Skip to content

Malware Tracker

Tracking active malware infrastructure: C2 servers that malware phones home to, and distribution hosts that deliver payloads. Updated daily from sandbox analysis and community threat intel.

291
Families Tracked (7d)
5,372
Active C2 Hosts (7d)
1,115
Active Distribution Hosts (7d)

C2 Infrastructure Type (7d)

Hosting 89% (4,919)
ISP 6% (335)
sinkhole 3% (184)
Unknown 1% (51)
Business 1% (46)
Education 0% (20)
Government 0% (1)

Distribution Infrastructure Type (7d)

ISP 84% (941)
Hosting 13% (145)
Business 3% (28)
Government 0% (1)

C2 Hosting Countries (7d)

Country Hosts
  1. 1 🇺🇸 US 2,973
  2. 2 🇨🇳 CN 529
  3. 3 🇩🇪 DE 279
  4. 4 🇬🇧 GB 194
  5. 5 🇭🇰 HK 182
  6. 6 🇷🇺 RU 179
  7. 7 🇸🇨 SC 155
  8. 8 🇫🇷 FR 115
  9. 9 🇮🇱 IL 91
  10. 10 🇯🇵 JP 80
  11. 11 Other 595

C2 Hosting Providers (7d)

Provider Hosts
  1. 1 Cloudflare, Inc. 1,514
  2. 2 Hangzhou Alibaba Advertising Co.,Ltd. 184
  3. 3 Microsoft Corporation 171
  4. 4 Shenzhen Tencent Computer Systems Company Limited 171
  5. 5 Amazon.com, Inc. 166
  6. 6 Omegatech LTD 145
  7. 7 DigitalOcean, LLC 132
  8. 8 Google LLC 124
  9. 9 Hetzner Online GmbH 111
  10. 10 HostPapa 108
  11. 11 Other providers 2,546

Distribution Countries (7d)

Country Hosts
  1. 1 🇨🇳 CN 740
  2. 2 🇵🇰 PK 119
  3. 3 🇺🇸 US 86
  4. 4 🇩🇪 DE 23
  5. 5 🇮🇳 IN 17
  6. 6 🇬🇧 GB 15
  7. 7 🇷🇺 RU 14
  8. 8 🇭🇰 HK 11
  9. 9 🇪🇹 ET 9
  10. 10 🇨🇦 CA 6
  11. 11 Other 75

Distribution Providers (7d)

Provider Hosts
  1. 1 CHINA UNICOM China169 Backbone 688
  2. 2 National WiMAX/IMS environment 112
  3. 3 Offshore LC 28
  4. 4 China Unicom IP network China169 Guangdong province 26
  5. 5 Cloudflare, Inc. 23
  6. 6 CHINANET BACKBONE 21
  7. 7 National Internet Backbone 16
  8. 8 Ethio Telecom 9
  9. 9 1337 Services GmbH 5
  10. 10 AS56971 Cloud 4
  11. 11 Other providers 183

All Tracked Malware (7d)

1–25 of 291 families
Cobalt Strike 1,451 C2 · May 30, 2026 AsyncRAT 1,426 C2 · May 30, 2026 ClearFake 863 C2 · May 30, 2026 Remcos 749 C2 · May 30, 2026 Lumma Stealer 695 C2 · May 30, 2026 NetWire RC 288 C2 · May 30, 2026 IcedID 266 C2 · May 26, 2026 Vidar 237 C2 · May 30, 2026 Nanocore RAT 224 C2 · May 30, 2026 XOR DDoS 212 C2 · May 25, 2026 Quasar RAT 156 C2 · May 30, 2026 AdaptixC2 153 C2 · May 30, 2026 SmokeLoader 146 C2 · May 30, 2026 XWorm 130 C2 · May 30, 2026 StealC 121 C2 · May 30, 2026 Amadey 99 C2 · May 30, 2026 VShell 92 C2 · May 30, 2026 Donutloader 87 C2 · May 30, 2026 DCRat 77 C2 · May 30, 2026 RedLine Stealer 77 C2 · May 30, 2026 Remus Stealer 75 C2 · May 30, 2026 Havoc 62 C2 · May 30, 2026 xmrig 59 C2 · May 30, 2026 Ghost RAT 57 C2 · May 30, 2026 Evilginx 54 C2 · May 30, 2026

Recent Research