Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Chinese Threat Actors Hosted 18,000 Active C2 Servers Across 48 Hosting Providers

In recent months, threat actors linked to Chinese hosting infrastructure have established a significant network consisting of over 18,000 active command-and-control (C2) servers across 48 different hosting providers.

In recent months, threat actors linked to Chinese hosting infrastructure have established a significant network consisting of over 18,000 active command-and-control (C2) servers across 48 different hosting providers.

This network highlights the challenges of detecting malicious infrastructure, which can remain hidden within trusted networks and cloud services. Traditional threat detection methods focusing on individual IP addresses or domain names may miss broader patterns as attackers regularly alter these indicators to evade detection.

Research indicates that these C2 servers account for approximately 84% of all malicious activity observed within Chinese hosting environments over a three-month analysis period.

Phishing infrastructure represents around 13% of identified threats, while malicious open directories and public indicators of compromise together account for less than 4%. This data suggests that command-and-control operations are predominant, with attackers using stable infrastructure to coordinate campaigns across multiple targets.

This network highlights the challenges of detecting malicious infrastructure, which can remain hidden within trusted networks and cloud services.
Leo Underwood · Thehackingpost

Analysis by Hunt.io, using the Host Radar platform, identified this extensive infrastructure network. The platform integrates C2 detection, phishing identification, open directory scanning, and indicator extraction into a comprehensive intelligence system. This approach maps threats to hosting providers and network operators, uncovering long-term abuse patterns despite frequent changes in individual IP addresses.

China Unicom emerged as the largest host of malicious infrastructure, with nearly 9,000 detections, representing almost half of the observed C2 servers. Alibaba Cloud and Tencent each hosted about 3,300 C2 servers, indicating that major cloud platforms are frequently targeted due to their rapid provisioning and high availability.

Infrastructure Concentration and Malware Distribution

The malware families operating through this infrastructure demonstrate clear patterns of framework abuse. The Mozi botnet dominates, with 9,427 unique C2 IP addresses, accounting for more than half of all observed command-and-control activity. The ARL framework follows with 2,878 C2 endpoints, suggesting extensive misuse of post-exploitation and red-team tools.

Advertisement

Cobalt Strike has 1,204 detections, while Vshell and Mirai round out the top five with 830 and 703 C2 servers, respectively. This concentration allows defenders to focus monitoring efforts on shared infrastructure patterns rather than individual malware variants, which continuously evolve.

The data indicates a complex threat ecosystem where cybercrime operations, botnet infrastructure, and state-linked espionage tools coexist within the same hosting environments. Campaigns range from basic remote access trojans to advanced persistent threat (APT) operations, challenging traditional indicator-based defenses to maintain their effectiveness.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories