Skip to content

Malware C2 Tracker

Tracking active malware infrastructure: C2 servers that malware phones home to, and distribution hosts that deliver payloads. Updated daily from sandbox analysis and community threat intel.

212
Families Tracked (7d)
1,053
Active C2 Hosts (7d)
1,954
Active Distribution Hosts (7d)

C2 Infrastructure Type (7d)

Hosting42%(895)
No DNS36%(767)
Sinkholed7%(149)
ISP5%(108)
Unregistered4%(90)
Unresolved3%(72)
Unknown2%(34)
Suspended1%(18)
Business1%(15)
Education0%(1)

Distribution Infrastructure Type (7d)

ISP44%(1,200)
No DNS28%(770)
Hosting27%(747)
Business0%(5)
Suspended0%(4)
Unresolved0%(3)
Education0%(1)
Unknown0%(1)

Top C2 Hosting Countries (7d)

CountryHosts
  1. 1🇺🇸 US397
  2. 2🇩🇪 DE95
  3. 3🇷🇺 RU76
  4. 4🇳🇱 NL68
  5. 5🇬🇧 GB45
  6. 6🇭🇰 HK43
  7. 7🇨🇳 CN31
  8. 8🇦🇪 AE22
  9. 9🇫🇷 FR21
  10. 10🇫🇮 FI17

Top C2 Hosting Providers (7d)

ProviderHosts
  1. 1Cloudflare, Inc.180
  2. 2Hetzner Online GmbH56
  3. 3Amazon.com, Inc.33
  4. 4Google LLC23
  5. 5SERVERS TECH FZCO22
  6. 6Omegatech LTD20
  7. 7HostPapa17
  8. 8Podaon SIA16
  9. 9NEON CORE NETWORK LLC13
  10. 10Amazon.com, Inc.13

Top Distribution Countries (7d)

CountryHosts
  1. 1🇺🇸 US672
  2. 2🇨🇳 CN651
  3. 3🇮🇳 IN170
  4. 4🇵🇰 PK161
  5. 5🇵🇭 PH38
  6. 6🇷🇺 RU27
  7. 7🇳🇱 NL22
  8. 8🇮🇩 ID18
  9. 9🇸🇪 SE18
  10. 10🇪🇹 ET17

Top Distribution Providers (7d)

ProviderHosts
  1. 1Cloudflare, Inc.625
  2. 2CHINA UNICOM China169 Backbone550
  3. 3National Internet Backbone152
  4. 4National WiMAX/IMS environment150
  5. 5CHINANET-BACKBONE70
  6. 6Globe Telecom Inc.37
  7. 7China Unicom IP network China169 Guangdong province19
  8. 8Ethio Telecom17
  9. 9PT Telekomunikasi Indonesia16
  10. 10Telkom SA Ltd.15

All Tracked Malware (7d)

Recent Research