Map-style illustration showing a Bulgarian server hub radiating command-and-control network traffic across Eastern Europe.

UPDATE: Bulgarian Host Pushed Back on a Malware Report. Researchers Revised It. Twice.

A three-month Hunt.io analysis claims that one Bulgarian host accounted for 2,100 of 3,900 detected C2 servers tied to Eastern European malware operations.

Just one hosting company is responsible for housing half of the command-and-control activity flowing out of Eastern Europe, a region that researchers say punches well above its weight in global cybercrime.

Command-and-control servers are the backbone of modern cybercrime. They support the remote infrastructure that lets attackers direct malware, coordinate ransomware deployments, and siphon stolen data from compromised systems worldwide. Hosting companies are the physical infrastructure where websites, applications, and, in this case, criminal operations exist online.

A three-month sweep of Eastern Europe’s malware infrastructure, published Wednesday by security vendor Hunt.io, turned up a hornet’s nest of criminal activity. The report decidedly does not focus on individual rogue IPs, rather who is hosting them.

“A single Bulgarian provider accounted for more than half of all detected C2 infrastructure, a level of concentration that doesn’t surface when you’re tracking individual IPs or domains,” the Hunt.io team explained.

“It only becomes visible when you look at the hosting layer itself.”

That host, Friendhosting LTD, was found to be housing 2,100 of the 3,900 catalogued C2 servers that were traced back to operators in Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine. That amounts to roughly 53% of all C2 activity running through a single hosting provider.

Friendhosting disputes research

UPDATE 6/26: Initially, Security Point Break reached out to Friendhosting, but didn’t receive a respond to a request for comment. On June 26, Friendhosting did reply stating only: “This is the first time we have become aware of the Hunt.io report. We are currently reviewing the publication and its methodology in order to provide you with an accurate and considered response.” Security Point Break will update this report with any additional Friendhosting comments.

UPDATE, July 14, 2026: Hunt.io issued a second update on July 10 to the research underlying this report, this time after completing a data-sharing exercise with Friendhosting LTD. According to Hunt.io, Friendhosting reviewed the data provided by the researchers and identified a set of accounts worth investigating, and told Hunt.io it had tightened its internal abuse detection as a result. Friendhosting also told Hunt.io that the cases raising credible concern involved traffic distribution infrastructure — not infrastructure it could identify as hosting command-and-control servers. Hunt.io acknowledged in its update that this was precisely the distinction it failed to draw in the original report. “Keitaro is a commercial traffic distribution system,” the researchers wrote. “Its presence on a network tells you the software is there. It does not tell you the network is running C2.” Hunt.io added: “Our counts have not changed. How we describe them has.” The updated report also no longer singles out Friendhosting as the provider behind the concentration finding. (https://hunt.io/blog/eastern-europe-malicious-infrastructure-report)

UPDATE, June 27, 2026: Hunt.io has issued a formal update to the research underpinning this report. In a note published on the original blog post and signed by the company’s co-founders, Hunt.io acknowledged that the original report “conflated the presence of certain software with malicious impact” and called that “a failure in our editorial review process.” The company apologized to readers and to the entities referenced in the report. Hunt.io has since replaced the term “C2” throughout the report with “threat activity enabling” and softened references to “malicious” activity to “potentially malicious.” The company also added a specific update noting that Friendhosting hosts “many instances of Keitaro which can be abused” and that Friendhosting is working with the data to analyze potential abuse. The co-founders also introduced the framing of “Threat Activity Enablers” as a more precise descriptor for software that has legitimate, unwanted, and malicious use cases depending on context. Security Point Break will continue to update this report as the situation develops.

UPDATE, June 26, 2026: Friendhosting LTD responded to a request for comment from Security Point Break after this story was first published. The company said it was unaware of the Hunt.io report until contacted by this publication, and disputed the methodology behind the findings.

“We have not been provided with the IP addresses, observation timestamps, technical indicators, or any other data that would allow us to verify the conclusion that Friendhosting LTD’s infrastructure included approximately 2,100 servers classified by the authors as C2 infrastructure,” a company representative said.

Friendhosting also questioned how Keitaro deployments were classified as C2 infrastructure in the report, noting that Keitaro is a traffic distribution system rather than a command-and-control framework — a distinction Security Point Break raised in its own coverage.

The company added that the 2,100 figure “appears unusually high,” citing the relatively low volume of abuse reports and law enforcement requests it receives. Friendhosting said it has since contacted Hunt.io directly to request the underlying data, and stated that any servers confirmed to be involved in malicious activity will be suspended immediately.

Hunt.io did not indicate in its report that it contacted the company prior to publication.

Timeline continued

Just weeks ago Europol’s 2026 Internet Organised Crime Threat Assessment warned that cybercriminals are deploying increasingly complex hosting arrangements to evade detection. Also just a month ago, the Dutch authorities dismantled a bulletproof hosting network linked to cyberattacks, disinformation campaigns, and Russian sanctions evasion.

While Hunt.io focused on a single portion of Eastern Europe, its findings have a global significance due to the region’s outsized role in the cybercrime landscape. A cocktail of lax law enforcement, unscrupulous hosting providers, and murky extradition policies has made the region a haven for malware, ransomware, and botnet operators.

The region is less a storefront than a back office — roughly 90% of the observed activity was C2 traffic running between attackers and infected machines, while the phishing pages and exploit sites that victims actually encounter were hosted elsewhere.

Among the most popular names to be connected to the identified C2 servers was Keitaro, a commercial traffic distribution system that threat actors have long abused to route victims toward phishing pages, malware downloads, and exploit kits.

A joint study by Infoblox and Confiant published in March identified roughly 15,500 domains tied to malicious Keitaro deployments over a four-month period, underscoring the platform’s entrenched role in cybercrime distribution infrastructure.

Additionally, the Hunt.io team found that several popular offensive frameworks including Cobalt Strike and Tactical RMM were making heavy use of hosting and management services in the region.

Hunt.io also identified C2 infrastructure linked to Cloud Atlas, the long-running espionage group, operating across multiple Eastern European providers. Kaspersky researchers confirmed in May that Cloud Atlas remained active into early 2026, targeting government and diplomatic entities in Russia and Belarus.

“The dominance of Keitaro across the malware family distribution reflects the region’s established role in traffic distribution and redirect infrastructure, a foundational layer for malvertising, phishing, and exploit kit operations,” the researchers said.

“The simultaneous presence of Cobalt Strike, Sliver, and Tactical RMM indicates that Eastern European hosting serves both commodity criminal operations and more sophisticated post-exploitation campaigns sharing the same infrastructure layer.”

Editor’s note: June 25, 2026. Security Point Break contacted Friendhosting LTD prior to publication; the company did not respond before the original deadline but subsequently provided a detailed statement disputing the Hunt.io methodology. That statement is incorporated above. Hunt.io issued a first correction on June 27, acknowledging that its original language conflated the presence of software with evidence of malicious use. On July 10, Hunt.io issued a second correction after sharing its underlying data with Friendhosting and receiving the results of Friendhosting’s internal investigation. That update explicitly states that Keitaro’s presence on a network does not indicate C2 activity, and removes the specific concentration claim about Friendhosting from the report body. Security Point Break’s reporting prompted Hunt.io’s review, as acknowledged by the researchers. The headline and framing of this article have been updated at each stage to reflect the evolving status of the underlying research.

Editor’s note: This article has been updated multiple times since original publication. Security Point Break contacted Friendhosting LTD prior to publication. The company did not respond before the original publication deadline but subsequently provided a detailed statement disputing the Hunt.io methodology, which was incorporated into this article. Hunt.io has since issued a formal correction to the underlying report, acknowledging that its original language conflated the presence of certain software with evidence of malicious use. Hunt.io’s co-founders cited questions from Friendhosting LTD and Security Point Break as prompting their review. The headline and subheadline of this article have been updated to reflect the changed status of the underlying research. Security Point Break will continue to update this report as additional information becomes available.

Editor’s note: Security Point Break contacted Friendhosting LTD prior to publication of this report. The company did not respond before the original publication deadline. Friendhosting subsequently replied with a detailed statement disputing several findings in the Hunt.io research, which has been incorporated into this article. Hunt.io did not indicate in its published report that it contacted Friendhosting before publication, and had not responded to Security Point Break’s request for comment at the time this update was added. Security Point Break will continue to update this report as additional responses are received.

The headline of this article has been updated to reflect standard attribution practice for third-party research findings. Friendhosting LTD, named in the Hunt.io report, has disputed elements of the methodology underlying the original findings. Hunt.io had not responded to a request for comment at the time of this update. Security Point Break will continue to update this report as additional responses are received.

Total
0
Shares
Previous Article
Close-up of a smart doorbell camera lens mounted on a stainless steel panel, reflecting a residential building — illustrating how home internet-connected devices can be exploited by residential proxy networks

Your Doorbell Is Somebody Else's Cybercrime Tool: Here's How

Next Article
AI coding tools and code editors on a developer monitor illustrate the challenge of tracking AI-generated code through the AppSec audit trail.

AI Code Is Moving Faster Than AppSec’s Audit Trail

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading