Cyber Security News

Chinese Threat Actors Hosted 18,000 Active C2 Servers Across 48 Hosting Providers

Threat actors linked to Chinese hosting infrastructure have established a massive network of over 18,000 active command-and-control servers across 48 different hosting providers in recent months.

This widespread abuse highlights a serious issue in how malicious infrastructure can hide within trusted networks and cloud services.

Traditional threat hunting methods that focus on individual IP addresses or domain names often miss the bigger picture because attackers constantly change these indicators to avoid detection.

The research reveals that these C2 servers make up about 84 percent of all malicious activity observed within Chinese hosting environments during the three-month analysis period.

Host Radar functions (Source – Hunt.io)

Phishing infrastructure accounts for around 13 percent, while malicious open directories and public indicators of compromise together represent less than 4 percent of detected threats.

This shows that command-and-control operations dominate the threat landscape, with attackers preferring stable infrastructure that can coordinate ongoing campaigns across multiple targets.

Hunt.io analysts identified this extensive infrastructure network using their Host Radar platform, which combines C2 detection, phishing identification, open directory scanning, and indicator extraction into a single intelligence system.

Rather than treating each malicious artifact as isolated, the platform maps these threats back to the hosting providers and network operators where they exist. This approach reveals long-running abuse patterns even when individual IP addresses change frequently.

China Unicom emerged as the largest host of malicious infrastructure, accounting for nearly half of all observed C2 servers with approximately 9,000 detections.

Alibaba Cloud and Tencent each hosted around 3,300 C2 servers, showing that major cloud platforms are heavily targeted by threat actors who value their rapid provisioning and high availability.

These three providers alone represent the majority of detected malicious command-and-control infrastructure within China.

Infrastructure Concentration and Malware Distribution

The malware families operating through this infrastructure show clear patterns of repeated framework abuse. Mozi botnet dominates with 9,427 unique C2 IP addresses, representing more than half of all observed command-and-control activity.

The ARL framework follows with 2,878 C2 endpoints, suggesting extensive misuse of post-exploitation and red-team tooling for malicious purposes.

Top 10 Chinese infrastructure providers by number of detected C2 servers (Source – Hunt.io)

Cobalt Strike appears with 1,204 detections, while Vshell and Mirai round out the top five with 830 and 703 C2 servers respectively.

This concentration means defenders can focus monitoring efforts on shared infrastructure patterns rather than chasing individual malware variants that constantly evolve.

The data shows that cybercrime operations, botnet infrastructure, and state-linked espionage tools coexist within the same hosting environments.

Campaigns ranging from commodity remote access trojans to sophisticated APT operations leverage these providers, creating a complex threat ecosystem where traditional indicator-based defenses struggle to maintain effectiveness.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

48 seconds ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

7 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

17 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

16 hours ago