcPpVQYxLOxS2bteWDlIdMEeXPjJOC0AiAcGS8mMrGJRtJA9q6q9EoO2kL3RJd2vBvqRGXwk%2FPjYSr8BAi1%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIM%2FAQ3h53yw3orUjItKtAEIXLUCvdvmnrt705RVwfRGIaxvMUHVNmP7D3owBZq2g5J9qVVzr3Bj3fnK%2BWSbswf%2B7JP%2F2Ez3bAjV4E2iLeOK1DzTdk9FlyQFGHR4rIQttfLLuNvUA6%2F65L0cJNbXRFMFOtSu3PpkIXoBeYu5QTR6nQw9jhUQNDGF8u6cdGea3vLl%2BeMMxgBmh4UgkJHzTdjFDzuEV5N1FA8yrvOyn6B0IvpH31iU9tpq8mXWAzY%2FO%2F7SckOOHMYe8c7lcAj%2Fj%2BnzaHnaIUbnYtTyOYeGOrjvdB1sUX60rxuNEPCTL6mRHphut7AkhApivSqy8wFQcHNB1Mn8rkl2vzLSIJDzEljB92APtryZAbiRymenc3VwI4Gh%2FQ%2BbXM8J%2FWazt5EcBJc21fNbRNhMQeo5%2BYVg7RFb5FIrBYIVZzaqDXQZOHfiD4AIs%2FyRcTht55sl%2FxRW9VETNQHereL9O1ueIIwji5WjISQs%2FHmxNpviODH7DdRF6I2qq%2B3QftOTOviyJLYkj%2BABePYYBen3TUyTwmkuv3kDFJ2P9i%2BRA8LnZ3122qpfxPIPRuLUOq9lvA0jVvDXoEQ3EnMuitxoWN2Zkm8dQSPYjThxcUNWVpbm%2FceuvE%2FrU6VmUJn7OJ1juXM5e%2Bhu9v0GpVZNALLp5n1ULC3QLVNJGAz9gyND%2FCWv87rivKr3hR%2FU8VV3z5wnFxfaPI9EqDpY%2BuLtF%2B7p%2FXOy8Q5hIqQ3byAphVWMB3YnYXwm4D%2BSIQX7g%2FBmWf9WGwOJCX4JCwju1uZcjEOUFJifDcUtr7q5TDswYHPBjqZAQ15QTKDocGO9sc4zRzb5Ag7nkmr7%2FxCrUW06mBmFSaZi1haZDwaAMZO%2FP9Q%2BejjN2OHjDEVK%2FlsPV%2BLD6g5yDniDFhEhF9JeSPA1%2FWXNeZzO2TgOdKSaONMlnSrs%2FQ25n32y%2FeWHGIDwxFbommOqUP4NTx4nBEHoVj%2BvZkSCeSdkVleRz73hXrBvHzxf%2BEQQdRaFCgtFlT5EQ%3D%3D&amp;Expires=1776315486\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Across the full dataset, Host Radar recorded approximately 1,290 malicious artifacts during the observation period. C2 infrastructure dominates, accounting for roughly 88.6% of all detected activity with 1,252 servers confirmed. <\/p>\n<p>Malicious open directories make up about 5.3%, <a href=\"https:\/\/cybersecuritynews.com\/ai-tools-direct-users-phishing-sites\/\" id=\"114161\" target=\"_blank\" rel=\"noreferrer noopener\">phishing sites<\/a> roughly 4.9%, and publicly reported indicators of compromise around 1.2%. <\/p>\n<p>TimeWeb leads with 311 detected C2 servers over 90 days, followed by WebHost1 with 140, REG.RU with 138, VDSina with 86, and PROSPERO OOO with 80.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/77fcd6c7-a878-417c-bf0d-fe04eec71bb1\/1250-C2-Servers-Mapped-Across-Russian-Hosting-Across-165-Providers.pdf?AWSAccessKeyId=ASIA2F3EMEYE7U6H4COB&amp;Signature=BMkz2VFX1GbzGfGn%2FbygZEnD5MA%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEO3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIAv7OyYzVQ8gYRcPpVQYxLOxS2bteWDlIdMEeXPjJOC0AiAcGS8mMrGJRtJA9q6q9EoO2kL3RJd2vBvqRGXwk%2FPjYSr8BAi1%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIM%2FAQ3h53yw3orUjItKtAEIXLUCvdvmnrt705RVwfRGIaxvMUHVNmP7D3owBZq2g5J9qVVzr3Bj3fnK%2BWSbswf%2B7JP%2F2Ez3bAjV4E2iLeOK1DzTdk9FlyQFGHR4rIQttfLLuNvUA6%2F65L0cJNbXRFMFOtSu3PpkIXoBeYu5QTR6nQw9jhUQNDGF8u6cdGea3vLl%2BeMMxgBmh4UgkJHzTdjFDzuEV5N1FA8yrvOyn6B0IvpH31iU9tpq8mXWAzY%2FO%2F7SckOOHMYe8c7lcAj%2Fj%2BnzaHnaIUbnYtTyOYeGOrjvdB1sUX60rxuNEPCTL6mRHphut7AkhApivSqy8wFQcHNB1Mn8rkl2vzLSIJDzEljB92APtryZAbiRymenc3VwI4Gh%2FQ%2BbXM8J%2FWazt5EcBJc21fNbRNhMQeo5%2BYVg7RFb5FIrBYIVZzaqDXQZOHfiD4AIs%2FyRcTht55sl%2FxRW9VETNQHereL9O1ueIIwji5WjISQs%2FHmxNpviODH7DdRF6I2qq%2B3QftOTOviyJLYkj%2BABePYYBen3TUyTwmkuv3kDFJ2P9i%2BRA8LnZ3122qpfxPIPRuLUOq9lvA0jVvDXoEQ3EnMuitxoWN2Zkm8dQSPYjThxcUNWVpbm%2FceuvE%2FrU6VmUJn7OJ1juXM5e%2Bhu9v0GpVZNALLp5n1ULC3QLVNJGAz9gyND%2FCWv87rivKr3hR%2FU8VV3z5wnFxfaPI9EqDpY%2BuLtF%2B7p%2FXOy8Q5hIqQ3byAphVWMB3YnYXwm4D%2BSIQX7g%2FBmWf9WGwOJCX4JCwju1uZcjEOUFJifDcUtr7q5TDswYHPBjqZAQ15QTKDocGO9sc4zRzb5Ag7nkmr7%2FxCrUW06mBmFSaZi1haZDwaAMZO%2FP9Q%2BejjN2OHjDEVK%2FlsPV%2BLD6g5yDniDFhEhF9JeSPA1%2FWXNeZzO2TgOdKSaONMlnSrs%2FQ25n32y%2FeWHGIDwxFbommOqUP4NTx4nBEHoVj%2BvZkSCeSdkVleRz73hXrBvHzxf%2BEQQdRaFCgtFlT5EQ%3D%3D&amp;Expires=1776315486\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"malware-families-and-active-campaigns\"><strong>Malware Families and Active Campaigns<\/strong><\/h2>\n<p>Using HuntSQL, analysts queried telemetry across Russian networks to identify which malware families were hosting the most C2 infrastructure. <\/p>\n<p>Keitaro, a traffic distribution system frequently abused to redirect victims toward malware, leads the dataset with 587 unique C2 IP addresses \u2014 the largest concentration observed. <\/p>\n<p>Hajime, an IoT-focused botnet, follows with 191 C2 servers, while Mozi and Mirai reflect ongoing abuse of compromised routers and embedded devices. <\/p>\n<p>Offensive security frameworks including Tactical RMM (87 endpoints), Cobalt Strike variants (55 combined), Sliver, and Ligolo-ng were also found, all repurposed for malicious use. <\/p>\n<p>Scanning and phishing tools like Acunetix, Interactsh, and Gophish were detected as well, confirming this infrastructure supports reconnaissance and credential theft alongside direct intrusions.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiOxzzlkH3iEwEJe7R-k7XNtyh6S864G2GcCyK8yKaoYLZ7hYwfUluuO5AMZVanih8VyJZpYg2Q39Ozl-4O5VT2SzLmA5C11XEQBtfrlyve6DIgYv-HGOIMoKqAI32v-pocB_5zRtX-Iwv03zQAn_lIB1X3nj05Hko4srFMvXrcyQtZUQNG9aD7Xtl46Gs\/s16000\/Top%252010%2520Malware%2520Command-and-Control%2520%28C2%29%2520Families%2520%28Source%2520-%2520Hunt.io%29.webp?ssl=1\" alt=\"Top 10 Malware Command-and-Control (C2) Families (Source - Hunt.io)\"><figcaption class=\"wp-element-caption\">Top 10 Malware Command-and-Control (C2) Families (Source \u2013 Hunt.io)<\/figcaption><\/figure>\n<\/div>\n<p>Active campaigns tied to this infrastructure reinforce the gravity of these findings. One campaign on JSC TIMEWEB used a <a href=\"https:\/\/cybersecuritynews.com\/fake-captcha-delivers-eddiestealer\/\" id=\"109164\" target=\"_blank\" rel=\"noreferrer noopener\">fake CAPTCHA<\/a> technique called ClickFix to trick users into executing a PowerShell command that downloaded Latrodectus v2.3 malware communicating with attacker-controlled domains.\u00a0<\/p>\n<p>REG.RU-hosted infrastructure was linked to a <a href=\"https:\/\/cybersecuritynews.com\/lumma-stealer-github-delivery\/\" id=\"76764\" target=\"_blank\" rel=\"noreferrer noopener\">Lumma Stealer<\/a> operation abusing Google Groups redirectors to push malicious archives across Windows and Linux systems. <\/p>\n<p>On Hosting Technology LTD infrastructure, the SmartApeSG campaign delivered <a href=\"https:\/\/cybersecuritynews.com\/remcos-rat-masquerade-as-veracrypt-installers\/\" id=\"140025\" target=\"_blank\" rel=\"noreferrer noopener\">Remcos RAT<\/a> through fake CAPTCHA prompts on compromised sites, establishing persistence via DLL sideloading. <\/p>\n<p>Beget LLC infrastructure hosted activity tied to the UAC-0252 campaign, which impersonated Ukrainian government institutions and deployed SHADOWSNIFF and SALATSTEALER infostealers through a WinRAR vulnerability tracked as CVE-2025-8088.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiHA6Tgt83VUlAS_ngDTWP_jorBaQfQ3ydypsTXD-APP4lEGacFqQu0KCvZmWOVFk_T3_BTGAl89Uayupce4VWugx5ygnym0Id7TjZLDE8syytnqX0xDJANByjiHtFq8bTOhWzweKk2QxxP4JY9VNp22bhyphenhyphen8oQ56LhXjJl6NK-BeWaltYNBmovDEdSH7b4\/s16000\/Top%2520ISPs%2520hosting%2520malware%2520%28Source%2520-%2520Hunt.io%29.webp?ssl=1\" alt=\"Top ISPs hosting malware (Source - Hunt.io)\"><figcaption class=\"wp-element-caption\">Top ISPs hosting malware (Source \u2013 Hunt.io)<\/figcaption><\/figure>\n<\/div>\n<p>Proton66 OOO infrastructure was separately connected to a BoryptGrab infostealer operation abusing over 100 public GitHub repositories through SEO manipulation.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/77fcd6c7-a878-417c-bf0d-fe04eec71bb1\/1250-C2-Servers-Mapped-Across-Russian-Hosting-Across-165-Providers.pdf?AWSAccessKeyId=ASIA2F3EMEYE7U6H4COB&amp;Signature=BMkz2VFX1GbzGfGn%2FbygZEnD5MA%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEO3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIAv7OyYzVQ8gYRcPpVQYxLOxS2bteWDlIdMEeXPjJOC0AiAcGS8mMrGJRtJA9q6q9EoO2kL3RJd2vBvqRGXwk%2FPjYSr8BAi1%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIM%2FAQ3h53yw3orUjItKtAEIXLUCvdvmnrt705RVwfRGIaxvMUHVNmP7D3owBZq2g5J9qVVzr3Bj3fnK%2BWSbswf%2B7JP%2F2Ez3bAjV4E2iLeOK1DzTdk9FlyQFGHR4rIQttfLLuNvUA6%2F65L0cJNbXRFMFOtSu3PpkIXoBeYu5QTR6nQw9jhUQNDGF8u6cdGea3vLl%2BeMMxgBmh4UgkJHzTdjFDzuEV5N1FA8yrvOyn6B0IvpH31iU9tpq8mXWAzY%2FO%2F7SckOOHMYe8c7lcAj%2Fj%2BnzaHnaIUbnYtTyOYeGOrjvdB1sUX60rxuNEPCTL6mRHphut7AkhApivSqy8wFQcHNB1Mn8rkl2vzLSIJDzEljB92APtryZAbiRymenc3VwI4Gh%2FQ%2BbXM8J%2FWazt5EcBJc21fNbRNhMQeo5%2BYVg7RFb5FIrBYIVZzaqDXQZOHfiD4AIs%2FyRcTht55sl%2FxRW9VETNQHereL9O1ueIIwji5WjISQs%2FHmxNpviODH7DdRF6I2qq%2B3QftOTOviyJLYkj%2BABePYYBen3TUyTwmkuv3kDFJ2P9i%2BRA8LnZ3122qpfxPIPRuLUOq9lvA0jVvDXoEQ3EnMuitxoWN2Zkm8dQSPYjThxcUNWVpbm%2FceuvE%2FrU6VmUJn7OJ1juXM5e%2Bhu9v0GpVZNALLp5n1ULC3QLVNJGAz9gyND%2FCWv87rivKr3hR%2FU8VV3z5wnFxfaPI9EqDpY%2BuLtF%2B7p%2FXOy8Q5hIqQ3byAphVWMB3YnYXwm4D%2BSIQX7g%2FBmWf9WGwOJCX4JCwju1uZcjEOUFJifDcUtr7q5TDswYHPBjqZAQ15QTKDocGO9sc4zRzb5Ag7nkmr7%2FxCrUW06mBmFSaZi1haZDwaAMZO%2FP9Q%2BejjN2OHjDEVK%2FlsPV%2BLD6g5yDniDFhEhF9JeSPA1%2FWXNeZzO2TgOdKSaONMlnSrs%2FQ25n32y%2FeWHGIDwxFbommOqUP4NTx4nBEHoVj%2BvZkSCeSdkVleRz73hXrBvHzxf%2BEQQdRaFCgtFlT5EQ%3D%3D&amp;Expires=1776315486\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Security teams should treat provider-level monitoring as a core defensive priority. Applying controls against the highest-volume providers \u2014 especially TimeWeb, REG.RU, WebHost1, VDSina, and PROSPERO OOO \u2014 can meaningfully reduce exposure. <\/p>\n<p>Organizations should monitor outbound connections to Russian ASNs with elevated C2 activity, apply threat intelligence covering infrastructure-level indicators beyond file hashes, restrict curl-to-PowerShell chains vulnerable to ClickFix-style lures, and maintain visibility into IoT and edge devices given the continued activity of Hajime, Mozi, and Mirai botnets.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/1250-c2-servers-mapped-across-russian-hosting\/\">1,250+ C2 Servers Mapped Across Russian Hosting Across 165 Providers<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/1250-c2-servers-mapped-across-russian-hosting\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>1,250+ C2 Servers Mapped Across Russian Hosting Across 165 Providers Cybersecurity researchers have uncovered a large and organized network of malicious infrastructure quietly running inside Russia\u2019s commercial hosting ecosystem. Over a three-month window from January 1 to April 1, 2026, more than 1,250 active command-and-control (C2) servers were detected across 165 Russian infrastructure providers, spanning [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-12154","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12154"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12154"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12154\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12154"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12154"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12154"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}