Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Chinese Hackers Control 18,000 Active Servers Across 48 Hosting Providers

Chinese infrastructure is currently hosting more than 18,000 active command-and-control (C2) servers across 48 providers, with activity heavily concentrated on a handful of major telecom and cloud networks in China. This clustering of malware, phishing,…

Chinese infrastructure is currently hosting more than 18,000 active command-and-control (C2) servers across 48 providers, with activity heavily concentrated on a handful of major telecom and cloud networks in China. This clustering of malware, phishing, and advanced persistent threat (APT) tooling on shared infrastructure highlights the significance of host-centric telemetry for threat hunting, as indicator-based approaches often fail to capture how attackers reuse the same networks at scale.

Recent analysis identified over 18,000 active C2 servers operating within the Chinese IP space over a three-month period, mapped to 48 distinct ISPs and hosting providers. This dataset recorded 21,629 malicious artifacts, including more than 18,000 C2 servers, 2,837 phishing sites, 528 malicious open directories, and 134 public indicators of compromise (IOCs).

C2 infrastructure accounts for approximately 84% of all observed malicious artifacts, while phishing activity contributes about 13%, and open directories plus public IOCs together comprise less than 4%. This imbalance indicates that Chinese infrastructure is primarily used for long-term command-and-control and post-exploitation operations rather than simple lure or hosting activity.

High-Risk Providers and Malware Families

China Unicom emerges as a critical hotspot, with around 9,000–9,100 C2 servers detected over 90 days, representing nearly half of all observed C2 activity in the dataset. Alibaba Cloud and Tencent each host approximately 3,300 C2 servers, illustrating how high-capacity cloud platforms are used by threat actors for scalable, resilient infrastructure.

A small group of malware families drives most of this abuse, led by Mozi with 9,427 unique C2 IPs, more than half of all C2 endpoints identified in China.
Michael Reeves · Thehackingpost

A small group of malware families drives most of this abuse, led by Mozi with 9,427 unique C2 IPs, more than half of all C2 endpoints identified in China. ARL follows with 2,878 C2s, while Cobalt Strike, Vshell, and Mirai account for additional C2 servers, combining commercial red-team frameworks with IoT and botnet tooling.

The concentration of C2 nodes in a few families demonstrates that infrastructure-level fingerprints are repeatable and framework-driven, allowing defenders to track clusters even when individual IPs change. High-trust academic and backbone networks, such as CERNET and China Unicom’s China169, have been linked to botnet C2 and large-scale browser extension abuse, showing how attackers utilize bandwidth-rich environments when services are exposed.

Advertisement

The same infrastructure also supports state-aligned activity, with APT operations like DarkSpectre, Silver Fox, and Gold Eye Dog coexisting alongside cryptominer deployments, phishing frameworks, and commodity RAT campaigns. This overlap between cybercrime and espionage operations turns Chinese hosting ecosystems into shared staging grounds where different threat actors reuse the same providers, complicating attribution and takedown efforts.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories