Securityaffairs.Co Middle East Telecoms Targeted for Command-and-Control Operations
Article Content
- •Over 1,350 C2 servers identified in the Middle East, primarily through telecom providers.
- •Saudi Telecom Company (STC) accounts for more than 72% of regional C2 activity.
- •Shift in threat intelligence focus from individual indicators to infrastructure-level tracking.
A recent report from Hunt.io reveals that over 1,350 command-and-control (C2) servers are active across 98 providers in the Middle East, with Saudi Telecom Company (STC) responsible for over 72% of the activity. This infrastructure is often compromised customer systems, making it challenging for defenders to differentiate between legitimate and malicious traffic. The report indicates a shift in threat intelligence focus from individual indicators to infrastructure-level tracking, as attackers utilize diverse malware tools like Cobalt Strike and AsyncRAT. The findings highlight the use of trusted telecom networks as launchpads for cyberattacks, complicating defense strategies. The report emphasizes the need for a more stable view of attacker habits based on infrastructure patterns rather than ephemeral indicators. The situation poses significant challenges for cybersecurity professionals in the region.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track AsyncRAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Surge in Exploited CVEs and Malware Activity in H1 2026 In the first half of 2026, Insikt Group reported 215 actively exploited CVEs, marking a 34% increase from the previous year. Notably, AsyncRAT emerged as the leading malware, with nearly 60,000 unique hashes. The report highlighted a significant rise in NFC-based Android attacks, which surged by 188%. Threat actors…
HBO Max Account Compromise Fuels ClickFix Malware Campaign In September 2026, hackers compromised the verified HBO Max Reddit account, launching a ClickFix campaign that distributed 108 malicious ads over 48 hours. The ads targeted both macOS and Windows users, tricking them into executing commands that installed information-stealing malware. This operation, dubbed…