PULSE NAME
Middle East Malicious Infrastructure Report: 1,350+ C2 Servers Mapped Across 98 Providers
WHITE Eagle Werewolf, ENERGETIC BEAR, Velvet Tempest, APT28, GrayCharlie AlienVault 2026-05-21 Modified: 2026-05-22
6
IOCs
LOW VOLUME
Between February and May 2026, over 1,350 active command-and-control servers were identified across 98 infrastructure providers spanning 14 Middle Eastern countries. Saudi Arabia's STC hosted 981 C2 servers, representing 72.4% of all regional malicious infrastructure, the largest concentration globally. C2 infrastructure dominated at 96.8% of detected activity, with IoT-focused botnets like Hajime, Mozi, and Mirai, alongside offensive frameworks including Tactical RMM, Cobalt Strike, and Sliver representing the primary malware families. The infrastructure supported diverse operations from state-sponsored espionage campaigns like Eagle Werewolf targeting state entities, to Malware-as-a-Service platforms, cryptomining operations, and destructive attacks such as DYNOWIPER. Key providers included SERVERS TECH FZCO in UAE, OMC in Israel, Türk Telekom, and Regxa in Iraq, demonstrating how telecommunications giants and specialized hosting services enable both commodity cybercrime and advanced persistent threat op...
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Phorpiex Twizt XMRig LockBit Black EchoGather Sliver SoullessRAT AquilaRAT DYNOWIPER RondoDox Mirai Phexia HellsUchecker Termite NetSupport RAT Tactical RMM Keitaro AsyncRAT Cobalt Strike - S0154 Hajime Mozi Acunetix Gophish Prism X
Indicators of Compromise (6)
All CVE IPv4
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2025-11953 2026-05-21
IPv4 197.51.170.131 2026-05-21
IPv4 37.32.15.8 2026-05-21
IPv4 5.109.182.231 2026-05-21
IPv4 93.113.62.247 2026-05-21
IPv4 94.252.245.193 2026-05-21